www.thestar.com - RSS Results of type article
· collected 2026-09-06 · by Nicholas Keung
Canada Border Services Agency (CBSA) is woefully behind when it comes to protecting its only facilities at airports, ports of entry and offices from security threat and risk, an audit found.
asserted
audit → come → threat
A recent effort to catch up on that work has exposed major shortcomings: Unauthorized people walked into secure areas through “piggybacking.”
asserted
people → catch → piggybacking
Surveillance cameras were missing or too blurry to be useful to guard the facilities.
asserted
cameras → miss → facilities
And official stamps used to process travellers and goods at ports of entry couldn’t be accounted for.
asserted
stamps → use → entry
The report examined the security controls at premises of the border agency, which operates in more than 1,000 facilities across the country, including airports, land border crossings, mail processing centres, warehouses, telephone reporting sites and office buildings.
asserted
which → examine → airports
Of the 410 sites classified as “critical facilities,” 312 or 75 per cent had no records of threat and risk assessments or had one that was more than five years old — and only 69 or 40 per cent of 162 “medium and high-risk” premises had a valid evaluation, the internal audit found.
asserted
audit → classify → evaluation
“This indicates that the agency does not have a comprehensive or up to date baseline understanding of the risks and vulnerabilities present in most of its facilities,” said the report, released on Monday.
asserted
report → indicate → Monday
Advocates say they are alarmed by the pushback of immigration authorities against migrants trying to exercise their right to protest.
asserted
they → say → right
Advocates say they are alarmed by the pushback of immigration authorities against migrants trying to exercise their right to protest.
asserted
they → say → right
Security and intelligence expert Wesley Wark said it’s incumbent on every federal department and agency, especially those with a role in national security, to protect their data and infrastructure.
asserted
it → say → data
“That level of seriousness in terms of responding to a potential threat is not there for CBSA and improvements have to be made,” said Wark, a senior fellow at the Centre for International Governance Innovation.
asserted
Wark → respond → Innovation
“This is an important responsibility that needs to be done in a better, more rigorous way.”
asserted
that → need → way
The CBSA audit, covering the period between April 2022 and September 2025, focused on its physical security rules and oversight, internal controls and processes such as risk management, as well as monitoring and reporting of physical security activities.
asserted
audit → cover → activities
Auditors reviewed more than 300 documents, interviewed over 75 people involved and affected by these measures and visited 18 sites with walk-throughs in facilities in Ontario, the Pacific and Quebec regions.
asserted
Auditors → review → regions
They pored over 180 physical security recommendations issued during the audit period but found only 25 per cent had been implemented, while the rest were either not carried out or could not be confirmed, indicating the identified vulnerabilities may have persisted, the report warned.
uncertain
report → pore → period
The border agency’s management attributed the lacking valid threat and risk assessments to other priorities and limited human and financial resources.
asserted
management → attribute → priorities
Reasons for lagging implementations included insufficient funding, infeasibility and no clear order of priority.
asserted
Reasons → lag → priority
In an email, CBSA said it’s on track to complete all ongoing threat and risk assessments by March 2027, at which time it will establish annual compliance monitoring of threat risk assessment recommendations.
asserted
it → say → recommendations
“We treat this matter seriously and take immediate action whenever gaps in physical security are identified,” said the agency, which has conducted an internal analysis to ensure its physical security data is accurate and up to date.
asserted
data → treat → date
“The CBSA has worked to address these issues over recent years by investing in physical security elements such as alarm systems, distress alarms, lighting, fences, barriers, signage, doors and windows.”
asserted
CBSA → work → systems
During a number of walk-throughs in various locations, audit team members were able to access all secure and non-secure floors unannounced, at various times of day, without access cards or visible CBSA identification.
asserted
members → access → cards
They were let in by occupants of the floors or entered through “piggybacking” — following an authorized person.
asserted
They → let → person
They were only questioned on one of the six secure floors and two of the nine non-secure floors.
asserted
They → question → floors
On two occasions, employees were found to be away from their workstations, with computer screens unlocked and unattended.
asserted
screens → find → workstations
Sensitive documents were left at printers, including financial documents and documentation containing personal traveller data such as names, passage dates, passport numbers and dates of birth.
asserted
documents → leave → birth
“In some instances, the audit team was also able to consult paper documents with Protected B and C information, in cabinets that were left open, without being questioned,” said the report, referring to classified information pertaining to private personal data and business records.
asserted
report → consult → data
Although all 18 inspected sites had some form of electronic surveillance or CCTV infrastructure, problems were identified at half of them, including no coverage in key operational areas and low-quality resolution:
- There was no CCTV installed at one primary inspection lane that processes millions of crossing vehicles yearly;
- Three other locations had no CCTV coverage in areas such as the bond rooms, where seized goods are held;
- The remaining five locations had CCTV cameras with such poor resolution that in some cases images were not visible.
asserted
images → inspect → cases
“The most significant deficiencies were noted in one facility that had no electronic access management system; the entire Port of Entry (POE) leveraged locks with a pin code and/or keys with the same code for the entire facility,” the audit noted.
asserted
audit → note → facility
“This facility had no intrusion alarm, although the audit notes that it is manned 24/7 with officers.
asserted
it → have → officers
Another three POE had access management systems which were deemed to be at a very high risk of failure.”
asserted
which → have → failure
Gaps in port stamp management
The team also audited the management of port stamps that are used to identify the date, location, purpose and duration of a traveller’s authorized stay, or the personal and commercial goods entering and exiting Canada.
asserted
that → audit → Canada
They authenticate documents and identify the issuing officers with their unique numbers.
asserted
They → authenticate → numbers
They found that the government’s database was consistently out of date and didn’t match the actual stamps on hand at border crossings, while others in the system were missing, damaged, moved, reassigned or unaccounted for.
asserted
others → find → system
There were also stamps in storage that were not in the inventory data.
asserted
that → be → data
“Compromise, such as a lost or stolen stamps, can directly impact the integrity of Canada’s border,” the report cautioned.
asserted
report → lose → border
Throughout his nine years in Canada, the Egyptian man has gone through — and passed — three extensive security checks by multiple federal agencies.
asserted
man → go → agencies
Throughout his nine years in Canada, the Egyptian man has gone through — and passed — three extensive security checks by multiple federal agencies.
asserted
man → go → agencies
Security expert Wark believes the gaps identified in the audit have more to do with what he calls the “security culture” at CBSA, rather than lacking resources because infrastructure such as access controls and CCTV cameras are not “a big money pit.”
asserted
infrastructure → believe → controls
He said a lot of people don’t understand the threat and risk until they are convinced to take it seriously, but more often than not major changes only happen after there’s a security crisis.
asserted
changes → say → it
“The security culture at CBSA is a little more lax than they should be comfortable with,” said Wark.
asserted
Wark → say → CBSA
…and 5 more, not listed.