Services
Cybersecurity
Incident response, ransomware recovery, and hardening that holds up under audit.
What you get
- Containment and eradication during an active incident
- Ransomware recovery and negotiation-free restoration from clean backups
- External and internal penetration testing with a prioritised remediation plan
- Security architecture review across network, cloud, identity and application layers
- Hardened baselines for servers, endpoints, and CI/CD pipelines
- Written incident response runbook your team can actually follow at 3am
Outcomes
- Systems restored without paying a ransom
- A ranked list of what to fix, with effort and risk attached to each item
- Evidence and documentation suitable for insurers, auditors and legal counsel
- Measurable reduction in attack surface, verified by retest
Capabilities
Ransomware response and recovery
Containment, forensic triage, and restoration from verified-clean backups. We work to get you operating again without funding the attacker.
Incident response and forensics
Establish what happened, what was accessed, how they got in, and whether they are still inside. Documented for insurers and regulators.
Penetration testing
External perimeter, internal network, web application and API testing. Findings ranked by exploitability, not by scanner severity.
Security hardening and architecture
Network segmentation, identity and access management, least-privilege enforcement, secrets management, and secure deployment pipelines.
Backup integrity and recovery testing
Most ransomware victims have backups. Far fewer have backups that restore. We test yours before you need them.
Security assessments and compliance readiness
Gap assessments mapped to recognised frameworks, with a realistic remediation roadmap for small and mid-sized teams.
Security work that assumes you have a business to run
Most security vendors sell either a scanner subscription or a six-figure engagement. Neither helps a fifteen-person company in Longueuil whose file server just got encrypted on a Friday afternoon.
We work the way an in-house senior engineer would: find the actual exposure, fix what matters first, and write it down so your team can maintain it after we leave.
During an active incident
Speed matters, but uncontrolled speed destroys evidence and reinfects clean systems. Our sequence is deliberate:
- Contain. Isolate affected hosts at the network layer while preserving volatile memory and logs.
- Scope. Establish entry point, dwell time, lateral movement, and what data was actually accessed — not what was theoretically reachable.
- Eradicate. Remove persistence mechanisms, rotate every credential in the blast radius, close the original entry vector.
- Recover. Restore from backups that have been verified clean, in a dependency-correct order, into a rebuilt environment.
- Document. Produce the written record your insurer, your lawyer and your board are going to ask for.
Why the backup conversation comes first
In practice, the difference between a bad week and an existential event is almost never the sophistication of the attack. It is whether the backups are real.
The failure modes we find repeatedly: backups on a network share the ransomware encrypted too; backup jobs that have been silently failing for months; restores nobody has ever tested; and retention windows shorter than the attacker’s dwell time. All four are cheap to fix beforehand and catastrophic to discover afterwards.
This is why our cybersecurity practice and our infrastructure practice are not separate products. Recoverability is a security control.
Experience behind the work
Over twenty-five years across aerospace certification, financial data platforms and production systems that could not go down quietly. Aerospace in particular teaches a specific discipline: you assume failure, you document the failure path, and you prove the recovery works before anyone signs off.
That mindset transfers directly. Security is not a product you install. It is a property of a system you can demonstrate.
Frequently asked questions
We are being ransomwared right now. What should we do first?
Disconnect affected machines from the network but do not power them off, as memory often contains recoverable keys and forensic evidence. Do not delete anything. Do not pay yet. Email us with URGENT in the subject and we will begin triage immediately.
Should we pay the ransom?
Almost never as a first move. Payment funds the attacker, does not guarantee a working decryptor, and marks you as a paying target for repeat attacks. Our first objective is always restoration from clean backups. We advise on payment only after recovery options are genuinely exhausted, and we do not broker payments.
How fast can you respond to an active incident?
For active incidents in the Montreal and South Shore area we aim to begin remote triage the same business day. Write URGENT in your message and it is prioritised ahead of everything else.
Do you work with our cyber insurance provider?
Yes. We produce the timeline, scope-of-access findings and remediation documentation insurers require, and we keep evidence handling clean so your claim is not compromised.
We are a small business. Is penetration testing overkill?
No, but a full red-team engagement probably is. For most small businesses the right starting point is an external perimeter test plus a review of identity, backups and email security, which is where the overwhelming majority of real-world breaches actually begin.
Related services
Infrastructure & Backup
Servers, clusters and backups designed so that failure is survivable and boring.
Learn moreWordPress Development
Custom builds, hardening, and cleanup for sites that have been hacked or abandoned.
Learn moreCrypto & Blockchain
Contracts, trading automation, custody security, and wallet recovery done honestly.
Learn moreTell us what is breaking — or what you are trying to build.
You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.
Active incident? Write “URGENT” in your message and we prioritise it.