About Canada Cyber-Safe
We answer to the board, not to a vendor
Canada Cyber-Safe is an independent cyber and AI governance practice working with Canadian organisations, based in Toronto. We do not sell software, we do not resell anybody else’s, and we take no commission from vendors. What we sell is judgement and the evidence that goes with it.
Why we exist
Most Canadian organisations under a few hundred people have no security function, and no realistic prospect of hiring one. The questions arrive anyway. A customer sends a security questionnaire. An insurer asks what has changed since last renewal. A director wants to know whether anybody checked the AI tool before it was switched on.
None of those are technical questions. They are governance questions, and the reason they go unanswered is rarely that nobody cares. It is that nobody owns them. There is an IT manager already fully occupied, a finance lead who signs things, and a board that has never been given the information it would need to decide anything.
AI has widened that gap faster than anything we have seen. Organisations are deploying it quickly, and the oversight is nowhere near it.
16%of Canadian businesses were hit by a cyber incident in 2023, down from 21% in 2019
$1.2Bspent recovering from incidents in 2023, double 2021 and triple 2019
88%of Canadian ransomware victims did not pay
Statistics Canada, Canadian Survey of Cyber Security and Cybercrime, released October 2024.

How we work
Three rules we do not bend
We either help you fix it, or we assess you. Never both.
An assessment is only worth something if the person doing it has no stake in the result. If we have designed your controls or written your policies, we will not then turn round, assess you and tell the world you passed. It costs us work. We think that is the point.
Our method is published before you engage us.
The thirty-six controls we assess against are on this site in full, with the evidence each one requires and what it maps to in Canadian law. You can read it, disagree with it, or work through it yourself without paying us anything.
The output is evidence, not a score.
A number out of ten helps nobody. What helps is a dated document you can hand to a customer, an insurer or the Privacy Commissioner that shows what you looked at, what you decided, and why.
So there is no confusion
What we are not
We are not an accredited certification body, and nothing we issue is a certification. Where a recognised mark is what you actually need, we will say so and help you get ready for it.
We are not a managed security provider. We do not monitor your systems or run your firewalls.
We are not a reseller. We hold no vendor partnerships and earn nothing on anything you buy.
We work with Canadian organisations only, under Canadian law, with data held in Canada.
The people who do the work
Five specialists, and what each one is for
Security testing and incident work. Canadian privacy law and whether you can evidence it. Quebec and Law 25, in French or English. Personal information crossing borders. And the principles underneath rules that have not been written yet.
We publish qualifications you can check with the bodies that issue them. We do not publish employment histories, and the page explains why that is a deliberate decision rather than an omission.
The one disagreement we have never resolved
Henry Cole
Nobody touches the kettle during an incident bridge. Marc drinks Earl Grey and holds firm views about brewing time; the rest of us drink coffee and hold firm views about Marc’s views. Everything else in this practice is documented, evidenced and agreed. Not this.
Security assessment and incident work · meet the people, Marc included
Start with a conversation
Tell us what has been asked of you and who is asking. We will tell you what we think it needs, and whether that is us. There is no charge for the first conversation and no obligation at the end of it.