Risk & Compliance
Risk and compliance services measure your security program against recognized frameworks, harden your systems to known-good baselines, and build the skills your teams need to keep improving.
Risk & Compliance services
-
Security Assessments & Compliance
Independent assessments against NIST, ISO 27001, CIS Controls, CyberSecure Canada, and more.
-
Threat Modeling
Design-stage analysis that finds and prioritizes threats before they are built in.
-
Security Baselines & Hardening
Hardening your systems to industry-standard secure configurations (CIS Benchmarks, DoD STIGs).
-
Security Training Services
Training for developers, technical teams, and employees, from secure coding to awareness.
Other services
- Application Security Scoped testing of your web and mobile apps and their code, from black-box to source-assisted.
- Network Security Scoped testing of your internal, external, and cloud infrastructure, plus ongoing scanning.
- Adversary Simulation Goal-driven attack simulations that test your people, processes, and detection.
Talk to us about risk & compliance
Tell us what you need to protect, and we'll recommend the right engagement and scope.