Sponsored by:
When summer 2026 saw autonomous AI agents push beyond the limits of secure testing environments, it underscored how rapidly the cybersecurity threat landscape is maturing and how much sharper enterprise defenses need to become as a result.
At Bell’s second cybersecurity summit in September, that momentum took center stage: Canada’s cybersecurity leaders, tech executives and government officials reconvened against the backdrop of these developments, making it clear how quickly the cyber landscape is evolving.
“Every time a new model comes out, it’s not incrementally better; it’s exponentially better,” said John Menezes, president and CEO of Bell Cyber. “Cybersecurity is now an economic issue, a national security issue and increasingly an issue of Canadian sovereignty.”
Menezes sees frontier AI as both a threat and an opportunity. The key, he said, is to build trust in the tools at our disposal, and give organizations confidence to embrace them.
“We have an extraordinary opportunity to put those capabilities to work for defense. The decisions we make now will shape our ability to trust and benefit from AI,” he said.
Here are three cybersecurity imperatives experts believe leaders need to act on to protect their data and critical infrastructure in a rapidly changing digital landscape.
Fight AI with AI
Experts were quick to point out that AI hasn’t changed the cat and mouse game of cyber attacks and defense, but it has changed the pace at which it’s played.
“We’re still dealing with social engineering, phishing attacks, compromised credentials and also inconsistent cyber hygiene,” said Mary Carmichael, field CISO at Bell Cyber. “What has changed? AI. We’re dealing with speed, scale and amplification of the impact of AI, especially on our business operations.”
Breakout times – how long it takes for a hacker to move laterally once the first machine has been compromised – are significantly shorter, at an average of 29 minutes according to CrowdStrike, while the fastest recorded breakout to date was just 27 seconds.
Rajiv Gupta, head of the Canadian Centre for Cyber Security, pointed out that these models have the skills to identify and exploit vulnerabilities that were previously confined to just a few hundred people in the world. “It’s a democratization of cyber exploitation capabilities,” he said.
Combating this speed and scale of attacks requires AI, Gupta said. “You can use it to actually find threats and detect threats autonomously, so that when people are using AI to exploit systems, you’re using AI to defend systems as well.”
The industry will rapidly move beyond “human in the loop” as a result, because humans simply can’t act at machine speed, Menezes said. Instead of having humans review and approve AI decisions before implementing them, we’ll rely on “human-guided autonomy”: enabling AI to act on its own within the parameters of clear guardrails.
“It’s really about accepting that humans can’t deal with the volume of information we’re going to have thrown at us and we’re not going to be able to make the decisions fast enough to protect our environments,” said Ash Rajendra, CIO of Superior Propane. “I strongly believe it’s just a matter of time before we’re in fully autonomous environments with really removed human decision making and we’re going to find the threat and capability associated are likely much more effective and acceptable for us than continued human assurance.”
Taking another step toward that autonomous future, Bell and Canadian enterprise AI company Cohere announced the deployment of a domain-specific cybersecurity AI model within Bell Cyber’s security operations. The specialized cybersecurity LLM operates on Cohere’s platform, trained with Bell Cyber data and running on Bell AI Fabric infrastructure; it’s being integrated into Bell Cyber’s Autonomous Security Operations Centre (ASOC).
Menezes likens it to putting an LLM in a box and ensuring it “eats, drinks and sleeps cybersecurity” within clearly established guardrails. Because the companies and data involved are entirely Canadian, “we now have a sovereign ASOC”, he said.
Treat sovereignty as a target benchmark – and a national opportunity
Sovereignty is top of mind for Canadians, but experts encourage business and government leaders to think expansively about what sovereignty means in the context of cybersecurity.
“Sovereignty, at its core, is resilience in the context of geopolitical disruptions and tensions,” said Michel Richer, president of Bell AI, AI Fabric: Operations and Quantum.
Lukas Lhotsky, president of Bell Sovereign Platforms and National AI Alliance, put it in a pragmatic context: Who has what rights to turn things off? And what courts control certain jurisdictional decisions?
“The way we’ve been defining this is that the only jurisdiction that could compel us to act is a Canadian one,” Lhotsky said.
But it’s challenging when the data is subject to other rules of law – and most Canadian data, even if it resides in Canada, is still housed by a U.S. entity. “We don’t have a Canadian hyperscaler,” Menezes pointed out.
Lhotsky recounted a recent conversation with a senior executive at one of the largest Canadian banks. “He told me with great clarity that the entirety of their data, not part of their data, is extrajurisdictional. We’re talking about a tier one financial institution that has this extrajurisdictional risk that is material and real to the way in which they operate.”
Menezes suggested that Canada is at least 10 to 15 years away from achieving true data sovereignty, and emphasized that it will require significant commitment and investment from government to support Canadian companies.
To that end, Lhotsky proposed that a focus on data sovereignty alone isn’t sufficiently dimensional. “Sovereignty should also be about economic opportunity in this country,” he said.
He sees the discussion of sovereignty as an opportunity to reframe the narrative about what’s possible to build and scale here in Canada – particularly when Canada is uniquely positioned to lead and succeed as the digital economy ultimately becomes a trust ecosystem.
“My great aspiration is that we can break this as a politicized word and use it as a mechanism to work more effectively together, to repatriate Canadian jobs, to build intellectual property here, to industrialize our asset base in a new and emerging digital economy,” he said.
Prioritize collaboration over competition
That economic opportunity will be grounded in deep collaboration, as opposed to competition, across organizations and industries.
“Security isn’t necessarily a competitive advantage because we all work with each other. Sharing threat information makes it that much better in terms of a resilient ecosystem, which is what we really need,” said Abhay Raman, senior vice-president and chief security officer at Sunlife.
Tara Drover, chief information officer at Hatch, described how the global engineering and project delivery firm is sharing more and more data amongst international teams, clients, vendors and partners, each resulting in more connection points that need securing.
“We’re dealing with different maturity levels of the supply chain, which requires different levels of sophistication in terms of technology and protection,” she said. “Not all of our clients and supply chains are ready to deal with data.”
Carmichael phrased it as “inheriting your vendor’s vendors’ risk.”
For that reason, Raman called for organizations to return to the fundamentals. “It’s really important to get our hygiene right, to have visibility into your assets, your identities, into where your data is sitting. Because if you assume breach, to recover and reconstitute, you need to know what you have and where,” he said.
“If we can’t close our fundamentals, it’s going to be harder and harder for us to recover from compromise in the future.”
For Ash Rajendra, CIO, Superior Propane, that “all in this together” mentality makes partnering with specialized third parties an easy decision to bolster your organization’s defenses.
“That is why we’re a Bell Cyber partner. [Cybersecurity] is not our core competency,” Rajendra said. “We need partners at the table to upskill us and provide an injection of talent where we don’t have it.”
Prepare for even more accelerated change
Above all, Menezes said, it’s vital for business and government leaders to adopt an agile approach, “because the policy you develop today is going to be obsolete next month” given how fast technology is evolving.
“The fundamentals of cyber will remain the same, but AI is just forcing us to do things faster, and it’s something we’re not used to,” he said. “We need to dramatically change the way we think about how we defend ourselves.”
This content was paid for and directed by Bell and was produced independently of The Logic’s newsroom in consultation with the advertiser. You can read our policies on advertising, sponsorships and partnerships here.
Loading...
Thanks for sharing!
You have shared 5 articles this month and reached the maximum amount of shares available.
CloseThis account has reached its share limit.
If you would like to purchase a sharing license please contact The Logic support at [email protected].
CloseGift the full article!
You have gifted 0 article(s) this month and have 5 remaining.
Recipients will be able to read the full text of the article after submitting their email address. They will not have access to other articles or subscriber benefits.