8 firms list this service
3Tenets Consulting
Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.
- Pen testing
- AppSec
- GRC advisory
- IR and forensics
- Privacy
- NIST CSF
- CIS Controls
- ISO 27001
- MITRE ATT&CK
- OWASP
IRM Consulting & Advisory
Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.
- GRC advisory
- Audit and certification
- Privacy
- Pen testing
- AppSec
- +3
- SOC 2
- ISO 27001
- CMMC
- CIS Controls
- GDPR
- +3
Koasec
Quebec-based firm offering managed security services and 24/7 monitoring using Microsoft Sentinel, plus DevSecOps consulting, security architecture reviews, cloud security, penetration testing and virtual CISO services.
- MDR and SOC
- MSSP
- AppSec
- GRC advisory
Mirai Security
Application security testing, red team and vulnerability assessment, incident response, cloud security, GRC and security awareness training.
- AppSec
- Red team
- Vulnerability mgmt
- IR and forensics
- Cloud security
- +2
- SOC 2
- ISO 27001
PlutoSec
Etobicoke firm covering penetration testing, red team, compliance readiness (ISO 27001, SOC 2, PCI DSS, HIPAA), cloud security, managed SOC/MDR, secure development and incident response.
- Pen testing
- Red team
- GRC advisory
- Audit and certification
- Cloud security
- +3
- ISO 27001
- SOC 2
- PCI DSS
- NIST CSF
- ITSG-33
- +2
Software Secured
Manual penetration testing for web, API, mobile, cloud, infrastructure, AI and IoT; secure code review, red teaming, threat modeling, PTaaS and developer training on the OWASP Top 10.
- Pen testing
- Red team
- AppSec
- Cloud security
- Training
- SOC 2
- HIPAA
- ISO 27001
- PCI DSS
- GDPR
- +1
Stingrai
Penetration testing for applications, networks and cloud, social engineering, and red/purple team exercises, delivered with a PTaaS platform and retesting.
- Pen testing
- Red team
- AppSec
- Cloud security
- SOC 2
- ISO 27001
- CMMC
- PCI DSS
- HIPAA
- +1
Vumetric
Penetration testing and security assessment provider covering network, application, API, specialized (medical device, IoT, SCADA/ICS), red team and social engineering testing, plus vulnerability assessment.
- Pen testing
- Red team
- Vulnerability mgmt
- AppSec
- OT and ICS
- PCI DSS
- SOC 2
- ISO 27001
- GDPR
- OWASP
- +1
// more
Other services
- Penetration testing
- Red teaming
- Vulnerability assessment and management
- Cloud security
- Managed detection and response
- Incident response and forensics
- Governance, risk, and compliance advisory
- Audits, attestations, and certification
Listings reflect what each firm says on its own website. Inclusion is not an endorsement. How the directory works.