A cyber practice builtinside a compliance firm

A Canadian cyber compliance practice, backed by 4S Consulting Services Inc. — twenty years of taking organisations through audits that count.

We work with Canadian organisations from offices in Markham, Ontario and Ottawa — testing systems by hand, closing what the testing finds, and taking companies through the certifications their customers and their contracts now demand. The company is new. The firm behind it is not.

Backed by 4S Consulting Services Inc.

4SYBER was founded by 4S Consulting Services Inc., a Canadian consultancy that has been in the compliance business since 2004. Its practice is occupational health and safety — COR®, ISO 45001, WSIB Excellence — and it has taken more than 750 organisations through those programmes across construction, manufacturing, healthcare, municipalities and the public sector.

That is a different subject from information security. It is not a different discipline. Both are compliance regimes where an external assessor arrives, asks for evidence, and either accepts it or does not. Twenty years of building management systems that survive that moment is the thing 4SYBER inherited, and it is the part most security consultancies are weakest at.

Why a safety firm started a cyber practice

Because the same clients started asking. An organisation that already holds COR® or ISO 45001 understands what a management system is, what an internal audit costs, and why evidence collected the week before fieldwork is evidence nobody trusts. When their customers began sending security questionnaires, and when CPCSC and CMMC began appearing in contracts, they asked whether the firm that got them through the safety audit could do the same for the security one.

So the answer had to be a real practice rather than a line item — testers who exploit systems by hand, and assessors who have sat on the other side of a certification audit. That is what this is.

Markham and Ottawa

The Markham office covers the Greater Toronto Area and most of our commercial work. The Ottawa office matters for a specific reason: Canadian defence procurement is decided there, and CPCSC readiness is not a programme you run well at arm’s length from the people setting the requirements.

Nine lines, and no tiers

Small businesses, enterprises and defence suppliers all need the same nine things. A twenty-person firm handling client financial data needs the same penetration test, the same cloud review and the same trained staff as a company a hundred times its size — what differs is scope and duration, not which lines it is allowed to buy. There is no bronze package, no upsell ladder, and nothing on this site is priced to make the next tier look reasonable.

How we are different

  • We break systems and we certify them. Those are usually sold by two different kinds of company. A control set written by people who have never exploited anything is a filing exercise, and a penetration test that ignores your compliance obligations produces findings nobody is funded to fix.
  • We sell enablement, not fear. Our proposals lead with what you will be able to do afterwards — bid on the contract, pass the customer review, ship without a security gate.
  • Named people, named certifications. You know who is on your engagement before you sign, and what they hold.
  • Two readouts, one week. The executive briefing and the engineering readout are written separately, for two different rooms, and neither is a translation of the other.
  • A good engagement ends with you needing us less. You keep the runbooks, the risk register and the evidence pipeline.
  • No tooling resale, no vendor commissions. If a product would answer your question, we will name it and tell you to buy it directly.

Security spend is only defensible when it is tied to a risk someone signed for.

10+

Engagements delivered

Since 2024

100%

First-audit pass rate

ISO 27001 and SOC 2

10

Business days to report

Median, penetration testing

100%

Findings re-tested free

Within 90 days

Tell us what triggered the search. We will scope to that.

We reply to every assessment request within one business day.