Ownership Is Not a Security Control

Updated: 3 days ago
Commentary on "From Sovereignty to Control: A Clear-Eyed View of Canadian Cloud Policy" · Information Technology and Innovation Foundation

This series has made the sovereignty argument more than once. It is worth engaging seriously with the strongest case against it, and the ITIF report is that case. It also caused us to sharpen how we use the word, and this post reflects that.
The report's central move is to check the sovereignty framing against the actual threat record. Over four years at least twenty Government of Canada networks were compromised by actors linked to the People's Republic of China. Reported fraud losses climbed from $383 million in 2021 to $567 million in 2023. Average ransom payments reached $1.13 million, up nearly 150 per cent in two years.
Then the observation that does the damage: none of those incidents involved an American prosecutor with a warrant. The attacks compromising Canadian systems arrive through credential theft and misconfiguration, not through allied legal process subject to judicial oversight. Domestic ownership addresses none of them.
That is correct, and the sovereign compute conversation has been sloppy about it.
Where the report is right
A Canadian-owned facility with weak identity management is compromised exactly as fast as a foreign-owned one. Ransomware does not check the incorporation documents. The Canadian Centre for Cyber Security names ransomware as the top cybercrime threat to Canadian critical infrastructure, and the operational controls that address it, segmentation, privileged access management, monitoring, patching, backup integrity, are wholly independent of who owns the building.
Any operator claiming that domestic ownership makes data secure is selling something. It does not, and the industry's habit of using sovereignty as a proxy for security has earned this rebuttal.
Where the framing is too narrow
But the report answers a question about the attack surface, and the sovereignty case is about a different surface entirely.
The risk domestic control addresses is not intrusion. It is continuity and compulsion. Whether a service can be modified, degraded, or withdrawn by a provider responding to commercial pressure or to its home government's policy. Whether an allied jurisdiction's legal change reaches your data lawfully, without any intrusion occurring at all. Whether a dependency exists that a counterparty can price against you later.
More than half a million Canadians, including remote communities, emergency responders, and critical infrastructure operators, currently depend on a foreign-controlled satellite constellation for connectivity. Nothing in that arrangement has been hacked. The exposure is that the decision to continue it sits somewhere else.
That is not a cybersecurity risk. It is a supply concentration risk, and it is the kind of thing infrastructure policy has always been for. Countries do not hold domestic refining, transmission, or port capacity because foreign operators are careless. They hold it because dependency is a position, and positions get used.
Both are true and they need different instruments
The useful conclusion is that these are two distinct problems requiring two distinct responses, and Canada has been running them together.
Security is an operational discipline, verified through audit, certification, and continuous monitoring, and it should be required of every facility handling sensitive Canadian workloads regardless of ownership. Sovereignty is a structural property, established through ownership, control, jurisdiction, and residency, and it addresses continuity rather than intrusion.
A domestic facility with poor controls delivers sovereignty without security. A foreign facility with excellent controls delivers the reverse. Sensitive public workloads require both, and a procurement framework that treats either as a substitute for the other will buy the wrong thing.
What this means going forward
The federal programme's criteria already gesture at both, listing ownership, control, data residency, and Canadian vendor use alongside technical capability. What the ITIF report exposes is that the security half needs to be as specified as the ownership half, with named standards and independent verification rather than assertions in a proposal.
For operators, the implication is uncomfortable and correct. Claiming sovereignty is easy, because incorporation documents prove it. Demonstrating security is expensive, continuous, and auditable by people who will find things. The second is what a serious anchor customer will actually require, and it is the part of the sovereignty pitch this industry has been quietest about.
VOLTEDGE
Reference: "From Sovereignty to Control: A Clear-Eyed View of Canadian Cloud Policy" · ITIF · April 2026 · read the article




Comments