After more than three decades at the Communications Security Establishment, including leading the Canadian Centre for Cyber Security from 2021 to 2024, Khoury shares his perspective on quantum threats, frontier AI and Canada’s cyber resilience.

Quantum computers are not yet capable of breaking today’s encryption at scale. Why does quantum computing already represent a cybersecurity risk for Canadian organizations?
Quantum computers capable of breaking today’s public-key encryption do not exist yet, but the risk to sensitive data is already real. Malicious actors can collect encrypted information today with the intention of decrypting it later, once sufficiently powerful quantum computers become available. This is what is known as “harvest now, decrypt later.” If an organization holds information that needs to remain confidential for five, 10 or 20 years, the clock is already ticking.
That is why organizations need to start preparing for the quantum threat and planning their transition over the next several years. This is not simply a theoretical or scientific challenge. Governments and financial regulators have already begun setting timelines for migration. The Government of Canada’s own roadmap targets the end of 2031 for migrating high-priority federal systems and the end of 2035 for everything else. Those dates are set for federal departments rather than for businesses, but they are a fair indication of the pace this transition will demand.
The risk also goes beyond data confidentiality. Quantum computing could affect the systems of trust that underpin our digital lives. If a future quantum computer can compromise digital signatures, for example, a malicious actor could potentially make an update or application appear to come from a trusted provider. So the issue is not only protecting encrypted data, but also preserving digital trust.

What should organizations be doing today to prepare for post-quantum cybersecurity, particularly small and medium-sized businesses?
Organizations should begin with three things: understand their data, understand their cryptography and understand their vendor ecosystem.
First, know what data you hold and how long it needs to remain confidential. Not all data has the same shelf life. An online purchase may have little sensitivity 10 years from now, while medical records, financial histories or government information may need to remain confidential for decades. If your data has a long shelf life, it may already be exposed to the risk of being collected today and decrypted in the future.
Second, organizations should understand where cryptography is used across their systems. Building an inventory takes effort, but it is an important step in determining what will eventually need to change.
Third, speak with your technology providers and understand their roadmap for becoming post-quantum ready. Larger organizations will have significant work ahead of them, but smaller businesses should not assume the issue does not apply to them. A clinic or doctor’s office, for example, may hold highly sensitive information and should understand how its IT providers plan to protect that information as the transition approaches.

How is frontier AI changing the cyber threat landscape, and which AI-enabled threats concern you most today?
Frontier AI is changing the threat landscape through scale, speed and sophistication. Scale and speed worry me most, but it is the combination of all three that is genuinely new.
There have always been highly skilled people capable of developing sophisticated exploits. The difference with frontier AI is that, when used maliciously, it can scale activity beyond normal human capacity. Instead of launching attacks one at a time, an attacker can potentially launch many at once, while AI systems can operate at speeds humans cannot match.
We are also seeing AI demonstrate the ability to identify sophisticated exploits and chain them together. When you combine that capability with scale and speed, cybersecurity teams are facing something fundamentally different from what they have traditionally had to contend with.
It is important to remember that frontier AI can also be used defensively. The technology itself is not inherently offensive, but in malicious hands, those three characteristics can significantly change the game.

As frontier AI systems become more capable and autonomous, how concerned should we be about maintaining control over what they can and cannot do?
I would not say that we have lost control over frontier AI. What we are seeing is that the push to develop increasingly capable models is also teaching us more about the guardrails that need to be built into them.
There have been reports of frontier AI models acting autonomously in unexpected ways. The companies developing these systems need to apply those lessons and ensure their models have appropriate controls over what they can and cannot do. Government has a role here as well. It needs enough independent expertise to test these systems rather than taking the developers’ assurances at face value.
As capabilities increase, guardrails cannot be an afterthought. They need to evolve alongside the models themselves.

Looking at Canada’s overall cybersecurity landscape, where do you see the greatest gap between our current level of preparedness and the threats we will face in the coming years?
Canada has a strong cybersecurity ecosystem. What is missing is greater connectivity between the different parts of that ecosystem.
From a federal perspective, the Canadian Centre for Cyber Security, part of the Communications Security Establishment, plays an important role, but Canada is a huge country. We need stronger connections across provinces, territories, organizations and sectors so that reporting a cyber incident becomes a natural instinct.
We are not yet at the point where the Cyber Centre is on every organization’s speed dial. There can still be reluctance to report incidents, whether because an organization does not know who to call, has legal concerns, does not want to involve government or is simply focused on responding to the immediate problem. Bill C-8, which received royal assent in June, will change that at the top end. It will require designated operators in four critical infrastructure sectors to report incidents to the Cyber Centre and notify their regulator, although those obligations are not yet in force. Even then, it reaches a relatively small number of organizations, and the instinct I am describing needs to extend well beyond them.
The value of reporting is that the Cyber Centre can connect the dots at a national scale. An incident at a hospital in British Columbia might have similarities to something seen in Newfoundland and Labrador or at a university in Ontario. Connecting those points can reveal a broader vulnerability or emerging threat that no single organization could see on its own. We need more of that sense that we are all in this together.

Digital sovereignty has become a much bigger part of the national conversation. What should Canadian organizations be thinking about when they assess their digital dependencies?
Organizations should look closely at their digital stack and understand where they may be vulnerable to external influences or disruptions.
That means asking practical questions. Where is your data hosted and processed? Where do critical systems and components come from? If there is a supply-chain disruption, can you still obtain the parts you need? Is the maintenance contract for your data centre provided by a company outside Canada? Do any contractual or legal obligations create exposure to another jurisdiction?
The point is not that every dependency outside Canada is inherently a problem. It is to understand those dependencies so decision-makers can assess where their operations could be affected by tariffs, sanctions, supply-chain issues or other external events, and determine whether adjustments are needed.
At the same time, Canada continues to have strong cybersecurity collaboration with its Five Eyes partners and beyond. Beneath the headlines, information sharing on cyber incidents, threats and intelligence remains important and well established. Digital sovereignty is therefore about understanding and managing dependencies while continuing to benefit from strong international partnerships.
