Ron Lloyd BETWEEN INTENT AND OUTCOMES

Home / Published Work / Nine Actionable Decisions for the Prime Minister

POLICY PAPERCGAI, TRIPLE HELIXAUGUST 2025

Nine Actionable Decisions for the Prime Minister to Best Posture Defence

Nine decisions, none requiring legislation, to align the policy foundation with the government's stated intent

Defence & National Security Governance & Decision-Making Digital Government & Procurement

SYNOPSIS

In the last twenty years there has been a war, three much heralded defence policy updates and a pandemic, and Canadian Defence continues to fall behind its allies, partners and adversaries. This paper argues the reason is a flawed “small p” policy foundation, and sets out nine decisions that would let the government's stated objectives actually be delivered. They are described as actionable because none of them requires legislation, and because once taken they immediately begin to mitigate real world risks: a lack of interoperability with allies, poor posturing of the Canadian Armed Forces to prevail in conflict, and the inability to provide modern digital services to the CAF or to Canadians.

THE ARGUMENT

A capital P Policy articulates a government's intent, such as meeting NATO's five per cent spending target. Small p policies are the hundreds of non-legislative instruments, the policies, directives, guidelines, IT security guidance and tools, within which departments must deliver their mandates to realize that intent. The paper's contention is that the announcements of 2025 set out the government's capital P Policy intent, and that the small p foundation beneath them had not changed.

It also reframes the risk conversation. There are risks in moving away from the status quo, but they are policy, process, transition and implementation risks, not real world ones. The real world risks are the ones being carried today.

“In today's world, the nations that operate at the speed of trust are more likely to prevail in crisis or conflict. Individuals operate at the speed of trust. Process does not.”

From the paper, page 6

THE NINE DECISIONS

  1. 1

    Wait on organizational change until the policy foundation has been amended. Building new structures on a flawed foundation is not what right looks like, and form should follow function. Standing up a defence procurement agency before the small p policies that constrain defence procurement have been addressed carries a high probability that the intended outcomes still will not be realized, since many of those policies do not sit within the authorities of the departments likely to be implicated.

  2. 2

    Adopt a new security classification framework of Official (Official Sensitive), Secret and Top Secret. The paper argues that Canada's framework is unique among its allies in treating the compromise of personal information as equivalent to the compromise of information in the national interest. It calls changing it the necessary first step to reset the risk management culture of the public service, and projects that it would deliver a reorientation to NATO, savings in the hundreds of millions if not billions, better interoperability, greater transparency of government data and an improved national cyber security posture.

  3. 3

    Amend the thousands of affected small p policies. Hundreds horizontally across central agencies and thousands vertically across departments, to reflect a focus on results rather than process. Two instruments are singled out: the 2007 Harmonized Threat and Risk Assessment Methodology, which should be rescinded immediately, and ITSG-33, which the Cyber Centre should be in a position to rescind once it has consolidated the digital security instruments into a single document that can be amended annually.

  4. 4

    Empower Defence digitally by removing its dependency on SSC as directed in Order in Council 2015-1071. It is unrealistic for the Deputy Minister and the Chief of the Defence Staff to be responsible for mitigating national defence and security risk when they do not control the digital levers required to be successful. The Order made sense a decade ago; in a world of cloud, Zero Trust, data centric security, artificial intelligence and quantum it undermines Defence's ability to exploit those technologies at pace and scale.

  5. 5

    Map the “as is” defence procurement process end to end, then develop options to cut approval timelines by 50 and 75 per cent. The mapping runs from the departmental level to the central agencies, and implicates Treasury Board's own internal approvals, the Project Complexity and Risk Assessment tool that codifies almost all digital procurements as evolutionary or transformational, the requirement for policy coverage through a memorandum to cabinet, PSPC, SSC and Defence's own internal directives. The options go to the Prime Minister, because the overlapping authorities shared between ministers produce impasses that staff cannot resolve.

  6. 6

    Then make the organizational changes required. With a comprehensive understanding of the modernized policy foundation in hand. Canada has been talking about fixing defence and government procurement for decades; waiting roughly a year to put a solid foundation in place first would be time exceptionally well spent.

  7. 7

    Decentralize ADM HR Civ and ADM IE and re-empower the commanders. Written from the experience of having been the departmental lead for the Deficit Reduction Action Plan and then having had to live with its consequences as Commander of the Royal Canadian Navy. The economies of centralization that were envisioned were not realized. Those authorities may have made sense in a time of austerity; they will not serve Defence well while the enterprise is growing.

  8. 8

    Build an integrated implementation plan and report progress to the Prime Minister monthly. You get what you inspect, not what you expect. Implementing even one of these decisions in an environment of overlapping authorities is complex, and every executive involved has a demanding day job in which the urgent tends to displace the important. A governance body empowered to clear obstacles as they emerge is what keeps the plan aligned with the government's intent rather than drifting back to the status quo.

  9. 9

    Accept the transition risk. There are two sides to the risk management coin: identification and mitigation on one, innovation and opportunity on the other. The current small p paradigm will contextualize the government's bet on innovation as too risky. Short term successes will come from exceptional means used to bypass process or over-pressurize the system, and will be false positives of the kind heralded during Afghanistan and the pandemic, not a sustainable basis for the mandate.

WHERE THIS FITS

Added September 2026

The four earlier papers diagnosed. This one was written to be acted on. It gave the mechanism a name that a decision maker could use, the distinction between capital P Policy and small p policy, and then translated four papers of analysis into a sequence: fix the foundation, then restructure, in that order. It is also the paper that put sequencing itself at the centre of the argument, which is the thread the later work on institutional architecture picks up.

SINCE PUBLICATION

What has changed, and where the argument went

UPDATE · SEPTEMBER 2026

WHAT HAS CHANGED

  • On 2 October 2025, two months after this paper was published, the government launched the Defence Investment Agency, a special operating agency within Public Services and Procurement Canada, to consolidate and accelerate defence procurement. Decision 1 had recommended waiting on organizational change until the policy foundation and its authorities, responsibilities and accountabilities had been amended, and named a defence procurement agency specifically.
  • On 1 April 2026 the Cyber Centre's ITSP.10.033-01 superseded the ITSG-33 Protected B profile, one of the digital security instruments Decision 3 addressed. It was issued in a new series, Cyber security and privacy risk management: A lifecycle approach.

Sources: Prime Minister's Office, 2 October 2025; Public Services and Procurement Canada, Defence Investment Agency backgrounder; Canadian Centre for Cyber Security, ITSP.10.033-01, effective 1 April 2026.

HOW THE THINKING HAS DEVELOPED

The earlier papers examined individual policies, programs and risk mechanisms. This paper brought those findings together as a sequencing problem: changing organizational structures before changing the policy foundation risks reproducing the same outcomes in a new organization. Later work developed that observation into the concept of institutional architecture, the policies, authorities, risk frameworks and governance mechanisms between strategic intent and delivery.

The paper also placed implementation at the centre of reform. Its call for an integrated plan, empowered governance, measurement and adjustment anticipated the later iC2 argument that institutional execution is itself a capability that must be designed, exercised and measured.

ABOUT THE AUTHOR

Vice-Admiral (Ret'd) Ron Lloyd was the 35th Commander of the Royal Canadian Navy and is a Fellow of the Canadian Global Affairs Institute. Transparency →