Independent advisory firm · Canada
Cybersecurity driven by risk, not by products.
We help Canadian organizations understand their real exposure, prioritize their investments and demonstrate compliance — in English and in French.
- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
Services
Nine areas of expertise, one point of contact
Focused engagements, mapped to public frameworks, that always end with costed recommendations.
Cybersecurity risk assessment
Map your real exposure, rank risks by business impact and deliver a roadmap your board can defend.
NIST CSF 2.0 ISO/IEC 27005 Learn more → 02Third-party & vendor security review
Assess suppliers, subcontractors and managed providers before signature — and throughout the contract.
SOC 2 Type II ISO/IEC 27036 Learn more → 03Cloud security assessment
Configuration review of Azure, AWS or Microsoft 365: identity, logging, encryption, public exposure.
CSA CCM v4 CIS Benchmarks Learn more → 04Healthcare cybersecurity consulting
Protecting health information, maintaining continuity of care and securing connected devices.
Law 25 PIPEDA Learn more → 05Security governance & compliance
Policies, committees, roles and metrics: a security governance that survives an audit.
ISO/IEC 27001:2022 Law 25 Learn more → 06Security architecture & project advisory
Build security into your projects from design, without derailing delivery dates.
SABSA Zero Trust (NIST SP 800-207) Learn more →Why SpaceNet
Independent advice, usable deliverables
Full independence
We resell no products and take no vendor commissions: our recommendations serve your interest only.
Public frameworks
Every finding is mapped to NIST CSF, ISO/IEC 27001 or CIS Controls, so your auditors can understand and verify it.
Usable deliverables
Reports written to be read by leadership and applied by teams, in English or in French.
Industries
The sectors we know
Health & social services
Clinics, labs and medical device suppliers: protecting health information without slowing down care.
Financial services & insurance
High regulatory expectations, long supplier chains, low tolerance for risk.
Public & parapublic sector
Municipalities, crown corporations and bodies subject to Law 25 and procurement requirements.
Technology & SaaS
Vendors who must prove their security posture at every sales and renewal cycle.
Manufacturing & logistics
IT/OT convergence, operational continuity and critical supplier dependency.
Let’s talk about your real exposure.
A first 30-minute conversation, with no commitment, to understand your context and priorities.