Baseline Security Checkup
From $75090 minutes on-site, 20 controls scored, your top risks in plain English and a 30-day plan. The fee credits toward whatever you book next.
Owners and partners: the executive briefing
Book the baseline checkup →Client portal’s on the way
No login needed to get your files.
Already working with us? Call or email and we’ll send your reports and certificates the same business day.
Questions? Contact your team →A 12-person clinic, a 40-person accounting firm, a 100-person construction company - most businesses this size have nobody who owns security. We’re that person: live training your team remembers, the basics fixed and verified, the first hour of a bad day rehearsed, and ongoing coverage so it stays that way. Plain English, clear starting prices.
Assess where you stand, train the team, fix the basics, prepare for the bad day, test the defences - and stay ready. Clear starting prices, published - and a scored report every time. Most companies start with the checkup.
90 minutes on-site, 20 controls scored, your top risks in plain English and a 30-day plan. The fee credits toward whatever you book next.
Owners and partners: the executive briefing
Book the baseline checkup →Live, scored, at your office - from the 90-minute team drill to the three-hour flagship, with sector editions.
See the training →MFA enforced, email authentication set up, backups restore-tested, devices checked - with a “what we changed” page for your insurer.
Book the tune-up →A first-hour plan with real names and numbers, a tabletop rehearsal, and insurer-first escalation - before you ever need it.
Plan the first hour →Partner-delivered by our senior testing partner - scoped by us, translated into plain English, coordinated end to end.
See how testing works →We stay your security person: monthly check-ins, a live scorecard, no-shame phishing practice, every new hire trained.
See the Partner Plan →Sector drills and checkups tuned to your industry:
Five questions, 90 seconds, scored like the real checkup. No email address - nothing leaves your browser.
That’s more common than you’d think, and it’s fixable. The Baseline Security Checkup puts where you stand on paper in 90 minutes: a 20-point score, your top risks in plain English, and a 30-day plan with owners.
Want the full picture first? Take the free 10-minute self-check - or try Spot-the-Phish with your team.
Most offices land here - and the gap between “we think so” and “we can prove it” is exactly where incidents live. A 90-minute checkup turns your maybes into a scored answer you can put on an insurance questionnaire - because it’s true.
Want the full picture first? Take the free 10-minute self-check - or try Spot-the-Phish with your team.
Answers are easy in a quiz. The Cyber Fire Drill makes them hard: live scenarios, cloned voices, a scored simulation - so you find out whether the reflexes hold when it’s convincing and urgent.
Want the full picture first? Take the free 10-minute self-check - or try Spot-the-Phish with your team.
Nothing is recorded or sent - the score exists only on your screen. The 90-minute on-site checkup is the scored version you can hand your insurer or a client.
And a real heist rarely stops at one door - it chains them. Step through a composite heist, minute by minute, and count the moments it could have stopped.
A password the bookkeeper has reused since 2019 - leaked in a breach years ago - still opens their work inbox. No alarm rings. The visitor doesn’t touch a thing. They read.
An unfamiliar device quietly syncs that inbox every night, and nothing flags it. They learn who pays, who approves, how everyone signs off - and that a supplier is owed $48,200 on Friday.
Accounts payable gets a call. It’s the owner’s voice - the pace, the impatience, even the joke. A few minutes of audio is enough to clone a voice now. “I’m boarding a flight. Their new account details are coming by email - please get it out before 5.”
The email lands inside the real invoice thread. Same signature, same footer, same PDF. “Please note our updated banking details for this payment.” The sender’s domain is one character off - and nobody is counting characters at 4:52 on a Friday.
The payment is keyed in. The invoice was due, the thread was real, the boss called ahead. The one callback that stops everything is the step under the most time pressure - so it’s the step that gets skipped.
The real supplier calls about their overdue invoice. Now it’s the bank, the insurer’s breach line and a very long week - and the money has been gone since Friday at 5:07.
Five ordinary moments - one at every door - and none of them needed a security expert. Just a reflex that still fires at 4:52 p.m. on a Friday, when everything looks right. Installing that reflex is the job: in The Heist, the fire drill’s 35-minute story-driven simulated attack, your team beats a heist like this one together, against the clock - and drills the stop-moments until the right move is boring. Boring is the goal.
We train all five doors - email, the phone, passwords, devices & Wi-Fi, money movement - with your industry’s real examples: spot it, stop it, report it.
A composite training scenario - no real client, no real names; the amount is illustrative. The pattern is the one we drill.
A two-person IT team keeping a 100-person company running has no time to own security. An office with no IT at all has nobody to even ask. Either way, we own readiness - training your people, verifying and fixing the basics, rehearsing the first hour, and coordinating partner-delivered testing - and we put the boundary in writing. No products to resell you. No 400-page reports. No fear.
Live training and drills, the Baseline Security Checkup, the five basics verified and fixed under the Tune-Up, incident rehearsal, and the reports your insurer and clients ask for - with the boundary stated in writing on every engagement.
Help desk, endpoints, patching, networks, servers, backups and day-to-day administration stay with your IT company or internal IT. We coordinate with them respectfully - many of our best referrals come from IT providers.
That’s how we’d buy security too. The controls we score are public, starting prices are published for every service, and you can read the exact scored deliverable before you pay a cent.
You’ll never wait a week to find out what it costs.
Scored, plain-English, with a 30-day plan - not a slide deck.
You reach a person, not a ticket queue - and we don’t cold-call.
The Baseline Security Checkup. It’s 90 minutes on-site, it produces the scored report that answers insurer and client questionnaires, and the full fee credits toward any training or Tune-Up booked within 30 days - so it costs nothing extra if you act on it. If training is the urgent need, start with a Fire Drill instead.
No - training is where most clients meet us, but the firm covers the full readiness cycle: scored checkups, hands-on fixes like MFA and backups, incident planning (insurer-first), and partner-delivered penetration testing. Your IT provider keeps running the systems; we handle readiness and put the boundary in writing.
Most are between 5 and about 150 people - clinics, law and accounting firms, construction offices, and companies where a small IT team (or nobody) is holding it all. Published packages quote the most common team sizes; larger teams usually run multiple sessions or a tailored program, scoped on the fit call with a written proposal before anything is booked.
Starting prices are published for everything: checkup from $750 · training from $1,800 (flagship from $3,900) · Tune-Up from $1,800 · incident readiness from $2,900 · partner-delivered penetration testing $6,000–$18,000+ by quote. Ongoing Partner Plan tiers are on the pricing page. Your written proposal shows the rate and the estimated hours before you commit. All CAD, plus HST.
Book the 20-minute fit call. We’ll recommend the smallest useful first step - and if you don’t need us, we’ll say so and point you to the free tools.