Canada Moves to Dollar for Dollar Retaliation as 50% US Tariffs Take Hold, Putting Supplier Continuity Back on the Risk Register
Trade negotiations between Canada and the United States collapsed minutes before the deadline, and 50% US tariffs on roughly $28 billion of Canadian goods are now in force. Prime Minister Mark Carney suspended talks and committed Canada to matching the measures dollar for dollar, with Finance Minister François Philippe Champagne setting out the retaliatory package this week and Canadian counter tariffs scheduled to begin September 8. A further US threat covers all cars, trucks, automotive parts, and steel from January 1, 2027.
Reporting puts roughly 87,000 Canadian jobs at risk, concentrated in Ontario, Quebec, and British Columbia, with machinery and electronics, plastics and rubber, agriculture, aluminum, and steel among the exposed categories. Two of the sticking points are worth noting for governance teams: the US position limited automotive tariff relief to light vehicles rather than medium and heavy trucks, and it pressed Canada to drop Canadian content obligations on foreign streaming platforms. The government said it would not compromise sovereignty or undermine key industries. Ottawa also plans to expand Employment Insurance for affected workers.
- US tariffs of 50% apply to about $28 billion of Canadian goods; talks are suspended, not concluded
- Canadian counter measures matched dollar for dollar, taking effect September 8
- Threatened January 1, 2027 expansion covers all vehicles, automotive parts, and steel
- Roughly 87,000 Canadian jobs identified as at risk, weighted to Ontario, Quebec, and British Columbia
Treat this as a supplier continuity and contract review exercise, not a trade policy story. Pull the supplier register, identify every single source input crossing the border, and confirm which contracts carry force majeure, price adjustment, or change in law clauses that a tariff actually triggers. Where a supplier substitution is possible, the security assessment has to run before the commercial one, because emergency onboarding is how unvetted vendors enter regulated environments. The same logic applies to digital services: pressure on Canadian content and data rules is a signal to document where regulated data resides and what a change in cross border terms would cost. In ISO/IEC 27001 terms this is Clause 8.1 operational planning and control together with the Annex A supplier relationship controls, and it belongs in the next management review, not the next fiscal year.
US Executive Order Bans Foreign Made Grid Equipment and Orders Replacement Plans for What Is Already Installed
The White House issued an executive order barring acquisition and installation of foreign made bulk power system equipment rated at 69,000 volts and above, covering transmission lines, substations, control rooms, power stations, reactors, and the software and firmware that run them. The order declares a national emergency with respect to the threat to the US bulk power system and states that certain foreign actors are creating and exploiting vulnerabilities that permit remote access or supply chain disruption.
The Departments of Defense, Commerce, and Energy are tasked with reviewing transactions, conditions can be attached to equipment already purchased, and pre qualified equipment and vendor lists must be produced within 120 days. Operators will also have to identify at risk equipment currently in service and produce replacement plans. No country is officially named in the order.
- Applies to bulk power system equipment rated 69,000 volts and above, including firmware and software
- Pre qualified vendor and equipment lists due within 120 days
- Identification and replacement plans required for at risk equipment already installed
Pre qualified vendor lists are the mechanism to watch. Once a government publishes one it becomes the de facto procurement standard for every operator and integrator selling into that market, and Canadian suppliers to North American utilities should expect to be asked where their components, firmware, and update channels originate. The practical step now is a component and firmware level bill of materials for anything you supply into or operate within energy, water, or transport, plus evidence of how you control software updates reaching that equipment. Country of origin has moved from a procurement preference to a security control.
Boston Scientific Cannot Process and Ship Customer Orders After a Cyberattack Takes Down Global Systems
Medical device manufacturer Boston Scientific discovered a cybersecurity incident on August 25 that produced a network outage across its global operations and cut access to operating systems and business applications. The company confirmed the disruption reached its ability to process and ship customer orders, and said a timeline for full restoration is still unknown. External cybersecurity specialists have been engaged.
The company, which makes pacemakers and stents and reported $5.4 billion in net sales in the second quarter of 2026, declined to confirm whether ransomware was involved, and no group had claimed the attack. Investors were told restoration could take weeks. The incident follows attacks on other major medical device manufacturers this year.
- Outage reached global operations and blocked order processing and shipping
- No restoration timeline published; recovery estimated in weeks
- No group has claimed the attack and ransomware involvement is unconfirmed
The failure mode here is fulfilment, not data. When a manufacturer of implantable devices cannot ship, the consequence lands in hospitals that scheduled procedures around delivery dates. If your organization depends on a single manufacturer for clinical or safety critical consumables, the question for this week is what your substitution plan is and how many days of buffer stock stand between a supplier outage and a cancelled service. Business continuity plans that model your own outage but not your supplier's are only half written.
A Federal Law Enforcement Agency Declares a Major Incident After Qilin Lists It on a Leak Site
The US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cyberattack on a standalone computer system holding information about targets of ATF investigations, after the Qilin ransomware group added the agency to its leak site. Federal officials designated the breach a major incident and the Justice Department is investigating.
The agency says the system was not connected to any other ATF environment, including case management, laboratory, and eForms systems, and that it was shut down when the breach was found. Qilin listed the agency without publishing data samples. The group was among the most active ransomware operations of 2025 and ranked second by reported attack volume in July 2026.
- Standalone system containing investigation target information was compromised and taken offline
- Designated a major incident; no operational impact reported on other systems
- Qilin listed the agency without releasing data, a common pressure tactic
Isolation limited the blast radius and that is the transferable lesson: segmentation earns its cost on the day it is tested. It did not prevent the compromise. Standalone and legacy systems tend to sit outside patching cycles, logging, and identity governance precisely because they are isolated, which makes them attractive and hard to monitor. Inventory the systems your organization treats as exceptions, confirm each one is actually isolated rather than assumed to be, and make sure they still appear in your incident response scope.
Four in Ten Breached German Companies Now Attribute an Incident to a Foreign Intelligence Service
A Bitkom survey of 1,003 German companies with at least ten employees found that nearly four in ten of those hit by data theft, industrial espionage, or sabotage in the past year traced at least one incident to a foreign intelligence service. That share was 28% last year and 7% in 2023, moving state services into second place behind organized crime as the most commonly identified attacker.
More than half of affected companies attributed at least one attack to China, with Russia second and roughly one in ten citing Iran. Bitkom put the total cost of cyberattacks to German businesses at between $186 billion and $240 billion over the year, counting business interruption, investigation, recovery, legal disputes, extortion, lost revenue, and lost competitive advantage.
- State attribution rose from 7% in 2023 to nearly 40% of breached firms
- China cited by more than half of affected companies, Russia second, Iran roughly one in ten
- Annual cost estimated at $186 billion to $240 billion across the German economy
State linked activity aimed at commercial intellectual property changes what a proportionate control set looks like for mid sized manufacturers, engineering firms, and research intensive businesses, which is much of Canada's industrial base. If your threat model still assumes opportunistic crime, revisit it: nation state tradecraft implies long dwell times, targeting of design and process data rather than payment systems, and insider and supplier vectors. Start with a clear answer to which datasets would genuinely damage the business if copied quietly, then apply monitoring proportionate to that answer.
The Cyber Centre Publishes a TeamViewer Advisory Covering the Full Remote Access Client Range
The Canadian Centre for Cyber Security issued advisory AV26 852 on August 26 for TeamViewer, spanning Full Client, Host, QuickSupport, and Portable versions before 15.64.7 across multiple platforms. The advisory points administrators to vendor bulletins TV 2026 1008 and TV 2026 1009 and encourages review and application of updates as they become available.
Remote access and remote support tooling continues to feature in both advisories and incident reports, because the same software that lets a support desk reach an endpoint lets an intruder do the same once credentials or a session are obtained. The Cyber Centre issued this advisory in the same week it updated its Citrix advisory AV26 645.
- AV26 852 issued August 26 covering TeamViewer Full Client, Host, QuickSupport, and Portable
- Portable versions before 15.64.7 named explicitly; vendor bulletins TV 2026 1008 and TV 2026 1009
- Published in the same week as an update to the Cyber Centre's Citrix advisory AV26 645
Remote access software deserves an inventory of its own. Most organizations can name their primary support tool and very few can name every remote access agent installed across the estate, including the ones a vendor left behind after a project. Build that list, remove what is unused, restrict what remains to named administrators with multifactor authentication, and log every session. Unmanaged remote access tooling is one of the few findings that shows up in both a vulnerability advisory and a post incident report, which is a strong argument for treating it as a control rather than a convenience.
PSPC Holds Its Cyber Security Readiness Session as CPCSC Level 1 Phases Into Defence Contracts
Public Services and Procurement Canada held a supplier session on August 26 covering its work to support cyber security readiness and future engagement opportunities. It lands as Level 1 of the Canadian Program for Cyber Security Certification begins appearing in select defence contracts through summer 2026, with certification required at contract award rather than during bidding in this initial phase.
The program structure is unchanged. Level 1 requires an annual cyber security self assessment against 13 controls. Level 2 requires an external assessment led by an accredited certification body against 98 controls plus annual affirmation. Level 3 requires assessment conducted by National Defence against 200 controls plus annual affirmation. The stated objective is protection of unclassified Government of Canada contractual information held on supplier networks, systems, and applications.
- Level 1 required at contract award, not at bid, during the initial phase in
- Thirteen controls at Level 1 with annual self assessment; 98 at Level 2 with external assessment
- Level 3 assessments are conducted by National Defence against 200 controls
The award trigger is the part suppliers misread. Because certification is not tested during bidding in this phase, a company can win work it is not yet able to accept, and the gap between award and certification is measured in weeks while the underlying evidence takes longer to assemble. The right time to complete the Level 1 self assessment is before a solicitation appears, not after. For anyone whose contracts could reach Level 2, note the difference in kind rather than degree: 98 controls assessed externally means documented policy, evidence retention, and a system security plan that survives someone else reading it.
More Than 100 AI and Security Companies Sign a Joint Call for Coordinated Defence Against AI Enabled Attacks
OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta, Fortinet, and more than 100 other companies including financial institutions and internet infrastructure providers published a joint letter on August 27 urging public and private sector coordination on AI related cyber defence, and calling for governments at local, national, and international levels to work together on security standards. The letter states that AI enabled cyber attacks will become far more widespread and sophisticated as models become more capable.
The signatories point to their own defensive programs and to a run of incidents in which AI agents operated outside their intended boundaries. The tension in the letter is visible: most signatories build the capability they are asking governments to help defend against, which is part of why the ask is for shared standards rather than voluntary restraint.
- More than 100 signatories spanning AI labs, security vendors, financial institutions, and infrastructure firms
- Calls for new public private partnerships and coordinated security standards across jurisdictions
- Premise stated plainly: AI enabled attacks scale with model capability
When the vendors building a capability publicly ask to be regulated on it, the standards that follow tend to arrive quickly and to reference existing frameworks. Organizations do not need to wait. Three things will be asked for: an inventory of where AI systems and agents operate inside your environment, defined human oversight and escalation points for anything that can act rather than only advise, and logging that captures what an agent did with the permissions it held. ISO/IEC 42001 already frames all three, and building them now costs less than retrofitting them to a published standard later.
The Privacy Commissioner Goes to Federal Court to Enforce a De Listing Finding Against a Search Engine
The Office of the Privacy Commissioner of Canada filed an application with the Federal Court on August 28 seeking an order to implement recommendations from its investigation into Google's search de listing practices. The OPC concluded that Google contravened PIPEDA by continuing to display media articles about an individual when that person's name was searched, and found that Canadians have a right to have certain information de listed in limited circumstances.
The filing exists because the Commissioner cannot make binding orders. Where an organization declines to implement recommendations, the route is Federal Court, and the OPC had one year from the release of its report to file. De listing removes results from search, it does not remove content from the internet.
- Application filed August 28 to make investigation recommendations enforceable
- Finding is that continuing to surface the articles on a name search contravened PIPEDA
- Filing is necessary because the Commissioner holds no independent order making power
Two things follow for Canadian organizations. First, an OPC recommendation you decline is not the end of the matter; it is the start of a court process on a one year clock, and litigation risk should be weighed against implementation cost at the recommendation stage, not after filing. Second, the substance matters for anyone operating a search, index, or recommendation function over personal information, including internal systems: if your product surfaces information about identifiable people, the ability to act on a de listing or correction request is becoming a design requirement rather than a support process. Privacy law reform under discussion would add order making and penalty powers, which removes the court step entirely.
The Privacy Commissioner Files Comments on Canada's Proposed Consumer Driven Banking Regulations
The Office of the Privacy Commissioner of Canada submitted comments on the proposed Consumer Driven Banking Regulations on August 26, the framework that will govern how Canadians authorize the sharing of their financial data between institutions and accredited third party providers.
Open banking regimes concentrate a specific privacy problem: consent given once at onboarding has to remain meaningful across an ongoing data flow between parties the consumer may never interact with again. The regulator's comments at the drafting stage indicate where its expectations on consent, purpose limitation, and accountability across participants will sit once the framework is operating.
- Comments filed August 26 on the proposed Consumer Driven Banking Regulations
- Framework governs consumer authorized financial data sharing with accredited providers
- Regulator positioning at the drafting stage signals its supervisory expectations
Any organization planning to participate in consumer driven banking, as a data holder, an accredited provider, or a technology supplier to either, should read the regulator's comments as an early statement of what will be examined later. The preparation is unglamorous and specific: a data flow map showing every party that touches consumer financial data, a consent record that can be produced on request and shows what was authorized and when, and a defined withdrawal process that propagates to downstream recipients. Financial services teams already certified to ISO/IEC 27001 have the management system; what open banking adds is proof of consumer authorization, which is a records problem before it is a security one.
Canada Buys 64 Senior Researchers for Its Universities, and AI Is One of the Named Priority Disciplines
The federal Global Impact+ Research Talent Initiative has recruited 64 international academics in its first round, with $504 million allocated over eight years for this cohort inside a $1.7 billion program targeting 100 researchers. Health, environment, AI, and biotechnology are the named priority disciplines. Forty eight of the 64 come from United States institutions including Cornell, Harvard, Yale, and MIT, with four from the United Kingdom, two from China, and one each from Germany, India, and Japan among others. The University of British Columbia, the University of Ottawa, and the University of Toronto are among the receiving institutions.
Normand Labrie, chair of the Canada Research Coordinating Committee, framed the cohort around complex challenges and knowledge that strengthens communities. The program is explicitly built on conditions in the United States, where research funding cuts and restrictions on areas of academic study have made relocation attractive. Senior researchers do not arrive alone: they bring active collaborations, datasets, funding relationships, and graduate students, and those arrive with them.
- 64 researchers in round one; $504 million over eight years inside a $1.7 billion program
- AI and biotechnology named priorities alongside health and environment
- Forty eight recruits from US institutions; UBC, uOttawa, and the University of Toronto receiving
Concentrating AI and biotechnology expertise inside a few Canadian institutions raises their value as a target, and the Bitkom numbers earlier in this review show where that pressure comes from. Research security is the governance work that has to arrive with the funding: due diligence on inbound collaborations and their funders, classification of which datasets and methods are sensitive, and access controls that survive a researcher moving institutions or a student returning home. Canada's National Security Guidelines for Research Partnerships already set that expectation for federally funded work in sensitive technology areas, and AI is one of them. For companies partnering with these institutions the practical consequence is contractual: define who owns the data, who may access it, where it is stored, and what happens at the end of the project, before the work starts rather than at publication.