• Now booking Q3 · Montréal · Toronto · Miami · Rabat · • Odoo 17 migrations scheduling 6 weeks out
● Incident support included in every retainer · no emergency hourly rate
Home/ Services/ Cybersecurity & GRC
● Risk · policy · controls · vendor risk · vCISO

Cybersecurity and GRC for companies with no security department

We build the governance, risk and compliance program you’d have if you’d hired a security team three years ago. Risk register, policy library, control implementation, vendor reviews, incident readiness — run by senior people, on a monthly retainer, in English and French.

Book a risk review → See the program From CAD $6.5k / month
Security advisor and company executive discussing a printed risk register at a dark walnut boardroom table, crimson folder between them
31 programs · 100% first-pass audits
SOC 2 ISO 27001:2022 NIST CSF 2.0 Law 25 PCI DSS 4.0 CIS v8
EN · FR · AR
What the program covers

Six disciplines. Governance is the one nobody wants and everybody needs.

Tools get bought first because they’re easy to buy. We start with the decisions — what you protect, who owns it, what you’ve accepted — because that’s what determines whether the tools were the right ones.

C.01 · Governance

Governance & accountability

A security charter, a decision-rights matrix, and a quarterly review that puts real numbers in front of your executive team. Someone has to own each risk by name.

  • Security charter
  • Risk owners named
  • Quarterly board pack
  • Exception process
C.02 · Risk

Risk management

A living risk register with likelihood, impact, treatment decision and owner — sized to your business rather than copied from a template with 200 irrelevant entries.

  • Asset & data inventory
  • Threat modelling
  • Treatment plans
  • Monthly review cadence
C.03 · Policy

Policy & control library

Short, plain-language policies written against how your teams actually work, mapped once to an internal control set that satisfies every framework you need.

  • 14–20 core policies
  • Single control mapping
  • EN + FR-CA
  • Annual review cycle
C.04 · Controls

Control implementation

The unglamorous work: identity and access, logging, endpoint hardening, encryption, change management, secure development. Implemented, not just documented.

  • IAM & MFA rollout
  • Logging & monitoring
  • Backup restore testing
  • Secure SDLC gates
C.05 · Third party

Vendor & supply-chain risk

A tiered vendor inventory, proportionate due-diligence questionnaires, contract security clauses, and the annual re-review that most programs quietly skip.

  • Tiered vendor register
  • Due-diligence packs
  • Contract clauses
  • Annual re-assessment
C.06 · Response

Incident readiness & response

An incident response plan with named roles and real phone numbers, regulator and customer notification paths, and two tabletop exercises a year so it’s been rehearsed.

  • IR plan & runbooks
  • Law 25 · 72h path
  • 2 tabletops / year
  • Post-incident rewrite
Frameworks

Map the controls once. Generate the evidence per framework.

Most of our clients owe two or three frameworks at the same time. Running parallel programs triples the internal cost, so we maintain one control set and produce framework-specific evidence from it.

Six navy index cards fanned in a grid on a slate desk, one crimson, over a printed control matrix sheet, representing one control set mapped to several frameworks
One control set · six frameworks
Enterprise buyers · US

SOC 2 Type II

The report North American enterprise procurement asks for. We run readiness, select the auditor, and manage the observation window end to end.

Readiness 3–5 moWindow 3–12 mo
International · regulated

ISO 27001:2022

A certifiable ISMS with Statement of Applicability across all 93 Annex A controls, internal audit, and Stage 1 and 2 support.

To certificate 11 moFull path →
Board & insurer

NIST CSF 2.0

The framework we use to describe posture to non-technical stakeholders — a maturity score per function that a board can actually read and track.

Baseline 4 weeksNot certifiable
Québec · Canada

Law 25 & PIPEDA

Privacy governance, consent records, privacy impact assessments, retention schedules, and the breach notification path Law 25 requires you to have in advance.

Program 2–4 moMandatory
Card payments

PCI DSS 4.0

Scope reduction first — most clients are paying for controls on systems that shouldn’t touch card data at all. Then SAQ or ROC support.

Scoping 3 weeksSAQ / ROC
Technical baseline

CIS Controls v8

Our default technical baseline underneath every framework above. Implementation Group 1 or 2 depending on your size and threat profile.

IG1 6 weeksMeasurable
How the engagement runs

Five phases. The blocking gap gets fixed first.

If a stalled enterprise deal or a regulator letter is what brought you here, we sequence around that rather than making you wait for a complete program before you can answer the question in front of you.

01
Week 1–3

Assess

Interviews, technical review, and a gap assessment against the frameworks you owe. Scored, prioritized, costed.

  • Gap assessment
  • Risk register v1
  • Costed roadmap
02
Week 3–4

Unblock

Whatever is holding up the deal or the audit — questionnaire answers, interim attestations, the two controls that matter.

  • Questionnaire support
  • Quick-win controls
  • Customer letter
03
Month 2–6

Build

Policy library, control implementation, vendor program, IR plan. Evidence collected as we go, not reconstructed later.

  • Policies & controls
  • Vendor register
  • Evidence pipeline
04
Month 6–11

Prove

Internal audit, management review, tabletop exercise, then the external audit or attestation itself.

  • Internal audit
  • Tabletop exercise
  • External audit
05
Ongoing

Operate

Monthly risk review, quarterly board reporting, annual re-certification and re-assessment of every tier-1 vendor.

  • Monthly risk review
  • Board reporting
  • Surveillance audits
Engagement models

Start with the assessment. Decide after you’ve read it.

The assessment is deliberately sellable on its own — you get a costed roadmap you could hand to another firm. Most clients continue with us, but nothing about the document requires it.

Assessment

Security & GRC assessment

$18kCAD · fixed · 3 weeks

A scored gap assessment against the frameworks you owe, a first risk register, and a costed twelve-month roadmap. Credited against a program if you continue within 90 days.

  • Gap assessment · scored
  • Risk register v1
  • Costed roadmap
  • Executive readout session
  • Yours to keep either way
Fractional

Fractional CISO

$6.5kCAD / month · 4 days · min 6 mo

Senior security leadership on retainer for companies with a program already running, or an internal team that needs someone accountable above them.

  • Named CISO · 4 days / month
  • Board & audit committee reporting
  • Program ownership
  • Customer security calls
  • Incident command
  • Team mentoring
Program outcomes

Across 31 programs since 2019.

Security programs are hard to measure honestly, so we report the things that are checkable: audit results, time to answer a customer questionnaire, and unblocked revenue.

100%
First-pass audit rate
0
Major nonconformities
9d → 2h
Questionnaire turnaround
$8.4M
Client pipeline unblocked
Client · Meridian Bank
“Our previous consultants left us 140 pages of policy nobody had read. Noordev deleted most of it, kept nineteen policies our engineers could actually follow, and we passed Stage 2 with zero major findings.”
AO
Amina Ouali · CTO, Meridian Bank · Toronto
Cybersecurity & GRC FAQ

Before you engage us.

If your question isn’t here, ask it on the call. We’ll tell you when you need a penetration test rather than a program, even though that’s someone else’s invoice.

What is GRC in cybersecurity?

+

GRC stands for governance, risk and compliance. Governance is who decides and who is accountable. Risk is knowing which threats matter to your business and what you have chosen to do about each one. Compliance is proving both to a customer, an auditor or a regulator. Technical controls without GRC produce a security posture nobody can explain; GRC without technical controls produces documents that protect nothing.

How much do cybersecurity and GRC services cost?

+

A one-time security assessment is CAD $18,000 fixed. A GRC program build runs $11,000 per month for six to twelve months, depending on how many frameworks you need to satisfy. A fractional CISO retainer starts at $6,500 per month for four days of senior time. Most clients start with the assessment and decide afterward.

Do we need a full-time CISO or is fractional enough?

+

Below roughly 300 employees, a fractional CISO is usually the better economics — you get senior judgement four days a month instead of a mid-level full-time hire. You should move to full-time when security decisions are needed weekly rather than monthly, when you have a security team to manage, or when a regulator expects a named accountable officer on site.

Which frameworks do you work with?

+

SOC 2 Type II, ISO 27001:2022, NIST CSF 2.0, Québec Law 25 and PIPEDA, PCI DSS 4.0, and CIS Controls v8. Most clients need two or more, so we map controls once against a single internal control set and generate the framework-specific evidence from it rather than running parallel programs.

How is this different from a penetration test?

+

A penetration test tells you what an attacker could exploit this quarter. A GRC program decides what you protect, who owns it, how you prove it and what happens when something fails. You need both, and they answer different questions — we run the program and coordinate independent testers rather than testing our own work.

Can you get us audit-ready for a customer requirement?

+

That is the most common reason clients call. When an enterprise deal is blocked on a security questionnaire or a SOC 2 report, we start with the gap that is actually blocking the deal, produce the evidence and interim attestations that unblock it, then build the rest of the program on the schedule your business can absorb.

Who writes the policies, and will anyone read them?

+

We write them, in plain language, against how your company actually builds and operates. A policy nobody follows is a finding waiting to happen, so we keep the library short, review it with the teams who have to live inside it, and delete controls you cannot realistically sustain rather than documenting fiction.

What happens if we have an incident during the engagement?

+

Incident support is included in every retainer at no additional hourly cost. We help you run the response, handle regulator and customer notification timelines including Law 25’s obligations, and rewrite the affected controls afterward. We also run tabletop exercises twice a year so the first real incident is not the first rehearsal.

● Start where you are

A 45-minute risk conversation. No scare tactics.

Tell us what triggered this — a customer questionnaire, a board directive, an insurer, an incident. We’ll tell you honestly what the next ninety days should look like and what you can safely defer.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.