Canadian Centre for Cyber Security
Baseline Cyber Security Controls for Small and Medium Organizations
Security guidance for small and medium organizations, including how to respond to incidents and recover.
Read the Canadian baselineSecurity
We treat security and privacy as part of delivery, not an add-on. Before work begins, we agree what client information and system access are actually required. We use least-privilege access, keep credentials out of project files, review and record changes, and avoid retaining client data longer than the work requires. Monitoring, backups, recovery plans, and clear incident communication are matched to the system and the risks involved.
How we work
We organize each engagement around six connected responsibilities. The safeguards we recommend are proportionate to the information, systems, people, and operational impact involved.
We define responsibilities, acceptable access, data-handling expectations, and decision points before technical work starts.
We document the systems, information, integrations, dependencies, and risks that need to be understood and protected.
We apply least-privilege access, secure credential handling, appropriate authentication, and reviewed configuration changes.
We use available logs, monitoring, and deployment records to identify unusual activity and understand what changed.
We contain the issue, preserve useful records, prioritize corrective work, and communicate known impact and next steps.
We plan backups, rollback paths, restoration, and post-recovery validation so service can return with confidence.
Reference standards
Canadian Centre for Cyber Security
Security guidance for small and medium organizations, including how to respond to incidents and recover.
Read the Canadian baselineNational Institute of Standards and Technology
A framework for assessing cybersecurity risks and organizing the work needed to address them.
Read NIST CSF 2.0OWASP Foundation
Testable requirements for web applications, APIs, authentication, access control, and configuration.
Read OWASP ASVS 5.0.0We use these references to help plan and review each project. Following them does not mean that a client is certified, independently audited, or fully compliant with every requirement.
Security help