Penetration Testing
We attack your systems the way a funded adversary would, then hand you the exact path they took — with a fix for every step of it.
- External, internal, web, API, mobile and cloud scope
- Manual exploitation — not a scanner report with a logo on it
- CVSS plus real-world business impact for every finding
- Free re-test of every remediated finding within 90 days
Cloud Security
Cloud adoption moved faster than the governance around it. We assess what you have actually deployed, close what migration left open, and leave you with an operating model that survives the next migration.
- Cloud security posture management (CSPM) and misconfiguration review across AWS, Azure and Google Cloud
- Identity, network and data-boundary design for multi-account estates
- Kubernetes, container and CI/CD pipeline hardening
- Cloud governance and operating model your platform team can run
Phishing Simulation
A simulation everybody passes has taught you nothing. We run campaigns calibrated to what is actually being sent to your sector, and report the click as a process problem rather than a person problem.
- Campaigns modelled on live lures aimed at your sector, not stock templates
- Baseline, run and measure — with reporting rate as the primary metric
- Business email compromise and MFA-fatigue scenarios, not just credential pages
- Named-individual data kept out of management reporting
Security Awareness Training
Most incidents begin with a reasonable person doing a reasonable thing at the wrong moment. We train for that moment — role by role — rather than for the annual compliance tick.
- Role-based tracks — finance, engineering, executive, frontline
- Built around the incidents your sector actually reports
- Live sessions and short async modules, in English and French
- Attendance and comprehension evidence formatted for your auditor
Incident Response Readiness
The worst time to design your response is during one. We build and rehearse the plan while nothing is on fire.
- IR plan, runbooks and escalation trees mapped to your org chart
- Tabletop exercises for the executive team and the on-call team
- Detection gap analysis against MITRE ATT&CK
- Bill C-26 and CCSPA cyber security programme support for designated operators
- Retainer options with defined response SLAs
ISO 27001
An information security management system your business can actually operate — built for certification, not for a binder.
- Gap assessment against Annex A and the 2022 control set
- Risk methodology, Statement of Applicability, and policy suite
- Internal audit and management review support
- We sit with you through Stage 1 and Stage 2
SOC 2
Type I to prove design, Type II to prove operation. We get you through both without stalling the roadmap.
- Trust Services Criteria scoping — you pay for the criteria you need
- Control design, evidence automation and audit-window monitoring
- Auditor liaison and readiness assessment before fieldwork
- Vendor security questionnaire playbook for your sales team
CPCSC
The Canadian Programme for Cyber Security Certification is becoming a condition of doing business with DND. We get suppliers ready early.
- Level determination against your contract requirements
- Control implementation aligned to CAN/DGSI 104 and NIST SP 800-171
- Evidence packages built for third-party assessment
- Supply-chain flow-down guidance for your subcontractors
CMMC
CMMC 2.0 decides whether you can bid. We take defence suppliers from scoping to assessment-ready.
- CUI scoping and enclave design to shrink the assessment boundary
- NIST SP 800-171 implementation with a defensible SPRS score
- System Security Plan and POA&M authored to assessor expectations
- Pre-assessment against the CMMC Assessment Guide