Cybersecurity
Technical security reviews, threat modelling and incident preparation for software teams. The focus is on your actual application, infrastructure and operating practices.
Example engagements
Threat-model workshop
Preparation, a half-day workshop and a written threat model for one application or proposed architecture. Includes trust boundaries, attack scenarios and prioritised mitigations.
Hands-on exploitation and implementation of mitigations are separate work.
Application security review
One web application or API with an agreed set of critical flows. Includes source and configuration review, authorised testing, a findings report and a remediation walkthrough.
This is a scoped assessment; compliance certification, unlimited endpoints and full red-team operations are not included.
Incident-readiness review
Review of logging, access, backups and response responsibilities, followed by a tabletop exercise and an actionable improvement plan.
Active incident response, forensic acquisition and round-the-clock coverage require a separate agreement.
For smaller advisory or implementation work: CAD $175–$225 per hour, or $1,250–$1,600 per day. Any minimum engagement is agreed in advance. Timing assumes timely access and feedback; it is not a guaranteed start date.
What you receive
- Findings tied to evidence and impact
- Prioritised remediation guidance
- A technical walkthrough with your team
- Defined scope and coverage limitations
How the work starts
We agree the assets, access and testing boundaries in writing. We review and test within that scope, discuss material findings promptly, and deliver recommendations your engineers can act on.
Useful before a launch, after an architectural change, or when an internal team wants an independent technical review.
Discuss a project
Send a brief description of the work, your current system and any relevant constraints. We can arrange a conversation to define the scope.
+1 (416) 830-5105
Toronto, Ontario