Services

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

Independent cyber and AI governance

Evidence that your board is doing its job

Canadian boards are increasingly asked to show — by insurers, by customers, by regulators, and by each other — that they took cyber and privacy risk seriously. Not that they were lucky. That they looked. We produce that evidence.

Most popular starting point

AI Deployment Review

An AI assistant does not break your file permissions. It inherits every one you got wrong, and turns a decade of quiet oversharing into something anyone can find by asking a question in plain English.

  • What your deployment would actually expose
  • The policy and oversight you need around it
  • Whether Quebec’s Law 25 automated decision rules apply
  • A written report and a one-page board summary

From $6,000Fixed scope

Board & executive session

A facilitated half-day with your board, and the evidence pack that records it. Boards do not buy training. They buy the ability to show, afterwards, that they exercised oversight.

  • A scenario chosen for your organisation
  • Who attended, what was rehearsed, on what date
  • Suggested wording for the minutes
  • A prioritised list of what to fix

From $4,500Half a day

Cyber simulation

Find out what your people do before it matters. A tabletop exercise against a scenario built for your business. Nothing goes near your live systems — this tests decisions, not firewalls.

  • Who declares the incident, who calls the customers
  • When the Law 25 notification clock starts
  • What happens when the leak came from an AI system
  • A written record of where the plan broke

From $5,000Half a day

Virtual CISO

Senior security judgement without the hire. Most Canadian organisations under a few hundred people cannot justify a full-time CISO and do not need one. They need someone accountable.

  • We own your risk register
  • Controls, policies and incident readiness
  • The security questionnaires your customers send
  • The quarterly report your board actually reads

From $3,500Per month, six-month minimum

Independent assessment

An evidence-based review against a defined set of controls, producing a dated report you can hand to a customer, an insurer or your board.

  • Not an accredited certification — and we say so
  • We are not a certification body and do not pretend to be
  • Need a recognised mark? We get you ready and introduce you
  • Never sold to an organisation we have advised

Typically $6,000–$9,000Priced on scope

Also available

Bounded pieces of work, priced up front

Third-party and AI vendor due diligence

Most companies have nobody qualified to read a supplier's security answers, and nobody who enjoys asking the questions. We do it for you: evidence checked rather than taken on trust, and a written recommendation your risk committee can act on. OSFI's Guideline B-10 has required this of federally regulated firms since May 2024. We pay particular attention to AI vendors, where the question is not only whether they are secure, but what they do with what you give them.

We do not review a vendor we have advised.

From $2,400 per vendor, or $9,500 for five

Cyber on call

For organisations with nobody whose job this is. Start-ups and AI teams are the clearest case: no CISO, no security function, and enterprise customers who send the same questionnaire they send everybody else. You get one named person who learns your business and stays with it, not a rota and not a ticket queue. Draw the hours down on whatever actually comes up: the questionnaire, the investor's diligence pack, a policy someone has asked for, a contract clause you do not like the look of, or an incident where you need a level head on the phone.

One named contact. No retainer, no monthly commitment, no minimum term.

From $2,500 ten hours, valid six months · $4,500 for twenty

AI use: staff session

Your people are already using AI. Most organisations have never told them what they may put into it, and have no record of having asked. A half-day session on what staff can and cannot paste into an AI tool, why, and what happens to it afterwards — built around the tools you actually run, not a generic deck. You get the attendance record and a one-page summary your board can minute.

This is training, so we will not then assess you. We say so before you book.

From $3,500 half a day, up to 30 people

Penetration testing

Delivered by our accredited testing partner, under our contract and our review. You get the technical report, and you get the part that usually goes missing: what it means for your board, what to fix first given everything else on your plate, and an independent check afterwards that the fixes actually landed.

We name our testing partner before you sign.

From $7,500 scoped per engagement

ISO 27001 Canadian overlay pack

Eight documents that add the Canadian layer to any ISO 27001:2022 toolkit — a Statement of Applicability mapped to Canadian obligations, a populated legal register, and a breach register built for both the federal and Quebec retention clocks. Documents, not consulting: buy them and use them yourself.

From $450

See what is in it →

How we stay independent

We either help you fix it,
or we assess you. Never both.

If we have advised you, designed your controls or written your policies, we will not then turn round and assess your organisation and tell the world it passed. An assessment is only worth anything if the person doing it has no stake in the answer.

It costs us work. We think that is the point.

Why boards are asking now

Law 25 is already in force

Since September 2023, decisions made exclusively by automated processing carry duties: notice, a human who can review, and the right to correct the information used.

Canada has no AI Act

AIDA died with Bill C-27. That does not mean no obligations — it means they reach you through privacy law instead, which is easy to miss.

Your customers are asking

Security questionnaires and procurement reviews increasingly want evidence of oversight, not assurances. Deals stall where that evidence does not exist.

Directors carry the duty

A duty of care requires demonstrable oversight. The question is never whether the board cared. It is whether the board can show what it looked at.

New markets

Growing beyond Canada

A customer in Berlin, a user in California, a contract with a British firm. Obligations attach quietly, and usually before anyone in the business has thought about them. Most Canadian companies assume the EU adequacy decision covers them — it covers only organisations subject to PIPEDA, and it says nothing about the GDPR applying to you directly.

We assess your governance against the regime you are entering and tell you what would not hold up. Through our United Kingdom office we act on UK matters directly. We are not your EU representative and we do not practise United States state law — where you need local counsel we will say so.

European Union and EEAUnited KingdomUnited States — 20 state laws

Read what attaches in each market →

$1,200

Adequacy and exposure check. A bounded answer to “what actually applies to us where we are going”, in about a week.


From $4,500

Market entry review, per market. Your governance assessed against that regime, with the gaps ranked and the local support you would need named.

Tell us where you are expanding

Start with a conversation

Most engagements begin with a board session or an AI deployment review, because both are bounded and both produce something the board can act on. There is no charge for the first conversation and no obligation at the end of it.

Tell us about your organisation+1 647 361 2215

French Version »