Skip to main content

About

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

About Canada Cyber-Safe

We answer to the board, not to a vendor

Canada Cyber-Safe is an independent cyber and AI governance practice working with Canadian organisations, based in Toronto. We do not sell software, we do not resell anybody else’s, and we take no commission from vendors. What we sell is judgement and the evidence that goes with it.

Why we exist

Most Canadian organisations under a few hundred people have no security function, and no realistic prospect of hiring one. The questions arrive anyway. A customer sends a security questionnaire. An insurer asks what has changed since last renewal. A director wants to know whether anybody checked the AI tool before it was switched on.

None of those are technical questions. They are governance questions, and the reason they go unanswered is rarely that nobody cares. It is that nobody owns them. There is an IT manager already fully occupied, a finance lead who signs things, and a board that has never been given the information it would need to decide anything.

AI has widened that gap faster than anything we have seen. Organisations are deploying it quickly, and the oversight is nowhere near it.

16%of Canadian businesses were hit by a cyber incident in 2023, down from 21% in 2019

$1.2Bspent recovering from incidents in 2023, double 2021 and triple 2019

88%of Canadian ransomware victims did not pay

Statistics Canada, Canadian Survey of Cyber Security and Cybercrime, released October 2024.

Chart: Canadian businesses impacted by cyber incidents fell from 21% in 2019 to 16% in 2023, while total recovery spending rose from about $400 million to $1.2 billion
Fewer organisations are being hit. The ones that are hit are paying far more. That is the shape of the risk a Canadian board is actually carrying.

How we work

Three rules we do not bend

01

We either help you fix it, or we assess you. Never both.

An assessment is only worth something if the person doing it has no stake in the result. If we have designed your controls or written your policies, we will not then turn round, assess you and tell the world you passed. It costs us work. We think that is the point.

02

Our method is published before you engage us.

The thirty-six controls we assess against are on this site in full, with the evidence each one requires and what it maps to in Canadian law. You can read it, disagree with it, or work through it yourself without paying us anything.

03

The output is evidence, not a score.

A number out of ten helps nobody. What helps is a dated document you can hand to a customer, an insurer or the Privacy Commissioner that shows what you looked at, what you decided, and why.

So there is no confusion

What we are not

We are not an accredited certification body, and nothing we issue is a certification. Where a recognised mark is what you actually need, we will say so and help you get ready for it.

We are not a managed security provider. We do not monitor your systems or run your firewalls.

We are not a reseller. We hold no vendor partnerships and earn nothing on anything you buy.

We work with Canadian organisations only, under Canadian law, with data held in Canada.

The people who do the work

Five specialists, and what each one is for

Security testing and incident work. Canadian privacy law and whether you can evidence it. Quebec and Law 25, in French or English. Personal information crossing borders. And the principles underneath rules that have not been written yet.

We publish qualifications you can check with the bodies that issue them. We do not publish employment histories, and the page explains why that is a deliberate decision rather than an omission.

Meet the people who would work on your engagement »

Henry Cole

The one disagreement we have never resolved

Henry Cole

Nobody touches the kettle during an incident bridge. Marc drinks Earl Grey and holds firm views about brewing time; the rest of us drink coffee and hold firm views about Marc’s views. Everything else in this practice is documented, evidenced and agreed. Not this.

Security assessment and incident work · meet the people, Marc included

Start with a conversation

Tell us what has been asked of you and who is asking. We will tell you what we think it needs, and whether that is us. There is no charge for the first conversation and no obligation at the end of it.

Tell us about your organisationRead the control set

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.