Issue 001 · Spring 2026Toronto · Global
← Home / Index§ Services
Available today · Engagements open Q2 2026

Senior security
on demand.

Ten engagements across four pillars. Every one delivered by certified practitioners — CISSP, TOGAF, SABSA, OSCP — who’ve done the work before, at scale.

The four pillarsAssess · Build · Defend · Respond
A.Assess

Quantify what you have, what you’re missing, and what would actually move the needle.

B.Build

Architecture, identity, cloud — designed for the way your team actually ships.

C.Defend

Day-in, day-out leadership and awareness. The boring work that prevents incidents.

D.Respond

Compliance, audit, IR. When it matters, you don’t want to be looking for a phone number.

CISSP · TOGAF · SABSA · OSCPToronto · Global Engagements24/7 IR RetainerQ2 2026 — 3 Slots AvailableCISSP · TOGAF · SABSA · OSCPToronto · Global Engagements24/7 IR RetainerQ2 2026 — 3 Slots Available
§ 02 — Engagements

Ten engagements. One standard.

A · Assess
i.

Threat & risk assessment.

Know what you’re defending — and from whom.

CSF, CIS, ISO 27001, PCI — pick the lens, we run the analysis. Outputs are decision-grade, not décor.

  • Asset & data flow mapping
  • Threat modelling (STRIDE / PASTA)
  • Quantified residual risk
  • Board-ready report
Investment
From $14K
Discuss this engagement →
A · Assess
ii.

Penetration testing.

Web · Mobile · Infra · Red-team.

Reports your engineers will actually read — and act on. Practical remediation guidance included.

  • OWASP ASVS-aligned methodology
  • Manual + tooling-assisted
  • Retest included
  • Exploitable proof, not theoretical findings
Investment
From $12K / engagement
Discuss this engagement →
B · Build
iii.

Security architecture.

Zero-trust, identity, cloud, network.

We design with your engineering reality in mind, then help your team operate it.

  • TOGAF / SABSA practitioners
  • Cloud-native patterns (AWS / GCP / Azure)
  • Reference architectures + runbooks
  • Phased implementation roadmap
Investment
Scoped per engagement
Discuss this engagement →
B · Build
iv.

Identity & access.

The single biggest leverage point in your security program.

SSO, MFA, lifecycle management, privileged access — implemented end-to-end with the workflows your team will actually use.

  • Okta / Entra ID design + deployment
  • Privileged Access Management (PAM)
  • Joiner-mover-leaver automation
  • Access reviews + recertification
Investment
Scoped per engagement
Discuss this engagement →
B · Build
v.

Cloud security.

AWS, GCP, Azure — securely.

CSPM, container security, IAM hardening, network controls. Designed for your existing platform stack, not bolted on.

  • Landing zone review + hardening
  • Container & Kubernetes security
  • Secrets management
  • Continuous compliance baseline
Investment
From $18K
Discuss this engagement →
C · Defend
vi.

vCISO leadership.

Senior judgment without full-time cost.

Fractional CISO leadership for orgs that need a security voice in the room — board, audits, customers, vendors — without a $400K hire.

  • Board reporting + risk register
  • Audit & customer security reviews
  • Vendor & contract review
  • Team mentorship
Investment
From $4,500/mo
Discuss this engagement →
C · Defend
vii.

Security awareness.

Training that doesn’t feel like training.

Role-based programs that move the actual numbers your auditor cares about — phishing click rates, MFA adoption, policy attestations.

  • Phishing simulation + remediation
  • Role-based curriculum
  • Engineering-specific content
  • Quarterly KPI reporting
Investment
From $6K / year
Discuss this engagement →
D · Respond
viii.

Incident response.

Calm hands when it matters.

24/7 retainers, on-demand IR, forensics, breach communications. We help you contain, recover, and learn — without the panic markup.

  • Retainer + on-demand options
  • Digital forensics + root cause
  • Regulator & customer comms support
  • Post-incident program hardening
Investment
$2,500/mo retainer + hours
Discuss this engagement →
D · Respond
ix.

Compliance & audit.

SOC 2, ISO 27001, PIPEDA, Law 25.

Get audit-ready without the consulting markup. We pair you with vetted auditors when you’re ready to certify.

  • SOC 2 Type 1 + Type 2 readiness
  • ISO 27001:2022 implementation
  • PIPEDA + Law 25 (Quebec) advisory
  • Auditor matching
Investment
From $24K
Discuss this engagement →
D · Respond
x.

Infrastructure assessment.

Network, endpoint, identity — top to bottom.

A structured review of your security posture across infrastructure, with prioritized remediation aligned to your roadmap.

  • Network segmentation review
  • Endpoint posture (EDR / MDM)
  • Identity perimeter assessment
  • Quarterly delta reports
Investment
From $16K
Discuss this engagement →
§ 03 — Engage

Let’s talk scope.

A 30-minute call to understand your situation, scope what’s realistic, and confirm fit. No deck, no discovery loop, no obligation.