Cybersecurity

Cybersecurity services

Most security incidents start with something ordinary: a phishing email, a reused password, an unpatched laptop. We help organizations close those gaps with assessments, endpoint detection and response, email security and staff training, then keep watch with 24/7 monitoring and support for managed-service clients.

Who this service is for

A good fit if

  • You handle personal, financial or health information and need to show customers, insurers or regulators that it is protected.
  • Your cyber insurance renewal asks about MFA, EDR, backups or training, and you are not sure how to answer.
  • You rely on antivirus and a firewall and suspect that is no longer enough.
  • You have no in-house security specialist, or your IT team needs help with monitoring and response.
  • You want one provider for assessment, rollout and ongoing monitoring instead of a separate vendor for each.

Another approach may suit you better if

  • You need an audit opinion or certification. We prepare you for it, but the attestation must come from an independent, accredited assessor.
  • You want a single product installed with no configuration, tuning or follow-up.
  • You are in the middle of an incident and have cyber insurance: call your insurer's incident line first, because many policies require their approved response firm.

What this service is

Promatics provides cybersecurity services, consultations and ongoing protection. We cover the whole cycle: find the gaps, fix the ones that matter most, train the people who use the systems, prepare for incidents, and keep watch afterwards.

You can engage us for a single project, such as an assessment or an EDR rollout, or for ongoing managed security with 24/7 monitoring and support for managed-service clients. The main services are:

What you gain

  • Focus on your core business. We handle the security work, so your team is not pulled away from its own work to chase alerts.
  • Protection for your business and your data from unexpected problems and unwanted intruders, through layered controls instead of a single product.
  • Security that fits how people work. Controls such as MFA and conditional access are rolled out in stages, so productivity does not suffer.
  • Predictable costs. Ongoing managed security is priced as a monthly service, with scope defined in the agreement, and packages sized to your organization and budget. Estimates are in CAD.
  • Someone always watching. Managed-service clients get round-the-clock monitoring of key infrastructure, computers and servers, including holidays.

Canadian obligations and expectations

Organizations face specific expectations, and security work should be planned with them in mind:

  • PIPEDA requires private-sector organizations to report breaches of security safeguards that create a real risk of significant harm, notify affected individuals, and keep records of all breaches.
  • Provincial laws add their own rules, including Quebec's Law 25 for confidentiality incidents, Alberta and British Columbia's PIPA, and Ontario's PHIPA for health information custodians.
  • Federally regulated financial institutions are expected to follow OSFI Guideline B-13 on technology and cyber risk, and B-10 on third-party risk.
  • Cyber insurers increasingly ask about MFA, EDR, email security, tested backups and staff training before they issue or renew a policy.

We help you meet these expectations in practice. We describe obligations in general terms only; this is not legal advice, and your counsel should confirm what applies to you.

Mistakes we see most often

  • Relying on antivirus alone, with no one reviewing alerts.
  • MFA on some accounts but not on administrators, remote access or older email protocols.
  • Shared administrator accounts, or every user with local administrator rights.
  • Backups that have never been restored, or that an attacker could delete with the same stolen password. See backup and disaster recovery.
  • No written plan for who decides what during an incident.
  • Treating training as a once-a-year video instead of a regular habit.

Part of a wider IT service

Security works best when it is connected to day-to-day IT. Alongside security, Promatics offers technical implementation, managed IT services, an IT help desk, IT consulting, network support and on-site support by arrangement. The same team that monitors your devices can patch them, manage accounts and fix what the alerts uncover.

What is included

The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.

Typical deliverables

  • A security assessment covering identities, devices, email, network, backups and cloud services, with risks ranked by likelihood and impact.
  • A prioritized remediation plan with owners, effort estimates and quick wins.
  • Multi-factor authentication and conditional access for email, remote access and administrator accounts.
  • Endpoint detection and response (EDR) deployed, tuned and monitored on workstations and servers.
  • Email security, including filtering, SPF, DKIM and DMARC, and protection against impersonation and payment fraud.
  • Security awareness training and phishing simulations for staff.
  • An incident response plan and contact list, rehearsed in a tabletop exercise.
  • 24/7 monitoring and alert triage for managed-service clients, with regular reports.
  • Security consultations when you buy new systems, sign vendor contracts or complete insurer questionnaires.

Not included unless agreed separately

  • Security software and hardware licences, billed separately or bought directly by you.
  • Legal advice, regulatory filings and breach notifications, which remain your organization's responsibility (we help you prepare them).
  • Certification, audit opinions or attestation reports.
  • Digital forensics for litigation, unless arranged with a specialist firm.
  • Work on systems outside the agreed scope.

What we will need from you

Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.

  • Administrator access to the systems in scope, through named accounts.
  • A named contact who can approve changes and make risk decisions.
  • A current list of users, devices and key applications, or time for us to build one.
  • Your cyber insurance policy and questionnaires, if you have them.
  • Staff time for training and for testing changes before they are enforced.
Delivery

How the work is delivered

Security work can be a one-time project or an ongoing managed service. Both start the same way.

  1. Assess

    Review identities, devices, email, network, backups and cloud services against a recognized baseline, and talk to the people who run them.

    Output: Risk register and ranked findings.

  2. Plan

    Agree what to fix first, weighing risk, cost and disruption to staff.

    Output: Remediation roadmap.

  3. Harden and deploy

    Roll out MFA, EDR, email protection and configuration changes in stages, starting with a pilot group.

    Output: Deployed controls and change log.

  4. Train and rehearse

    Train staff, run phishing simulations, and walk leaders through a realistic incident scenario.

    Output: Training records and tabletop findings.

  5. Monitor and improve

    For managed-service clients, 24/7 monitoring and alert triage, with regular reviews of new risks and results.

    Output: Monitoring reports and an updated roadmap.

Testing and handover

  • Each control is tested after deployment, for example by confirming that MFA prompts appear and EDR alerts actually fire.
  • Changes go to a pilot group before everyone, with a rollback plan.
  • Administrator access is reviewed, and shared accounts are removed or documented.
  • The incident response plan names who does what, and it is rehearsed before we call it finished.
  • You receive documentation of every setting we changed and the reason for it.

What affects the cost

We do not publish package prices. Each estimate is based on an agreed scope, in Canadian dollars, with taxes shown separately. These are the things that move the number most:

  • The number of users, devices, servers and locations.
  • The platforms in use, such as Microsoft 365, Google Workspace, on-premises servers and cloud workloads.
  • How much remediation the assessment uncovers.
  • Whether you need ongoing 24/7 monitoring or a one-time project.
  • Regulatory, client or insurer requirements that add documentation.

Questions buyers usually ask

Is antivirus not enough?

Traditional antivirus mostly blocks known malicious files. Many attacks now use stolen passwords, legitimate administration tools and email fraud, which antivirus does not see. EDR, MFA and email protection close much of that gap.

Do you provide 24/7 monitoring?

Yes, for managed-service clients. Monitoring covers the tools and systems in scope, and response targets are set out in the service agreement rather than promised on a web page.

Can you help with our cyber insurance questionnaire?

Yes. We explain what each question is asking, check what is actually in place, and help you close gaps before renewal. The answers remain your organization's, so we never guess on your behalf.

What happens if we have a breach?

Contain first, then assess. If personal information is involved, PIPEDA requires organizations to report breaches that create a real risk of significant harm to the Privacy Commissioner of Canada, notify affected people and keep a record of every breach. We help you gather the facts; your legal counsel advises on obligations. This is not legal advice.

Which security tools do you work with?

We work with platforms such as Microsoft Defender, CrowdStrike, SentinelOne and Fortinet, and recommend based on your environment, existing licences and budget. We check what you already own before suggesting anything new.

Not sure where your biggest security gaps are?

Tell us about your systems, your team and any insurer or regulatory requirements. We will reply to arrange a conversation about where to start.