CANCDTGEN 001/26
Canadian Cadet General Order (CANCDTGEN)
CJCR Gp Cyber Security and Privacy Updates
References:
- CANCDTGEN 002/25, Authorized Use and Dissemination of Cadet Program Information
- CJCR Gp O 2008-6, Internet Publishing and Social Media
- Throughout 2025, CJCR Gp IT Security Services tracked an increase in phishing attempts and other targeted cyber threats against staff, volunteers, and cadets. To help ensure safety and privacy, Corps/Squadron commanding officers will liaise with sponsors and supporting organizations that host websites and other publicly available resources to remove personal CJCR Gp email addresses from publicly accessible platforms. When required, only the Corps/Squadron common email address should be published (+NumberElement@cadets.gc.ca) or provide a link to the Corps/Squadron Directory.
- All staff, volunteers, and cadets have access to contact information within Cadet365 and parents and guardians should be provided with relevant contact information through local communications. All communications from Corps and Squadrons will be via Cadet365 email and related resources.
- Microsoft Teams Chats are intended for day-to-day interaction and quick contact/check-ins between staff, volunteers and cadets. The system is not intended for decision making, records of business value, or long-term storage of information. In June 2025, a 10-day retention period was implemented on Defence365.
- The implementation of retention limits on Microsoft Teams Chat is a measure to improve data management and compliance with organizational policies, including effective information management, record keeping, and providing timely responses to access to information requests. Retention limits ensure that chat messages are automatically deleted after a specified period, reducing the risk of data breaches and ensuring that only relevant and up-to-date information is retained.
- As of 15 February 2026, Cadet365 will be subject to a 75-day team chat retention policy. This means that chats will be available for a maximum of 75 days, after which time they will be automatically deleted. A 75-day retention period was chosen to be reflective of the unique nature of CJCR Gp which includes accommodation for part-time staff, and to accommodate key training or break periods.
- Questions concerning Cyber Security and Privacy Updates can be directed to your RCSU J6.