Consultation · Cybersecurity & Risk Management · Calgary, AB

Cyber risk decisions, backed by evidence.

Independent cybersecurity and risk management advice that shows you where you are exposed, what it could cost the business, and exactly what to fix first — in language leadership and IT can both act on.

  • NIST CSF 2.0
  • ISO/IEC 27001 & 27005
  • CIS Controls v8
  • MITRE ATT&CK
  • Zero Trust

01 / Consulting services

Expert guidance from assessment to execution

Engage us for a single assessment or as an ongoing partner. Every engagement ends with a written, prioritized plan your team can act on — whether or not you continue with us.

Assess

Cyber Risk Assessment

A clear picture of your exposure, ranked by business impact.

  • Assets, data flows and critical processes
  • Threat and vulnerability analysis
  • Likelihood and impact scoring
  • Risk register and heat map
Plan

Security Program & Roadmap

Know where you stand and what to do next, in the right order.

  • NIST CSF 2.0 or CIS Controls gap assessment
  • Current vs. target maturity profile
  • 12–24 month prioritized roadmap
  • Budget and resourcing guidance
Lead

Virtual CISO (vCISO)

Senior security leadership without a full-time executive hire.

  • Security strategy and governance
  • Board and executive risk reporting
  • Vendor, project and budget oversight
  • Ongoing advisory as your business changes
Comply

Compliance Readiness

Prepare for audits, certifications and customer security reviews.

  • ISO/IEC 27001 and SOC 2 readiness
  • PIPEDA and Alberta PIPA privacy obligations
  • Cyber-insurance questionnaires and controls
  • Customer security questionnaires
Govern

Policy, Governance & Third-Party Risk

The policies and oversight that make security consistent.

  • Information security policy suite
  • Roles, responsibilities and risk ownership
  • Vendor and supply-chain risk reviews
  • Acceptable use and data handling standards
Prepare

Incident Response & Business Continuity

Be ready before an incident, not during one.

  • Incident response plan and playbooks
  • Business continuity and disaster recovery planning
  • Backup and recovery validation
  • Tabletop exercises for leadership and IT

02 / How we engage

A clear process with no surprises

DISCOVER

A free initial consultation to understand your business, your concerns and what success looks like. We agree on scope and deliverables up front.

ASSESS

Interviews, documentation review and technical checks across people, process and technology — mapped to recognized frameworks.

PRIORITIZE

Findings are ranked by business risk and effort, so the first actions you take remove the most risk for the least cost.

ADVISE

An executive briefing and a practical roadmap — with hands-on help to implement it if you want it.

03 / Deliverables

What you walk away with

  • Executive summaryYour risk posture in plain business language, ready for leadership and the board.
  • Risk register and heat mapEvery risk with an owner, a rating and a recommended treatment.
  • Prioritized remediation roadmapQuick wins first, then the longer-term program, with effort and cost estimates.
  • Framework mappingHow your controls line up against NIST CSF 2.0, CIS Controls or ISO/IEC 27001.

Engagement options

Choose the model that fits

  • Fixed-scope assessmentA defined assessment with a fixed price and a clear end date.
  • Project-based advisoryExpert support for a specific initiative such as a compliance audit, cloud migration or policy overhaul.
  • Ongoing vCISO retainerRegular leadership time each month for strategy, reporting and decision support.
  • Confidential by defaultMutual NDA available before any sensitive information is shared.

04 / Questions

Frequently asked questions

Is the initial consultation really free?

Yes. The first conversation is free and without obligation. We use it to understand your situation and recommend the right next step — which is sometimes something your team can do without us.

We are a small business. Is this for us?

Yes. Engagements are scoped to the size and risk of your organization. Smaller businesses often benefit the most from a short assessment and a focused roadmap, because every dollar has to go to the controls that matter.

How long does a risk assessment take?

It depends on the size and complexity of your environment. Smaller organizations can typically be assessed in a few weeks; we confirm the timeline and deliverables in writing before any work begins.

Will you help us implement the recommendations?

If you would like us to. Our team can carry out the technical work — hardening, identity and cloud security, monitoring and incident response planning — or support your internal IT team or existing provider.

How do you handle our sensitive information?

All engagements are confidential, a mutual NDA can be signed before any information is shared, and access to your systems and data is limited to what the agreed scope requires.

05 / Start here

Book a free consultation

A focused conversation about your risks and priorities. You leave with concrete next steps — whether you hire us or not.

Book a free consultation Looking to train your team? See training

Response within one business day. Under active incident? Call us.