Call Book a call

Security that fits a business your size

Most small-business breaches are not clever. They are a reused password, an account that was never disabled, or a domain anyone can send email as. Those are fixable in an afternoon.

Start with your email

Email is where small businesses actually get hit: a spoofed invoice, a fake request to change payment details, a message to your clients that looks like it came from you.

Three DNS records decide whether that is easy or hard. This check reads them and tells you which state you are in, in plain English.

Free email security check

See whether your domain can be spoofed. We check SPF, DKIM and DMARC and explain each result in one sentence.

No signup. We log the domain and the time, nothing else, unless you ask for the full report.

What we cover

Included on Managed Support plans, or delivered as a one-off project.

Multi-factor authentication

On every account that touches email, files or money — not just the admins. The most common way a small business gets breached is still a password that worked somewhere else.

Admin access clean-up

Global admin rights handed out years ago, accounts belonging to people who left, and the former IT provider who still has delegated access. We find them, document them, and remove what should not be there.

Endpoint protection

Defender for Business deployed and actually managed — alerts going somewhere a person reads them, rather than to a console nobody opens.

Backup that has been restored from

A backup nobody has tested is a hope, not a backup. We cover mail, OneDrive or Drive, SharePoint and Teams, and we restore something during onboarding to prove it works.

Awareness training

Short sessions on spotting spoofed email and fake document requests, with simulated phishing if you want a number to track. For accounting firms this is usually the highest-value hour of the year.

Cameras and access control

Physical security belongs in the same conversation. Avigilon video and door access, configured and supported alongside everything else.

Cameras & access control

IT & Security Assessment

A practical review of how your systems are actually configured: identity and MFA, admin accounts, email authentication, endpoint protection, backup coverage, network exposure, and who can see what in your cloud storage.

You get a written report with findings ranked by risk, a fix list you could hand to any competent provider, and a 45-minute review call. The report is yours whether or not you hire us afterwards.

  • Written report with prioritized fixes
  • 45-minute review call
  • Credited toward the first 3 months of an annual Managed Support term

$1,500

One-time. Credited in full against an annual Managed Support term started within 90 days.

Book an assessment

A note on privacy law

If your business collects personal information about people in Canada, PIPEDA sets expectations about how you protect it, who you let see it, and what you do when something goes wrong. Good practice on MFA, access control and backup is most of what that looks like day to day.

We can tell you where your setup sits against those expectations, and that is the extent of it. We are not auditors, we do not issue certifications, and any IT provider offering to make your business “certified compliant” is selling you something that does not exist.

Common questions

What does the IT & Security Assessment cover?

Identity and MFA, admin accounts, email authentication, endpoint protection, backup coverage, network exposure and who can see what in your cloud storage. You get a written report with the findings ranked by risk and a fix list, plus a 45-minute review. It is $1,500, credited toward the first 3 months of an annual Managed Support term.

Is this a compliance audit?

No, and we will not claim otherwise. It is a practical security review of how your systems are actually set up. We can point out where your handling of personal information sits relative to PIPEDA expectations, but that is informational — we are not auditors and we do not issue certifications.

Do you do security awareness training?

Yes — short sessions for staff on spotting spoofed email and document-request scams, plus simulated phishing if you want to measure it. For accounting firms this is usually the highest-value hour of the year.

Not sure what you need? Start with a call.

Twenty minutes, no obligation. Tell us what is breaking and we will tell you what it would take to fix it — including when the answer is that you do not need us.

Book a 20-minute call 647-969-6900

We reply to new inquiries within one business day.