- 30+ years of experience: Sami Khoury brings over three decades of cybersecurity expertise from roles like head of the Canadian Centre for Cyber Security (CCCS).
- Strategic shift: Khoury's move from government to SecurityScorecard highlights the growing trend of public-private collaboration in cybersecurity.
- AI-powered defense: SecurityScorecard's TITAN AI platform aims to continuously monitor and prioritize supply chain risks.
Experts would likely conclude that Khoury's appointment underscores the critical need for merging public-sector cybersecurity expertise with private-sector innovation to defend against evolving digital threats.
Securing the Digital Backbone: A Top Cyber Official's Move to Fortify Chains
NEW YORK, NY – August 26, 2026 – In the intricate dance between national security and corporate innovation, the lines are not just blurring; they are being strategically interwoven. The recent appointment of Sami Khoury, the recently retired head of the Canadian Centre for Cyber Security (CCCS), to the Public Sector Advisory Board of SecurityScorecard is more than a high-profile hire. It represents a critical inflection point in how Western nations are approaching the defense of their most vital digital arteries—the vast, interconnected supply chains that underpin everything from power grids to public services.
Khoury, who until July 2026 served as the Government of Canada Senior Official for Cyber Security, brings over three decades of front-line experience from the Communications Security Establishment (CSE), Canada’s signals intelligence agency. His move into the private sector with SecurityScorecard, a global leader in third-party risk management (TPRM), is a powerful acknowledgment of a fundamental truth: the battle for cyber resilience can no longer be fought from government silos alone. It requires a fused front, where deep statecraft and public-sector insight guide the deployment of agile, commercially-driven technology.
The Public-Private Nexus in Action
The revolving door between government and the private sector is often viewed with cynicism, but in the realm of cybersecurity, it has become an essential mechanism for knowledge transfer. Khoury is not merely a former bureaucrat; he was the architect and leader of Canada's national technical authority for cybersecurity. During his tenure as head of the CCCS from 2021 to 2024, he was at the helm during responses to major cyber incidents and was a chief architect of Canada's strategy for protecting critical infrastructure.
His appointment is a testament to a growing trend where seasoned intelligence and defense officials lend their strategic acumen to technology firms. This synergy is vital. While private firms develop cutting-edge tools, officials like Khoury provide the contextual understanding of the threat landscape, the nuances of governmental procurement, and the complex geopolitical factors that shape cyber warfare. He understands the difference between a theoretical vulnerability and an actively exploited threat vector aimed at destabilizing a nation's infrastructure.
“Sami has spent his career helping public sector and critical infrastructure organizations understand which threats matter most—and what to do about them,” said Dr. Aleksandr Yampolskiy, CEO and Co-Founder of SecurityScorecard. “His leadership will be invaluable as we help public-sector organizations in Canada and around the world take a more continuous, threat-informed, and AI-powered approach to cybersecurity.” This partnership aims to bridge the gap between the government's mandate to protect and the private sector's ability to innovate at speed and scale.
Fortifying the Global Supply Chain
At the heart of this appointment is the increasingly perilous nature of the global supply chain. Our modern cities and economies run on a complex web of third-party vendors, software providers, and managed service partners. This digital backbone, while efficient, is riddled with potential points of failure. As Khoury himself stated, “Governments and critical infrastructure operators depend on ecosystems of suppliers and technology providers they neither own nor fully see.”
This lack of visibility is the central challenge SecurityScorecard aims to solve. The company's platform is designed to move organizations beyond periodic, compliance-based check-ins—an approach that is woefully inadequate against persistent, sophisticated adversaries. Instead, it advocates for a model of continuous monitoring. This shift is crucial for critical infrastructure, where the compromise of a single, seemingly minor vendor can create a cascading failure across an entire sector. Khoury's experience representing Canada globally on supply chain risk provides the company with unparalleled insight into the priorities and pain points of allied nations grappling with this exact problem.
His deep roots in the Five Eyes intelligence alliance and his work building international partnerships will be instrumental as SecurityScorecard deepens its work not just in Canada, but with allied governments who face common threats from shared adversaries. The goal is to create a common operational picture of supply chain risk, enabling a more coordinated and proactive collective defense.
The AI Frontier in Infrastructure Defense
The scale of today's digital ecosystems makes manual monitoring impossible. This is where artificial intelligence becomes a force multiplier. SecurityScorecard’s TITAN AI platform is engineered to continuously scan the internet, analyze vast datasets, and unify third-party risk data with advanced threat intelligence. It aims to deliver what Khoury calls the ability to “watch that ecosystem continuously and act on what you find.”
By bringing an AI-powered, threat-informed approach directly into risk management workflows, the platform helps organizations prioritize threats. It answers the critical question that plagues every security chief: of the thousands of potential vulnerabilities across my hundreds of vendors, which ones pose a clear and present danger right now? AI helps sift through the noise to find the signal, allowing security teams to move from a passive, reactive posture to an active, predictive one.
Khoury’s role will be to help strategically guide the application of this technology for the unique needs of the public sector. Having seen firsthand how AI is also being weaponized by adversaries for more sophisticated phishing, impersonation, and vulnerability discovery, his perspective is invaluable in ensuring that defensive AI tools stay ahead of offensive capabilities. This appointment isn't just about selling a product to governments; it's about co-developing a security doctrine fit for an era where the resilience of our physical world is inextricably linked to the security of its digital twin.
Topics & Related
Threat Landscape
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →