Cyber Risk Office — Executive Cyber Risk Leadership

Services

Advisor-led cybersecurity for Canadian businesses.

Independent, executive-focused advisory built for Canadian small and mid-sized organizations.

Service catalogue

Cyber Business Assessment

2 to 3 weeks

A structured executive review across the risks most likely to disrupt a Canadian SMB, with a plain-language board-ready summary.

  • Leadership interviews and evidence review
  • Prioritized 12 month roadmap
  • Board-ready summary and debrief
Discuss this service →

Cyber Readiness Review

1 to 2 weeks

A focused confirmation that key protections are actually in place: MFA, backups, incident response, and insurer requirements.

  • Control spot-checks
  • Gap list ranked by business impact
  • One hour executive debrief
Discuss this service →

Cyber Insurance Readiness

1 week

Map your controls to insurer expectations, prepare accurate renewal answers, and reduce surprises at underwriting.

  • Questionnaire walkthrough
  • Evidence pack for your broker
  • Pre-renewal remediation list
Discuss this service →

Microsoft 365 Security Review

1 week

Professional review of the platform where most Canadian SMBs actually operate: admin exposure, forwarding rules, sharing, and monitoring.

  • Tenant configuration review
  • Admin and identity exposure findings
  • Step-by-step hardening plan
Discuss this service →

Business Email Fraud Protection Review

3 to 5 days

Prevent payment fraud and executive impersonation with layered controls and a written verification process.

  • SPF, DKIM and DMARC review
  • Payment verification procedure
  • Finance team briefing
Discuss this service →

Incident Response Readiness

2 to 3 weeks

Documented plans, defined leadership roles, and rehearsed tabletop exercises so you are not making it up in the moment.

  • Written IR plan and call tree
  • Executive tabletop exercise
  • Post-exercise improvement plan
Discuss this service →

Cyber Due-Diligence Review

2 to 4 weeks

Cybersecurity and privacy due diligence for buyers, investors, lenders, and owners preparing for a transaction.

  • Target posture and privacy review
  • Risk-adjusted findings for deal teams
  • Post-close remediation plan
Discuss this service →

Security Awareness Workshop

Half day

A practical, non-technical session for leadership teams and staff on fraud, phishing, and everyday decision-making.

  • Tailored Canadian examples
  • Live scenario walkthroughs
  • Leadership takeaway summary
Discuss this service →

Ongoing advisory

Most clients start with an assessment, then keep an advisor on call. Retainers are month to month after an initial three month term.

Advisor · Essentials

Quarterly executive reviews, roadmap maintenance, and advisor access for key decisions.

Compare plans

Advisor · Growth

Monthly touchpoints, insurance renewal support, vendor risk reviews, and execution oversight.

Compare plans

Fractional CISO

Senior security leadership in your leadership team, board reporting, governance, and program ownership.

Compare plans

Every engagement is scoped in writing after a short discovery call, so you know exactly what is included before anything starts.

Not sure where to start?

Take the free Cyber Risk Office Scorecard and get a preliminary view of where your business is exposed before you spend a dollar.