Call Book the fit call
Toronto & GTA · Cybersecurity for companies of 5–150 people

Your company’s security, handled.

A 12-person clinic, a 40-person accounting firm, a 100-person construction company - most businesses this size have nobody who owns security. We’re that person: live training your team remembers, the basics fixed and verified, the first hour of a bad day rehearsed, and ongoing coverage so it stays that way. Plain English, clear starting prices.

16%of Canadian businesses were hit by a cyber incident in 2023 (Statistics Canada)
41%of attacked small businesses report costs of $100k or more (Insurance Bureau of Canada)
34%of small-business staff report mandatory cyber awareness training (Insurance Bureau of Canada)
3 hoursone live drill to turn clicks into catches
What we do

One local firm for the whole security job.

Assess where you stand, train the team, fix the basics, prepare for the bad day, test the defences - and stay ready. Clear starting prices, published - and a scored report every time. Most companies start with the checkup.

Train

Cyber Fire Drill training

From $1,800 · flagship from $3,900

Live, scored, at your office - from the 90-minute team drill to the three-hour flagship, with sector editions.

See the training →
Fix

Security Tune‑Up & hardening

From $1,800

MFA enforced, email authentication set up, backups restore-tested, devices checked - with a “what we changed” page for your insurer.

Book the tune-up →
Prepare

Incident readiness

From $2,900

A first-hour plan with real names and numbers, a tabletop rehearsal, and insurer-first escalation - before you ever need it.

Plan the first hour →
Test

Penetration testing

$6,000–$18,000+ by partner quote

Partner-delivered by our senior testing partner - scoped by us, translated into plain English, coordinated end to end.

See how testing works →
Stay ready

Security Partner Plan

Ongoing coverage · after your first engagement

We stay your security person: monthly check-ins, a live scorecard, no-shame phishing practice, every new hire trained.

See the Partner Plan →

Sector drills and checkups tuned to your industry:

The 90-second spot check

Would your office catch the email that costs a year of rent?

Five questions, 90 seconds, scored like the real checkup. No email address - nothing leaves your browser.

A supplier emails “updated banking details” on a real invoice thread - the day a payment is due.

A caller who sounds exactly like the boss asks for an urgent transfer while “stuck in a meeting”.

Where does two-step sign-in (MFA) actually stand across your email, banking and payroll?

Ransomware locks every file at 9 a.m. tomorrow. How do you know your backups actually restore?

Someone on the team clicks a bad link and realizes it. What happens in the next hour?

Exposed

Several doors are open - and nobody’s watching them.

That’s more common than you’d think, and it’s fixable. The Baseline Security Checkup puts where you stand on paper in 90 minutes: a 20-point score, your top risks in plain English, and a 30-day plan with owners.

Want the full picture first? Take the free 10-minute self-check - or try Spot-the-Phish with your team.

Developing

Good instincts. Unverified basics.

Most offices land here - and the gap between “we think so” and “we can prove it” is exactly where incidents live. A 90-minute checkup turns your maybes into a scored answer you can put on an insurance questionnaire - because it’s true.

Want the full picture first? Take the free 10-minute self-check - or try Spot-the-Phish with your team.

Ready

Strong habits. Now pressure-test them.

Answers are easy in a quiz. The Cyber Fire Drill makes them hard: live scenarios, cloned voices, a scored simulation - so you find out whether the reflexes hold when it’s convincing and urgent.

Want the full picture first? Take the free 10-minute self-check - or try Spot-the-Phish with your team.

Nothing is recorded or sent - the score exists only on your screen. The 90-minute on-site checkup is the scored version you can hand your insurer or a client.

What we train against

Every scam that empties a business account walks through one of five doors.

And a real heist rarely stops at one door - it chains them. Step through a composite heist, minute by minute, and count the moments it could have stopped.

  1. Tuesday, 9:12 a.m.Passwords

    A password the bookkeeper has reused since 2019 - leaked in a breach years ago - still opens their work inbox. No alarm rings. The visitor doesn’t touch a thing. They read.

  2. The next three weeksDevices & Wi-Fi

    An unfamiliar device quietly syncs that inbox every night, and nothing flags it. They learn who pays, who approves, how everyone signs off - and that a supplier is owed $48,200 on Friday.

  3. Friday, 4:41 p.m.The phone

    Accounts payable gets a call. It’s the owner’s voice - the pace, the impatience, even the joke. A few minutes of audio is enough to clone a voice now. “I’m boarding a flight. Their new account details are coming by email - please get it out before 5.”

  4. Friday, 4:52 p.m.Email

    The email lands inside the real invoice thread. Same signature, same footer, same PDF. “Please note our updated banking details for this payment.” The sender’s domain is one character off - and nobody is counting characters at 4:52 on a Friday.

  5. Friday, 5:07 p.m.Money movement

    The payment is keyed in. The invoice was due, the thread was real, the boss called ahead. The one callback that stops everything is the step under the most time pressure - so it’s the step that gets skipped.

  6. Monday, 9:15 a.m.The aftermath

    The real supplier calls about their overdue invoice. Now it’s the bank, the insurer’s breach line and a very long week - and the money has been gone since Friday at 5:07.

It could have stopped five times.

Five ordinary moments - one at every door - and none of them needed a security expert. Just a reflex that still fires at 4:52 p.m. on a Friday, when everything looks right. Installing that reflex is the job: in The Heist, the fire drill’s 35-minute story-driven simulated attack, your team beats a heist like this one together, against the clock - and drills the stop-moments until the right move is boring. Boring is the goal.

We train all five doors - email, the phone, passwords, devices & Wi-Fi, money movement - with your industry’s real examples: spot it, stop it, report it.

A composite training scenario - no real client, no real names; the amount is illustrative. The pattern is the one we drill.

Works with the IT you have - or don’t have

Somebody has to own security. That’s us.

A two-person IT team keeping a 100-person company running has no time to own security. An office with no IT at all has nobody to even ask. Either way, we own readiness - training your people, verifying and fixing the basics, rehearsing the first hour, and coordinating partner-delivered testing - and we put the boundary in writing. No products to resell you. No 400-page reports. No fear.

Bastani owns readiness

Live training and drills, the Baseline Security Checkup, the five basics verified and fixed under the Tune-Up, incident rehearsal, and the reports your insurer and clients ask for - with the boundary stated in writing on every engagement.

Your IT provider keeps operations

Help desk, endpoints, patching, networks, servers, backups and day-to-day administration stay with your IT company or internal IT. We coordinate with them respectfully - many of our best referrals come from IT providers.

Don’t trust us - verify us

Check everything before you commit.

That’s how we’d buy security too. The controls we score are public, starting prices are published for every service, and you can read the exact scored deliverable before you pay a cent.

  • Insurer-first incident guidance - we tell you to call your insurer’s breach line first, never us.
  • Starting prices published for every service - and a written proposal, with the rate and estimated hours, within 48 hours.
  • Our full security checklist is public - the same controls we score, free to read before you buy.
  • A full sample report to read before you pay a cent - the exact scored deliverable, on an example office.
  • Nothing is simulated without your signed authorization, and results are aggregate - no one is named or shamed.
  • Aligned to the Canadian Centre for Cyber Security baseline - not a framework we made up.
The three promises

Proposals within 48 hours

You’ll never wait a week to find out what it costs.

Reports within 3 business days

Scored, plain-English, with a 30-day plan - not a slide deck.

A human reply the same business day

You reach a person, not a ticket queue - and we don’t cold-call.

See a sample report →
Straight answers

What business owners usually ask before the first call.

What should we start with?

The Baseline Security Checkup. It’s 90 minutes on-site, it produces the scored report that answers insurer and client questionnaires, and the full fee credits toward any training or Tune-Up booked within 30 days - so it costs nothing extra if you act on it. If training is the urgent need, start with a Fire Drill instead.

Do you only do training?

No - training is where most clients meet us, but the firm covers the full readiness cycle: scored checkups, hands-on fixes like MFA and backups, incident planning (insurer-first), and partner-delivered penetration testing. Your IT provider keeps running the systems; we handle readiness and put the boundary in writing.

How big are the companies you work with?

Most are between 5 and about 150 people - clinics, law and accounting firms, construction offices, and companies where a small IT team (or nobody) is holding it all. Published packages quote the most common team sizes; larger teams usually run multiple sessions or a tailored program, scoped on the fit call with a written proposal before anything is booked.

What does it cost?

Starting prices are published for everything: checkup from $750 · training from $1,800 (flagship from $3,900) · Tune-Up from $1,800 · incident readiness from $2,900 · partner-delivered penetration testing $6,000–$18,000+ by quote. Ongoing Partner Plan tiers are on the pricing page. Your written proposal shows the rate and the estimated hours before you commit. All CAD, plus HST.

The first attack shouldn’t be the first rehearsal.

Book the 20-minute fit call. We’ll recommend the smallest useful first step - and if you don’t need us, we’ll say so and point you to the free tools.