Frequently asked questions
Answers to the questions we hear most. Don't see yours? Get in touch.
What is an MSSP, and how is it different from hiring IT staff?
A managed security services provider (MSSP) delivers cybersecurity as an ongoing service — monitoring, detection, and response — without you having to recruit, train, and retain a full in-house security team. Your IT staff keep systems running; we focus specifically on defending against threats.
Do you replace our existing IT team or security tools?
No. We work alongside your team and, wherever possible, with the tools you already own. We're vendor-agnostic — if something you have works well, we use it; if there's a genuine gap, we'll tell you.
How long does onboarding take?
Onboarding is scoped to the size and complexity of your environment and set out in your agreement. Critical systems are brought into monitoring first, so coverage starts with what matters most.
What size of business do you work with?
We focus on small and mid-sized Canadian organizations — typically from around 10 to 500 employees — that need enterprise-grade security without an enterprise-sized team.
Where will our security data be stored?
Data residency is set out in your service agreement, because it depends on the platforms in scope. Tell us what your obligations are — PIPEDA, Quebec Law 25, a procurement requirement — and we will confirm in writing where your data would sit before you sign anything.
What happens when you detect a security incident?
The service investigates, confirms whether it's a real threat, and moves to contain it — for example, isolating an affected device. Your designated contacts are notified, remediation is guided, and a root-cause review follows so the same gap is not left open.
How is your service priced?
Pricing is based on the number of users and systems we protect and the plan you choose, rather than a fixed package. Our pricing page shows what each plan includes — from there you can request a quote tailored to your environment.
Do you help with compliance and audits?
Yes. Our compliance and risk advisory service helps you assess gaps against frameworks like PIPEDA and SOC 2, build the necessary policies, and produce audit-ready evidence.