You Are Selling to a CISO. Canada Mandates a Chief Security Officer.
The title that appears once
The Government of Canada publishes its employee directory as open data: 194,106 records spread across 141 root organizations (Shared Services Canada, 2026). Every figure below was re-derived on 1 September 2026 from the JSON distribution of the file published 23 August.
Naming the distribution matters. A dataset published in more than one format is really several files, each rebuilt on its own schedule, and a download that succeeds tells you nothing about what arrived: an HTTP 200, a valid archive and the correct schema are all perfectly compatible with a payload that is missing what you came for. The only way to tell a real answer from an empty one is to confirm the file contains something you already know should be in it. That is the same habit this article is about, one layer further down. An empty answer looks exactly like a true one until you have shown the source worked.
Not every record carries a title. 184,432 have one in English and 184,111 have one in French, so 9,674 records — 5.0% — carry no job title at all. No record carries a French title without an English one.
One record carries the title Chief Information Security Officer. It sits at the Treasury Board of Canada Secretariat, and the full title is Chief Information Security Officer of the GC — the Government of Canada's, not a department's (Shared Services Canada, 2026).
That is not, as I first assumed, evidence that the federal security buyer is unreachable. It is evidence that the category is addressing a job that Canada does not organise the way the category imagines.
The spine. Canada's Policy on Government Security makes the deputy head accountable, and requires them to designate "a chief security officer responsible to the deputy head or to the departmental executive committee to provide leadership, coordination and oversight for departmental security management activities" (Treasury Board of Canada Secretariat, 2019, s. 4.1.1). The instrument names a role, in lowercase, not a job title anyone must publish. Search for the title anyway and you find 31 records across 26 organizations, of which 11 publish a substantive holder — the rest publish a deputy or an acting appointee. The CISO title appears once. On the evidence of the titles themselves, the holder is a generalist: executive directors of facilities management, directors general of human resources, a vice-president of human resources, a senior director of plant operations. Your product is being evaluated against guard contracts and screening programmes by someone whose day job is not information security Sagentix GTM Methodology, 2026.
The control, before the conclusion
A count of one is the most dangerous result in this kind of analysis, because a broken title search and a genuinely absent title produce identical output. So before that number could be published, the search had to be shown to work.
The same instrument, unchanged, was run against other executive titles of the same shape in the same field. Each row matches the English title or an enumerated official French equivalent — dirigeant principal des finances, dirigeant principal de l'information, and so on:
| Title searched (both official languages) | Records | Organizations |
|---|---|---|
| Chief Financial Officer | 100 | 63 |
| Chief Information Officer | 51 | 39 |
| Chief Audit Executive | 25 | 24 |
| Chief Data Officer | 14 | 14 |
| Chief Privacy Officer | 3 | 3 |
| Chief Information Security Officer | 1 | 1 |
(Shared Services Canada, 2026)
The probe returns 100 CFOs and 51 CIOs from the identical code path. The single CISO is therefore a property of the directory, not of my search. I also pushed the CISO row harder than any other, because everything here rests on it: CISO as a bare acronym returns nothing, the French RSSI returns nothing, cyber security officer returns nothing, and every French construction of the form dirigeant / chef / responsable … de la sécurité de l'information returns the same single organization. The count of one survives each of them.
One row taught me something about the method. My first Chief Audit Executive pattern paired the English phrase with the French dirigeant principal de la vérification, and returned 19. It was missing dirigeant principal de l'audit — the form Canadian Heritage, the Courts Administration Service, Fisheries and Oceans Canada and Global Affairs Canada actually publish. A pattern can be reproducible and still be wrong, which is why the rubric belongs in the article and not in my notebook.
A second control, and the one that corrected me. Searching the exact phrase Chief Information Security Officer returns one organization. Allow for the obvious synonyms and it returns four: Canada Mortgage and Housing Corporation publishes Head, Information Security, Canadian Heritage publishes Head, Physical and Information Security, and National Defence publishes Director Information Security (Shared Services Canada, 2026). All carry French equivalents and all are findable in English, so this is not a bilingual-search problem, as I first wrote it. No record in the directory has a French title without an English one, which kills the theory outright rather than by example. It is a vocabulary problem: Chief, Head and Director name the same job, and a search for one finds a quarter of what a search for all three would.
The role the policy actually names
This is the correction that reframes everything, and I make it because my own first search was for the wrong term.
The 2009 Policy on Government Security told deputy heads to appoint "a departmental security officer (DSO) functionally responsible to the deputy head or to the departmental executive committee" (Treasury Board of Canada Secretariat, 2009, s. 6.1.2). That phrase appears exactly once in the whole directory, at Fisheries and Oceans Canada, and its official French form agent de sécurité du ministère sits on the same single record. Searching for it tells you nothing except that the term is obsolete.
The policy in force took effect 1 July 2019, replacing the 2009 version, and was amended effective 6 January 2025 (Treasury Board of Canada Secretariat, 2019). Its requirement, quoted above, changed the title but kept the reporting line intact.
Now the part that took me two passes to get right. The policy requires a designation, not a published title. Section 4.1.1 says "a chief security officer" in lowercase; it creates a role and assigns it to whoever the deputy head names. A department that designates its ADM Corporate Services as CSO is fully compliant and may publish nothing of the sort in the directory. So the directory measures a publication rate, not a designation rate, and no title search — mine included — can tell you which departments have complied. It can only tell you which ones say so out loud.
Said out loud, here is the shape of it. The exact phrase returns 31 records across 26 organizations, two of them duplicate rows for the same Transport Canada position. Seventeen of the 31 are Deputy or Acting variants and one is an Executive Advisor to the Chief Security Officer, which leaves 11 organizations publishing a substantive designated holder: Atomic Energy of Canada Limited, the Canada Border Services Agency, the Canada School of Public Service, the Courts Administration Service, Library and Archives Canada, the National Capital Commission, the Office of the Chief Electoral Officer, the Office of the Secretary to the Governor General, the Royal Canadian Mint, the Supreme Court of Canada and Transport Canada (Shared Services Canada, 2026).
That gap will cost you. Global Affairs Canada, the CRTC, Canadian Heritage, Fisheries and Oceans Canada, Health Canada and Shared Services Canada all appear in a search for the title, and every one of them publishes only a deputy. If you build a contact list from the string, you are writing to fifteen deputies and calling it an executive list.
Two further cautions on that set. The policy applies "to departments as defined in section 2 and entities included in Schedules IV and V of the Financial Administration Act" (Treasury Board of Canada Secretariat, 2019, s. 6.1), and the directory's 141 root organizations include Crown corporations that are none of those. Three of the eleven — Atomic Energy of Canada Limited, the National Capital Commission and the Royal Canadian Mint — are Crown corporations, so their chief security officer exists for their own reasons rather than because this policy required it. And the holders are almost never security specialists: the titles read Exec Dir, Facilities Management & Chief Security Officer (CSO); Director General, Human Resources and Chief Security Officer; Vice-President & Chief Security Officer, Human Resources and Workplace Management; Senior Director, Plant Operations & Chief Security Officer. The designation sits on top of a facilities, HR or operations job.
The buyer was published the whole time. I was searching for a title from a policy that was replaced seven years ago — which is precisely the currency failure this series keeps warning about, arriving in my own draft.
The role I missed the first time
There is a second designation, and leaving it out would repeat the mistake this article is about.
The Directive on Service and Digital assigns cyber security to "the designated official for cyber security, in collaboration with the departmental CIO and Chief Security Officer as appropriate" (Treasury Board of Canada Secretariat, 2019b, s. 4.5). The supporting guideline is blunter about who that is: "the deputy head could designate the CSO as the DOCS. However, in larger departments and agencies, it may be preferred to have another senior official designated as the DOCS" (Treasury Board of Canada Secretariat, 2019c, s. 1.1).
Read that against a target list. In a small organization your buyer probably is the CSO. In a large department, Canada expects the cyber mandate to sit with a different named executive, and that title is no more required to be published than the CSO's. Exactly one record spells it out: Global Affairs Canada publishes Executive Director - Cyber Security / Designated Official for Cyber Security (DOCS) — the same department that publishes a deputy chief security officer and no substantive one (Shared Services Canada, 2026). Two designations, one accountable deputy head, one published example of each.
That is the real finding, and it is worse for the standard playbook than a missing CISO. You are not looking for a title that does not exist. You are looking for two designations that exist and are almost never published, held by people whose directory titles describe their day jobs instead.
Searching 194,106 federal employee records for the role
- All directory records194,106both official languages
- Security-titled1,834
- Chief Security Officer31across 26 organizations
- Substantive holder11organizations
Why four in five of the directory's security titles look like noise
Search the directory for job titles carrying the standalone word security — excluding the income-support senses, Social Security and Old Age Security, which are benefit programmes rather than the security function — and you find 1,834 records (Shared Services Canada, 2026).
Sorting them needs a rubric, and an unpublished rubric is an opinion. A title counts as cyber if it carries cyber, IT, informatics, information technology, information security, infosec, network, systems, digital, data centre, COMSEC or cryptographic; as physical if it carries physical, personnel, screening, clearance, maritime, marine, aviation, air, transport, rail, port, guard, commissionaire, facilities, building, premises, site, protective, emergency, fire or occupational; as ambiguous if both; and as unqualified if neither. Move a keyword between those lists and the middle two rows move with it, which is the honest caveat on the table:
| Category | Records | Share |
|---|---|---|
| Cyber / IT / information security | 357 | 19.5% |
| Physical, personnel, screening, maritime, aviation or transport security | 604 | 32.9% |
| Unqualified security (role type not determinable from the title) | 870 | 47.4% |
| Ambiguous (matches both) | 3 | 0.2% |
| Total | 1,834 | 100% |
(Shared Services Canada, 2026)
A vendor who filters on the keyword and then keeps only what reads as cyber keeps 357 records and discards 1,477 — 80.5% of the security-titled directory — as noise. That reading is wrong, and expensively so. Under an all-hazards CSO mandate, the physical, personnel and screening roles are not a different market; they are the same security function, in the same reporting line, competing for the same programme budget. The policy says so directly, defining the security function to span screening, IT security, physical security, business continuity, information management security, security in contracts and security event management (Treasury Board of Canada Secretariat, 2019, Appendix B). The 32.9% is not junk in your list. It is the rest of your buyer's job. And the 47.4% whose titles say only security is not a rounding error either: it is the largest single block, invisible to any filter that requires the word cyber.
What this changes about the message
If the accountable executive is a generalist answering to the deputy head or the executive committee, then the standard category pitch is mis-aimed in three specific ways.
Threat-actor framing lands weakest. A CSO's portfolio is dominated by mandated, audited obligations — screening, physical safeguards, security assessment and authorization. Positioning against a threat narrative competes with a compliance calendar and loses.
The competing spend is not another security tool. It is a guard contract, a screening backlog, a facility upgrade. Cost-justification against a rival platform answers a question this buyer is not asking.
Find out who holds the cyber designation before you decide who to write to. In a small organization the CSO usually holds it. In a large department the DOCS is likely someone else, and the 357 cyber and IT-security records are a third population again — real, and they will assess the product, but assessing is not deciding. Ask which of the three you are talking to. The answer is not in the title.
None of that argues for a weaker technical case. It argues for a technical case addressed to someone whose accountability spans three domains and whose authority runs to the deputy head or the executive committee Sagentix GTM Methodology, 2026.
Where this fits in how I work
Sagentix advises on go-to-market strategy and prepares organizations for independent assessment. Sagentix prepares organizations for independent assessment; it is not a 3PAO and does not perform the independent assessment, issue certification, run penetration tests, or operate a security operations centre. Nothing here is security advice — the subject is who a security vendor can address, not how any organization should be secured.
Every Phase 01 market-intelligence engagement builds the persona from the governing instrument and the directory rather than from what the category assumes, because a persona defined by industry habit is a plan aimed at a job title that may not exist in the market you are selling into Sagentix Phase 01 Market Intelligence, 2026. The full delivery system runs 6–8 weeks, draws on 1,412 curated artifacts, and is priced from CA$4,500 for Phase 1 up to CA$45,000 for the Full GTM build, depending on scope — with a Phase 1 money-back guarantee, subject to engagement terms: a full refund if the engagement reveals nothing new, and you keep the deliverable.
The habit underneath it is free: read the instrument that creates the role before you write to the role.
Three ways to act on this
Find the instrument, then the title. For any regulated buyer, locate the policy, directive or statute that creates the accountability you are selling into, and take the role from there — checking whether the instrument has been replaced or amended, and whether it requires a designation or a published title. I searched a 2009 term against a 2019 policy and got a null that looked like a finding. This costs an afternoon and it is the option I would take first.
Re-aim the message, and check the list. Eleven organizations publish a substantive chief security officer; another fifteen publish only a deputy. If your list came from a title search, split it on that line before you write, then test your deck against a reader who owns physical and personnel security as well as information security.
Bring in a structured market-intelligence pass when the persona is holding something up — a hiring plan, a territory design, a number a board has seen. That is a Phase 01 engagement, and it is last on this list because the first two are free.
The federal security buyer is not hiding. They have a different job than your deck assumes, and the policy that created the job says so in one sentence.
Which instrument defines the buyer in your plan — and when did you last check it had not been replaced?
Corrections
1 September 2026. This post was published on 20 August 2026 with figures derived from the 16 August build of the GEDS distribution. Five corrections have been applied, and every figure re-derived from the 23 August build. The original said the directory's 194,428 records each carried an English job title and 184,429 carried a French one; in fact 5.0% of records carry no title at all, and the second figure was the English count mislabelled. The original said "25 organizations publish the executive" while also noting that the substantive number was smaller — the substantive number is 11, and that correction is now carried through the article rather than left implicit. The Chief Audit Executive control row was undercounted at 19 because its French pattern omitted dirigeant principal de l'audit. The Chief / Head synonym control missed National Defence's Director Information Security, making four organizations rather than three. And the article did not mention the designated official for cyber security, which materially changes who a vendor should write to in a large department; that role now has a section of its own. The count of one CISO, the reporting line in s. 4.1.1, and every quoted title were re-verified and stand unchanged. The derivation is reproducible from tools/geds_security_titles_derive.py.
References
- Shared Services Canada. (2026). Government of Canada Employee Contact Information (GEDS) [Data set; JSON distribution
gedsOpenDataJson.zip, file published 23 August 2026, re-derived 1 September 2026]. Government of Canada. Open Government Licence – Canada. - Treasury Board of Canada Secretariat. (2009). Policy on Government Security (effective 1 July 2009; rescinded 30 June 2019) [Archived]. Government of Canada.
- Treasury Board of Canada Secretariat. (2019). Policy on Government Security (effective 1 July 2019; amended 6 January 2025). Government of Canada.
- Treasury Board of Canada Secretariat. (2019b). Directive on Service and Digital. Government of Canada.
- Treasury Board of Canada Secretariat. (2019c). Guideline on Service and Digital. Government of Canada.
Aggregate counts derived from Shared Services Canada's GEDS data set. Contains information licensed under the Open Government Licence – Canada. The Policy on Government Security, the Directive on Service and Digital and the Guideline on Service and Digital are quoted for commentary and are not covered by that licence. Neither Shared Services Canada nor the Treasury Board of Canada Secretariat endorses Sagentix or this use of their material.
Subscribe + get the workbook
The Bottom-Up TAM / SAM / SOM Workbook — free with your subscription
An 11-page tactical workbook with fillable worksheets — NAICS lookup, three-filter SAM test, Bull/Base/Bear SOM, and the diligence cross-checks. Not published anywhere else. Then get evidence-backed analysis every other Tuesday. No spam. Unsubscribe anytime. See past issues.

Stéphane Raby, CISSP, CMC, P.Eng., MBA
Founder & Principal — Sagentix Advisors
CMC | CISSP | P.Eng. | uOttawa Telfer Executive MBA — ranked #1 globally by CEO Magazine, 2023. 25+ years in technology strategy, cybersecurity, and management consulting.
Want This Evidence Applied to Your Market?
Phase 1 Market Intelligence starts at CA$4,500 with a money-back guarantee.