Communications Security Establishment
CSE wordmark | |
Edward Drake Building, CSE headquarters | |
| Agency overview | |
|---|---|
| Formed | 1946 |
Preceding agency |
|
| Type | government agency responsible for
|
| Headquarters |
|
| Employees | 3,841 (2024-25)[2] |
| Annual budget | $1.0417 Billion (2024–25)[3] |
Minister responsible | |
Agency executive |
|
Child agencies | |
Key document |
|
| Website | www |
The Communications Security Establishment (CSE; French: Centre de la sécurité des télécommunications, CST) is Canada's national cryptologic intelligence and security agency. It is responsible for foreign signals intelligence, conducting cyber operations, cyber security and information assurance, and providing technical and operational assistance to the military, federal law enforcement, and other security agencies.[4][5]
CSE is a standalone agency under the National Defence portfolio. The current head of CSE, the Chief, is Caroline Xavier, who assumed the office on 31 August 2022. The Chief is accountable to the Minister of National Defence. The National Defence Minister is in turn accountable to the Cabinet and Parliament.[6][7]
History
[edit]CSE originates from Canada's joint military and civilian code-breaking and intelligence efforts during the Second World War.[8]
Examination Unit
[edit]The Examination Unit (XU) was established in June 1941, as a branch of the National Research Council.[9]
The original mandate of the Examination Unit during World War II was to intercept the communications of Vichy France and Nazi Germany. Its mandate later expanded to include interception and decryption of Imperial Japanese communications after Japan entered the war. The unit was estimated to have had 50 staff members at any one time. In total 77 people worked there.[10]
In March 1942, XU moved to Laurier House in Sandy Hill, Ottawa.[11] This location was chosen because they felt it would draw no suspicion from adversaries.[10] In September, the Department of External Affairs established its Special Intelligence Section at XU with the purpose of reviewing decoded SIGINT with other collateral information to produce intelligence summaries.[11]
In September 1945, U.S. President Harry Truman declared it would be vital to carry out such operations in peacetime, and Canadian authorities came to the same conclusion in December later that year.[9][12]
On 13 April 1946, a secret Order in Council allowed for postwar continuation of wartime cryptologic efforts and thus the Communications Branch of the National Research Council of Canada (CBNRC) was founded. This agency would be the predecessor to today's Communications Security Establishment (CSE).[9][11][12]
Communications Branch of the National Research Council
[edit]The Communications Branch of the National Research Council (CBNRC) was the first peace-time cryptologic agency and was kept secret for much of its beginning.[8] The CBNRC was established through a secret Order in Council signed on 13 April 1946, combining the civilian Examination Unit (XU) and the military Joint Discrimination Unit (JDU) and was located at LaSalle Academy.[9]
With Edward Drake as its first director, the agency worked with intercepted foreign electronic communications, collected largely from the Royal Canadian Signal Corps (RCCS) station at Rockcliffe Airport in Ottawa. CSE also worked with Canadian Forces Station Leitrim (CFS Leitrim; formerly 1 Special Wireless Station till 1949, and Ottawa Wireless Station till 1966), Canada's oldest operational signal intelligence (SIGINT) collection station, established by the RCCS in 1941 and located just south of Ottawa. In 1946, the station's complement was 75 personnel (compared to its around 2,000 employees in 2013–2014).[13] This unit successfully decrypted, translated, and analyzed these foreign signals, and turned that raw information into useful intelligence reports during the course of the war.
CBNRC finally began domestic COMSEC efforts on 1 January 1947.[11] During the Cold War, the CBNRC was primarily responsible for providing SIGINT data to the Department of National Defence regarding the military operations of the Soviet Union.[14]
In February 1950, R. S. McLaren was appointed the first CBNRC Senior Liaison Officer (CBSLO) to Washington, D.C. In March 1962: CBNRC installed its first IBM supercomputer, costing CA$372k. In December 1964, CBNRC began collaboration on "Canadian ALVIS" (CID 610), the first and only Canadian cipher machine to be mass-produced based on the British ALVIS (BID 610).[11]
CBNRC and the information it gathered and shared was kept secret for 34 years until 9 January 1974, when CBC Television aired a documentary titled The Fifth Estate: The Espionage Establishment.[15] This was the first time that the organization had ever been mentioned in public.[9] This resulted in an outcry in the House of Common and an admission by the Canadian government that the organization existed.[16]
Communications Security Establishment
[edit]In 1975, the CBNRC was transferred to the Department of National Defence (DND) by an Order in Council, and became the Communications Security Establishment.[8] CSE was now publicly known, and had diversified since the Cold War becoming the primary SIGINT resource in Canada.
In 1988, CSE created the Canadian System Security Centre to establish a Canadian computer security standard among other goals.[17] This led to the publication of the Canadian Trusted Computer Product Evaluation Criteria.[17]
Following the September 11 attacks in 2001, Canada's Anti-terrorism Act (ATA) was ratified, receiving royal assent on 18 December 2001. It amended the National Defence Act to formally acknowledge and mandate the activities of CSE. It also made amendments to the Canadian Security Intelligence Service Act, the Criminal Code, and the Official Secrets Act (later the Security of Information Act).[9]
In early 2008, in line with the Federal Identity Program (FIP) of the Government of Canada, which requires all federal agencies to have the word Canada in their name,[18] CSE adopted the applied title Communications Security Establishment Canada (CSEC; French: Centre de la sécurité des télécommunications Canada, CSTC). Since mid-2014, the organization has used its legal name (Communications Security Establishment) and initials (CSE) on its website and in public statements.
In November 2011, CSE was made an independent agency.[9]
In June 2019, the Communications Security Establishment Act was passed as part of an omnibus national security bill called the National Security Act 2017. Coming into force two months later, in August, the act set out the mandate and powers of CSE.[19] As part of the omnibus bill, oversight of CSE activities was assumed by the newly created National Security and Intelligence Review Agency (NSIRA).[20]
In August 2021, CSE foreign signals intelligence assisted Global Affairs Canada and the Canadian Armed Forces with the operation to airlift Canadians out of Kabul after the Taliban retook Afghanistan.[21]
On October 11, 2023, CSE Chief Caroline Xavier said in an interview with CBC News that CSE offices in various cities may be opened to alleviate staffing shortages.[22]
On June 29, 2026, it was reported that the CSE targeted criminals brokering fentanyl ingredients through cyberhacks.[23]
Activities
[edit]Unique within Canada's security and intelligence community, the Communications Security Establishment employs code-makers and code-breakers (cryptanalysis) to provide the Government of Canada with foreign intelligence and information technology security (IT Security) services. CSE also provides technical and operational assistance to the military, and federal law enforcement and security agencies including the Royal Canadian Mounted Police, Canada Border Services Agency and the Canadian Air Transport Security Authority.
Foreign Intelligence
[edit]As part of the Five Eyes, CSE works with its closest foreign intelligence allies, the US, UK, Australia and New Zealand to share the collection burden and the resulting intelligence yield. Canada is a substantial beneficiary and participant of the collaborative effort within the partnership to collect and report on foreign communications.[14]
During the Cold War, CSE's primary client for signals intelligence was National Defence, and its focus was the military operations of the then Soviet Union. Since the end of the Cold War, Government of Canada requirements have evolved to include a wide variety of political, defence, and security issues of interest to a much broader range of client departments.
While these continue to be key intelligence priorities for Government of Canada decision-makers, increased focus on protecting the safety of Canadians has prompted greater interest in intelligence on transnational issues, including terrorism.
Cyber Operations
[edit]CSE's mandate authorizes it to conduct foreign cyber operations that disrupt the capabilities of adversaries to help protect Canada and Canadians. Cyber operations conducted by CSE is broken down to defensive and active cyber operations, and must relate to international affairs, defence or security.[24]
Defensive cyber operations authorizes CSE to defend Canadian systems against foreign cyber attacks. For instance, a cyber actor trying to steal information from a government network could be thwarted by CSE by disabling the cyber actor's server. In addition to government systems, the Minister of National Defence can designate systems of importance such as: energy grids, telecom networks, healthcare databases, banking systems, elections infrastructure in order for CSE to be authorized to defend them.[24]
Active cyber operations authorizes CSE to take pre-emptive action against threats to Canada such as: terrorist groups, cyber criminals, transnational criminals,[25] hostile intelligence agencies, state-sponsored hackers. For instance, CSE can disrupt an adversary's means of communication as part of a military operation.[24]
Assistance to Federal Partners
[edit]CSE's mandate authorizes it to provide technical and operational assistance to federal partners including the military, law enforcement and other intelligence agencies. The type of assistance itself can include: the collection and processing of communications, technical solutions, linguistic support, and conducting operations.[26]
While assisting, CSE operates under the requesting agency's legal authority and restrictions. This means that CSE can, in fact, target Canadians and individuals in Canada while operating under its assistance mandate, as long as the requesting agency has the legal authority to, such as a court-issued warrant.[26]
Canadian Centre for Cyber Security
[edit]| Centre Canadien pour la Cyber Sécurité | |
1625 Vanier Parkway, Cyber Centre | |
| Agency overview | |
|---|---|
Agency executive |
|
Parent department | Communications Security Establishment |
| Website | cyber.gc.ca |
The Canadian Centre for Cyber Security (CCCS or Cyber Centre; French: Centre Canadien pour la Cyber Sécurité) is the Government of Canada authority responsible for monitoring threats, protecting national critical infrastructure against cyber incidents, and coordinating the national response to any incidents related to cyber security. Although its main focus is protecting federal government systems, other systems can be designated as systems of importance by the Minister of National Defence under special circumstances.
As a unit under the Communications Security Establishment (CSE), the agency is Canada's computer emergency response team (CSIRT) and the Canadian government's computer Incident response team (CIRT).[9]
Officially created on 1 October 2018, CCCS consolidated the existing operational cyber-security units of several federal government organizations, including Public Safety Canada's Canadian Cyber Incident Response Centre, Shared Services Canada's Security Operations Centre, and CSE's Information Technology Security branch.[28][29]
History
[edit]Formerly known as communications security (COMSEC), CSE's Information Technology Security branch grew out of a need to protect sensitive information transmitted by various agencies of the government, especially the Department of Foreign Affairs and International Trade (DFAIT), Canada Border Services Agency (CBSA), DND, and the Royal Canadian Mounted Police (RCMP).[30]
The Cyber Centre was developed in response to CSE's consultations with Canadians in 2016 which identified various issues pertaining to cyber security in relation to the federal government, including accountability, departmental coordination, and leadership. In February 2018, the federal budget allocated funds for CSE, in collaboration with Public Safety Canada and Shared Services Canada, to launch the Cyber Centre.[31]
Officially created on 1 October 2018, CCCS consolidated the existing operational cyber-security units of several federal government organizations, including the Canadian Cyber Incident Response Centre of Public Safety Canada; the Security Operations Centre of Shared Services Canada; and the Information Technology Security branch of CSE.[28][29]
Prior to opening, in June 2018, Minister Ralph Goodale appointed Scott Jones the head of the new Centre.[32][30]
In 2024-25, CSE reportedly used the Cyber Centre's automated defence systems to defend against a total of 2.3 trillion malicious actions. This averages to around 6.3 billion a day.[33]
Vulnerability Research Centre
[edit]| Centre de Recherche sur les Vulnérabilités | |
| Research division overview | |
|---|---|
| Type | research division |
Parent department | Communications Security Establishment |
| Website | www |
The Vulnerability Research Centre (VRC; French: Centre de Recherche sur les Vulnérabilités) is part of CSE's Research Directorate. Its focus is to advance Canada's interests through world-class strategic vulnerability research.[34] To do so, the VRC:
- conducts security reviews against systems of importance to the Government of Canada
- researches computer security vulnerabilities through source code auditing, software reverse engineering and dynamic analysis
- provides advice and guidance on vulnerability prevention and mitigation
- researches and develops novel vulnerability research techniques and tradecraft
- collaborates with other Government of Canada departments, international partners and other CSE divisions to promote the exchange of expertise
- performs recruitment, training and mentorship to help develop the next generation of vulnerability research practitioners within Canada[34]
The VRC augments its capabilities by partnering with universities, such as the following publicly revealed so far: the University of Toronto, Ontario Tech University, and Concordia University.[25]
Tutte Institute for Mathematics and Computing
[edit]| Institute overview | |
|---|---|
| Formed | 2011[35] |
| Type | research institute |
| Jurisdiction | Canada |
| Headquarters |
|
Institute executive |
|
Parent department | Communications Security Establishment |
| Website | www |
The Tutte Institute for Mathematics and Computing (TIMC) is a research institute programme of the Government of Canada responsible for conducting both classified and unclassified research in the areas of cryptology and knowledge discovery to support the Canadian Cryptologic Program and its Five-Eyes international partners.[37][38]
Though officially founded in 2009, TIMC officially opened and formally named in September 2011.[38][35] Named after cryptanalyst and mathematician William T. Tutte, TIMC is based within CSE's Edward Drake Building in Ottawa.[38]
Sponsored and funded by the Communications Security Establishment, the institute is partnered with Institute for Defence Analysis: CCR Princeton, CCR La Jolla, CCS Bowie; the Heilbronn Institute for Mathematical Research, Carleton University, and the University of Calgary and is working to create partnerships with other research institutes, government agencies and universities.[39] Led by Dr. Drew Vandeth, CSE researchers proposed and established the institute. The institute's first director was Dr. Hugh Williams with Dr. Drew Vandeth as the first Deputy Director.
Unclassified Academic & Open-Source Contributions
[edit]Researchers Leland McInnes and John Healy at the Tutte Institute developed a technique called Uniform Manifold Approximation and Projection (UMAP), originally designed to analyze malware. The algorithm and software of UMAP has since been released by TIMC to the open-source community. UMAP has become an instrumental tool used by scientist to analyze large datasets such as when developing AI, or bioinformatics research with the case of the COVID-19[40] pandemic.
As of 2024-25, TIMC's open-source contributions averaged over 2.5 million downloads per month[25] and have been adapted to NVIDIA's RAPIDS and HypernetX.[37]