Security assessments and risk reviews
A clear look at your security: what could go wrong, how likely it is, and what to fix first, explained in plain language.
Most security incidents start with something ordinary: a phishing email, a reused password, an unpatched laptop. We help organizations close those gaps with assessments, endpoint detection and response, email security and staff training, then keep watch with 24/7 monitoring and support for managed-service clients.
Promatics provides cybersecurity services, consultations and ongoing protection. We cover the whole cycle: find the gaps, fix the ones that matter most, train the people who use the systems, prepare for incidents, and keep watch afterwards.
You can engage us for a single project, such as an assessment or an EDR rollout, or for ongoing managed security with 24/7 monitoring and support for managed-service clients. The main services are:
Organizations face specific expectations, and security work should be planned with them in mind:
We help you meet these expectations in practice. We describe obligations in general terms only; this is not legal advice, and your counsel should confirm what applies to you.
Security works best when it is connected to day-to-day IT. Alongside security, Promatics offers technical implementation, managed IT services, an IT help desk, IT consulting, network support and on-site support by arrangement. The same team that monitors your devices can patch them, manage accounts and fix what the alerts uncover.
The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.
Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.
Security work can be a one-time project or an ongoing managed service. Both start the same way.
Review identities, devices, email, network, backups and cloud services against a recognized baseline, and talk to the people who run them.
Output: Risk register and ranked findings.
Agree what to fix first, weighing risk, cost and disruption to staff.
Output: Remediation roadmap.
Roll out MFA, EDR, email protection and configuration changes in stages, starting with a pilot group.
Output: Deployed controls and change log.
Train staff, run phishing simulations, and walk leaders through a realistic incident scenario.
Output: Training records and tabletop findings.
For managed-service clients, 24/7 monitoring and alert triage, with regular reviews of new risks and results.
Output: Monitoring reports and an updated roadmap.
We do not publish package prices. Each estimate is based on an agreed scope, in Canadian dollars, with taxes shown separately. These are the things that move the number most:
Traditional antivirus mostly blocks known malicious files. Many attacks now use stolen passwords, legitimate administration tools and email fraud, which antivirus does not see. EDR, MFA and email protection close much of that gap.
Yes, for managed-service clients. Monitoring covers the tools and systems in scope, and response targets are set out in the service agreement rather than promised on a web page.
Yes. We explain what each question is asking, check what is actually in place, and help you close gaps before renewal. The answers remain your organization's, so we never guess on your behalf.
Contain first, then assess. If personal information is involved, PIPEDA requires organizations to report breaches that create a real risk of significant harm to the Privacy Commissioner of Canada, notify affected people and keep a record of every breach. We help you gather the facts; your legal counsel advises on obligations. This is not legal advice.
We work with platforms such as Microsoft Defender, CrowdStrike, SentinelOne and Fortinet, and recommend based on your environment, existing licences and budget. We check what you already own before suggesting anything new.
A clear look at your security: what could go wrong, how likely it is, and what to fix first, explained in plain language.
Choose, deploy, tune and monitor endpoint detection and response, so suspicious activity on laptops and servers is caught and contained.
Ten common cybersecurity mistakes in organizations and the practical fix for each, based on Canadian Centre for Cyber Security guidance.
Tell us about your systems, your team and any insurer or regulatory requirements. We will reply to arrange a conversation about where to start.