You Are Selling to a CISO. Canada Mandates a Chief Security Officer.
The title that appears once
The Government of Canada publishes its employee directory as open data: 194,106 records spread across 141 root organizations (Shared Services Canada, 2026). Every figure below was re-derived on 1 September 2026 from the JSON distribution of the file published 23 August. A re-run on 24 September 2026 against the 20 September build (191,849 records) found the same single CISO record and the same eleven substantive chief security officers (Shared Services Canada, 2026).
Naming the distribution matters. A dataset published in more than one format is really several files, each rebuilt on its own schedule, and a download that succeeds tells you nothing about what arrived: an HTTP 200, a valid archive and the correct schema are all perfectly compatible with a payload that is missing what you came for. The only way to tell a real answer from an empty one is to confirm the file contains something you already know should be in it. That is the same habit this article is about, one layer further down. An empty answer looks exactly like a true one until you have shown the source worked.
Not every record carries a title. 184,432 have one in English and 184,111 have one in French, so 9,674 records — 5.0% — carry no job title at all. No record carries a French title without an English one.
One record carries the title Chief Information Security Officer. It sits at the Treasury Board of Canada Secretariat, and the full title is Chief Information Security Officer of the GC — the Government of Canada's, not a department's (Shared Services Canada, 2026).
That is not, as I first assumed, evidence that the federal security buyer is unreachable. It is evidence that the category is addressing a job that Canada does not organise the way the category imagines.
The spine. Canada's Policy on Government Security makes the deputy head accountable, and requires them to designate "a chief security officer responsible to the deputy head or to the departmental executive committee to provide leadership, coordination and oversight for departmental security management activities" (Treasury Board of Canada Secretariat, 2019, s. 4.1.1). The instrument names a role, in lowercase, not a job title anyone must publish. Search for the title anyway and you find 31 records across 26 organizations, of which 11 publish a substantive holder — the rest publish a deputy, an acting appointee or, in one case, an adviser. The CISO title appears once. On the evidence of the titles themselves, the holder is usually a generalist: an executive director of facilities management, a director general of human resources, a vice-president of human resources, a senior director of plant operations. Your product is most often evaluated against guard contracts and screening programmes by someone whose day job is not information security Sagentix GTM Methodology, 2026.
The control, before the conclusion
A count of one is the most dangerous result in this kind of analysis, because a broken title search and a genuinely absent title produce identical output. So before that number could be published, the search had to be shown to work.
The same instrument, unchanged, was run against other executive titles of the same shape in the same field. Each row matches the English title or an enumerated official French equivalent — dirigeant principal des finances, dirigeant principal de l'information, and so on:
| Title searched (both official languages) | Records | Organizations |
|---|---|---|
| Chief Financial Officer | 100 | 63 |
| Chief Information Officer | 51 | 39 |
| Chief Audit Executive | 25 | 24 |
| Chief Data Officer | 14 | 14 |
| Chief Privacy Officer | 3 | 3 |
| Chief Information Security Officer | 1 | 1 |
(Shared Services Canada, 2026)
The probe returns 100 CFOs and 51 CIOs from the identical code path. The single CISO is therefore a property of the directory, not of my search. I also pushed the CISO row harder than any other, because everything here rests on it: CISO as a bare acronym returns nothing, the French RSSI returns nothing, cyber security officer returns nothing, and every French construction of the form dirigeant / chef / responsable … de la sécurité de l'information returns the same single organization. The count of one survives each of them.
One row taught me something about the method. My first Chief Audit Executive pattern paired the English phrase with the French dirigeant principal de la vérification, and returned 19. It was missing dirigeant principal de l'audit, and with it six Chief Audit and Evaluation Executive records — at the Canadian Grain Commission, Correctional Service Canada, Justice Canada, Natural Resources Canada, the Public Health Agency of Canada and Public Safety Canada — that the English phrase never matched. A pattern can be reproducible and still be wrong, which is why the rubric belongs in the article and not in my notebook.
A second control, and the one that corrected me. Searching the exact phrase Chief Information Security Officer returns one organization. Allow for the obvious synonyms and it returns four: Canada Mortgage and Housing Corporation publishes Head, Information Security, Canadian Heritage publishes Head, Physical and Information Security, and National Defence publishes Director Information Security (Shared Services Canada, 2026). All carry French equivalents and all are findable in English, so this is not a bilingual-search problem, as I first wrote it. No record in the directory has a French title without an English one, which kills the theory outright rather than by example. It is a vocabulary problem: Chief, Head and Director name the same job, and a search for one finds a quarter of what a search for all three would.
The role the policy actually names
The term the policy uses matters, because a title search built on the popular one looks in the wrong place.
The 2009 Policy on Government Security told deputy heads to appoint "a departmental security officer (DSO) functionally responsible to the deputy head or to the departmental executive committee" (Treasury Board of Canada Secretariat, 2009, s. 6.1.2). That phrase appears exactly once in the whole directory, at Fisheries and Oceans Canada, and its official French form agent de sécurité du ministère sits on the same single record. Searching for it tells you nothing except that the term is obsolete.
The policy in force took effect 1 July 2019, replacing the 2009 version, and was amended effective 6 January 2025 (Treasury Board of Canada Secretariat, 2019). Its requirement, quoted above, changed the title but kept the reporting line intact.
Now the part that took me two passes to get right. The policy requires a designation, not a published title. Section 4.1.1 says "a chief security officer" in lowercase; it creates a role and assigns it to whoever the deputy head names. A department that designates its ADM Corporate Services as CSO is fully compliant and may publish nothing of the sort in the directory. So the directory measures a publication rate, not a designation rate, and no title search — mine included — can tell you which departments have complied. It can only tell you which ones say so out loud.
Said out loud, here is the shape of it. The exact phrase returns 31 records across 26 organizations, two of them duplicate rows for the same Transport Canada position. Seventeen of the 31 are Deputy or Acting variants and one is an Executive Advisor to the Chief Security Officer, which leaves 11 organizations publishing a substantive designated holder: Atomic Energy of Canada Limited, the Canada Border Services Agency, the Canada School of Public Service, the Courts Administration Service, Library and Archives Canada, the National Capital Commission, the Office of the Chief Electoral Officer, the Office of the Secretary to the Governor General, the Royal Canadian Mint, the Supreme Court of Canada and Transport Canada (Shared Services Canada, 2026).
That gap will cost you. Global Affairs Canada, the CRTC, Canadian Heritage, Fisheries and Oceans Canada, Health Canada and Shared Services Canada all appear in a search for the title, and every one of them publishes only a deputy. If you build a contact list from the string, you are writing to fourteen deputies and an adviser and calling it an executive list.
Two further cautions on that set. The policy applies "to departments as defined in section 2 and entities included in Schedules IV and V of the Financial Administration Act" (Treasury Board of Canada Secretariat, 2019, s. 6.1), and the directory's 141 root organizations include Crown corporations that are none of those. Three of the eleven — Atomic Energy of Canada Limited, the National Capital Commission and the Royal Canadian Mint — are Crown corporations, so their chief security officer exists for their own reasons rather than because this policy required it. And most holders are not security specialists: the titles read Exec Dir, Facilities Management & Chief Security Officer (CSO); Director General, Human Resources and Chief Security Officer; Vice-President & Chief Security Officer, Human Resources and Workplace Management; Senior Director, Plant Operations & Chief Security Officer. The designation sits on top of a facilities, HR or operations job.
The buyer was published the whole time. I was searching for a title from a policy that was replaced seven years ago — which is precisely the currency failure this series keeps warning about, arriving in my own draft.
The second designation
There is a second designation, and leaving it out would repeat the mistake this article is about.
The Directive on Service and Digital assigns cyber security to "the designated official for cyber security, in collaboration with the departmental CIO and Chief Security Officer as appropriate" (Treasury Board of Canada Secretariat, 2019b, s. 4.5). The supporting guideline is blunter about who that is: "the deputy head could designate the CSO as the DOCS. However, in larger departments and agencies, it may be preferred to have another senior official designated as the DOCS" (Treasury Board of Canada Secretariat, 2019c, s. 1.1).
Read that against a target list. In a small organization your buyer probably is the CSO. In a large department, Canada expects the cyber mandate to sit with a different named executive, and that title is no more required to be published than the CSO's. Two records spell it out: Global Affairs Canada publishes Executive Director - Cyber Security / Designated Official for Cyber Security (DOCS) and Fisheries and Oceans Canada publishes Director and Designated Officials for Cyber Security (DOCS) — both departments that publish a deputy chief security officer and no substantive one (Shared Services Canada, 2026). In the 20 September build only the Fisheries and Oceans record remains. Two designations, one accountable deputy head, and the cyber designation published in at most two departments.
That is the real finding, and it is worse for the standard playbook than a missing CISO. You are not looking for a title that does not exist. You are looking for two designations that exist and are almost never published, held by people whose directory titles describe their day jobs instead.
Searching 194,106 federal employee records for the role
- All directory records194,106both official languages
- Security-titled1,834
- Chief Security Officer31across 26 organizations
- Substantive holder11organizations
Why four in five of the directory's security titles look like noise
Search the directory for job titles carrying the standalone word security — excluding the income-support senses, Social Security and Old Age Security, which are benefit programmes rather than the security function — and you find 1,834 records (Shared Services Canada, 2026).
Sorting them needs a rubric, and an unpublished rubric is an opinion. A title counts as cyber if it carries cyber, IT, informatics, information technology, information security, infosec, network, systems, digital, data centre, COMSEC or cryptographic; as physical if it carries physical, personnel, screening, clearance, maritime, marine, aviation, air, transport, rail, port, guard, commissionaire, facilities, building, premises, site, protective, emergency, fire or occupational; as ambiguous if both; and as unqualified if neither. Move a keyword between those lists and the middle two rows move with it, which is the honest caveat on the table:
| Category | Records | Share |
|---|---|---|
| Cyber / IT / information security | 357 | 19.5% |
| Physical, personnel, screening, maritime, aviation or transport security | 604 | 32.9% |
| Unqualified security (role type not determinable from the title) | 870 | 47.4% |
| Ambiguous (matches both) | 3 | 0.2% |
| Total | 1,834 | 100% |
(Shared Services Canada, 2026)
A vendor who filters on the keyword and then keeps only what reads as cyber keeps 357 records and discards 1,477 — 80.5% of the security-titled directory — as noise. That reading is wrong, and expensively so. Under an all-hazards CSO mandate, the physical, personnel and screening roles are not a different market; they are the same security function, in the same reporting line, competing for the same programme budget. The policy says so directly, defining the security function to span screening, IT security, physical security, business continuity, information management security, security in contracts and security event management (Treasury Board of Canada Secretariat, 2019, Appendix B). The 32.9% is not junk in your list. It is the rest of your buyer's job. And the 47.4% whose titles say only security is not a rounding error either: it is the largest single block, invisible to any filter that requires the word cyber.
What this changes about the message
If the accountable executive is a generalist answering to the deputy head or the executive committee, then the standard category pitch is mis-aimed in three specific ways.
Threat-actor framing lands weakest. A CSO's portfolio is dominated by mandated, audited obligations — screening, physical safeguards, security assessment and authorization. Positioning against a threat narrative competes with a compliance calendar and loses.
The competing spend is not another security tool. It is a guard contract, a screening backlog, a facility upgrade. Cost-justification against a rival platform answers a question this buyer is not asking.
Find out who holds the cyber designation before you decide who to write to. In a small organization the CSO usually holds it. In a large department the DOCS is likely someone else, and the 357 cyber and IT-security records are a third population again — real, and they will assess the product, but assessing is not deciding. Ask which of the three you are talking to. The answer is not in the title.
None of that argues for a weaker technical case. It argues for a technical case addressed to someone whose accountability spans three domains and whose authority runs to the deputy head or the executive committee Sagentix GTM Methodology, 2026.
Where this fits in how I work
Sagentix advises on go-to-market strategy and prepares organizations for independent assessment. Sagentix prepares organizations for independent assessment; it is not a 3PAO and does not perform the independent assessment, issue certification, run penetration tests, or operate a security operations centre. Nothing here is security advice — the subject is who a security vendor can address, not how any organization should be secured.
Every Phase 01 market-intelligence engagement builds the persona from the governing instrument and the directory rather than from what the category assumes, because a persona defined by industry habit is a plan aimed at a job title that may not exist in the market you are selling into Sagentix Phase 01 Market Intelligence, 2026. The full delivery system runs 6–8 weeks, draws on 1,425 curated artifacts, and is priced from CA$4,500 for Phase 1 up to CA$45,000 for the Full GTM build, depending on scope — with a Phase 1 money-back guarantee, subject to engagement terms: a full refund if the engagement reveals nothing new, and you keep the deliverable.
The habit underneath it is free: read the instrument that creates the role before you write to the role.
Three ways to act on this
Find the instrument, then the title. For any regulated buyer, locate the policy, directive or statute that creates the accountability you are selling into, and take the role from there — checking whether the instrument has been replaced or amended, and whether it requires a designation or a published title. I searched a 2009 term against a 2019 policy and got a null that looked like a finding. This costs an afternoon and it is the option I would take first.
Re-aim the message, and check the list. Eleven organizations publish a substantive chief security officer; another fourteen publish only a deputy, and one only an adviser. If your list came from a title search, split it on that line before you write, then test your deck against a reader who owns physical and personnel security as well as information security.
Bring in a structured market-intelligence pass when the persona is holding something up — a hiring plan, a territory design, a number a board has seen. That is a Phase 01 engagement, and it is last on this list because the first two are free.
The federal security buyer is not hiding. They have a different job than your deck assumes, and the policy that created the job says so in one sentence.
Which instrument defines the buyer in your plan — and when did you last check it had not been replaced?
References
- Shared Services Canada. (2026). Government of Canada Employee Contact Information (GEDS) [Data set; JSON distribution
gedsOpenDataJson.zip, file published 23 August 2026, re-derived 1 September 2026]. Government of Canada. Open Government Licence – Canada. - Treasury Board of Canada Secretariat. (2009). Policy on Government Security (effective 1 July 2009; rescinded 30 June 2019) [Archived; text as archived 31 March 2012]. Government of Canada.
- Treasury Board of Canada Secretariat. (2019). Policy on Government Security (effective 1 July 2019; amended 6 January 2025). Government of Canada.
- Treasury Board of Canada Secretariat. (2019b). Directive on Service and Digital. Government of Canada.
- Treasury Board of Canada Secretariat. (2019c). Guideline on Service and Digital. Government of Canada.
Aggregate counts derived from Shared Services Canada's GEDS data set. Contains information licensed under the Open Government Licence – Canada. The Policy on Government Security, the Directive on Service and Digital and the Guideline on Service and Digital are quoted for commentary and are not covered by that licence. Neither Shared Services Canada nor the Treasury Board of Canada Secretariat endorses Sagentix or this use of their material.
Subscribe + get the workbook
The Bottom-Up TAM / SAM / SOM Workbook — free with your subscription
An 11-page tactical workbook with fillable worksheets — NAICS lookup, three-filter SAM test, Bull/Base/Bear SOM, and the diligence cross-checks. Not published anywhere else. Then get evidence-backed analysis every other Tuesday. No spam. Unsubscribe anytime. See past issues.

Stéphane Raby, CISSP, CMC, P.Eng., MBA
Founder & Principal — Sagentix Advisors
CMC | CISSP | P.Eng. | uOttawa Telfer Executive MBA — ranked #1 globally by CEO Magazine, 2023. 25+ years in technology strategy, cybersecurity, and management consulting.
Want This Evidence Applied to Your Market?
Phase 1 Market Intelligence starts at CA$4,500 with a money-back guarantee.