
Filter by Tag
Fractional CISO for SaaS Companies: What the Role Actually Looks Like
Security leadership at most SaaS companies follows a predictable pattern. The CTO handles it. Not because they volunteered, but because nobody else...
CPCSC Compliance Consulting for Defence Contractors
CPCSC Level 1 attestation becomes a procurement requirement for Department of National Defence contracts in April 2026. Companies that can't attest...
What Does a SOC 2 Readiness Assessment Actually Include?
A SOC 2 readiness assessment is not the audit. It is the diagnostic step that tells a company exactly where it stands before committing budget and...
ISO 27001 Consultant in Canada: When It Makes Sense and What It Actually Takes
ISO 27001 certification gives you a one-to-two-page certificate. SOC 2 gives you a 40-to-50-page report describing every control, how it was tested,...
SOC 2 Implementation Cost and Timeline: What to Actually Budget
SOC 2 has four cost components. Most companies only budget for two of them, then get surprised by the rest halfway through the engagement.
Here is...
How to Choose a SOC 2 Consultant: A Checklist for SaaS Companies
The Two Types of SOC 2 Consultants
Platform-first firms compress the engagement into days or a few weeks. They take a policy template library, swap...
What Project Glasswing Actually Means for Your Security Program
I have been thinking about what Anthropic's Project Glasswing announcement actually means for the clients we advise. The honest answer is that it...
Risk Assessment and Security Planning for ITSP.10.171
The majority of ITSP.10.171 control families deal with operational security: how you configure systems, manage access, protect data. The Risk...
SOC 2 to CPCSC: Extending Your Security Program
The question comes up consistently when companies with established security programs look at entering the Canadian defence supply chain: Do we need...
Physical Security and Personnel Controls Under CPCSC
Every other control family in ITSP.10.171 has a reasonable analogue in the commercial compliance world. Access control maps to SOC 2 CC6. Incident...
Protecting Controlled Information: Media and Communications Security (CPCSC)
In a compliance landscape that increasingly assumes cloud-first architecture, media protection controls tend to get deprioritized. The assumption is...
Incident Response and System Integrity Under CPCSC
An incident response plan that exists only in a shared drive is not evidence of preparedness. It is evidence of intent, and the Canadian Program for...
Security Awareness, Training, and Governance for CPCSC
The previous twelve posts in this series covered the technical and operational control families in ITSP.10.171: access control, incident response,...
Configuration Management and System Maintenance for Defence Contractors Under CPCSC
There is a specific phrase that comes up in nearly every environment that has never been through a formal configuration review: We know our systems....
Audit Logging, Monitoring, and Accountability for CPCSC
Most organizations produce logs. Application servers generate them, firewalls record them, identity providers track them. The volume is rarely the...
Supply Chain Risk Management Under CPCSC
For most of the history of Canadian defence procurement, cybersecurity obligations ended at the prime contractor's perimeter. A prime could hold a...
Access Control and Identity Management Under ITSP.10.171
Every security program has access controls of some kind. Password policies exist, MFA is probably enabled somewhere, and someone has a spreadsheet...
CPCSC vs CMMC: What Dual-Jurisdiction Contractors Need to Know
CPCSC (Canada) and CMMC (United States) both derive from NIST SP 800-171, so their control sets largely overlap. They differ in how each program...
SOC 2 Configuration Baselines for Bare Metal: CIS Benchmarks & Beyond
In cloud environments, configuration compliance is a toggle. Enable AWS Config, deploy a conformance pack, and the platform continuously evaluates...
CPCSC Level 1 Self-Assessment: A Practical Guide
CPCSC Level 1 is an annual self-assessment of your organization against the expected security requirements of the Canadian Program for Cyber Security...
SOC 2 Backup and Disaster Recovery for On-Premise Infrastructure
Cloud disaster recovery is a region failover. Click a button, spin up infrastructure in another availability zone, and the platform handles...
SOC 2 Access Control for On-Premise and Bare Metal Environments
In cloud environments, access control is a managed service. AWS IAM provides centralized identity, Okta handles SSO across every SaaS tool, and the...
SOC 2 Logging and SIEM for Bare Metal Servers
In a cloud environment, centralized logging is a toggle. Enable CloudTrail, turn on VPC Flow Logs, configure GuardDuty, and the compliance platform...
CPCSC: What Defence Contractors Need Before April 2026
The Canadian Program for Cyber Security Certification (CPCSC) is Canada's mandatory cybersecurity certification for companies bidding on Department...
SOC 2 Network Security Controls for On-Premise Environments
Every SOC 2 guide on network security assumes the infrastructure lives in AWS. The advice is always the same: configure security groups, enable VPC...
SOC 2 Vulnerability Scanning for On-Prem Servers
Every SOC 2 vulnerability scanning guide assumes the same starting point: connect a cloud-native scanner, enable automated assessments, and let the...
SOC 2 Readiness for Bare Metal SaaS: What to Expect
A pattern keeps showing up. A SaaS company that has been running successfully for years, sometimes a decade or more, gets a call from a major...
The SOC 2 Snowball: How Law 25 Pushes Compliance Down Supply Chains
SOC 2, and compliance in general, is self-perpetuating. Once a company achieves certification, one of the first things the framework requires is...
Bridging the Evidence Gap: How to Turn Solid Security into SOC 2 Compliance
The most common compliance gap has nothing to do with missing controls. It's missing evidence.
What we see often is that technically competent teams...





























