About

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

About Canada Cyber-Safe

We answer to the board, not to a vendor

Canada Cyber-Safe is an independent cyber and AI governance practice working with Canadian organisations, based in Toronto. We do not sell software, we do not resell anybody else’s, and we take no commission from vendors. What we sell is judgement and the evidence that goes with it.

Why we exist

Most Canadian organisations under a few hundred people have no security function, and no realistic prospect of hiring one. The questions arrive anyway. A customer sends a security questionnaire. An insurer asks what has changed since last renewal. A director wants to know whether anybody checked the AI tool before it was switched on.

None of those are technical questions. They are governance questions, and the reason they go unanswered is rarely that nobody cares. It is that nobody owns them. There is an IT manager already fully occupied, a finance lead who signs things, and a board that has never been given the information it would need to decide anything.

AI has widened that gap faster than anything we have seen. Organisations are deploying it quickly, and the oversight is nowhere near it.

16%of Canadian businesses were hit by a cyber incident in 2023, down from 21% in 2019

$1.2Bspent recovering from incidents in 2023, double 2021 and triple 2019

88%of Canadian ransomware victims did not pay

Statistics Canada, Canadian Survey of Cyber Security and Cybercrime, released October 2024.

Chart: Canadian businesses impacted by cyber incidents fell from 21% in 2019 to 16% in 2023, while total recovery spending rose from about $400 million to $1.2 billion
Fewer organisations are being hit. The ones that are hit are paying far more. That is the shape of the risk a Canadian board is actually carrying.

How we work

Three rules we do not bend

01

We either help you fix it, or we assess you. Never both.

An assessment is only worth something if the person doing it has no stake in the result. If we have designed your controls or written your policies, we will not then turn round, assess you and tell the world you passed. It costs us work. We think that is the point.

02

Our method is published before you engage us.

The thirty-six controls we assess against are on this site in full, with the evidence each one requires and what it maps to in Canadian law. You can read it, disagree with it, or work through it yourself without paying us anything.

03

The output is evidence, not a score.

A number out of ten helps nobody. What helps is a dated document you can hand to a customer, an insurer or the Privacy Commissioner that shows what you looked at, what you decided, and why.

So there is no confusion

What we are not

We are not an accredited certification body, and nothing we issue is a certification. Where a recognised mark is what you actually need, we will say so and help you get ready for it.

We are not a managed security provider. We do not monitor your systems or run your firewalls.

We are not a reseller. We hold no vendor partnerships and earn nothing on anything you buy.

We work with Canadian organisations only, under Canadian law, with data held in Canada.

Coming shortly

The people who do the work

A full page on the team is in preparation, with backgrounds, qualifications and the kind of engagements each person has actually run. We would rather publish that properly than post photographs and job titles.

Not yet published

Start with a conversation

Tell us what has been asked of you and who is asking. We will tell you what we think it needs, and whether that is us. There is no charge for the first conversation and no obligation at the end of it.

Tell us about your organisationRead the control set

French Version »