Governance you can prove.
Compliance is where claims meet evidence — the assessments that establish where you stand, the privacy analysis regulators expect, and the readiness work that turns security effort into something a customer or auditor can rely on. Structured, scoped to your environment, and free of theatre.
Security Threat and Risk Assessment (STRA)
A structured look at what can actually hurt you.
The STRA is our flagship assessment: a methodical review of a system or service that identifies the threats that apply to it, weighs their likelihood and impact, and measures your existing controls against recognized frameworks. Findings arrive ranked by real risk, not alphabetically, with a remediation path your team can actually execute. It is the document that lets executives, auditors, and engineers argue from the same facts.
- Structured STRA methodology
- Threat & risk modelling
- Control gap analysis
- Ranked remediation plan
Read moreRead less
When to run one
A STRA belongs wherever risk changes shape: a new system going live, a major change to an existing environment, data being shared with an outside party, or a regulator or customer asking for evidence that risk was assessed before go-live. Many clients run them continuously on a subscription cadence rather than as one-off projects.
What's included
- Threat modelling with likelihood & impact scoring
- Control-effectiveness review — current & planned
- Residual-risk documentation & acceptance
- Executive reporting with clear risk scoring
- Central risk repository your team keeps
- Per-system or continuous subscription cadence
Methodology
Assessments align to the frameworks your stakeholders already recognize — ISF IRAM2, NIST 800-30 and 800-53, ISO 27004, and ITSG-33 for public-sector environments — so the output slots into audits instead of sitting beside them.
Privacy Impact Assessment (PIA)
Know how personal data moves through your organization — and prove it is protected.
A PIA maps how personal information is collected, used, stored, and shared across a system or initiative, then measures those flows against PIPEDA and the provincial privacy laws that apply to you. We identify where the gaps are and pair each one with a safeguard that is proportionate, not performative. The result is documentation that stands up to a regulator and a design your privacy officer can defend.
- Data-flow mapping
- PIPEDA & provincial alignment
- Proportionate safeguards
- Regulator-ready documentation
Read moreRead less
When a PIA is required
Any new system, technology, or process that handles personal information — or a material change to one — can trigger the obligation, and several privacy regimes make it mandatory where processing presents high risk (the GDPR’s DPIA being the clearest example).
What's included
- Scoping, discovery & data-flow mapping
- PIA / DPIA execution & independent review
- Reusable, customized PIA templates
- Privacy policy & procedure development
- Role-based PIA training for your teams
- Ongoing updates & maintained risk registers
Depth behind the work
Assessments are led by IAPP-certified privacy specialists (CIPP, CIPM, CIPT) and measured against PIPEDA, the GDPR, ISO 27701, and the NIST Privacy Framework — whichever combination actually applies to your data.
SOC 2 Readiness
Walk into your audit already knowing the answer.
We scope the trust services criteria that actually apply to your business, run a gap assessment against them, and help you design controls and evidence habits that fit how your team already works. When the auditor arrives, the evidence exists because it was produced in the normal course of business — not assembled in a two-week scramble. We stay through the audit itself to keep the process moving. The attestation report is issued by your CPA firm — our work is getting you ready for it and supporting the engagement.
- Scoping & gap assessment
- Control design
- Evidence & automation habits
- Audit-cycle support
Read moreRead less
The path to attestation
- Requirements & report-objective scoping
- Gap analysis & risk assessment
- Control design & documentation
- Control-effectiveness testing & scoring
- Internal audit & management review
- CPA engagement & attestation support
Report types
Type 1 attests control design at a point in time; Type 2 attests operating effectiveness over a period — the one enterprise customers usually ask for. SOC 2+ reports fold in adjacent requirements such as HIPAA or PCI DSS where one audit can serve several masters. We scope only the Trust Services Criteria that apply to your business rather than defaulting to all five.
Data Protection & Regulatory
Privacy, payments, and the data itself — one control set instead of three scrambles.
Data-protection obligations overlap heavily, so we treat them as one program: know where sensitive data lives, control how it moves, and map each control once to every regulation that demands it. That covers data loss prevention that people don’t route around, GDPR readiness for organizations touching EU data, and PCI DSS scoping that keeps cardholder environments small. One control set, maintained once, defensible everywhere.
- Data loss prevention (DLP)
- GDPR readiness
- PCI DSS scoping & compliance
- Unified control mapping
Read moreRead less
What's included
- Data discovery & classification across systems
- DLP policy, monitoring & enforcement design
- Coverage for data at rest, in motion, in use & in cloud
- GDPR readiness & gap analysis
- Data inventory & flow-mapping audits
- DPO-as-a-Service for ongoing obligations
- PCI DSS v4.0 readiness & scope reduction
- SAQ / AOC completion & pre-audit support
How the pieces connect
Discovery and classification feed the DLP program; the same data inventory satisfies GDPR’s mapping obligations; and a deliberately small cardholder environment keeps PCI assessment effort proportionate. Incident response procedures are built to meet the GDPR’s 72-hour notification window, because that clock is the one that hurts.
Cloud Security Assessment
Know how your cloud is actually configured — not how it was designed.
Cloud environments drift: the architecture diagram says one thing, and eighteen months of tickets say another. We assess your real posture across AWS, Azure, GCP, and Microsoft 365 — identities and their permissions, network paths, storage exposure, logging — and rank what we find by exploitability, not by scanner severity. When you want the fixes watched continuously rather than annually, this hands off directly to Managed CloudSec.
- Posture & configuration review
- AWS · Azure · GCP · M365
- Identity & network paths
- Pathway to Managed CloudSec
Read moreRead less
What we review
- Configuration measured against CIS Benchmarks
- Identity, roles & privileged-access paths
- Network segmentation & zero-trust design
- Storage & data exposure
- Logging, telemetry & detection coverage
- Container & Kubernetes posture
How it lands
You get two reports from one assessment: an executive view that ranks findings by exploitability and business impact, and a technical remediation plan your platform teams can execute directly. Architecture-level recommendations — segmentation, guardrails, DevSecOps integration — come with the reasoning, not just the diagram. When you want the posture watched continuously, the same findings seed Managed CloudSec.