>
CISA-practitioner cybersecurity for Canadian business. EDR deployment, SIEM and threat detection, vulnerability work, identity hardening, and the incident response you hope you never need. Evidence trail generated as you go, not scrambled together at audit time.
Each sub-service is deployable on its own or stacked into a full programme. No implementation surprises, no change-order theatre. Tools are picked for actual catch rate, not vendor quadrant placement.
Agent rollout across every endpoint, policy baseline tuned to your environment, exclusions reviewed. Alert triage runs through our team, not a vendor SOC.
Log aggregation from endpoints, firewalls, cloud, and SaaS. Detection rules tuned to your actual environment, not vendor defaults. Alerts closed, not just filed.
Scheduled scans with remediation tickets, not PDF dumps. Annual pen test by a Canadian-based consultancy. Findings tracked to closure, not just logged.
SSO, MFA, privileged access management, and lifecycle automation. Deprovisioning that actually fires on offboarding, not three weeks later.
Retainer-based IR with 24/7 phone escalation. Containment, eradication, forensic timeline, breach notification support where PIPEDA requires it.
The primary tools we actively deploy. Each one earned its place by catching things in real client environments, not by scoring well in vendor-sponsored reports. Other tools used on request.
Centralized logs from endpoints, firewalls, cloud. Correlation rules tuned, not vendor defaults.
NGFW, DNS filtering, VPN and zero-trust access. Rulebase reviewed quarterly, not set and forgotten.
Identity-first security plus continuous vulnerability visibility. The two things most breaches start with.
Most security spending ends up in dashboards nobody opens, reports nobody reads, and alerts nobody closes. Here is what we insist on.
Every alert gets a disposition: true positive, false positive, benign, or needs tuning. If an alert fires three times with no action, the detection rule is wrong and we fix it.
You get a weekly disposition report with the real numbers, not a vanity dashboard.
PIPEDA, Law 25, PIPA, OSFI B-13, SOC 2 controls mapped to each deployment during Phase 01. Your evidence binder populates itself as we work.
At audit time you point at the evidence, not scramble to generate it from logs.
Your CISA-certified principal runs the engagement. Not a BDR, not an account manager, not a vendor SOC analyst reading from a runbook.
When something breaks at 2am, the person who understands your environment is the one who picks up.
Our team handles triage and response directly. We do not resell a vendor SOC where a Tier-1 analyst reads from a script and escalates everything.
When your EDR fires at 2am, the person investigating is someone who already knows your environment. For scale events during an active incident, we have escalation paths with established DFIR firms, but the primary responder is us.
Most MSSPs sell monitoring volume: alerts collected, logs stored, dashboards available. We sell alerts closed with disposition, which is a different number.
Ask any MSSP for their average alert-to-close time, false-positive rate, and detection-rule tuning cadence. If they cannot answer those three questions concretely, they are selling you dashboards.
Yes, and that commitment is in the engagement document. Every tool we deploy is either your own license or runs on infrastructure you own. All detection rules, playbooks, and tuning configs are documented in your repository, not ours.
If you move to another provider or in-house, we hand off everything. No vendor-locked tooling, no proprietary dashboards you lose access to on day one.
By default: PIPEDA, Quebec Law 25, BC/AB PIPA, OSFI B-13, SOC 2 Type II controls, ISO 27001 Annex A, NIST CSF 2.0. Other frameworks (HIPAA for cross-border work, PCI DSS for payments, CIS Controls) added on request.
Mapping happens during Phase 01 scoping and the evidence trail generates automatically as deployment proceeds.
SIEM logs, EDR telemetry, and backup storage default to Canadian regions (ca-central-1, Canada Central, northamerica-northeast). If a vendor cannot keep data in Canada, we flag it in writing before deployment and let you decide.
For jurisdictionally sensitive clients (regulated financial services, healthcare, government subcontractors), we deploy on private cloud or your own tenancy by default.
Flat monthly per sub-service, scoped by endpoint count or user count depending on the service. Includes tooling, alert triage, tuning, monthly report, and incident response under X hours per month. Overage beyond that is quoted at a stated hourly rate before any work starts.
No hour-counting for routine work. No change-order theatre for small requests. The things that cost extra are large projects (M&A integration, major migrations, breach-level incidents) and we tell you before we touch them.