In October 2023, ransomware attackers hit London Health Sciences Centre, forcing five hospitals offline and exposing the catastrophic operational cost of underinvesting in public sector cyber defences. The incident reverberated far beyond southwestern Ontario. In BC, it accelerated conversations that procurement officers and CISOs had been quietly holding for years, opening budget lines that are now appearing as active RFPs on the BC Bid registry.
The numbers are moving fast. IDC Canada projects that Canadian public sector cybersecurity spending will grow at a compound annual rate exceeding 10 per cent through 2027, driven largely by healthcare and municipal government procurement. In BC, that translates into a concrete near-term pipeline: zero-trust architecture deployments, endpoint detection and response retainers, and incident response contracts are all moving through competitive procurement processes at provincial ministries, regional health authorities, and school districts.
For Vancouver’s cybersecurity founders, the timing is critical. Spring 2026 budget approvals across BC’s public sector are locking in multi-year contract allocations, meaning the window to position for anchor public-sector work is open now.
Why government beats enterprise for recurring revenue
The pitch to founders is straightforward: public sector contracts are sticky in ways that enterprise deals rarely are. Government bodies do not churn the way corporate clients do. A three-year incident response retainer with a health authority offers a fundamentally different revenue profile than a 12-month enterprise SaaS subscription with renewal risk.
The BC Office of the Chief Information Officer has been pushing a zero-trust security framework across provincial ministries, creating a standardized requirements language that well-prepared vendors can align their offerings to directly. That standardization is a feature: founders who invest in understanding the framework can compete across multiple ministries with the same core product positioning.
The Canadian Centre for Cyber Security's most recent threat assessment identified state-sponsored actors and ransomware-as-a-service operators as the primary threats to Canadian critical infrastructure. BC health authorities and Crown corporations are now citing this language directly in their procurement justifications. That alignment between federal threat intelligence and provincial procurement rationale is creating a coherent policy environment that makes government sales more predictable than they have historically been.
The procurement learning curve
Government procurement has a learning curve that punishes the unprepared. BC’s public sector operates under specific rules, and the BC Bid registry requires vendors to meet compliance thresholds—security certifications, insurance minimums, and sometimes specific Canadian data residency requirements—before a proposal is evaluated.
The CIRA's Canadian Internet Security report has consistently flagged that smaller public institutions, particularly school districts, are often the least protected and increasingly targeted because attackers know procurement cycles are slow and IT budgets are thin. That vulnerability is also an opportunity: smaller institutions often have more procurement flexibility and faster decision cycles than large ministries, making them viable first-contract targets for startups building a government reference base.
The Vancouver angle
Innovate BC and the BC Tech Association have identified cybersecurity as a priority sector for provincial scaling support. The cluster of security-focused firms in Vancouver—many with roots in the city's broader SaaS and cloud infrastructure ecosystem—is better positioned than it may realize to compete for this emerging public-sector pipeline.
The strategic play is sequencing. A school district or regional health authority contract establishes the government reference, the compliance track record, and the procurement relationships that make the next contract—with a larger ministry or Crown corporation—significantly easier to win. In a market where BC government IT spending is increasingly weighted toward security and resilience, that sequencing strategy has a clear ceiling worth building toward.
The ransomware attackers who hit London Health Sciences did not intend to create a startup market, but they did.





