Close the gaps before someone else finds them.

Most small businesses do not get breached by anything sophisticated. They get caught by an account without multi-factor authentication, a backup nobody has restored from, or a former employee whose access was never removed.

What tends to be wrong

  • Accounts

    Multi-factor authentication missing where it matters, shared logins, and access that was never removed when someone left.

  • Backups

    Backups that run but have never been restored from. An untested backup is a belief, not a control.

  • Suppliers

    Third parties with access to your systems, on terms nobody has read since they were signed.

  • Unsupported software

    Software no longer receiving patches, which is both the easiest gap to exploit and the easiest to find.

What you get

Findings in plain English, ranked by risk, with what it would take to fix each one. Not a scan report with four hundred items and no order of work.

The ranking is the useful part. Everything on a security list is worth doing in principle; the question a business actually faces is what to do first with the budget available this quarter.

Insurance and customer audits

Cyber insurance questionnaires and customer security reviews increasingly ask specific questions: multi-factor authentication, backup testing, patching, access removal. Being unable to answer them is now a commercial problem as much as a technical one.

We are not lawyers or auditors, and this is not a certification. It is a practical review of whether the answers you would have to give are true, and what it takes to make them true.

Common questions

What does a security review cover?

Accounts and access, backups and whether they have been tested, supplier access, patching and unsupported software, and the practical controls that insurance questionnaires and customer audits ask about. Findings come back in plain English, ranked by risk.

We are small. Is this really necessary?

Small businesses are targeted because the common gaps are easy to find automatically, not because anyone chose them. The controls that prevent most of it are unglamorous and cheap, which is the good news.

Is this a certification?

No. We are not auditors or lawyers and this is not ISO 27001 or SOC 2. It is a practical review of where the gaps are and what closing them involves. If you need formal certification we will tell you that is a different exercise.

Can you help with a cyber insurance questionnaire?

That is one of the most common reasons businesses ask. The review establishes whether the answers you would give are actually true, which is the part that matters if you ever need to claim.

Does PIPEDA apply to us?

Most private-sector organisations handling personal information in Canada have obligations under PIPEDA, and British Columbia has its own provincial legislation. We can tell you which practical controls are relevant, but for a legal opinion on your obligations you want a lawyer.

Do you fix what you find, or just report it?

Either. The review is the free assessment; the work that follows is scoped to a fixed price and a fixed date. You can also take the findings and have someone else do the work, and the report is written so that is possible.

Find out what would fail an audit.

It starts with a 15-minute call. If we are a fit, the free assessment that follows produces plain-English findings ranked by risk, alongside a 12-month roadmap you can hand to any supplier. Yours to keep either way.