Same proven approach, delivered remotely or on-site as needed. Ideal for teams that want executive clarity, fast execution, and evidence-ready outcomes.
Pricing is based on a $1,500 CAD/day rate. Invoices can be issued in CAD.
US engagements can be invoiced in USD (FX-aligned). Scope and deliverables remain identical.
Support for SOC 2, ISO 27001, vendor risk, and board reporting across Canadian and US stakeholder expectations.
A four-week engagement that turns uncertainty into a prioritized plan and board-ready risk reporting. Fixed scope: 20 consulting days at CAD $1,500/day (CAD $30,000).
These are tailored to your environment, but they are designed to be immediately actionable (not shelfware).
| Deliverable | What you get |
|---|---|
| Executive risk narrative | A plain-English, board-ready summary: top risks, business impact, and decisions required. |
| Risk register + heat map | Prioritized risks with likelihood/impact, owners, and remediation options. |
| Control gap assessment | Mapping to a practical baseline (NIST CSF / CIS Controls) with what’s missing and why it matters. |
| Identity & access review | Identity architecture, privileged access, MFA coverage, and high-risk access paths. |
| Endpoint & vulnerability reality check | What’s installed vs what’s effective, patch/vuln cadence, and top exposures. |
| Cloud & data protection review | Data flows, backups, encryption, key management, and misconfiguration risks. |
| Incident readiness assessment | IR plan health, tabletop exercise, communications plan, and insurance-readiness items. |
| Vendor & third‑party exposure snapshot | Top vendors, critical data access, and a right-sized vendor review process. |
| 90-day roadmap | A sequenced plan aligned to your capacity with “quick wins” and measurable milestones. |
| Metrics & cadence | A reporting rhythm (monthly/quarterly) + KPIs leadership can actually interpret. |
Clear internal structure for humans and search engines — and a practical path from priority to measurable outcome.