// directory
Canadian cybersecurity and compliance firms
41 firms mapped by the services they offer and the frameworks they name, compiled from each firm’s own website. Not a ranking, and not an endorsement.
41 firms
3Tenets Consulting
Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.
- Pen testing
- AppSec
- GRC advisory
- IR and forensics
- Privacy
- NIST CSF
- CIS Controls
- ISO 27001
- MITRE ATT&CK
- OWASP
Appollon Inc.
Managed detection and response with 24/7 SOC monitoring, behavioural detection, active threat response and forensic investigation and remediation, aimed at gaming and tech companies in Quebec.
- MDR and SOC
- IR and forensics
- SOC 2
- ISO 27001
- Law 25
Arista Cyber
Industrial cybersecurity firm for OT and ICS: risk assessments, gap analysis, IEC 62443 zone and conduit design, vulnerability assessments and incident response planning for energy and industrial operators.
- OT and ICS
- GRC advisory
- Vulnerability mgmt
- IR and forensics
- IEC 62443
- NERC CIP
- NIST CSF
C3SA
Cybersecurity organization offering consulting, systems integration, training and cyber ranges, incident response and threat intelligence, with compliance work for ITSG-33, CMMC, CPCSC and SOC 2.
- Architecture
- IR and forensics
- Threat intel
- Privacy
- ITSG-33
- CMMC
- CPCSC
- SOC 2
Canadian Cyber
Toronto firm offering ISO 27001 and SOC 2 consulting, internal audits, audit simulation workshops, virtual CISO services and CIS framework implementation.
- GRC advisory
- Audit and certification
- ISO 27001
- SOC 2
- CIS Controls
Castellan Information Security Services Inc.
Governance, risk and compliance services including gap analysis, policy development, audit preparation, CPCSC and CMMC readiness, penetration testing, business continuity, and security staff augmentation.
- GRC advisory
- Audit and certification
- Pen testing
- IAM
- CPCSC
- CMMC
- PCI DSS
CyberClan
Incident response, post-breach remediation, 24/7 managed detection and response, risk management, IT services and eDiscovery.
- IR and forensics
- MDR and SOC
- GRC advisory
CyberHunter Solutions
Penetration testing (web, network, cloud, mobile), threat hunting, protection and monitoring, vulnerability scanning and framework-based security assessments.
- Pen testing
- Vulnerability mgmt
- GRC advisory
- Cloud security
- NIST CSF
- CIS Controls
CyberSpective
Montreal-based firm offering virtual CISO, privacy impact assessments, cybersecurity maturity assessments and audits, vendor risk, governance consulting, penetration testing and awareness training across Canada.
- GRC advisory
- Privacy
- Pen testing
- Training
- Audit and certification
- SOC 2
- PIPEDA
Cyberwall
Ten managed security services including 24/7 managed SOC, MDR, SIEM as a service, endpoint, identity and cloud security, plus consulting in incident response, penetration testing, compliance and privacy.
- MDR and SOC
- MSSP
- IR and forensics
- Pen testing
- GRC advisory
- +3
- SOC 2
- PIPEDA
- HIPAA
- PCI DSS
- ISO 27001
CYPFER
Incident response, ransomware response and recovery, digital forensics, eDiscovery, incident response retainers, offensive security testing, threat intelligence and security awareness training.
- IR and forensics
- Threat intel
- Training
- GRC advisory
Digital Fort
Winnipeg consultancy offering fractional CISO, SOC 2, ISO 27001 and PCI DSS readiness, risk and maturity assessments, awareness training, and vulnerability and penetration testing.
- GRC advisory
- Audit and certification
- Training
- Pen testing
- Vulnerability mgmt
- SOC 2
eSentire
24/7 managed detection and response and SOC service with digital forensics and incident response, response and remediation, and autonomous penetration testing and continuous threat exposure management.
- MDR and SOC
- IR and forensics
- Pen testing
- SOC 2
- ISO 27001
- MITRE ATT&CK
EthiSecure Services Inc.
Quebec firm offering audit and compliance, security consulting and advising (architecture, vulnerability assessment, risk analysis, policies, virtual CISO and privacy officer roles) and training and certification.
- Audit and certification
- GRC advisory
- Architecture
- Vulnerability mgmt
- Privacy
- ISO 27001
- PCI DSS
- HIPAA
- SOC 2
Field Effect
Managed detection and response across endpoint, network, cloud and identity, with a 24x7 SOC, incident response, IR readiness and cybersecurity assessments. Focus on small and mid-sized organisations and their partners.
- MDR and SOC
- IR and forensics
- MITRE ATT&CK
Indigo Consulting
Identity security consultancy covering identity and access management, privileged access management, identity governance, cloud identity, managed services and advisory, with English and French site versions.
- IAM
- GRC advisory
IRM Consulting & Advisory
Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.
- GRC advisory
- Audit and certification
- Privacy
- Pen testing
- AppSec
- +3
- SOC 2
- ISO 27001
- CMMC
- CIS Controls
- GDPR
- +3
ISA Cybersecurity
Compliance management, risk and privacy assessments, penetration testing, vulnerability management, cloud and data security, incident response and readiness, managed EDR and SIEM, awareness training.
- GRC advisory
- Privacy
- Pen testing
- Vulnerability mgmt
- Cloud security
- +4
Koasec
Quebec-based firm offering managed security services and 24/7 monitoring using Microsoft Sentinel, plus DevSecOps consulting, security architecture reviews, cloud security, penetration testing and virtual CISO services.
- MDR and SOC
- MSSP
- AppSec
- GRC advisory
Kobalt.io
Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.
- GRC advisory
- Audit and certification
- Pen testing
- IR and forensics
- MDR and SOC
- +1
- CPCSC
- CMMC
- NIST 800-171
- SOC 2
- ISO 27001
- +6
Korland Inc.
Calgary firm offering corporate and operational technology cybersecurity assessment, architecture and design, implementation and remediation, and ongoing support including cloud security work.
- OT and ICS
Mirai Security
Application security testing, red team and vulnerability assessment, incident response, cloud security, GRC and security awareness training.
- AppSec
- Red team
- Vulnerability mgmt
- IR and forensics
- Cloud security
- +2
- SOC 2
- ISO 27001
Noraa Consulting
Montreal consultancy offering Law 25 compliance support, ISO 27001 and 27005 training and certification preparation, Microsoft 365 security configuration and security architecture consulting; French and English.
- GRC advisory
- ISO 27001
- Law 25
- SOC 2
OKIOK
Offensive security (penetration testing, vulnerability assessment), incident response, digital forensics, cybersecurity consulting, compliance and governance, and identity compliance as a service.
- Pen testing
- Vulnerability mgmt
- IR and forensics
- GRC advisory
- IAM
- +1
- ISO 27001
- SOC 2
- PCI DSS
- CPCSC
Packetlabs
A Toronto-based firm that describes its work as penetration testing and related offensive security testing.
- Pen testing
Pilotcore
Cloud and compliance consultancy offering DevSecOps, readiness assessments for CPCSC and CMMC, SOC 2 readiness, zero trust architecture and fractional CTO support.
- Cloud security
- GRC advisory
- Audit and certification
- Architecture
- CPCSC
- CMMC
- SOC 2
Plurilock
Cybersecurity services firm covering adversary simulation, cloud and data protection, identity and compliance readiness, including CPCSC and CMMC readiness for defence suppliers.
- Pen testing
- Red team
- Cloud security
- IAM
- GRC advisory
- +2
- CPCSC
- CMMC
- NIST 800-171
- MITRE ATT&CK
- OWASP
PlutoSec
Etobicoke firm covering penetration testing, red team, compliance readiness (ISO 27001, SOC 2, PCI DSS, HIPAA), cloud security, managed SOC/MDR, secure development and incident response.
- Pen testing
- Red team
- GRC advisory
- Audit and certification
- Cloud security
- +3
- ISO 27001
- SOC 2
- PCI DSS
- NIST CSF
- ITSG-33
- +2
Prairie Cyber Security
Winnipeg firm serving small and mid-sized organizations with security assessments, managed detection and response, incident response, virtual CISO consulting and security awareness training.
- GRC advisory
- MDR and SOC
- IR and forensics
- Training
- PIPEDA
- PCI DSS
SAV Associates
Toronto CPA firm and ISO certification body offering SOC 1/2/3 attestation, ISO certification, IT audit, GRC consulting, CMMC and CPCSC readiness, and penetration testing and incident response.
- Audit and certification
- GRC advisory
- Pen testing
- Vulnerability mgmt
- IR and forensics
- SOC 2
- ISO 27001
- CMMC
- CPCSC
Secrecy Evolution
Toronto firm providing fractional and virtual CISO retainers: security roadmaps, policies, risk registers, board reporting, vendor risk assessment and compliance oversight for organizations across Canada.
- GRC advisory
- ISO 27001
- SOC 2
- PIPEDA
Secur-IT Data Solutions
Toronto managed security provider offering OT security for industrial and utility networks alongside network, cloud, endpoint and email security, penetration testing and risk assessment.
- OT and ICS
- MSSP
- Pen testing
- Vulnerability mgmt
- Cloud security
- +1
Secur01
Anjou, Quebec firm offering managed protection and SOC-as-a-service, vulnerability scanning, penetration testing, vCISO, incident response planning, awareness training and Law 25 compliance evaluation; French and English.
- MDR and SOC
- Pen testing
- Vulnerability mgmt
- GRC advisory
- Privacy
- +3
- Law 25
Secure State Cyber
Cybersecurity consultancy with offices in Halifax and Toronto offering technical cybersecurity review, management and compliance support, GDPR and data privacy officer service, awareness training and threat intelligence.
- GRC advisory
- Privacy
- Training
- Threat intel
- ISO 27001
- GDPR
SecureOps
Boutique managed security services provider offering co-owned MDR, custom 24/7 SOC services, infrastructure security (firewall, VPN, segmentation, SASE), vulnerability management and security staffing.
- MDR and SOC
- MSSP
- Vulnerability mgmt
- GDPR
Software Secured
Manual penetration testing for web, API, mobile, cloud, infrastructure, AI and IoT; secure code review, red teaming, threat modeling, PTaaS and developer training on the OWASP Top 10.
- Pen testing
- Red team
- AppSec
- Cloud security
- Training
- SOC 2
- HIPAA
- ISO 27001
- PCI DSS
- GDPR
- +1
Stingrai
Penetration testing for applications, networks and cloud, social engineering, and red/purple team exercises, delivered with a PTaaS platform and retesting.
- Pen testing
- Red team
- AppSec
- Cloud security
- SOC 2
- ISO 27001
- CMMC
- PCI DSS
- HIPAA
- +1
TwelveDot Incorporated
Ottawa technology and security consulting practice offering virtual CSO, ethical hacking, cloud, mobile and IoT assessments, ISO 27001 implementation and audit, breach mitigation and incident response.
- GRC advisory
- Pen testing
- Cloud security
- Audit and certification
- IR and forensics
- +1
- ISO 27001
- OWASP
Vumetric
Penetration testing and security assessment provider covering network, application, API, specialized (medical device, IoT, SCADA/ICS), red team and social engineering testing, plus vulnerability assessment.
- Pen testing
- Red team
- Vulnerability mgmt
- AppSec
- OT and ICS
- PCI DSS
- SOC 2
- ISO 27001
- GDPR
- OWASP
- +1
Wezoom Cybersecurity Agency
Montreal agency offering black-box and white-box penetration testing for web applications, mobile applications, cloud and network infrastructure, reconnaissance assessments, and cybersecurity awareness training.
- Pen testing
- Training
Xanthus Security
Offensive security assessments including web, network, cloud, wireless, mobile, ICS and IoT penetration testing, red team engagements, mentorship and training.
- Pen testing
- Red team
- OT and ICS
- Training
No firms match those filters. Try removing one.
// browse
By service and framework
Services
- Penetration testing
- Red teaming
- Vulnerability assessment and management
- Application security
- Cloud security
- Managed detection and response
- Incident response and forensics
- Governance, risk, and compliance advisory
- Audits, attestations, and certification
- Security architecture and engineering
- Identity and access management
- Privacy and data protection
- Security awareness and training
- OT and industrial control system security
- Threat intelligence
- Managed security services
Is your firm missing or listed wrongly?
Ask for a listing, a correction, or removal. We check every change against your website.