Cybersecurity and GRC for companies with no security department
We build the governance, risk and compliance program you’d have if you’d hired a security team three years ago. Risk register, policy library, control implementation, vendor reviews, incident readiness — run by senior people, on a monthly retainer, in English and French.

Six disciplines. Governance is the one nobody wants and everybody needs.
Tools get bought first because they’re easy to buy. We start with the decisions — what you protect, who owns it, what you’ve accepted — because that’s what determines whether the tools were the right ones.
Governance & accountability
A security charter, a decision-rights matrix, and a quarterly review that puts real numbers in front of your executive team. Someone has to own each risk by name.
- Security charter
- Risk owners named
- Quarterly board pack
- Exception process
Risk management
A living risk register with likelihood, impact, treatment decision and owner — sized to your business rather than copied from a template with 200 irrelevant entries.
- Asset & data inventory
- Threat modelling
- Treatment plans
- Monthly review cadence
Policy & control library
Short, plain-language policies written against how your teams actually work, mapped once to an internal control set that satisfies every framework you need.
- 14–20 core policies
- Single control mapping
- EN + FR-CA
- Annual review cycle
Control implementation
The unglamorous work: identity and access, logging, endpoint hardening, encryption, change management, secure development. Implemented, not just documented.
- IAM & MFA rollout
- Logging & monitoring
- Backup restore testing
- Secure SDLC gates
Vendor & supply-chain risk
A tiered vendor inventory, proportionate due-diligence questionnaires, contract security clauses, and the annual re-review that most programs quietly skip.
- Tiered vendor register
- Due-diligence packs
- Contract clauses
- Annual re-assessment
Incident readiness & response
An incident response plan with named roles and real phone numbers, regulator and customer notification paths, and two tabletop exercises a year so it’s been rehearsed.
- IR plan & runbooks
- Law 25 · 72h path
- 2 tabletops / year
- Post-incident rewrite
Map the controls once. Generate the evidence per framework.
Most of our clients owe two or three frameworks at the same time. Running parallel programs triples the internal cost, so we maintain one control set and produce framework-specific evidence from it.
SOC 2 Type II
The report North American enterprise procurement asks for. We run readiness, select the auditor, and manage the observation window end to end.
ISO 27001:2022
A certifiable ISMS with Statement of Applicability across all 93 Annex A controls, internal audit, and Stage 1 and 2 support.
NIST CSF 2.0
The framework we use to describe posture to non-technical stakeholders — a maturity score per function that a board can actually read and track.
Law 25 & PIPEDA
Privacy governance, consent records, privacy impact assessments, retention schedules, and the breach notification path Law 25 requires you to have in advance.
PCI DSS 4.0
Scope reduction first — most clients are paying for controls on systems that shouldn’t touch card data at all. Then SAQ or ROC support.
CIS Controls v8
Our default technical baseline underneath every framework above. Implementation Group 1 or 2 depending on your size and threat profile.
Five phases. The blocking gap gets fixed first.
If a stalled enterprise deal or a regulator letter is what brought you here, we sequence around that rather than making you wait for a complete program before you can answer the question in front of you.
Assess
Interviews, technical review, and a gap assessment against the frameworks you owe. Scored, prioritized, costed.
- Gap assessment
- Risk register v1
- Costed roadmap
Unblock
Whatever is holding up the deal or the audit — questionnaire answers, interim attestations, the two controls that matter.
- Questionnaire support
- Quick-win controls
- Customer letter
Build
Policy library, control implementation, vendor program, IR plan. Evidence collected as we go, not reconstructed later.
- Policies & controls
- Vendor register
- Evidence pipeline
Prove
Internal audit, management review, tabletop exercise, then the external audit or attestation itself.
- Internal audit
- Tabletop exercise
- External audit
Operate
Monthly risk review, quarterly board reporting, annual re-certification and re-assessment of every tier-1 vendor.
- Monthly risk review
- Board reporting
- Surveillance audits
Start with the assessment. Decide after you’ve read it.
The assessment is deliberately sellable on its own — you get a costed roadmap you could hand to another firm. Most clients continue with us, but nothing about the document requires it.
Security & GRC assessment
A scored gap assessment against the frameworks you owe, a first risk register, and a costed twelve-month roadmap. Credited against a program if you continue within 90 days.
- Gap assessment · scored
- Risk register v1
- Costed roadmap
- Executive readout session
- Yours to keep either way
GRC program build
We build and run the program to audit or attestation — governance, risk, policy, controls, vendor and incident readiness. Where most clients sit for the first year.
- All six disciplines
- Policy library · EN + FR-CA
- Control implementation support
- Audit or attestation management
- Tabletop exercises included
- Incident support · no hourly rate
Fractional CISO
Senior security leadership on retainer for companies with a program already running, or an internal team that needs someone accountable above them.
- Named CISO · 4 days / month
- Board & audit committee reporting
- Program ownership
- Customer security calls
- Incident command
- Team mentoring
Across 31 programs since 2019.
Security programs are hard to measure honestly, so we report the things that are checkable: audit results, time to answer a customer questionnaire, and unblocked revenue.
“Our previous consultants left us 140 pages of policy nobody had read. Noordev deleted most of it, kept nineteen policies our engineers could actually follow, and we passed Stage 2 with zero major findings.”
Before you engage us.
If your question isn’t here, ask it on the call. We’ll tell you when you need a penetration test rather than a program, even though that’s someone else’s invoice.
What is GRC in cybersecurity?
+GRC stands for governance, risk and compliance. Governance is who decides and who is accountable. Risk is knowing which threats matter to your business and what you have chosen to do about each one. Compliance is proving both to a customer, an auditor or a regulator. Technical controls without GRC produce a security posture nobody can explain; GRC without technical controls produces documents that protect nothing.
How much do cybersecurity and GRC services cost?
+A one-time security assessment is CAD $18,000 fixed. A GRC program build runs $11,000 per month for six to twelve months, depending on how many frameworks you need to satisfy. A fractional CISO retainer starts at $6,500 per month for four days of senior time. Most clients start with the assessment and decide afterward.
Do we need a full-time CISO or is fractional enough?
+Below roughly 300 employees, a fractional CISO is usually the better economics — you get senior judgement four days a month instead of a mid-level full-time hire. You should move to full-time when security decisions are needed weekly rather than monthly, when you have a security team to manage, or when a regulator expects a named accountable officer on site.
Which frameworks do you work with?
+SOC 2 Type II, ISO 27001:2022, NIST CSF 2.0, Québec Law 25 and PIPEDA, PCI DSS 4.0, and CIS Controls v8. Most clients need two or more, so we map controls once against a single internal control set and generate the framework-specific evidence from it rather than running parallel programs.
How is this different from a penetration test?
+A penetration test tells you what an attacker could exploit this quarter. A GRC program decides what you protect, who owns it, how you prove it and what happens when something fails. You need both, and they answer different questions — we run the program and coordinate independent testers rather than testing our own work.
Can you get us audit-ready for a customer requirement?
+That is the most common reason clients call. When an enterprise deal is blocked on a security questionnaire or a SOC 2 report, we start with the gap that is actually blocking the deal, produce the evidence and interim attestations that unblock it, then build the rest of the program on the schedule your business can absorb.
Who writes the policies, and will anyone read them?
+We write them, in plain language, against how your company actually builds and operates. A policy nobody follows is a finding waiting to happen, so we keep the library short, review it with the teams who have to live inside it, and delete controls you cannot realistically sustain rather than documenting fiction.
What happens if we have an incident during the engagement?
+Incident support is included in every retainer at no additional hourly cost. We help you run the response, handle regulator and customer notification timelines including Law 25’s obligations, and rewrite the affected controls afterward. We also run tabletop exercises twice a year so the first real incident is not the first rehearsal.
Related services
GRC services
A 45-minute risk conversation. No scare tactics.
Tell us what triggered this — a customer questionnaire, a board directive, an insurer, an incident. We’ll tell you honestly what the next ninety days should look like and what you can safely defer.