Canada is entering a new phase of its AI journey. With the launch of Canada’s National Artificial Intelligence Strategy: AI for All, the federal government’s renewed focus on adoption, trust, talent and infrastructure shows how central AI has become to Canada’s economy. At the same time, cyber threats are getting faster, more sophisticated and increasingly enhanced by AI.
For Canadian organizations, the challenge is no longer preparing for the future – it’s adapting to a reality that is already here. The leaders who succeed will pair advanced technology with trusted partnerships and strong security foundations. Done well, they can capture the benefits of AI while building resilience against emerging threats.
That resilience will depend not only on technology, but on a broader ecosystem that brings together industry, government and Canada’s growing community of cybersecurity innovators. Across the country, organizations are increasingly turning to AI-powered tools, threat intelligence and homegrown expertise to strengthen defenses while accelerating innovation.
John O’Brien, National Security Officer at Microsoft Canada, shares how AI is reshaping the cybersecurity landscape, the critical priorities organizations should focus on today, and how collaboration across industry, government and customers can strengthen cyber resilience for the future
How should organizations think about the relationship between AI and cybersecurity?
John O’Brien: AI is both an opportunity and a risk. That means innovation and security must move together. Security should not be seen as an anchor, but as the plow that clears the path, to enable adoption of AI at scale with confidence. As AI adoption continues to grow, organizations need the infrastructure, skills and security foundations to use these technologies effectively and responsibly. The optimal path is clear guardrails, strong identity, data protections and operational safety—baked in from day one—so AI can be used safely and productively. The organizations that will be best positioned to realize the benefits of AI are those that invest not only in technology, but also in the capabilities needed to support long-term adoption and resilience.
How is AI changing the threat landscape facing Canadian organizations?
John O’Brien: The tactics look familiar; the speed and sophistication do not. In one of our recent Threat Intelligence podcasts, we examine how threat actors are leveraging AI to make existing attacks more effective, from reconnaissance and social engineering to influence operations and other cyber-enabled activities. We’re also seeing continued growth in cybercrime-as-a-service offerings and increased targeting of Canadian assets by nation state actors, making the threat landscape more complex. What’s changing most is the pace – as I often tell customers, our security roadmaps need to align with the adversaries’ plans, as they set the pace. The good news is that AI can help defenders too, if we make the capabilities available. Organizations can and should empower their security teams with access to AI-powered security tools, threat intelligence and stronger identity protections to identify threats earlier, respond faster and build resilience as the threat landscape continues to evolve.
As Canada continues to invest in AI, critical infrastructure and digital innovation, why is cybersecurity foundational to national resilience, economic growth and public trust?
John O’Brien: Security is a foundation for growth and public trust. It keeps essential systems across energy, health, finance, and transportation industries online when it matters most. Canada needs domestic expertise and threat intelligence that reflects local realities. Organizations must be ready to operate through disruption with tested resilience plans, strong recovery capabilities and trusted partners in place before an incident occurs. But we can’t expect commercial entities to fend off attacks alone. This is where national capability, public–private cooperation and an ecosystem mindset matter. My goal as Microsoft Canada’s National Security Officer is to ensure security experts in Canada have an opportunity to work together with Microsoft, combining our global intelligence and their expertise to help organizations build resilience and better navigate an evolving threat landscape.
Microsoft recently announced commitments in Canada’s cybersecurity ecosystem, including the Ottawa Threat Intelligence Hub. Why is that important?
John O’Brien: Last November, we announced a 5-point plan to protect Canada’s digital sovereignty, with cybersecurity as the key pillar. The Ottawa Threat Intelligence Hub, a part our global Threat Intelligence organization, was created to contribute to the protection of Canada’s cybersecurity. Its objective is to track and interdict nation state and organized crime actors, working closely with the Government of Canada and law enforcement partners. It’s about acknowledging and harnessing the outstanding security talent across the country and plugging those experts into our global security organization in support of Canada’s national cyber resilience. We are dedicated to making this cybersecurity protection even stronger going forward, contributing to a durable ecosystem that serves Canada for the long term.
Many organizations continue to struggle with identity-based attacks. Why does this remain such a persistent challenge?
John O’Brien: Most security compromises still start with identity. As threat actors become more sophisticated, traditional sign-in methods are no longer enough on their own, requiring organizations to adopt and enforce phish-resistant multi-factor authentication approaches like passkeys. People are navigating an increasingly complex digital environment, and even the most security-conscious users can be tricked by convincing phishing or social engineering attempts. Our job is to design systems that keep people safe, even when they click a malicious link or perform risky actions unknowingly. That means reducing unnecessary prompts, setting strong defaults and using conditional access to minimize opportunities for risk. Cut down the places where one slip leads to a breach. The goal isn’t to change human behaviour; it’s to build systems that remove opportunities for error and make the secure choice the easy choice.
As cyber threats become more sophisticated and AI accelerates the pace of attacks, what changes do organizations need to make to better protect themselves?
John O’Brien: The most effective security strategy is to reduce opportunities for attackers in the first place. The goal is to stop threats early by making systems more resilient and harder to compromise. That means limiting unnecessary access to sensitive systems, putting extra protections around critical assets and making sure high-risk actions have the right safeguards in place. As organizations increasingly deploy AI tools and agents across the business, those same principles need to extend to these new agent identities and workflows, with clear visibility into what systems they can access and what actions they can take. We need to build processes where the safe path is the easy path. And most importantly, adopt a safety culture: post-incident reviews should aim to identify root causes and fix systems, not to place blame on individuals. The goal isn’t to make people perfect. The goal is to build systems that are harder to misuse. Empower your workforce with the right tools and knowledge to drive iterative change. Organizations also need to recognize how quickly the threat landscape is evolving. Our latest Cyber Pulse report offers practical insights into the emerging risks as AI agents become embedded in every day business operations. Cyber threats are rapidly evolving from technical problems affecting business to events impacting all aspects of our society. That reality makes resilience, preparedness, and strong security fundamentals more important than ever. Multi-year roadmaps that delay proven controls are no longer realistic – organizations should focus on implementing proven protections now, then continuously adapt as threats evolve. And for the many smaller and mid-sized organizations that call Canada home with limited resources, that doesn’t mean trying to do everything at once. Focus on the fundamentals, lean on trusted partners where needed, and keep your plan manageable. Prioritize the next three fixes, not the next thirty. Progress beats perfection.
What gives you optimism about Canada’s cybersecurity future?
John O’Brien: The urgency is real across all sectors. Boards and leaders are asking the right questions, and collaboration is growing across industry, government, and academia. Canada’s security talent is strong and recent geopolitical events are driving necessary conversations. Critical infrastructure owners are planning for resilience in concrete terms. We’re seeing real momentum around cybersecurity, AI and resilience at the same time. This moment is unlocking momentum – and that is what we need.