Canada’s cyber defence dilemma: Should private companies be allowed to go on the offensive?


Canada has long promoted a collaborative approach to cybersecurity, bringing together government agencies, law enforcement, industry and academia to defend against increasingly sophisticated cyber threats. Recent developments south of the border, however, could raise important questions for Canadian policymakers and businesses alike.

In August 2026, the White House released a National Security Presidential Memorandum (NSPM) establishing a framework under which vetted private-sector organisations can participate in government-supervised offensive cyber operations against foreign cybercriminal networks. The policy represents one of the most significant shifts in American cybersecurity strategy in decades, moving beyond defence and threat intelligence towards active disruption of criminal actors. The White House memorandum states that the United States intends to leverage private-sector capabilities to combat transnational cyber-enabled crime.

While the policy is American, the implications extend far beyond the United States. Canada shares deep economic, technological and intelligence relationships with its southern neighbour, and Canadian organisations face many of the same ransomware groups, fraud operations and nation-state linked threat actors. The question is whether expanding the private sector’s role in offensive cyber operations could strengthen digital security or create a host of new legal, operational and geopolitical risks.

Canada’s evolving cyber landscape

Canada has adopted a different path. The Government of Canada’s National Cyber Security Strategy places emphasis on partnership, resilience and the disruption of cyber threat actors through coordinated action involving government, industry, academia and law enforcement.  According to Public Safety Canada, the strategy is built around three pillars: protecting Canadians and businesses from cyber threats, making Canada a global cybersecurity leader, and detecting and disrupting cyber threat actors.

A notable feature of the strategy is the creation of the Canadian Cyber Defence Collective, a public-private initiative designed to strengthen cooperation on national cyber challenges and cyber operations. The government has also invested in initiatives such as a Cyber Attribution Data Centre to better understand and identify cybercriminal activities.  Yet even with these proactive measures, Canada’s cybersecurity framework remains fundamentally defensive. Unlike the new American NSPM, there is currently no Canadian policy permitting private firms to undertake offensive cyber operations against adversaries.

The criminal discovery trap

One issue attracting increasing attention among cybersecurity legal experts concerns what happens when offensive cyber activity successfully contributes to a criminal prosecution.

Rajeev Raghavan, a partner in Crowell & Moring’s Privacy & Cybersecurity Group and former Special Counsel to the Director of the Federal Bureau of Investigation (FBI), has highlighted concerns regarding criminal discovery obligations that may follow government-sanctioned private cyber operations. The challenge is potentially significant. A company participating in offensive cyber activities may utilise proprietary software, specialised forensic tools, unique intelligence-gathering techniques or previously undisclosed software vulnerabilities. If criminal prosecutions arise from those activities, defence lawyers may seek access to relevant evidence through discovery processes. The resulting legal obligations could require disclosure of proprietary technologies, internal security methodologies and sensitive operational details.

For Canadian cybersecurity companies, many of which operate in highly specialised global markets, the potential exposure of intellectual property could present an unacceptable commercial risk. In addition, personnel involved in operations may find themselves subject to detailed scrutiny and cross-examination regarding their methods and decision-making. In effect, the very capabilities that make private firms attractive operational partners may become liabilities in a courtroom.

A second concern is retaliation. Government agencies and intelligence services benefit from extensive institutional protections, legal authorities and diplomatic backing. Private companies generally do not. Supporters of offensive cyber activity argue that disrupting ransomware groups, phishing syndicates and criminal infrastructure can significantly reduce cybercrime. Critics counter that cyber adversaries rarely remain passive once targeted.

Cybercriminal organisations have repeatedly demonstrated their ability to adapt quickly. Retaliation can take many forms, including distributed denial-of-service (DDoS) attacks, theft of sensitive information, extortion campaigns, reputational attacks and targeting of employees or executives. For Canadian firms, many of which are considerably smaller than multinational technology companies, the implications could be severe. Participation in offensive cyber operations could transform a company from a victim of cybercrime into a deliberate target.

Such retaliation may not remain confined to cyberspace. Organisations could face legal challenges in foreign jurisdictions, attacks against customers and business partners, and persistent campaigns designed to undermine confidence in their services. The central question is whether private companies are equipped to bear risks that have traditionally been absorbed by governments.

Artificial intelligence changes the equation

The rise of artificial intelligence may further complicate the debate. AI already plays a central role in cybersecurity, helping analysts identify threats, detect anomalies and automate responses. The next stage of development is likely to involve increasingly autonomous cyber tools capable of acting with minimal human intervention.

The White House NSPM has been interpreted by legal and cybersecurity analysts as encouraging greater innovation and automation in cyber operations. A recent analysis by Crowell & Moring notes that the framework potentially opens the door to increased use of automated offensive capabilities. See the firm’s assessment, “License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations.”

While automation can improve efficiency, it may also create new categories of risk. Agentic AI systems can operate far more rapidly than human decision-makers. An error in an offensive cyber context could result in actions extending beyond approved targets or objectives before operators have sufficient opportunity to intervene.

Canada’s cybersecurity policy already recognises the growing significance of AI. The government’s strategy specifically highlights the need to build expertise around artificial intelligence, cyber attribution and emerging digital threats.  However, legal and regulatory systems remain largely designed around human actions and accountability. As AI becomes more deeply embedded in cybersecurity operations, policymakers will need to address difficult questions concerning responsibility, oversight and liability.

For Canada, the debate is, perhaps, ultimately about more than technical capability. Canada has traditionally favoured a rules-based approach to cybersecurity, focusing on intelligence sharing, international cooperation, public-private partnerships and law enforcement action. The country’s National Cyber Security Strategy continues to reflect these principles.

Attribution remains one of the most difficult challenges in cybersecurity. Determining the true source of an attack can be extremely complex, particularly when attackers route operations through multiple countries and compromised systems. A private-sector offensive response based on inaccurate attribution could create significant legal, diplomatic or financial consequences. There are also governance considerations. Government cyber operations are typically subject to oversight structures, legal review and accountability mechanisms. Translating similar safeguards into private-sector operations would require careful legislative design and substantial regulatory oversight.

At the same time, proponents argue that private firms often possess highly advanced technical capabilities and can sometimes react more quickly than government agencies. In a world where cybercriminal groups move rapidly and exploit jurisdictional boundaries, leveraging private-sector expertise may appear increasingly attractive.



Canada’s cyber defence dilemma: Should private companies be allowed to go on the offensive?

#Canadas #cyber #defence #dilemma #private #companies #allowed #offensive

Leave a Reply

Your email address will not be published. Required fields are marked *