You Are Selling to a CISO. Canada Mandates a Chief Security Officer.
The title that appears once
The Government of Canada publishes its employee directory as open data — 194,647 records, each carrying a job title in English and, for 184,607 of them, in French (Shared Services Canada, 2026). I pulled it on 14 August 2026 and searched every title field, in both languages, for the buyer that federal cybersecurity messaging is built around.
One record carries the title Chief Information Security Officer. It sits at the Treasury Board of Canada Secretariat, and the full title is Chief Information Security Officer of the GC — the Government of Canada's, not a department's (Shared Services Canada, 2026).
That is not, as I first assumed, evidence that the federal security buyer is unreachable. It is evidence that the category is addressing a job that Canada does not organise the way the category imagines.
The spine. Canada's Policy on Government Security requires every deputy head to designate a chief security officer — not a CISO — "to provide leadership, coordination and oversight for departmental security management activities" (Treasury Board of Canada Secretariat, 2019, s. 4.1.1). That title is published: 38 records across 28 of the directory's 141 root organizations. The CISO title appears once. So the accountable security executive exists, is named, and is reachable — and holds physical, personnel and information security in a single mandate. Your product is being evaluated by a generalist against guard contracts and screening programmes, not by an infosec specialist Sagentix GTM Methodology, 2026.
The control, before the conclusion
A count of one is the most dangerous result in this kind of analysis, because a broken title search and a genuinely absent title produce identical output. So before that number could be published, the search had to be shown to work.
The same instrument, unchanged, was run against other executive titles of the same grammatical shape in the same field:
| Title searched (both official languages) | Records | Organizations |
|---|---|---|
| Chief Financial Officer | 98 | 62 |
| Chief Information Officer | 50 | 38 |
| Chief Audit Executive | 19 | 19 |
| Chief Data Officer | 14 | 14 |
| Chief Privacy Officer | 3 | 3 |
| Chief Information Security Officer | 1 | 1 |
(Shared Services Canada, 2026)
The probe returns 98 CFOs and 50 CIOs from the identical code path. The single CISO is therefore a property of the directory, not of my search.
A second control I nearly failed: an English-only search finds one CISO-class organization; a bilingual search finds three. Canada Mortgage and Housing Corporation publishes Head, Information Security / Chef, Sécurité de l'information, and Canadian Heritage publishes Head, Physical and Information Security / Chef, Sécurité physique et de l'information (Shared Services Canada, 2026). Search a bilingual directory in one language and you miss two-thirds of what is in it.
The role the policy actually names
This is the correction that reframes everything, and I make it because my own first search was for the wrong term.
The 2009 Policy on Government Security used Departmental Security Officer, and that phrase — with its French form agent de sécurité ministériel — appears exactly once in the whole directory. Searching for it tells you nothing except that the term is obsolete.
The policy in force took effect 1 July 2019, replacing the 2009 version, and was amended effective 6 January 2025 (Treasury Board of Canada Secretariat, 2019). Its requirement reads: deputy heads are responsible for "Designating a chief security officer responsible to the deputy head or to the departmental executive committee to provide leadership, coordination and oversight for departmental security management activities" (Treasury Board of Canada Secretariat, 2019, s. 4.1.1).
Search for that title and the picture inverts: 38 records across 28 organizations, including Canada Border Services Agency, Global Affairs Canada, the Canada School of Public Service, the Canadian Radio-television and Telecommunications Commission, Canadian Heritage, Fisheries and Oceans Canada and the Canadian Food Inspection Agency (Shared Services Canada, 2026). Chief Security Officers, Deputy Chief Security Officers, and directors general who hold the CSO designation alongside a line role.
The buyer was published the whole time. I was searching for a title from a policy that was replaced seven years ago — which is precisely the currency failure this series keeps warning about, arriving in my own draft.
Why more than half of the directory's security titles look like noise
Search the directory broadly for security-titled staff and you find 737 records (Shared Services Canada, 2026). Decompose it:
| Category | Records | Share |
|---|---|---|
| Cyber / IT / information security | 340 | 46.1% |
| Physical, personnel, maritime, aviation or transport security | 198 | 26.9% |
| Unqualified security (role type not determinable from the title) | 197 | 26.7% |
| Ambiguous (matches both) | 2 | 0.3% |
| Total | 737 | 100% |
(Shared Services Canada, 2026)
A vendor filtering on the keyword concludes that over half the list is noise and discards it. That reading is wrong, and expensively so. Under an all-hazards CSO mandate, the physical, personnel and screening roles are not a different market — they are the same security function, in the same reporting line, competing for the same programme budget. The 26.9% is not contamination. It is the rest of your buyer's job.
What this changes about the message
If the accountable executive is a generalist reporting to the deputy head, then the standard category pitch is mis-aimed in three specific ways.
Threat-actor framing lands weakest. A CSO's portfolio is dominated by mandated, audited obligations — screening, physical safeguards, security assessment and authorization. Positioning against a threat narrative competes with a compliance calendar and loses.
The competing spend is not another security tool. It is a guard contract, a screening backlog, a facility upgrade. Cost-justification against a rival platform answers a question this buyer is not asking.
The specialist is a technical evaluator, not the economic buyer. The 340 cyber and IT-security records are real and they matter — they will assess the product. In most organizations they do not hold the mandate the policy assigns to the CSO.
None of that argues for a weaker technical case. It argues for a technical case addressed to someone whose accountability spans three domains and whose authority runs to the deputy head Sagentix GTM Methodology, 2026.
Where this fits in how I work
Sagentix advises on go-to-market strategy. It does not deliver cybersecurity, compliance assessment or certification services — SOC 2, CMMC and ISO 27001 among them — and nothing here is security advice — the subject is who a security vendor can address, not how any organization should be secured.
Every Phase 01 market-intelligence engagement builds the persona from the governing instrument and the directory rather than from the category's received wisdom, because a persona defined by industry habit is a plan aimed at a job title that may not exist in the market you are selling into Sagentix Phase 01 Market Intelligence, 2026. The full delivery system runs 6–8 weeks, draws on 727+ curated artifacts, and is priced between CA$4K and CA$50K depending on scope — with a Phase 1 money-back guarantee (subject to terms).
The habit underneath it is free: read the instrument that creates the role before you write to the role.
Three ways to act on this
Find the instrument, then the title. For any regulated buyer, locate the policy, directive or statute that creates the accountability you are selling into, and take the title from there — checking whether the instrument has been replaced or amended. I searched a 2009 term against a 2019 policy and got a null that looked like a finding. This costs an afternoon and it is the option I would take first.
Re-aim the message, not the list. The list is fine — 28 organizations publish the executive. Test your current deck against a reader who owns physical and personnel security as well as information security, and see how much of it still speaks to them.
Bring in a structured market-intelligence pass when the persona underwrites something — a hiring plan, a territory design, a number a board has seen. That is a Phase 01 engagement, and it is last on this list because the first two are free.
The federal security buyer is not hiding. They have a different job than your deck assumes, and the policy that created the job says so in one sentence.
Which instrument defines the buyer in your plan — and when did you last check it had not been replaced?
References
- Shared Services Canada. (2026). Government of Canada Employee Contact Information (GEDS) [Data set]. Government of Canada. Open Government Licence – Canada.
- Treasury Board of Canada Secretariat. (2019). Policy on Government Security (effective 1 July 2019; amended 6 January 2025). Government of Canada.
Contains information licensed under the Open Government Licence – Canada.
Subscribe + get the workbook
The Bottom-Up TAM / SAM / SOM Workbook — free with your subscription
An 11-page tactical workbook with fillable worksheets — NAICS lookup, three-filter SAM test, Bull/Base/Bear SOM, and the diligence cross-checks. Not published anywhere else. Then get evidence-backed analysis every other Tuesday. No spam. Unsubscribe anytime. See past issues.

Stéphane Raby, CISSP, CMC, P.Eng., MBA
Founder & Principal — Sagentix Advisors
CMC | CISSP | P.Eng. | uOttawa Telfer Executive MBA — ranked #1 globally by CEO Magazine, 2023. 25+ years in technology strategy, cybersecurity, and management consulting.
Want This Evidence Applied to Your Market?
Phase 1 Market Intelligence starts at CA$4,000–CA$5,000 with a money-back guarantee.