Layers that cover each other’s gaps
Attackers rarely pick a small business by name. Automated tools test leaked passwords against Microsoft 365, send invoice-fraud emails to bookkeepers and probe for unpatched firewalls around the clock. When one gets through, the damage is usually a hijacked mailbox sending fake payment requests to your clients, or ransomware that locks shared files. No single product stops all of that, and an antivirus licence on its own was never designed to.
We work in layers, so when one control misses, the next one catches it. MFA blocks most password attacks. EDR watches for suspicious behaviour on each computer. Email filtering and DMARC cut phishing and spoofing. Patching closes known holes, least-privilege access limits how far an intruder can move, tested backups make recovery possible, and short training sessions help staff spot what slips through. It suits any office that holds client, patient or financial data.
What’s covered
- Security review A structured look at accounts, devices, email, network and backups, ending in a short written list of risks, worst first, with the fix for each.
- MFA where it counts Authenticator-app or passkey sign-in on email, remote access and admin accounts, with legacy protocols that bypass MFA turned off.
- Endpoint detection and response Behaviour-based protection on every laptop and server that can stop a suspicious process and isolate the device mid-attack.
- Email security and DMARC Filtering for phishing and malicious attachments, plus SPF, DKIM and a DMARC policy moved step by step from monitoring to reject.
- Patching and vulnerability fixes Operating systems, browsers, PDF readers and firewall firmware kept current, with reports showing anything still outstanding.
- Least-privilege access Everyday accounts without admin rights, separate admin logins, and shared folders that only the right people can open.
- Backups that survive ransomware Copies kept offline or immutable so an attacker cannot delete them; see backup and disaster recovery.
- Awareness training Bite-sized sessions and simulated phishing emails that build the habit of pausing before clicking a link or paying an invoice.
- Managed detection and response For higher-risk environments, we can add a managed detection and response service from a specialist partner for 24/7 threat monitoring.
Plans and pricing
| Service | Price |
|---|---|
| Security review | From $950 |
| Remediation project | Quoted from your review findings |
| Ongoing security layers | Included in the Secure managed IT plan |
| Staff awareness training and phishing tests | From $5 per user/month |
Prices are in CAD. Every engagement starts with a short call and a written proposal.
Common questions
What does a cybersecurity review for a small business involve?
We check how people sign in, how devices are protected and updated, how email is filtered, how the network is segmented and whether backups can actually be restored. You get a short written report that ranks each finding and explains the fix in everyday terms. Most reviews take 1–2 weeks, including about half a day on site.
Is antivirus enough for a small office?
Traditional antivirus matches known threats, which modern attacks are built to avoid. EDR looks at behaviour instead, such as a process encrypting hundreds of files, and can stop it and isolate the machine. Even EDR is only one layer, though, and many real incidents begin with a stolen password or a fake email that no antivirus ever sees.
What should we do first if an employee clicked a phishing link?
Unplug the network cable or turn off Wi-Fi on that computer, but leave it powered on so evidence is kept. From a different device, change the password for any account typed into the fake page, then contact us. We check sign-in logs, look for mailbox rules that forward mail outward, revoke active sessions and contain anything suspicious before it spreads.
How does DMARC protect our business email?
DMARC tells receiving mail servers what to do with messages that use your domain but fail authentication. Set to reject, it stops criminals from sending convincing invoices in your name. We roll it out gradually, reading the reports so legitimate senders such as your billing platform or newsletter tool keep delivering.
Will these controls help with our cyber-insurance application?
They should. MFA, EDR, backups you have actually restored from and a record of staff training are the controls insurance questionnaires most often ask about, and we can document what is in place so your answers are accurate. We are not an insurer or broker; for the paperwork side, see compliance and insurance readiness.