Nine lines of work.No overlap.

Offensive testing, cloud security and the human layer on one side; certification and governance on the other; incident readiness across all of it. Not tiers, and not a bundle — small businesses, enterprises and defence suppliers need the same nine things, at different scopes. You buy the line that matches your trigger.

S-01 Offensive

Penetration Testing

We attack your systems the way a funded adversary would, then hand you the exact path they took — with a fix for every step of it.

  • External, internal, web, API, mobile and cloud scope
  • Manual exploitation — not a scanner report with a logo on it
  • CVSS plus real-world business impact for every finding
  • Free re-test of every remediated finding within 90 days

A prioritised, reproducible list of what is actually exploitable — and proof it is closed.

2–4 weeks

Details
S-02 Cloud

Cloud Security

Cloud adoption moved faster than the governance around it. We assess what you have actually deployed, close what migration left open, and leave you with an operating model that survives the next migration.

  • Cloud security posture management (CSPM) and misconfiguration review across AWS, Azure and Google Cloud
  • Identity, network and data-boundary design for multi-account estates
  • Kubernetes, container and CI/CD pipeline hardening
  • Cloud governance and operating model your platform team can run

A cloud estate whose security posture is a design decision, not a residue of how the migration happened.

3–6 weeks

Details
S-03 Human layer

Phishing Simulation

A simulation everybody passes has taught you nothing. We run campaigns calibrated to what is actually being sent to your sector, and report the click as a process problem rather than a person problem.

  • Campaigns modelled on live lures aimed at your sector, not stock templates
  • Baseline, run and measure — with reporting rate as the primary metric
  • Business email compromise and MFA-fatigue scenarios, not just credential pages
  • Named-individual data kept out of management reporting

A measured, improving reporting rate — and a short list of the processes that let a convincing email through.

3–12 months

Details
S-04 Human layer

Security Awareness Training

Most incidents begin with a reasonable person doing a reasonable thing at the wrong moment. We train for that moment — role by role — rather than for the annual compliance tick.

  • Role-based tracks — finance, engineering, executive, frontline
  • Built around the incidents your sector actually reports
  • Live sessions and short async modules, in English and French
  • Attendance and comprehension evidence formatted for your auditor

A workforce that recognises the moment it is being worked — and an audit trail that proves the training happened.

6–12 weeks to launch

Details
S-05 Resilience

Incident Response Readiness

The worst time to design your response is during one. We build and rehearse the plan while nothing is on fire.

  • IR plan, runbooks and escalation trees mapped to your org chart
  • Tabletop exercises for the executive team and the on-call team
  • Detection gap analysis against MITRE ATT&CK
  • Bill C-26 and CCSPA cyber security programme support for designated operators
  • Retainer options with defined response SLAs

A response your team has already run once, before it counts.

3–6 weeks

Details
S-06 Certification

ISO 27001

An information security management system your business can actually operate — built for certification, not for a binder.

  • Gap assessment against Annex A and the 2022 control set
  • Risk methodology, Statement of Applicability, and policy suite
  • Internal audit and management review support
  • We sit with you through Stage 1 and Stage 2

Certification, and an ISMS that survives the year after it.

4–9 months

Details
S-07 Attestation

SOC 2

Type I to prove design, Type II to prove operation. We get you through both without stalling the roadmap.

  • Trust Services Criteria scoping — you pay for the criteria you need
  • Control design, evidence automation and audit-window monitoring
  • Auditor liaison and readiness assessment before fieldwork
  • Vendor security questionnaire playbook for your sales team

A clean report your prospects’ security teams accept without a follow-up call.

3–12 months

Details
S-08 Defence — Canada

CPCSC

The Canadian Programme for Cyber Security Certification is becoming a condition of doing business with DND. We get suppliers ready early.

  • Level determination against your contract requirements
  • Control implementation aligned to CAN/DGSI 104 and NIST SP 800-171
  • Evidence packages built for third-party assessment
  • Supply-chain flow-down guidance for your subcontractors

Certification readiness ahead of the contract clause, not after it.

4–10 months

Details
S-09 Defence — US

CMMC

CMMC 2.0 decides whether you can bid. We take defence suppliers from scoping to assessment-ready.

  • CUI scoping and enclave design to shrink the assessment boundary
  • NIST SP 800-171 implementation with a defensible SPRS score
  • System Security Plan and POA&M authored to assessor expectations
  • Pre-assessment against the CMMC Assessment Guide

Level 2 assessment readiness with the boundary — and the cost — kept small.

4–12 months

Details

Questions we get asked before the first call.

The ones that actually arrive by email. If yours is not here, it is a one-line reply away.

Do you work with small businesses, or only large enterprises?

Both, and defence suppliers alongside them. The nine lines are not tiers and there is no upsell ladder — a twenty-person firm handling client financial data needs the same penetration test, the same cloud review and the same trained staff as a company a hundred times its size. What changes is scope and duration, not which lines you are allowed to buy.

Are you a Canadian company?

Yes. 4SYBER is a proudly Canadian cybersecurity consultancy based in Markham, Ontario, in the Greater Toronto Area. We work with organisations across Canada and with Canadian firms selling into the United States, which is why both CPCSC and CMMC are on the list.

Where do we start if we have never done any of this?

With whatever triggered the search. An audit date points at ISO 27001 or SOC 2; a customer security questionnaire usually points at a penetration test; a near-miss points at phishing simulation and incident response readiness. If nothing has triggered it yet, a cloud security review and a baseline phishing campaign are the two cheapest ways to find out where you actually stand.

How quickly can an engagement start?

We reply to every assessment request within one business day, and a delivery lead — not a sales rep — is who replies. Scheduling depends on the line: testing engagements typically start within two to three weeks, certification programmes begin with a gap assessment that can usually start sooner.

Do you resell security tools?

No. We do not resell tooling, we take no vendor commissions, and we do not run your SOC. If a product would genuinely answer your question, we will name it and tell you to go and buy it directly.

What do we actually keep at the end?

The runbooks, the risk register, the policy suite, the evidence pipeline and the tooling configuration — whichever of those the engagement produced. A good engagement ends with you needing us less, and the handover is a phase of the work rather than a favour at the end of it.

Tell us what triggered the search. We will scope to that.

We reply to every assessment request within one business day.