Connect with us

Technology

Due diligence increasingly critical for Canadian businesses reconfiguring supply chains amid U.S. tariffs

Published

on

Switching suppliers requires robust due diligence as fraud and cybersecurity risks are on the rise, KPMG forensic and cybersecurity specialists warn

TORONTO, March 6, 2025 /CNW/ – With the recent implementation of 25 per cent, across-the-board tariffs on Canadian goods, Canadian businesses that are considering or already making changes to their supply chain must remain extra vigilant for increased fraud and cybersecurity risks, KPMG in Canada specialists warn.

A recent KPMG in Canada survey of Canadian businesses found that in anticipation of tariffs, nearly half (44 per cent) of respondents said they are already reconfiguring their supply chains to divert U.S.-destined exports to these third-party countries, with another 44 per cent exploring that option.

Changing suppliers and reconfiguring supply chains can introduce numerous fraud risks, says Myriam Duguay, Partner and National Forensic Leader at KPMG in Canada.

“With U.S. tariffs now in place for Canadian exporters, many businesses might rush to switch suppliers, and in doing so, they might not do the rigorous due diligence that’s needed to reduce third party risks,” she says.

“Businesses must be vigilant about engaging new suppliers that make illegitimate or overstated claims about their capabilities,” she adds.

Hartaj Nijjar, KPMG in Canada’s National Cybersecurity Leader adds that engaging new suppliers increases an organization’s cybersecurity risks.

“If the new suppliers do not have robust cybersecurity measures in place, they could become a weak link in an organization’s supply chain, potentially leading to data breaches,” he says.

“Businesses should also be aware of fake suppliers that appear legitimate but are actually threat actors in disguise. This is becoming more prevalent now with the rise of AI-powered deepfakes,” he adds. 

KPMG’s forensic and cybersecurity specialists recommend Canadian organizations consider the following points when changing suppliers.

Supplier Due Diligence: When switching suppliers, conducting an integrity due diligence is the first and most critical step. This includes verifying the legitimacy and integrity of the new suppliers, checking their financial stability, and assessing their reputation. Skipping this critical step could lead to partnerships with potentially fraudulent entities that might engage in practices such as overcharging, delivering substandard goods, or even disappearing with prepayments.Contractual Risks: New contracts with suppliers can be a source of fraud if not carefully reviewed. There may be hidden clauses that could be exploited, or the supplier may misrepresent their capabilities or the quality of their products. Legal experts must review contracts to mitigate these risks.Payment Fraud: Changing suppliers often involves new payment processes. This can create opportunities for fraud, such as invoice fraud, where a fraudulent invoice is submitted for payment. According to Payments Canada, one in five Canadian businesses experienced some form of payment fraud in the past six months. Implementing strict controls and verification processes for invoices can help reduce this risk.Supply Chain Visibility: A reconfigured supply chain may lead to reduced visibility over the entire process. If there are multiple intermediaries involved, it can be challenging to track the flow of goods and payments, increasing the risk of fraud. Utilizing technology such as AI-powered digital twins or blockchain can enhance transparency and traceability in the supply chain.Internal Controls: Changes in suppliers and supply chain configurations may also affect internal controls. If these controls are not updated or reinforced, it can create vulnerabilities that fraudsters may exploit. Regular audits and assessments of internal controls are necessary to ensure they remain effective.Cybersecurity Risks: Engaging new suppliers could expose organizations to cybersecurity risks. If new suppliers do not have robust cybersecurity measures in place, they could expose an organization to a security breach. Before onboarding new suppliers, organizations should conduct rigorous risk assessments to evaluate their cybersecurity posture. Deepfake Risks: Deepfakes could be used to create false narratives about a supplier’s reliability or capabilities, which could lead to further risks and supply chain disruptions for organizations. Investing in advanced verification technologies and educating employees on how to identify deepfakes could help mitigate these risks. Employee Training: Employees in the supply chain and accounting departments should be trained to recognize potential fraud and cybersecurity risks associated with new suppliers. This includes understanding red flags and knowing the proper procedures for reporting suspicious activities.Regulatory Compliance: Depending on your industry, changing suppliers may also involve compliance with various regulations. Non-compliance can lead to legal issues, corruption and potential fraud if suppliers are not adhering to the necessary standards.

“While changing suppliers and reconfiguring supply chains can help businesses mitigate the added cost of tariffs, they need to be aware of the associated fraud and cybersecurity risks. Implementing robust due diligence, maintaining strong internal controls, and ensuring compliance with regulations can help mitigate these risks,” Ms. Duguay adds.

For more resources on fraud prevention, visit: Fraud prevention – KPMG Canada

Tune in to KPMG in Canada’s upcoming DX Coffee Chat, Outsmarting Fraud in a Digital World: Outsmarting fraud in a digital world Registration

For more resources on U.S. tariffs, visit: Navigating tariffs – KPMG Canada

About KPMG in Canada
KPMG LLP, a limited liability partnership, is a full-service Audit, Tax and Advisory firm owned and operated by Canadians. For over 150 years, our professionals have provided consulting, accounting, auditing, and tax services to Canadians, inspiring confidence, empowering change, and driving innovation. Guided by our core values of Integrity, Excellence, Courage, Together, For Better, KPMG employs more than 10,000 people in over 40 locations across Canada, serving private- and public-sector clients. KPMG is consistently ranked one of Canada’s top employers and one of the best places to work in the country. 

The firm is established under the laws of Ontario and is a member of KPMG’s global organization of independent member firms affiliated with KPMG International, a private English company limited by guarantee. Each KPMG firm is a legally distinct and separate entity and describes itself as such. For more information, see kpmg.com/ca 

For media inquiries:
Roula Meditskos
National Communications and Media Relations
KPMG in Canada
416-549-7982
rmeditskos@kpmg.ca

SOURCE KPMG LLP

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

American Binary Sets New Standard in Post-Quantum Cryptographic VPNs with Symbolic Proof and Attestation

Published

on

By

WASHINGTON, July 21, 2026 /PRNewswire/ — American Binary, a leader in deep-tech cybersecurity, today announced an independent attestation regarding the validity of all 120 security properties of MaxKyber, their network protocol at the heart of their Ambit Client enterprise VPN, now third-party verified to comply with all Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) requirements. This landmark verification is the result of an exhaustive private peer-review of their symbolic proof (Tamarin + ProVerif) and engineering documentation conducted by industry luminaries Dr. Joe Kiniry, PhD and Dr. Tom Shrimpton, PhD, both with long careers in academia and industry, including time at Galois as Principal Scientists.

“No known VPN — post-quantum or classical, deployed or research — has been subjected to specification and formal verification of comparable depth.” – Dr. Joe Kiniry, PhD and Dr. Tom Shrimpton, PhD

In a landscape defined by emerging quantum threats and unproven solutions, this formal third-party verification differentiates MaxKyber from traditional or hybrid solutions by providing certainty in engineering and compliance with National Security requirements. MaxKyber provides the world with long-term full post-quantum security unlike shorter-term temporary solutions such as hybrids (which mix classical and post-quantum encryption). This breakthrough marks a transition from speculative security to a foundation of verified, provable resilience, establishing a new global benchmark for secure communications.

“While organizations today are increasingly recognizing the significance of PQC, American Binary has been preparing for a post-quantum world for seven years. The result is a resilient foundation for secure operations, today and in the post‑quantum future” – Oracle

Additionally, American Binary signed ACM Turing Award winner Whitfield Diffie, cryptographic pioneer and co-inventor of the Diffie-Hellman key exchange, as a key advisor. Whitfield joins the ranks of existing cryptographic advisors Bruce Schneier and Brian LaMacchia.

“Buy American Binary and you’ll be safe”

– Whitfield Diffie at Quantum.Tech World 2026

Key security pillars of the MaxKyber attestation include:

Protection against “Harvest Now, Decrypt Later” (HNDL): By utilizing purely CNSA 2.0 algorithms, including ML-KEM-1024 without any classical key exchange variants, MaxKyber secures today’s data against decryption by quantum adversaries.Comprehensive Symbolic Verification: The attestation covers 120 security properties across 11 critical categories, including secrecy, authentication, forward secrecy, identity hiding, and resistance to Replay, Denial of Service, Resource Exhaustion, and Key Compromise Impersonation.Architectural Stability: Beyond its post-quantum cryptographic core, MaxKyber’s protocol architecture is rooted in well-established, operationally proven design patterns, retaining their performance and simplicity.

This foundational security architecture provides the necessary reliability to enable significant performance breakthroughs in the field and the following four key impacts.

Impact I: Unambiguous Security and Mitigation of “Harvest Now, Decrypt Later”

MaxKyber achieves the end-state of post-quantum cryptographic purity by utilizing a pure CNSA 2.0 post-quantum key exchange, without using any classical cryptography, hybrid cryptography, or legacy key exchange variants. Instead, American Binary’s more modern key exchange utilizes ML-KEM-1024 operations to replace the Diffie-Hellman Key Exchange. This approach ensures that modern enterprises are not tethered to the vulnerabilities of legacy components or negative market reactions to hybrid solutions being partially broken. If the classical encryption in hybrid solutions is verifiably broken, markets likely will not wait for forensics to determine whether the rest of the solution remains intact; reputation damage and capital flight will occur immediately.

MaxKyber exclusively employs CNSA 2.0 approved algorithms, specifically ML-KEM-1024 (FIPS 203), AES-256-GCM, and SHA-512/256. This construction provides the highest level of security available today without any loss of existing security properties.

Impact II: Optimal Performance from Mobile and Lossy Environments to High-Performance Scenarios

Historically, high-security protocols have suffered from significant system latency, creating a bottleneck for edge computing and mobile workforces. MaxKyber eliminates these traditional performance trade-offs, enabling high-performance security at the network’s most vulnerable points. One partner benchmarked Ambit Client, powered by MaxKyber, to have 70% faster download speeds than a comparable classically encrypted enterprise VPN.

The MaxKyber protocol optimizes efficiency through an “Authenticated Key Exchange” (AKE) which achieves mutual authentication in a single round trip, dramatically reducing the data burden on the network.

Quantifiably, the AKE saves approximately 4,600 bytes per handshake compared to the next best option. This ultra-low overhead ensures that robust post-quantum security functions reliably on mobile devices and in lossy environments where traditional, bulkier PQC handshakes consistently fail. Reliability in the field is a prerequisite for everything from remote work to warfighting environments, and MaxKyber’s AKE directly facilitates such operational readiness.

Additionally, MaxKyber is well suited for high-performance scenarios such as AI workloads, work with 3D models, and more thanks to Vector Packet Processing and Data Plane Development Kit further reducing overheads to the technical minimums and enabling line-rate speeds for server-to-server use cases.

Impact III: Compliance Savings

As the cost of compliance and diligence cycles for critical infrastructure continues to escalate, proofs can be a shortcut for approval. For CISO and Legal departments, formal verification provides a transparent, “glass-box” view of security that goes beyond traditional testing.

For integration partners, this symbolic proof significantly reduces diligence cycles. By providing an exhaustively checked security profile, American Binary allows partners to shorten the lengthy, costly investigative phases usually required for new cryptographic implementations. Verified compliance is transformed from a hurdle into a catalyst for product development.

Impact IV: R&D Acceleration

For engineering teams looking to integrate this technology and/or customize it, American Binary’s documentation serves as a powerful force multiplier. By providing pre-verified, exhaustive, and high-quality documentation, American Binary provides an extraordinary shortcut to rapid integration.

The scale of the documentation and formal models provided to partners is unprecedented in the VPN industry. This rigorous approach allows integration partners to save months, if not years, of R&D effort.

MaxKyber provides more than just a secure tunnel; it delivers a fully documented, mathematically proven blueprint that accelerates the transition to a quantum-safe future. With MaxKyber, American Binary has rewritten the industry standard for post-quantum network security.

About American Binary

American Binary is a leader in deep-tech cybersecurity, specializing in the development of CNSA 2.0 post-quantum cryptographic solutions. Through advanced rigor and high-performance engineering, American Binary provides the provable foundations for secure, resilient communication in the quantum era.

Learn more at www.ambit.inc

CONTACT: sales@ambit.inc 

View original content to download multimedia:https://www.prnewswire.com/news-releases/american-binary-sets-new-standard-in-post-quantum-cryptographic-vpns-with-symbolic-proof-and-attestation-302831415.html

SOURCE American Binary

Continue Reading

Technology

MetaOptics to Deploy its Direct Laser Writer at the University of Arizona’s Center of Semiconductor Manufacturing to Advance its U.S. Expansion

Published

on

By

SINGAPORE, July 21, 2026 /PRNewswire/ — MetaOptics Ltd (Catalist: 9MT) (“MetaOptics” or the “Company,” and together with its subsidiaries, the “Group”), announced that it has entered into an agreement to deploy its key metalens Direct Laser Writer (“DLW”) system at the University of Arizona’s Center of Semiconductor Manufacturing (the “University”). The agreement marks a critical step in advancing its U.S. expansion strategy and its collaborative research with world-class semiconductor stakeholders in Arizona. Installation of the DLW is expected to commence in 2027.

The DLW is designed for a 4-inch wafer to enable quick prototyping and fabrication of metalens samples within weeks. It also supports small-volume production for pilot builds and customer demand evaluation, enabling partners to iterate faster and move from concept to product more efficiently. The deployment of the Company’s DLW will allow prospective customers in the U.S. to physically witness the system in action for their metalens prototyping needs. It will also support collaborative research and evaluation by the University’s researchers under the guidance of Dr. Krishna Muralidharan of the University of Arizona’s Department of Materials Science and Engineering. MetaOptics expects the deployment to generate user feedback and user demonstration opportunities, providing further technical validation of its metalens equipment and products, and serve as a launchpad to scale commercial production and collaboration in the U.S. market.

The deployment of its DLW serves as a key milestone for MetaOptics’ U.S. expansion strategy, prospective U.S. customer engagement, and commercialization roadmap. It also positions the Group to support emerging U.S. initiatives in silicon photonics, co-packaged optics, and integrated photonics, where its metalens technology is directly applicable. The DLW will anchor a “mini foundry” at the University for small-volume, quick turnaround prototyping. Beyond research, the installation serves a commercial purpose: a U.S. demonstration site where potential distributors, universities, and research institutions can physically witness the DLW in operation. It will also produce metalens samples for prospective customers’ evaluation. With Arizona’s fast-growing semiconductor ecosystem home to world-class manufacturers and suppliers, the Company aims to leverage its presence at the University and the wider ecosystem to deepen engagement with prospective industry partners and end customers.

MetaOptics Executive Chairman Thng Chong Kim commented: “By placing our Direct Laser Writer within a world-class semiconductor research environment in Arizona, we will be able to strengthen technical validation and gather valuable user feedback. It also supports our ongoing engagements with potential industry partners and end-customers while showcasing our metalens manufacturing equipment to prospective distributors and institutions across the United States. We believe this deployment reinforces our broader U.S. expansion efforts and deepens our engagement in Arizona’s world-class semiconductor ecosystem.”

About MetaOptics Ltd

MetaOptics Ltd (Catalist: 9MT) is a semiconductor optics company pioneering glass-based metalens solutions enhanced by AI-driven image processing. Using advanced optical design and a scalable 12-inch DUV lithography process, it powers next-generation applications in CPO, mobile, AR VR, automotive, and other emerging markets. Find out more at www.metaoptics.sg.

Forward-Looking Statement

This press release contains forward-looking statements which can be identified by words or phrases such as “may,” “will,” “expect,” “anticipate,” “aim,” “estimate,” “intend,” “plan,” “believe,” “likely to,” “potential,” “continue” or other similar expressions. Any statements that are not historical facts, including statements about the Company’s beliefs and expectations, are forward-looking statements. Forward-looking statements involve inherent risks and uncertainties. A number of factors could cause actual results to differ materially from those contained in any forward-looking statement, including but not limited to the following: the Company’s growth strategies, its future business development, results of operations and financial condition, its research and development efforts, its ability to attract and retain customers, and its ability to establish and maintain relationships with suppliers and business partners; and assumptions underlying or related to any of the foregoing. All information provided in this press release is as of the date of this press release, and the Company undertakes no obligation to update any forward-looking statement, except as required under applicable law.

Singapore (HQ)
Metaoptics Technologies Pte Ltd. 81 Ayer Rajah Crescent, #01-45 Singapore 139967

United States
Metaoptics Inc. (USA) 1 Ferry Building, Suite 201 San Francisco, CA 9411

View original content:https://www.prnewswire.com/news-releases/metaoptics-to-deploy-its-direct-laser-writer-at-the-university-of-arizonas-center-of-semiconductor-manufacturing-to-advance-its-us-expansion-302830614.html

SOURCE METAOPTICS LTD

Continue Reading

Technology

11:11 Systems Announces Strategic Partnership with Cato Networks to Deliver SASE Solution for Distributed Enterprises

Published

on

By

New Managed Secure Access Service Edge (SASE) solution combines SD-WAN, cloud-native networking and security capabilities with 11:11’s connectivity, cyber resilience and cloud expertise

SYDNEY, July 22, 2026 /PRNewswire/ — 11:11 Systems, a leading managed infrastructure solutions provider, today announced the global availability of its 11:11 Managed Secure Access Service Edge (SASE) solution and a new strategic partnership with Cato Networks.

11:11 Managed SASE is a fully managed secure connectivity solution leveraging Cato Networks AI-native network security platform. This solution brings together intelligent SD-WAN, cloud-delivered security and global connectivity into a single offering. It enables organisations to simplify and secure access across branch offices, data centres, users and cloud environments, reducing complexity without sacrificing performance or control.

Built on the Cato Networks cloud-native SASE platform, 11:11 Managed SASE combines zero trust network access (ZTNA), firewall as a service (FWaaS), secure web gateway (SWG), cloud access security broker (CASB), advanced threat protection and centralised visibility into a unified managed experience. 11:11 also delivers 24x7x365 monitoring and support, incident management integration and operational accountability to help customers limit vendor sprawl, increase agility and free internal teams to focus on higher-value priorities.

The offering is backed by 11:11’s broader networking, cloud and cyber resilience capabilities. Through its global backbone, carrier-agnostic connectivity options and integrated portfolio spanning cloud, backup, disaster recovery and security services, 11:11 gives customers a practical path to modernise network and security architecture while strengthening resilience across the business.

“Enterprises are under pressure to support users, applications and locations that are more distributed than ever, while limiting complexity and improving security,” said Justin Giardina, CTO, 11:11 Systems. “Our Managed SASE solution provides customers with a unified approach to modernising networking and security, along with the visibility, support and flexibility they need to thrive in a rapidly changing environment.”

According to Karl Soderlund, global channel chief, Cato Networks, “As enterprises move beyond fragmented legacy networking and security stacks, they need a simpler way to gain visibility, context and control across hybrid work environments and reduce the operational burden on IT. Through our partnership, we can address these challenges head on and deliver end-to-end visibility and protection in a single service built for the reality of modern work.”

The joint offering is well suited for distributed enterprises, multi-site organisations, hybrid workforce initiatives, SD-WAN refreshes, security modernisation efforts and businesses with limited IT resources. 11:11 meets customers where they are by supporting existing environments, simplifying multi-vendor operations and serving as a single provider accountable for network, security, cloud and data integration.

This partnership expands 11:11’s Network as a Service portfolio and follows Forrester’s inclusion of 11:11 Systems in its report, “The Secure Access Service Edge Services Landscape, Q1 2026.”

About 11:11 Systems

11:11 Systems is a managed infrastructure solutions provider that empowers customers to modernise, protect and manage mission-critical applications and data, leveraging 11:11’s resilient cloud platform. Learn more at www.1111Systems.com and follow 11:11 on LinkedIn.

View original content:https://www.prnewswire.com/apac/news-releases/1111-systems-announces-strategic-partnership-with-cato-networks-to-deliver-sase-solution-for-distributed-enterprises-302830322.html

SOURCE 11:11 Systems

Continue Reading

Trending