18 firms list this service
3Tenets Consulting
Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.
- Pen testing
- AppSec
- GRC advisory
- IR and forensics
- Privacy
- NIST CSF
- CIS Controls
- ISO 27001
- MITRE ATT&CK
- OWASP
Appollon Inc.
Managed detection and response with 24/7 SOC monitoring, behavioural detection, active threat response and forensic investigation and remediation, aimed at gaming and tech companies in Quebec.
- MDR and SOC
- IR and forensics
- SOC 2
- ISO 27001
- Law 25
Arista Cyber
Industrial cybersecurity firm for OT and ICS: risk assessments, gap analysis, IEC 62443 zone and conduit design, vulnerability assessments and incident response planning for energy and industrial operators.
- OT and ICS
- GRC advisory
- Vulnerability mgmt
- IR and forensics
- IEC 62443
- NERC CIP
- NIST CSF
C3SA
Cybersecurity organization offering consulting, systems integration, training and cyber ranges, incident response and threat intelligence, with compliance work for ITSG-33, CMMC, CPCSC and SOC 2.
- Architecture
- IR and forensics
- Threat intel
- Privacy
- ITSG-33
- CMMC
- CPCSC
- SOC 2
CyberClan
Incident response, post-breach remediation, 24/7 managed detection and response, risk management, IT services and eDiscovery.
- IR and forensics
- MDR and SOC
- GRC advisory
Cyberwall
Ten managed security services including 24/7 managed SOC, MDR, SIEM as a service, endpoint, identity and cloud security, plus consulting in incident response, penetration testing, compliance and privacy.
- MDR and SOC
- MSSP
- IR and forensics
- Pen testing
- GRC advisory
- +3
- SOC 2
- PIPEDA
- HIPAA
- PCI DSS
- ISO 27001
CYPFER
Incident response, ransomware response and recovery, digital forensics, eDiscovery, incident response retainers, offensive security testing, threat intelligence and security awareness training.
- IR and forensics
- Threat intel
- Training
- GRC advisory
eSentire
24/7 managed detection and response and SOC service with digital forensics and incident response, response and remediation, and autonomous penetration testing and continuous threat exposure management.
- MDR and SOC
- IR and forensics
- Pen testing
- SOC 2
- ISO 27001
- MITRE ATT&CK
Field Effect
Managed detection and response across endpoint, network, cloud and identity, with a 24x7 SOC, incident response, IR readiness and cybersecurity assessments. Focus on small and mid-sized organisations and their partners.
- MDR and SOC
- IR and forensics
- MITRE ATT&CK
ISA Cybersecurity
Compliance management, risk and privacy assessments, penetration testing, vulnerability management, cloud and data security, incident response and readiness, managed EDR and SIEM, awareness training.
- GRC advisory
- Privacy
- Pen testing
- Vulnerability mgmt
- Cloud security
- +4
Kobalt.io
Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.
- GRC advisory
- Audit and certification
- Pen testing
- IR and forensics
- MDR and SOC
- +1
- CPCSC
- CMMC
- NIST 800-171
- SOC 2
- ISO 27001
- +6
Mirai Security
Application security testing, red team and vulnerability assessment, incident response, cloud security, GRC and security awareness training.
- AppSec
- Red team
- Vulnerability mgmt
- IR and forensics
- Cloud security
- +2
- SOC 2
- ISO 27001
OKIOK
Offensive security (penetration testing, vulnerability assessment), incident response, digital forensics, cybersecurity consulting, compliance and governance, and identity compliance as a service.
- Pen testing
- Vulnerability mgmt
- IR and forensics
- GRC advisory
- IAM
- +1
- ISO 27001
- SOC 2
- PCI DSS
- CPCSC
PlutoSec
Etobicoke firm covering penetration testing, red team, compliance readiness (ISO 27001, SOC 2, PCI DSS, HIPAA), cloud security, managed SOC/MDR, secure development and incident response.
- Pen testing
- Red team
- GRC advisory
- Audit and certification
- Cloud security
- +3
- ISO 27001
- SOC 2
- PCI DSS
- NIST CSF
- ITSG-33
- +2
Prairie Cyber Security
Winnipeg firm serving small and mid-sized organizations with security assessments, managed detection and response, incident response, virtual CISO consulting and security awareness training.
- GRC advisory
- MDR and SOC
- IR and forensics
- Training
- PIPEDA
- PCI DSS
SAV Associates
Toronto CPA firm and ISO certification body offering SOC 1/2/3 attestation, ISO certification, IT audit, GRC consulting, CMMC and CPCSC readiness, and penetration testing and incident response.
- Audit and certification
- GRC advisory
- Pen testing
- Vulnerability mgmt
- IR and forensics
- SOC 2
- ISO 27001
- CMMC
- CPCSC
Secur01
Anjou, Quebec firm offering managed protection and SOC-as-a-service, vulnerability scanning, penetration testing, vCISO, incident response planning, awareness training and Law 25 compliance evaluation; French and English.
- MDR and SOC
- Pen testing
- Vulnerability mgmt
- GRC advisory
- Privacy
- +3
- Law 25
TwelveDot Incorporated
Ottawa technology and security consulting practice offering virtual CSO, ethical hacking, cloud, mobile and IoT assessments, ISO 27001 implementation and audit, breach mitigation and incident response.
- GRC advisory
- Pen testing
- Cloud security
- Audit and certification
- IR and forensics
- +1
- ISO 27001
- OWASP
Related resource hubs
// more
Other services
- Penetration testing
- Red teaming
- Vulnerability assessment and management
- Application security
- Cloud security
- Managed detection and response
- Governance, risk, and compliance advisory
- Audits, attestations, and certification
Listings reflect what each firm says on its own website. Inclusion is not an endorsement. How the directory works.