Governance & Risk Management
                                                    ,
                                                            Operational Technology (OT)
                                                    ,
                                                            Video
                                                    
                    NAV Canada CISO Tom Bornais on Keeping IT and OT Systems Running
                
As cyberthreats grow more complex, securing critical services such as commercial aviation requires both proactive and resilient defense models. In advance of the OTsec Canada Summit (Nov. 4-5, 2025), event speaker Tom Bornais, CISO at NAV Canada, said his team focuses on readiness and response to keep operational technologies online.
See Also: From Data to Decisions: Maximizing Operational Efficiency Through IT-OT Integration
Protecting critical aviation infrastructure is no different from other OT operations in that it’s virtually impossible to air-gap all systems, so securing them takes collaboration across departments and strong alignment with executive leadership, he said.
“We’re never going to get to 100% security,” Bornais said. “It’s about having good hygiene, understanding the systems, and building a response capability that’s going to reduce the impact.” Simulation exercises not only improve coordination but they reinforce trust between operational and security teams, he said.
Vendors and supply chains are “a key attack vector,” he added. “So, we’re building the processes, and we’re doing the due diligence.”
In this video interview with Information Security Media Group, Bornais discussed:
- Why resilience – not perfection – should guide cybersecurity strategy;
- The role of tabletop exercises in improving security operations;
- How vendor oversight strengthens infrastructure protection.
Bornais leads cybersecurity, strategy and risk management at NAV Canada, a privately run, nonprofit corporation that owns and operates Canada’s civil air navigation system. He joined the company in 2002.
Want to learn more? Register to attend OTsec Canada, which unites more than 100 senior cybersecurity leaders, providing a valuable platform for experts to connect, learn and collaborate towards cyber resilience for Canada’s critical infrastructure and manufacturing industries.

