Line 02 · Governance & assurance

Governance you can prove.

Compliance is where claims meet evidence — the assessments that establish where you stand, the privacy analysis regulators expect, and the readiness work that turns security effort into something a customer or auditor can rely on. Structured, scoped to your environment, and free of theatre.

CMP-01of 06 · Flagship assessment

Threat Risk Assessments

A structured look at what can actually hurt you.

Our flagship assessment: a methodical review of a system or service that identifies the threats that apply to it, weighs their likelihood and impact, and measures your existing controls against recognized frameworks. Findings arrive ranked by real risk, not alphabetically, with a remediation path your team can actually execute. It is the document that lets executives, auditors, and engineers argue from the same facts.

  • Structured STRA methodology
  • Threat & risk modelling
  • Control gap analysis
  • Ranked remediation plan
Read moreRead less

When to run one

A STRA belongs wherever risk changes shape: a new system going live, a major change to an existing environment, data being shared with an outside party, or a regulator or customer asking for evidence that risk was assessed before go-live. Many clients run them continuously on a subscription cadence rather than as one-off projects.

What's included

  • Threat modelling with likelihood & impact scoring
  • Control-effectiveness review — current & planned
  • Residual-risk documentation & acceptance
  • Executive reporting with clear risk scoring
  • Central risk repository your team keeps
  • Per-system or continuous subscription cadence

Methodology

Assessments align to the frameworks your stakeholders already recognize — ISF IRAM2, NIST 800-30 and 800-53, ISO 27004, and ITSG-33 for public-sector environments — so the output slots into audits instead of sitting beside them.

CMP-02of 06 · Privacy assessment

Privacy Impact Assessment (PIA)

Know how personal data moves through your organization — and prove it is protected.

A PIA maps how personal information is collected, used, stored, and shared across a system or initiative, then measures those flows against PIPEDA and the provincial privacy laws that apply to you. We identify where the gaps are and pair each one with a safeguard that is proportionate, not performative. The result is documentation that stands up to a regulator and a design your privacy officer can defend.

  • Data-flow mapping
  • PIPEDA & provincial alignment
  • Proportionate safeguards
  • Regulator-ready documentation
Read moreRead less

When a PIA is required

Any new system, technology, or process that handles personal information — or a material change to one — can trigger the obligation, and several privacy regimes make it mandatory where processing presents high risk (the GDPR’s DPIA being the clearest example).

What's included

  • Scoping, discovery & data-flow mapping
  • PIA / DPIA execution & independent review
  • Reusable, customized PIA templates
  • Privacy policy & procedure development
  • Role-based PIA training for your teams
  • Ongoing updates & maintained risk registers

Depth behind the work

Assessments are led by IAPP-certified privacy specialists (CIPP, CIPM, CIPT) and measured against PIPEDA, the GDPR, ISO 27701, and the NIST Privacy Framework — whichever combination actually applies to your data.

CMP-03of 06 · Attestation readiness

SOC 2 Readiness

Walk into your audit already knowing the answer.

We scope the trust services criteria that actually apply to your business, run a gap assessment against them, and help you design controls and evidence habits that fit how your team already works. When the auditor arrives, the evidence exists because it was produced in the normal course of business — not assembled in a two-week scramble. We stay through the audit itself to keep the process moving. The attestation report is issued by your CPA firm — our work is getting you ready for it and supporting the engagement.

  • Scoping & gap assessment
  • Control design
  • Evidence & automation habits
  • Audit-cycle support
Read moreRead less

The path to attestation

  • Requirements & report-objective scoping
  • Gap analysis & risk assessment
  • Control design & documentation
  • Control-effectiveness testing & scoring
  • Internal audit & management review
  • CPA engagement & attestation support

Report types

Type 1 attests control design at a point in time; Type 2 attests operating effectiveness over a period — the one enterprise customers usually ask for. SOC 2+ reports fold in adjacent requirements such as HIPAA or PCI DSS where one audit can serve several masters. We scope only the Trust Services Criteria that apply to your business rather than defaulting to all five.

CMP-04of 06 · Regulatory coverage

Data Protection & Regulatory

Privacy, payments, and the data itself — one control set instead of three scrambles.

Data-protection obligations overlap heavily, so we treat them as one program: know where sensitive data lives, control how it moves, and map each control once to every regulation that demands it. That covers data loss prevention that people don’t route around, GDPR readiness for organizations touching EU data, and PCI DSS scoping that keeps cardholder environments small. One control set, maintained once, defensible everywhere.

  • Data loss prevention (DLP)
  • GDPR readiness
  • PCI DSS scoping & compliance
  • Unified control mapping
Read moreRead less

What's included

  • Data discovery & classification across systems
  • DLP policy, monitoring & enforcement design
  • Coverage for data at rest, in motion, in use & in cloud
  • GDPR readiness & gap analysis
  • Data inventory & flow-mapping audits
  • DPO-as-a-Service for ongoing obligations
  • PCI DSS v4.0 readiness & scope reduction
  • SAQ / AOC completion & pre-audit support

How the pieces connect

Discovery and classification feed the DLP program; the same data inventory satisfies GDPR’s mapping obligations; and a deliberately small cardholder environment keeps PCI assessment effort proportionate. Incident response procedures are built to meet the GDPR’s 72-hour notification window, because that clock is the one that hurts.

CMP-05of 06 · Cloud posture — assess

Cloud Security Assessment

Know how your cloud is actually configured — not how it was designed.

Cloud environments drift: the architecture diagram says one thing, and eighteen months of tickets say another. We assess your real posture across AWS, Azure, GCP, and Microsoft 365 — identities and their permissions, network paths, storage exposure, logging — and rank what we find by exploitability, not by scanner severity. When you want the fixes watched continuously rather than annually, this hands off directly to Managed CloudSec.

  • Posture & configuration review
  • AWS · Azure · GCP · M365
  • Identity & network paths
  • Pathway to Managed CloudSec
Read moreRead less

What we review

  • Configuration measured against CIS Benchmarks
  • Identity, roles & privileged-access paths
  • Network segmentation & zero-trust design
  • Storage & data exposure
  • Logging, telemetry & detection coverage
  • Container & Kubernetes posture

How it lands

You get two reports from one assessment: an executive view that ranks findings by exploitability and business impact, and a technical remediation plan your platform teams can execute directly. Architecture-level recommendations — segmentation, guardrails, DevSecOps integration — come with the reasoning, not just the diagram. When you want the posture watched continuously, the same findings seed Managed CloudSec.

CMP-06of 06 · Industrial environments

OT / ICS Security Assessment

Where uptime, safety and cyber risk meet.

Operational technology runs on different rules: availability first, patching windows measured in maintenance shutdowns, and equipment that predates the idea of a security update. We assess industrial control environments the way they need to be assessed — documentation review, staff interviews, and collection that stays passive on the operational network — and hand back tactical and strategic recommendations measured against ISA/IEC 62443 and NIST SP 800-82. The scope is protecting the process, not just the network.

  • Architecture & IT/OT boundary review
  • Crown-jewel identification
  • ISA/IEC 62443 & NIST SP 800-82
  • Process-safe, passive collection
Read moreRead less

What's included

  • Network architecture, segmentation and topology review — including the IT/OT boundary and DMZ
  • Asset inventory and vulnerability assessment from passive network telemetry
  • Crown-jewel identification: the systems whose failure stops the operation, found and prioritized
  • Detection and response capability review across SIEM, EDR and OT-specific tooling
  • Standards and regulatory alignment — ISA/IEC 62443, NIST SP 800-82, and NERC CIP where it applies

Environments

Electric, oil and gas, water and wastewater, transportation, building management, data centres, mining and manufacturing — the same operational-technology ground our Oil & Gas and Mining industry work already stands on.

Where it goes next

The assessment is the front door, not the whole house. Findings can carry into adversarial validation scoped for industrial environments — vulnerability assessment, penetration testing and purple-team exercises planned around live processes and maintenance windows — and into threat-baseline workshops and OT tabletop exercises that rehearse ransomware, IT/OT trust abuse, insider threat and vendor-compromise scenarios before one is real. For CrowdStrike environments, Falcon for XIoT deployment and operation run through our Center of Excellence.