Showing posts with label Canada. Show all posts
Showing posts with label Canada. Show all posts

Saturday, 18 November 2023

Cyber Education in Canada is Broken, Here's How to Fix It

I've been sitting on this one for some time. What's below is more like brainstorming than a clear solution, but I feel like it's moving in the right direction...

The Problem: Canada's Cyber-education system is broken - or doesn't exist at all

I've been ruminating on this since virtually attending the "How to protect our children in an increasingly digital and online world" meeting by Economic Development Ontario and the Canadian Trade commission a couple of weeks ago. James Hayes from Cyber Legends is a man on a mission. His keynote was both insightful and frustrating - the main point being that Ontario (and by extension Canada)'s cyber-education ecosystem is broken. I'd go so far as to say that in most places it doesn't exist at all; broken implies that there was something there to begin with.

This observation speaks to a cultural challenge that Canada faces. Other countries are able to leverage a collaborative approach to the asymmetrical global threat cyberattacks pose, but Canada's history and the loose confederation it has produced creates many gaps between levels of government. Those gaps are where cybercriminals operate.

The Problem: cybersecurity, cybersafety and online privacy are barely mentioned in Canadian school curriculum and educators are some of the least digitally experienced professionals able to resolve this skills crisis

In Ontario we've mandated mandatory eLearning for all students, but cybersecurity only just got into the computer studies curriculum in this year's rewrite, and what's there is thin (it immediately devolves into personal online data awareness and ignores the many interesting technical specialities in cybersecurity). This optional course doesn't run in most high schools (it was cancelled locally in mine), so this one mention isn't seen by most students.

Many other provinces don't mention cybersecurity at all even as they all depend on it every day with networked education technology delivering material in every classroom. Cyberskills are now essential skills if we want to keep the learning happening, but aren't treated that way in our education systems. New Brunswick is the exception with a full cyber-learning pathway for students interested in heading into the field professionally. Why does that matter? There is a global shortage of cybersecurity professionals, so Canada's usual approach of immigrating in solutions to its education failings won't work in this case.

James mentioned teacher cyber-illiteracy in his keynote as well.
There are solutions like CyberBytes that offer upskilling...
Our oblivious response to cybersecurity awareness is part of a larger problem in public education. When I first came into teaching in 2003 I was surprised to see the education system rocking early 90s information and communication technology. Throughout my career education has dragged its feet at every opportunity in terms of adopting digital transformation and the benefits it delivers. The result of this decades long drag is that people in education tend to be less digitally literate than the general population, even as they are expected to teach students essential digital skills like cyber awareness. 
Teachers are precisely who you want to be raising general cyberawareness and the skills needed to safely navigate our online world, but decades of status quo leadership means educators are missing the digital media literacy necessary to do it.


The Problem: we're happy to make online edtech solutions mandatory (usually as a cost cutting measure) but a surprising percentage of the people doing it don't think they should be held legally responsible for its safe delivery


I spoke on a panel about cybersecurity at the Canadian Edtech Summit the week before. The event had an online component so I started a poll aimed at the education administration and technology companies in attendance. Recently the SEC in the US sued a company for their failure to respond to cybersecurity problems that they were very much aware of that resulted in many clients' data being spilled onto the darkweb. This raises an interesting policy question: should school boards and provincial education ministries be held legally responsible for cybersecurity in Canadian classrooms? Canadian educational ministries and their school boards have increasingly adopted cloud based solutions to reduce costs on what used to be locally managed technology integration, but with internet based 'cloud' solutions come cybersecurity responsibilities. This US decision will likely influence our lax cyber responsibility policies in Canada and I was curious what the people implementing these technologies (often poorly) thought of the potential for liability penalties for failing to protect student data (which often also includes staff and family personal data too).

I expected the people delivering online edtech (school boards, ministries, not-for-profits and private edtech companies) to recognize that cybersecurity is very much their responsibility if their technology is vulnerable online, especially if they are going to demand that students use online learning tools. This should be especially obvious when our 'clients' are vulnerable sector children whose safety should be a primary concern.

Most did recognize the importance of taking responsibility for their technology delivery, but I'd love to have a chat with the quarter or so who thought they should be putting student learning online while bearing no legal responsibility for it. One of those people could well be managing your local school board's technology department.

If we've got a problem with the people delivering online edtech understanding that they are responsible for cybersecurity, we need to back the bus up and clarify those responsibilities with policy - legally binding policy.  I recently saw a memo which said data privacy wasn't even a paid job in the school board and is done outside of regular work responsibilities by IT staff, most of whom have no cybersecurity experience. Until we begin taking public sector cybersecurity seriously we will continue to see our public services being disrupted by breaches and system failures.

NIST's cybersecurity framework offers a technical policy approach to cybersecurity that clarifies what organizations need to do to provide viable online security. ISED has a Canadian version called ITSG-33 which is more policy focused.  This isn't an all or nothing thing with a solution for every problem. Any time you put data online you risk being hacked, but by following these best practices you can at least know you've taken reasonable steps towards preventing abuse. What you want to do is get up to Tier Four of the NIST framework where you're proactively defending against threats, but public education in Canada can't get out of Tier Two because "implementation is still piecemeal", and no one has "the proper resources needed to protect themselves." Our cyber failures in Canadian education are the result of poor policy and the resultant lack of funding. I'd hope that we'd follow best practices in protecting student data, but that ship sailed years ago. If that carrot isn't available, then a legal policy stick might be the only thing left that prompts ministries and schools to make student data privacy a priority.


The Problem: Public services in Canada are siloed bureaucracies that are difficult to work with


This isn't just an education problem, it's a
CANADA problem. Canada's history hasn't
produced a culture that can collaborate
against asymmetrical global threats.
During the panel talk at the EdTech summit one of the speakers said, "working with public school boards is very difficult. It can take years just to find the right person to talk to. Even if you can find that person, they'll tell you there are no resources." I talked to Kyle Bokyo, another of the panelists, after the event and we commiserated on this point.

There are not for profits and businesses in Canada who are attempting to provide solutions to Canada's ongoing cyber-education failures, but attempting to engage with any public service in Canada is a a difficult prospect. If you talk to the ministries they hold up their hands and say they only manage the funding and not the implementation of cybersecurity solutions. If you talk to the regional school boards they say that they aren't provided resources to do it.

In Canada's uncoordinated cyber policy landscape I suspect it's easier to play victim even as you assume greater cyber risk pushing user data into the cloud than it is to develop a coordinated response to this very asymmetrical problem. These gaps in responsibility make it easy for the people paid to protect student data to point the finger at each other rather than solve the problem, even as breach after breach occurs.

Canada's failure to
coordinate cyber response
is recognized as an
problem globally
.
What I learned through COVID as a classroom teacher is that the people running public education will ask all manner or ridiculousness just to maintain the illusion of a functional system. It's what got them into their offices and they aren't about to jeopardize that. Public education, along with other public services, are insular industries with generational employees and tightly knit networks of political operatives managing them. This might sound like immigrant complaining (and it is), but the best way to get into education 'leadership' is to have had family who did it, or marry into one. The next best way is to be willing to maintain the status quo at all costs. Agility and responsiveness aren't words often applied to this sector.

Cybersecurity in public education is dangerously under-prioritized even as we continue the rush to cloud based edtech solutions in an attempt to save money. On top of that a surprising percentage of the people delivering these solutions don't think they should be held legally responsible for its safe delivery. This deadlock suggests that we need policy that not only enforces best cybersecurity practices in education, but also makes resources for it a requirement rather than a politically motivated shell game.

But the fix needs to go further in education because we also have a responsibility for providing graduates with opportunities to learn the skills they need to survive in a rapidly changing world; something we're not doing as many jurisdictions continue to studiously ignore cyber education and digital skills in general. The key piece to this puzzle is policy that creates a responsive, responsible Canadian cybereducation system. In aligning resources to create cybersecure online learning we might also usher in a new era of relevant, richer digital skills development.


The Solution: A Viable 21st Century Canadian Digital Education Ecosystem

As both James and Kyle mentioned in their talks, technology moves so quickly that large public services are always going to struggle to keep up, but an agile edtech sector could help with that. Startups and small businesses can pivot to keep up with technology emergence in a way that larger organizations struggle with - that's why Google and the rest buy agility rather than trying to produce it in-house. The problem has been Canada's pigeon hole approach which doesn't aim to produce a coherent ecosystem of interrelated programs that provide a comprehensive Canadian shield.

As mentioned previously, the issue of regional school boards and provincial ministries making it difficult for anyone outside of these insular systems from collaborating with them is a key problem. We can't leverage digitally literate industry partners if they have no way to effectively communicate with education delivery systems.

The solution is to connect the federal government with the Council of Ministers of Education, Canada and The Insurance Bureau of Canada and design a centralized approval process that connects Canadian not for profits and industry edtech expertise with provincial ministries and clears the way for access to credible cybereducation materials through direct internal communications channels with education systems. Instead of individual boards doing cyber badly, a national partnership with a wide range of technology specializations and strengths would work together to build solutions at scale while also ensuring that these solutions are prioritized with mandatory funding. This relationship would also prompt meaningful updates to curriculum instead of the current 'in a bubble' approach that produces material well short of what is needed to prepare graduates for our technically challenging future.

I made this graphic after last year's CPI conference
at University of Waterloo
, where I first met James,
Cheryl and Cyber Legends.
In such an environment a startup like James' Cyber Legends, or an internationally partnered and long running national competition like CyberTitan would pass NIST levels of cyber-review nationally and then be welcomed into a Canada-wide edtech ecosystem that works through each provincial and territorial education ministry directly into school boards. Any edtech company working outside of this framework would find itself where we all do now: on the outside unable to make any significant change. But those who meet this national standard would be considered trusted internal partners with access to federal funding and direct internal access to provincial education at both the ministry and district levels. No more trying for years to find a person who may (or most likely doesn't) exist in a local school board who is in charge of cybereducation.

This ecosystem would reward collaboration. Members would only be accepted if they are producing complementary resources that create a full range of learning opportunities to all aspects of our increasingly digital world across all subjects, including cybersecurity. This nationally curated resource allows teachers from all corners of the country to develop meaningful digital skills, including the difficult ones to deliver like cybersecurity. This equity of access to resources would end nationally embarrassing PISA results that prevent smaller provincial education systems who lack resources from producing results below the world average.  Members of Canada's edtech program would find funding easier and be able to work with partners who ensure that their programs are successfully integrated and in a constant state of improvement in order to keep up with the impressive rate of technological change we're all dealing with. This would also give those providing federal funding clear guidelines for who they should be supporting.

The stick would come through policy changes that are both legal and regulatory. Any school board (and by association ministry) not making use of these secure, partner provided resources for improving student data protection would find themselves both liable for any breaches, and also uninsured. Educational cybersecurity would no longer be a political blame game. Local implementation would still very much remain the purview of school districts, and ministries would remain very much in charge of funding their province or territory, but with focused federal support many of the associated expenses would be reduced through the centralization of resources. These savings would also be a carrot. With national cyber standards and partnerships that leverage the strengths of all members of Canada's education ecosystem (federal government, private industry, national not for profit, education ministries, and local school boards), Canadian students would enjoy access to more Canadian made digital learning opportunities that raise digital fluency in a meaningful way, and they could do this while also exploring cybersecurity in a way that creates a more secure Canada. Imagine what all these cyber-aware students could do for our national security. It's the only solution we have that scales to meet the problem. Those students go home and raise cyberawareness in their families and communities, reducing the main reason for successful cyberattacks.

We have a habit of regionalizing our approaches to government in Canada, but in the face of wildly asymmetrical threats like cybercrime and (increasingly) international cyber espionage, we need to push back against this culture and build a collaborative defence. In doing so we would also create much richer digital learning opportunities in our schools that would make Canada more secure and competitive in the networked, global economy.


The Solution: collaboration doesn't end locally, regionally or even nationally in Canada

I'm attending The Global Forum for Cyber Excellence's inaugural Global Conference on Cyber Capacity Building in Accra, Ghana at the end of November. 

"It is paramount for all nations to have the expertise, knowledge and skills to strengthen their cyber-resilience"

I'm presenting a research paper a former student and CyberTitan (Louise Turner) and I have written about the disruption quantum computing will cause to cybersecurity encryption in the coming years. Doing this research with Louise has been both eye opening and very intellectually satisfying, but after 20+ years in the classroom I'm still very much a cyber-educator first and a cyber researcher second. It's why I invited one of the next generation of cyber professionals to write the paper with me.

Looking at the program for the conference, the lack of talent and focus on developing cyberskills both in the population and in those interested in pursuing work in the industry isn't a Canada only problem, it's a global one. If we can repair Canada's internal cyber-education system, we can then work with international partners to help them do the same. The cyber battlefield inherently favours the anonymity of hackers damaging our systems with impunity for their own gain, but through collaboration the defenders could become mighty. A cyber-aware population would be foundational for reducing cyberattacks in our public services.

As the GFCE so eloquently puts it: "Nations should work together and support each other with these capabilities, so that no country is left behind in their digital evolution. After all, a chain is only as strong as the weakest link."  Look for the Accra Call: a global action framework that supports countries in strengthening their cyber resilience being announced during the conference.

Saturday, 15 October 2022

Creating A Canadian Cybersecurity Ecosystem

Last week I attended my first conferences in a long time. Someone will have to explain to me why classroom teachers have no access to professional development like this. On Wednesday and Thursday morning I was at SecTor in Toronto, making many new contacts in industry and realizing that the vast majority of companies on the front lines of cyber-defence in Canada are eager to help both the public and public education get a handle on cybersafety and digital hygiene. On Thursday afternoon and Friday I was at the University of Waterloo for their Privacy & Cybersecurity Conference. These were two very different conferences with SecTor clearly focused on industry and sales and Waterloo's CPI on academic research and strategic thinking, but you'd be amazed how well the two fit together. I really wish they'd arrange things so people could do one and then the other instead of overlapping them, but that failure to look after each other symbiotically is emblematic of a larger problem in Canada.


I had a great chat with a colleague at ICTC a few weeks ago where he described his approach as 'serving the ecosystem', which I intend to emulate.  He sees ICTC's role as helping everyone working in Canada's digital skills development space to meet the council's mission, which is to strengthen Canada's digital advantage in an ever more connected and volatile global economy.  This sounds like a big ask but I believe in the goal, and that belief gives me the energy to take on this seemingly insurmountable task.

One of my favourite moments from the Waterloo CPI conference was when one of the audience, after listening to how five universities are connecting to each other, interrupted with a clear and present warning.  He guaranteed that in the next five years Canadians are going to be sitting in the dark after a cyber-attack from a well developed foreign aggressor.  When we're all sitting there in the cold and dark with no electricity, gas or communications, will we think we've done enough?  Intense, right?

Early in the talk that question came up in, the head of TMU's CyberSecure Catalyst was talking about how he headed to Israel to see how they created a world-class cybersecure ecosystem in the most challenging of circumstances.  His takeaway?  The Israeli system is predicated on familiarity, trust and connectivity.  After only a month and a bit observing Canada's approach, it seems we're doing the opposite.  I've stumbled across excellent resources in both government academia and industry, but each one is working from its own funding formula and entirely focused on meeting the targets in that formula.  Even our connectivity is fractured with numerous 'networks' forming independently of each other, all with the idea of uniting us.  It'd be funny if it weren't so absurd.  Here are a few of them:
They're all doing good work, but they're doing it in silos and in many cases repeating material found in other programs.  It's neither efficient nor is it anything like the Israeli approach of centralized trust, familiarity and cooperative development.  I'm not surprised that, after announcing yet another Canadian network that'll cure our cyber-skills shortage (which is so bad that the government says we need to bring in talent to fill the gap), that guy in the audience lost his patience.

"The siloed approach we know doesn't work anymore. We think it should change and this budget didn't give us the warm fuzzies."

Christyn is exactly right, Canada's initial approach of jumpstarting as many programs as it could to try and cover the cybersecurity shortfall doesn't scale well now that cybersafety is a part of everyone's lives from individuals and small businesses all the way along to multi-national corporations and federal governments.  COVID only accelerated our dependence on digital connectivity yet we continue to lag behind in terms of cyber capacity, especially in education.

At the conference, Ontario's Ministry of Economic Development representative kept describing Ontario's many cyber-focused companies and educational organizations as an ecosystem, but a lot of potted plants all sitting in the same area are not an ecosystem, which is exactly Canada's problem.

How Canada is approaching cybersecurity capacity development.

How Israel does it - with trust, interconnectivity and familiarity - no silos, and everyone looking after each other.

Canada needs to work together to create a national focus on cybersecurity skills development starting in elementary school with integrated digital hygiene and cybersafety learning that leads to middle school access to programs like CyberTitan that introduce students to hands on I.T. skills that demystify the subject and open up pathways.  In high school everyone should be learning essential digital skills (which are atrociously poor - more than 80% of successful cyber-attacks are the result of user ignorance) as a mandatory course. Students interested in pursuing cybersecurity should have early access to coop and STEM programs that will set them on the right track for post-secondary - no adult upskilling required.  This is also where we need to address how our high schools genderize pathways, knocking many girls out of these opportunities.

If we can demystify cyber in k-12 we will be able to graduate cyber-safe students who are able to operate in our interconnected digital economy in every pathway.  Digital fluency and access to cyber-opportunities is, of course, also an equity and inclusion issue; these opportunities aren't just for wealthy, urban boys, though they continue to dominate the industry.  Emerging digital careers tend to be more future proof and higher paying, and everyone deserves a crack at them.

Canada is the only major federation and one of few countries in the world without a national education standard, leaving our minors open to wildly differing political influences and support in our schools; there is no such thing as 'Canadian Education'.  Rather than start with central administration, I think Canada should start with a canadian student bill of rights to protect minors from these changeable winds, but I digress.  Canada's fractured approach to education (like its fractured approach to cyber) means that we need to reach a critical mass with government and industry partners in order to break into the siloed world of canadian public education.  But with no central authority to get onside, a win in Ontario does not mean a win in Quebec, or anywhere else in the country.

Canada's patchwork approach to governance along with its challenging geography means we're facing barriers that Israel and other world leaders in cyber have never had to contend with, which is precisely why we need to pool our resources, grow an interconnected ecosystem of pubic and private cyberskills supporters and then take on this seemingly insurmountable task.

Cybersecurity might sound like an esoteric reason for this big of a challenge, but cyber lives at the pointy end of a pyramid of digital infrastructure needs that Canada is still sorely in need of developing.  Focusing on cyber means we're also focusing on equity and inclusion by connecting everyone, including remote northern communities, new Canadians and people who can't afford Canada's monopolistic telecom infrastructure, to the digital economy.  To get to cyber we need to get through device accessibility, network connectivity and digital skills development, which is why it's a worthy strategic goal. 

The trick is going to be getting all these disparate interests to unite in order to tackle Canada's unique and challenging geography and history - otherwise we're all going to be sitting in the cold dark in a few years wondering why we didn't do more when we could have.

***

UPDATE:  News from the frontlines of 21st Century war, which includes cyber:  

"Collaborating, exchanging information, assisting one another — this is the best way to thwart cybercriminals."

"All told, cyber resiliency relies on collaborative efforts from the global community, he said. Addressing the corporate audience, he underscored the importance of investing in and building a cybersecurity system as a strategic method to improve the cyber resilience of the state."


The importance of collaboration in cybersecurity, including in education and user outreach, is more obvious than ever as the Ukraine conflict continues.  One day Canada will be in the crosshairs, will we be ready?  Or will we have dozens of competing interests all producing redundant content?