home / directory / services

// service

Penetration testing in Canada

Authorized attempts to break into networks, web applications, APIs, mobile apps, and wireless networks to find weaknesses before attackers do.

23 firms list this service

Full service · Greater Toronto Area, Ontario

3Tenets Consulting

Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.

  • Pen testing
  • AppSec
  • GRC advisory
  • IR and forensics
  • Privacy
  • NIST CSF
  • CIS Controls
  • ISO 27001
  • MITRE ATT&CK
  • OWASP
Focused · Winnipeg, Manitoba

Castellan Information Security Services Inc.

Governance, risk and compliance services including gap analysis, policy development, audit preparation, CPCSC and CMMC readiness, penetration testing, business continuity, and security staff augmentation.

  • GRC advisory
  • Audit and certification
  • Pen testing
  • IAM
  • CPCSC
  • CMMC
  • PCI DSS
Focused · Ottawa, Ontario

CyberHunter Solutions

Penetration testing (web, network, cloud, mobile), threat hunting, protection and monitoring, vulnerability scanning and framework-based security assessments.

  • Pen testing
  • Vulnerability mgmt
  • GRC advisory
  • Cloud security
  • NIST CSF
  • CIS Controls
Focused · Montreal, Quebec

CyberSpective

Montreal-based firm offering virtual CISO, privacy impact assessments, cybersecurity maturity assessments and audits, vendor risk, governance consulting, penetration testing and awareness training across Canada.

  • GRC advisory
  • Privacy
  • Pen testing
  • Training
  • Audit and certification
  • SOC 2
  • PIPEDA
Full service · Concord, Ontario

Cyberwall

Ten managed security services including 24/7 managed SOC, MDR, SIEM as a service, endpoint, identity and cloud security, plus consulting in incident response, penetration testing, compliance and privacy.

  • MDR and SOC
  • MSSP
  • IR and forensics
  • Pen testing
  • GRC advisory
  • +3
  • SOC 2
  • PIPEDA
  • HIPAA
  • PCI DSS
  • ISO 27001
Focused · Winnipeg, Manitoba

Digital Fort

Winnipeg consultancy offering fractional CISO, SOC 2, ISO 27001 and PCI DSS readiness, risk and maturity assessments, awareness training, and vulnerability and penetration testing.

  • GRC advisory
  • Audit and certification
  • Training
  • Pen testing
  • Vulnerability mgmt
  • SOC 2
Focused · Waterloo, Ontario

eSentire

24/7 managed detection and response and SOC service with digital forensics and incident response, response and remediation, and autonomous penetration testing and continuous threat exposure management.

  • MDR and SOC
  • IR and forensics
  • Pen testing
  • SOC 2
  • ISO 27001
  • MITRE ATT&CK
Full service · Toronto, Ontario

IRM Consulting & Advisory

Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.

  • GRC advisory
  • Audit and certification
  • Privacy
  • Pen testing
  • AppSec
  • +3
  • SOC 2
  • ISO 27001
  • CMMC
  • CIS Controls
  • GDPR
  • +3
Full service · Toronto, Ontario

ISA Cybersecurity

Compliance management, risk and privacy assessments, penetration testing, vulnerability management, cloud and data security, incident response and readiness, managed EDR and SIEM, awareness training.

  • GRC advisory
  • Privacy
  • Pen testing
  • Vulnerability mgmt
  • Cloud security
  • +4
Full service · Vancouver, British Columbia

Kobalt.io

Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.

  • GRC advisory
  • Audit and certification
  • Pen testing
  • IR and forensics
  • MDR and SOC
  • +1
  • CPCSC
  • CMMC
  • NIST 800-171
  • SOC 2
  • ISO 27001
  • +6
Full service · Laval, Quebec

OKIOK

Offensive security (penetration testing, vulnerability assessment), incident response, digital forensics, cybersecurity consulting, compliance and governance, and identity compliance as a service.

  • Pen testing
  • Vulnerability mgmt
  • IR and forensics
  • GRC advisory
  • IAM
  • +1
  • ISO 27001
  • SOC 2
  • PCI DSS
  • CPCSC
Specialist · Toronto, Ontario

Packetlabs

A Toronto-based firm that describes its work as penetration testing and related offensive security testing.

  • Pen testing
Full service · Vancouver, British Columbia

Plurilock

Cybersecurity services firm covering adversary simulation, cloud and data protection, identity and compliance readiness, including CPCSC and CMMC readiness for defence suppliers.

  • Pen testing
  • Red team
  • Cloud security
  • IAM
  • GRC advisory
  • +2
  • CPCSC
  • CMMC
  • NIST 800-171
  • MITRE ATT&CK
  • OWASP
Full service · Etobicoke, Ontario

PlutoSec

Etobicoke firm covering penetration testing, red team, compliance readiness (ISO 27001, SOC 2, PCI DSS, HIPAA), cloud security, managed SOC/MDR, secure development and incident response.

  • Pen testing
  • Red team
  • GRC advisory
  • Audit and certification
  • Cloud security
  • +3
  • ISO 27001
  • SOC 2
  • PCI DSS
  • NIST CSF
  • ITSG-33
  • +2
Full service · Toronto, Ontario

SAV Associates

Toronto CPA firm and ISO certification body offering SOC 1/2/3 attestation, ISO certification, IT audit, GRC consulting, CMMC and CPCSC readiness, and penetration testing and incident response.

  • Audit and certification
  • GRC advisory
  • Pen testing
  • Vulnerability mgmt
  • IR and forensics
  • SOC 2
  • ISO 27001
  • CMMC
  • CPCSC
Full service · Toronto, Ontario

Secur-IT Data Solutions

Toronto managed security provider offering OT security for industrial and utility networks alongside network, cloud, endpoint and email security, penetration testing and risk assessment.

  • OT and ICS
  • MSSP
  • Pen testing
  • Vulnerability mgmt
  • Cloud security
  • +1
Full service · Anjou, Quebec

Secur01

Anjou, Quebec firm offering managed protection and SOC-as-a-service, vulnerability scanning, penetration testing, vCISO, incident response planning, awareness training and Law 25 compliance evaluation; French and English.

  • MDR and SOC
  • Pen testing
  • Vulnerability mgmt
  • GRC advisory
  • Privacy
  • +3
  • Law 25
Specialist · Ottawa, Ontario

Software Secured

Manual penetration testing for web, API, mobile, cloud, infrastructure, AI and IoT; secure code review, red teaming, threat modeling, PTaaS and developer training on the OWASP Top 10.

  • Pen testing
  • Red team
  • AppSec
  • Cloud security
  • Training
  • SOC 2
  • HIPAA
  • ISO 27001
  • PCI DSS
  • GDPR
  • +1
Specialist · Toronto, Ontario

Stingrai

Penetration testing for applications, networks and cloud, social engineering, and red/purple team exercises, delivered with a PTaaS platform and retesting.

  • Pen testing
  • Red team
  • AppSec
  • Cloud security
  • SOC 2
  • ISO 27001
  • CMMC
  • PCI DSS
  • HIPAA
  • +1
Full service · Ottawa, Ontario

TwelveDot Incorporated

Ottawa technology and security consulting practice offering virtual CSO, ethical hacking, cloud, mobile and IoT assessments, ISO 27001 implementation and audit, breach mitigation and incident response.

  • GRC advisory
  • Pen testing
  • Cloud security
  • Audit and certification
  • IR and forensics
  • +1
  • ISO 27001
  • OWASP
Focused · Toronto, Ontario

Vumetric

Penetration testing and security assessment provider covering network, application, API, specialized (medical device, IoT, SCADA/ICS), red team and social engineering testing, plus vulnerability assessment.

  • Pen testing
  • Red team
  • Vulnerability mgmt
  • AppSec
  • OT and ICS
  • PCI DSS
  • SOC 2
  • ISO 27001
  • GDPR
  • OWASP
  • +1
Specialist · Montreal, Quebec

Wezoom Cybersecurity Agency

Montreal agency offering black-box and white-box penetration testing for web applications, mobile applications, cloud and network infrastructure, reconnaissance assessments, and cybersecurity awareness training.

  • Pen testing
  • Training
Focused · Ottawa, Ontario

Xanthus Security

Offensive security assessments including web, network, cloud, wireless, mobile, ICS and IoT penetration testing, red team engagements, mentorship and training.

  • Pen testing
  • Red team
  • OT and ICS
  • Training