Safeguards you can show, not just describe
BC PIPA and, for some activities, the federal PIPEDA require organizations to protect personal information with security safeguards suited to its sensitivity. In practice that means controlled access, protected devices, reliable backups and a plan for when something goes wrong. Cyber insurers have become far more specific, asking yes-or-no questions about MFA, EDR and offline backups, and an inaccurate answer can complicate a claim. Many small businesses have some controls in place but little evidence.
We map where personal information lives in your systems, compare current controls against what the law and your insurer expect, and close the gaps with practical fixes. Then we document it: policies, an access register, a breach response plan and evidence such as MFA and backup reports. Digi Mavericks is not a law firm or an insurer, so we work with your lawyer and broker on legal and coverage questions. It suits clinics, professional offices and non-profits.
What’s covered
- Personal information mapping A clear record of what personal data you hold, where it is stored and who can access it, from client files to HR records.
- Privacy safeguards under PIPA and PIPEDA Technical controls such as encryption, MFA, access reviews and logging, matched to the sensitivity of the information you hold.
- Breach response planning A written plan for containing an incident, preserving evidence, assessing harm and contacting your lawyer, insurer and the people affected.
- Cyber-insurance questionnaire readiness We go through the insurer’s questions line by line, confirm each control exists and collect screenshots and reports to back up every yes.
- Plain-language policies Acceptable use, access, device and data retention policies short enough that staff will actually read them.
- An evidence folder Exports and reports gathered in one place, ready for a renewal, a client’s vendor questionnaire or a privacy complaint.
- Staff privacy and security training Practical sessions on handling personal information and spotting phishing; see business cybersecurity for the technical layers.
- Annual review Controls, documentation and the breach plan rechecked each year, ideally before your insurance renewal, and folded into your IT roadmap.
Plans and pricing
| Service | Price |
|---|---|
| Compliance readiness review | From $950 |
| Policies and breach response plan | Quoted per project |
| Insurance questionnaire support | Included with your readiness review |
| Annual review | Quoted after your first review |
Prices are in CAD. Every engagement starts with a short call and a written proposal.
Common questions
What counts as personal information for a small business?
More than most owners expect: customer names with home addresses, client files, health or financial details, employee records, ID scans, security camera footage and notes in your CRM. The safeguards you need scale with how sensitive the data is, so a clinic’s charts call for stronger controls than a mailing list. Your lawyer can advise on obligations; we protect the data.
What do cyber-insurance questionnaires usually ask?
Expect questions about MFA on email and remote access, EDR on all endpoints, offline or immutable backups and how often they are tested, patching, staff training and whether you have an incident response plan. Answers need to be accurate, not optimistic. We help you check each control and collect evidence, while your broker handles the application itself.
Can you give us legal advice about privacy obligations?
That needs a lawyer. Digi Mavericks is not a law firm or an insurer, and we stay out of legal interpretation and coverage decisions. What we bring is the technical side: controls, documentation and evidence. If it helps, we can join a call with your lawyer or broker so the legal and technical pieces fit together.
What should a breach response plan include?
It should name who leads the response, how to contain the problem, how to preserve logs and evidence, when to call your insurer and lawyer, how to assess the risk of harm, and how to notify affected people or the privacy commissioner where required. We write the technical steps and can run a tabletop exercise as an optional add-on if you would like to rehearse it.