- $240 billion: Projected global cybersecurity spending in 2026
- 75% increase: Data breach notifications in Quebec over one year
- 1,500+ experts: Attendees expected at the GoSec conference in Montreal
Experts agree that the escalating cyber threats require a paradigm shift from reactive IT security to proactive, intelligence-driven strategies, blending corporate and espionage-grade defense tactics.
From Spycraft to Server Rooms: The New Frontier of Corporate Defense
MONTREAL, QC – September 15, 2026 – A fundamental paradox is haunting the global economy. As cybersecurity spending is projected to hit a staggering $240 billion in 2026, the frequency and severity of data breaches continue to escalate. In Quebec alone, notifications of security incidents to the province's information commission leaped by 75% in a single year. This disconnect—more money in, more data out—is the central challenge that will convene over 1,500 experts in Montreal for the 24th edition of the GoSec conference later this month.
The event has built its reputation on tackling the industry's most intractable problems by uniting the two sides of the corporate security coin: the executives in the boardroom who translate risk into strategy, and the technical practitioners on the front lines who build and maintain the digital defenses. But this year, the conversation is being shaped by a new and telling perspective, one that signals a profound shift in how we must approach corporate security.
The Intelligence Doctrine in Corporate Security
Headlining the conference is Ross Young, a figure whose career path embodies the evolving nature of the threat itself. Young is a former CIA intelligence officer who transitioned into the corporate world to become a Chief Information Security Officer (CISO). This is not merely a career change; it is a migration of an entire discipline. His journey, which includes high-level security roles at Capital One and Caterpillar Financial and a current position as CISO in Residence at venture capital firm Team8, illustrates a critical realization: defending a modern enterprise now requires the mindset of an intelligence agency.
For over a decade, Young honed his skills within the U.S. intelligence community, including the CIA, NSA, and the Federal Reserve Board. This background provides a starkly different lens through which to view corporate threats. Where a traditional IT security manager might see a malware infection, an intelligence analyst sees a potential actor with motives, resources, and a strategic objective. This shift from a reactive, tool-based approach to a proactive, intelligence-driven strategy is at the heart of the new security doctrine. Young’s work, such as the creation of the OWASP Threat and Safeguard Matrix (TaSM), aims to formalize this very process, helping organizations map threats to concrete defensive actions based on an analytical framework, not just a vendor checklist.
The inclusion of a speaker like Young signifies that the line between corporate espionage and nation-state cyber warfare has blurred to the point of being indistinguishable. The tactics once reserved for geopolitical conflict are now routinely deployed against financial institutions, manufacturers, and infrastructure providers. Consequently, the skills required to defend them must also evolve, incorporating principles of counterintelligence, threat modeling, and strategic adversary analysis.
Deconstructing the $240 Billion Paradox
The central paradox that GoSec aims to confront is not just a talking point; it's a symptom of systemic issues within the cybersecurity industry. The projection of a 12.5% year-over-year spending increase, according to Gartner, juxtaposed with rising breach statistics, suggests that simply throwing money at the problem is an ineffective strategy. The reasons are complex and multifaceted, touching on technology, talent, and strategy.
Industry experts point to a persistent and widening skills gap, where organizations have the budget for advanced tools but lack the human expertise to deploy and manage them effectively. Furthermore, the rapid expansion of the corporate attack surface—driven by cloud adoption, remote work, and interconnected IoT devices—means that defenses are stretched thinner than ever before. Attackers, meanwhile, are not static; they are highly organized, well-funded, and constantly innovating, often operating from jurisdictions beyond the reach of law enforcement.
GoSec's approach is to foster dialogue between those who understand the business risk and those who understand the technical reality. As Chief Revenue Officer Julien Turcot states, "Every speaker on our stage has managed a situation most attendees will only ever read about in an incident report. That's the perspective we built GoSec to deliver." This focus on lived experience is a direct countermeasure to the industry's over-reliance on theoretical, silver-bullet solutions. The goal is to move beyond product pitches and into the gritty reality of what works when an organization is actively under siege.
A Confluence of Expertise: From Boardroom to Bedrock
Reinforcing this mission is a speaker lineup that represents a cross-section of the entire security ecosystem. Alongside Ross Young, the GoSec stage will feature luminaries like Ira Winkler, President of Secure Mentem and a master of using espionage simulations to test corporate defenses. Winkler’s work focuses on the often-underestimated human element of security. Also speaking is John Strand of Black Hills Information Security, a leading voice in penetration testing and active defense, who represents the offensive mindset necessary to build resilient systems. Amy Yee, a seasoned board member and digital transformation expert, will bring the crucial perspective of governance and strategic alignment, ensuring that security initiatives support, rather than hinder, business objectives.
This deliberate curation of speakers—from the strategic to the deeply technical—is the essence of the conference. It acknowledges that a successful security program is not the sole responsibility of the CISO. It requires buy-in from the board, understanding from the C-suite, and flawless execution from engineers and analysts. GoSec's long history, which includes hosting figures like former Canadian Prime Minister Stephen Harper and retired four-star Admiral James Stavridis, underscores its role as a forum where security is treated not as an IT problem, but as a fundamental issue of national and economic stability.
Montreal's Ascendance as a Cybersecurity Nexus
While the challenges are global, GoSec has always maintained a strong connection to its roots, consistently spotlighting the innovative work emerging from its host city. Montreal has quietly but firmly established itself as a significant hub for cybersecurity research and talent. This year, the conference showcases this local strength by featuring Olivier Bilodeau, a principal researcher at Montreal-based firm Flare, and his collaborator Andréanne Bergeron, a criminologist-turned-cybersecurity researcher.
Their joint work on attacker behavior has gained international recognition, providing security teams around the world with crucial insights into how adversaries operate once inside a network. By giving local researchers a platform alongside global industry giants, GoSec not only nurtures homegrown talent but also enriches the global conversation. It highlights that the solutions to our most pressing digital threats can come from anywhere, including the dynamic tech ecosystem of Quebec. This commitment transforms the conference from a simple industry gathering into a vital part of a thriving regional innovation hub, connecting local expertise with a global audience and reinforcing Montreal's position on the world stage of cybersecurity. The event promises to be a critical barometer for the future of digital defense.
Topics & Related
Threat Landscape
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →