SECURITY-FIRST OFFER

Establish a Secure Foundation before expanding digital initiatives.

A defined engagement to understand priority risks, review cloud, identity, and email controls, implement agreed hardening, and document a 90-day roadmap.

FIT AND TRIGGERS

Designed for an organization that needs a shared starting point.

Ideal customer

  • Growing organization with roughly 15–100 employees
  • Microsoft 365 or Google Workspace at the centre of operations
  • Internal IT or an existing provider without a mature security function

Triggering events

  • A client security questionnaire or contract requirement
  • Insurance renewal, leadership change, or rapid growth
  • Accounts, external access, or AI use that has become hard to govern
ENGAGEMENT SCOPE

From leadership decisions to priority controls.

1. Executive risk assessment

Business context, critical assets, risk scenarios, and required decisions, presented without unnecessary jargon.

2. Technical baseline review

Targeted review of cloud configuration, identity, administrative accounts, email, and sharing controls.

3. Priority hardening

Implementation of the changes specifically agreed in scope, with validation and handoff to the IT team.

4. Governance foundation

Responsibilities, decisions, priority policies, and follow-up needed to support alignment with applicable obligations.

5. Documented 90-day roadmap

Sequenced actions, owners, dependencies, and verification criteria for the work that follows.

6. Strategic debrief

Leadership review of decisions made, residual risks, and the available next-step options.

What is implemented

The engagement does not stop at diagnosis: configuration and governance changes explicitly listed in the statement of work are implemented and verified with accountable stakeholders.

What is not included by default

  • Penetration testing, a security operations centre, or around-the-clock monitoring
  • Helpdesk service, full incident response, or daily user administration
  • Legal advice, certification, or a compliance guarantee
  • Licences and remediation outside the agreed scope
TIMELINE AND RESPONSIBILITIES

A schedule shaped by scope and access.

The roadmap covers the next 90 days. The delivery schedule is confirmed after scoping and depends on access, decision-maker availability, and IT-provider participation.

Client responsibilities

  • A decision-maker and a technical owner
  • Authorized access and available documentation
  • Timely decisions on proposed changes
  • Coordination with the IT provider when needed
INVESTMENT

Starting at CAD $4,500

Final pricing varies with user and domain count, platforms, licences, observed gaps, and the amount of hardening included. The proposal confirms scope, exclusions, and schedule before work begins.

AT COMPLETION

A documented baseline and clear options.

Baseline record

Findings, implemented changes, and items to monitor.

Governance record

Agreed responsibilities, decisions, and documents.

Roadmap

Sequenced work with owners and verification criteria.

AFTER THE FOUNDATION

The next step depends on risk and priorities.

Managed Security

Ongoing control maintenance and governance under a confirmed scope.

AI Workflow Automation

Selected automation with rules, access controls, and human review.

Cloud Modernization

Document structure, sharing, and access after the security baseline.

Strategic Oversight

Leadership cadence for risk, decisions, and investment.

FREQUENTLY ASKED QUESTIONS

Clarify scope before starting

Is this only an assessment?

No. It includes assessment and implementation of explicitly agreed changes. Remediation outside scope is placed on the roadmap.

Can you work with our IT provider?

Yes. Access, responsibilities, changes, and handoff are coordinated with the designated team or provider.

Does the engagement guarantee security or compliance?

No. It improves a defined baseline and supports alignment, but no engagement can guarantee the absence of incidents or replace legal advice or certification.

What if substantial remediation is discovered?

Out-of-scope items are documented, prioritized, and separately priced before additional implementation.

See whether Secure Foundation fits.

The fit call clarifies the trigger, fit, and next step. It is not a substitute for an assessment.

Book a fit call