GoCast Podcast: Julien Turcot & Yvan Fournier (Ministère de la Cybersécurité et du Numérique)
Download resourcesAbout this session
A GoCast interview with Yvan Fournier, deputy minister for cybersecurity and government chief information security officer for Quebec, ahead of his GoSec talk. Fournier recounts 28 years in the health network, where he ran early cybersecurity awareness events, before taking a dual mandate in 2018 to also build the province's cyber defense center. He explains Quebec's 22 mandatory security measures, drawn and prioritized from the NIST framework, which apply to all public bodies, and describes a structure of a central cyber defense center feeding 27 departmental operational centers, tied together by a certified CERT (the only Canadian province with FIRST certification) and recurring weekly coordination meetings. He highlights close, near-daily collaboration with federal counterparts and other provinces, an interprovincial intelligence-sharing agreement being signed the following week, and a push to build francophone partnerships with Belgium and France. Asked about AI and quantum computing, he describes an internal cryptographic inventory underway ahead of post-quantum migration planning, and a roadmap toward AI-assisted, eventually automated incident response, starting with alerting operators and moving toward automatic isolation of compromised servers by around 2027-2028.
Le GoCast sort du studio et s’installe directement sur la Main Stage de GoSec 2025 ! Au programme : une série de mini-interviews exclusives avec les esprits les plus brillants de la cybersécurité. Retrouvez l’ambiance unique et l’énergie du GoCast, en direct du cœur de l’événement, pour des échanges courts, dynamiques et toujours aussi captivants. Un rendez-vous incontournable pour capter les idées, les tendances et les voix qui façonnent l’avenir de la cybersécurité.
Key takeaways
- Prioritize a subset of a large framework like NIST into a smaller number of mandatory, enforceable measures rather than requiring the full standard at once.
- Pair a central coordinating body with distributed operational centers and a fixed weekly cadence of meetings to keep dozens of sub-teams aligned on priorities.
- Start a cryptographic inventory now to prepare for post-quantum migration, since no one can confirm today how close any actor is to breaking current cryptography.
- Automate incident response in stages: first alert human operators, then move toward automatic isolation of compromised systems once confidence is established.
- Build peer relationships with organizations facing the same regulatory and threat landscape (interprovincial, federal, or international) to share intelligence and compare incident response.
Speakers

Fort de plus de 30 ans d’expérience en technologies de l’information et en cybersécurité, Yvan Fournier occupe un rôle stratégique au sein du gouvernement du Québec. Il dirige le Réseau gouvernemental de cyberdéfense et coordonne 26 centres… Read moreRead less
Fort de plus de 30 ans d’expérience en technologies de l’information et en cybersécurité, Yvan Fournier occupe un rôle stratégique au sein du gouvernement du Québec. Il dirige le Réseau gouvernemental de cyberdéfense et coordonne 26 centres opérationnels à travers la province. Il a contribué à la création du Centre gouvernemental de cyberdéfense (CGCD) et assume depuis 2020 la responsabilité opérationnelle de la cyberdéfense du réseau de la santé. Son parcours inclut 25 ans au CHU de Québec, où il a évolué jusqu’au poste de directeur adjoint des technologies. Il est diplômé en administration et développement organisationnel de l’Université Laval, et certifié CISSP, CISM, CEH, Lean Six Sigma et coach de gestion. Chargé de cours depuis 2012, il partage son expertise en gestion du changement. Sa mission : renforcer la cybersécurité gouvernementale dans un contexte de menaces croissantes.
