Canada is Guest Country at BE-CYBER this year. Why is this the right moment to put the Canadian cybersecurity ecosystem in the spotlight?
The timing is particularly relevant because cybersecurity is undergoing a fundamental shift. For many years, we tended to think about cyber primarily in technical terms: protecting networks, deploying security products and responding to incidents. Those things remain essential, but the discussion has become much broader. Companies are now dealing simultaneously with ransomware, AI-enabled attacks, supply-chain vulnerabilities, geopolitical risk, regulatory requirements and questions around data and digital sovereignty.
Canada is facing many of the same challenges as Europe. Our latest National Cyber Security Strategy therefore takes what Canada calls a whole-of-society approach, bringing together government, business, academia, critical-infrastructure operators and international partners. That philosophy fits very naturally with this year’s BE-CYBER theme: “Cyber Renaissance – Where Trusted Collaboration Becomes Capability.” For companies, that matters because resilience cannot be purchased as a single product. It depends on technology, people, processes, trusted suppliers, information sharing and ultimately collaboration across an ecosystem. Our four Canadian speakers come from very different backgrounds, but together they tell a much bigger story about the Canadian approach to cybersecurity.
What actually distinguishes the Canadian cybersecurity ecosystem? Many countries today describe themselves as strong in cyber.
One of Canada’s real strengths is the combination of technology talent, research capacity, entrepreneurship and institutional collaboration. The ecosystem is also geographically diverse. Important clusters have developed across Canada, each with different strengths. There is a broad network of dedicated cybersecurity research institutions, and their capabilities go quite deep technically. The Canadian research landscape includes work in cryptography, privacy-enhancing technologies, quantum-resistant security, blockchain security, AI, network security and IoT security.
Perhaps the more interesting point for companies is what happens between research and the market. Canada’s National Cybersecurity Consortium was specifically designed to connect universities, private industry, governments and other organisations around R&D, commercialisation and training. Its areas of focus include critical-infrastructure protection, human-centric cybersecurity, network security, privacy-enhancing technologies and software security. That capacity to bring different players around a problem is one of Canada’s strongest characteristics.
From the perspective of a Belgian CEO or CISO, where are Canadian companies particularly relevant?
I would highlight several areas. The first is human cyber risk. The industry has become much more sophisticated in understanding that employees should not simply be treated as the weakest link. The objective is to understand behaviour, build a security culture and give people the tools to recognise and manage risk.
A second area is critical infrastructure and operational resilience. Canada is a large, highly connected economy with energy, telecom, transportation, financial, healthcare, defence and government systems spread across a vast geography. Protecting those interconnected systems creates practical expertise that is relevant to many European operators.
Third, I would point to secure digital infrastructure and defence. Cyber assurance is increasingly becoming a requirement throughout supply chains rather than something confined to the prime contractor. Canada is implementing a new Canadian Program for Cyber Security Certification for defence suppliers, and the programme has deliberately been aligned with international standards and allied requirements. That illustrates an important broader development: cybersecurity is increasingly becoming a condition for doing business.
Then there are specialist capabilities around privacy, software security, cryptography, quantum-safe technologies, AI security and secure cloud environments.
The four Canadian speakers at BE-CYBER have quite different profiles. What do they tell us about the Canadian approach?
I think their diversity is a strong element of Canada’s participation.
David Shipley, CEO and Field CISO of Beauceron Security, opens the conference with the keynote. His work centers on cyber risk, security culture and the role of people and behaviour.
Kevin de Snayer, Vice President of IT, Cyber and EMSEC for Calian Defence and Space, brings another dimension entirely: defence, critical infrastructure, secure digital transformation, sovereign cloud, electromagnetic assurance and mission-critical systems.
Richard Larose, Cyber Principal and Advisor for Cyber Partnership at the Communications Security Establishment Canada, will address collective resilience and the consequences of coordination succeeding—or failing—under sustained systemic pressure. That connects directly with Canada’s growing emphasis on cooperation between government, critical infrastructure and industry.
And Stephanie Carvin, Associate Professor of International Relations at Carleton University’s Norman Paterson School of International Affairs and a former Government of Canada national-security analyst, brings the national-security and critical-infrastructure perspective. Her contribution is centred on putting security practitioners back at the centre of defence.
Thus, you move from people to companies and infrastructure, to collective resilience, to national security and defence.
AI, geopolitics and digital sovereignty feature prominently in this year’s programme. How are these issues changing cybersecurity for companies?
The biggest change is that cyber risk has become inseparable from business risk and geopolitical risk. The Canadian Centre for Cyber Security’s National Cyber Threat Assessment identifies several trends that should be familiar to European companies: state actors becoming more aggressive, ransomware continuing to threaten critical infrastructure, digital supply-chain attacks, and AI lowering the barriers to sophisticated cyber activity. It specifically warns that generative AI can make social engineering and phishing more convincing and easier to deploy at scale. That has consequences at the board level.
A company may be highly secure internally but still depend on a cloud provider, software vendor, logistics operator or industrial supplier that creates a vulnerability. It may be adopting AI much faster than it can establish governance around it. Or it may discover that data residency, access to infrastructure or foreign technology dependencies have suddenly become strategic issues. This is where the concept of digital sovereignty needs some nuance. Sovereignty should not mean isolation or trying to build everything domestically. For a business, it is much more about understanding dependencies, retaining meaningful control, building resilience and having trusted alternatives. That makes international partnerships more important, not less.
Why do you see Belgium and Canada as particularly complementary in cybersecurity?
Belgium is an interesting market because it combines several things in a relatively small geographical area. You have sophisticated financial institutions, telecom operators, major transport and logistics infrastructure, industrial companies, healthcare and pharmaceutical players, a growing defence sector and an active cybersecurity industry. You also have NATO, the EU institutions and a very strong academic and research environment. Canada brings complementary capabilities, and our companies also need European partners.
That last point is important. I do not see the relationship as simply Canadian companies coming to Belgium to sell Canadian technology. A Belgian integrator may want to add a Canadian solution to its portfolio. A Canadian technology company may need a Belgian partner that understands NIS2, DORA, European procurement or local customer requirements. A Belgian cybersecurity company may use a Canadian partnership to develop its North American presence. Universities and companies can also collaborate on new technology. There are already mechanisms to make that practical. Thus when we talk about collaboration, it can be very concrete: a customer relationship, a distribution partnership, joint R&D, technology integration or joint market development.
Canada and Europe are often described as “trusted partners”. What does that actually mean commercially?
The useful interpretation of trust is about predictability and compatibility. If two markets have broadly compatible expectations around security, privacy, responsible technology, research integrity and the rule of law, it becomes easier for companies to develop long-term partnerships. That type of relationship is also becoming more strategic.
Canada and the EU launched negotiations for a Digital Trade Agreement in March 2026, building on CETA, with both sides explicitly linking the relationship to trade diversification, economic security and resilience. Belgium already has a substantial commercial relationship with Canada with C$2.3 billion (€1.4 billion) in bilateral services trade. There is already a foundation. The opportunity now is to deepen the digital and cybersecurity dimension of that relationship.
Finally, what should a Belgian company expect from Canada’s presence at BE-CYBER?
I encourage companies to use BE-CYBER as a place to compare approaches and identify potential partners. If you are looking at your supply-chain exposure, human risk, AI governance, secure cloud architecture, defence requirements or critical-infrastructure resilience, there is likely someone in the Canadian ecosystem worth speaking to. Equally, Canadian companies are coming to Belgium because there are Belgian capabilities and partners they want to discover. That is where the value of BE-CYBER lies: turning trusted conversations into concrete capability—and potentially into business.
BE-CYBER 2026 takes place on 22 September 2026 at La Sucrerie in Wavre, with Canada participating as Guest Country under the theme Cyber Renaissance – Where Trusted Collaboration Becomes Capability.
