You deal with the architect, not a call centre
IT Sincennes is a Canadian-owned cybersecurity firm led by Patrick Sincennes, a Microsoft-certified security architect (SC-100).
- Microsoft Cybersecurity Architect Expert (SC-100)
- Microsoft Azure Solutions Architect Expert
- Drata Alliance Partner
- Bilingual — English & French
- Based in Ottawa & Gatineau
- Canadian-owned · data stays in Canada
Subject to Law 25? Take the free 2-minute self-check →
Hands-on expertise for your business
The same expertise behind the free Cactus Security tools, available hands-on for businesses that need more than a self-serve check.
Cybersecurity assessments
A practical review of your organization’s security posture — what’s exposed, what matters most, and a prioritized plan to fix it.
Penetration testing
Authorized, real-world testing of your systems and applications, with a clear report your team can actually act on.
IT consulting & projects
Defined IT projects for small and mid-sized businesses: migrations, Microsoft 365, servers and networking, cloud — scoped and priced up front, with security built into the design.
Virtual CISO (vCISO)
Executive security leadership on demand: strategy, governance and compliance (Law 25) — at a fraction of a full-time CISO’s cost.
Everything else your environment needs
Compliance & frameworks
SOC 2 readiness, NIST CSF 2.0 audits and Quebec Law 25 / PIPEDA — get audit-ready and pass client and insurer requirements.
Microsoft Sentinel
Custom detections and automated response, implemented and tuned by the architect — your data kept in Canada.
Quebec Law 25 compliance
Quebec’s Law 25 made practical for SMBs — privacy officer, privacy impact assessments, governance and breach reporting, in French.
Canadian data sovereignty
A Canadian-owned firm hosting your data in Canada — reducing CLOUD Act exposure and supporting Law 25.
Vulnerability management
Continuous identification, prioritization and tracking of vulnerabilities — so the risks that matter get fixed first.
Incident response planning
Response plans, runbooks and tabletop exercises so your team knows exactly what to do when it counts.
Awareness & phishing training
Bilingual phishing simulations and awareness training that turn your employees into a first line of defense.
Microsoft 365 security
Entra ID and MFA, conditional access, Defender and Purview — Microsoft 365 locked down and aligned to Law 25, by an SC-100 architect.
Cloud & hosting
Secure migration and hosting on Azure, AWS and Google Cloud, plus Microsoft 365 and website hosting — with your data in Canadian regions.
Hardware & licensing
Lenovo laptops, desktops and servers (and other brands), accessories and software licensing — right-sized, sourced and configured.
Cloud desktops
Azure Virtual Desktop and Windows 365 Cloud PCs — a secure Windows desktop your team reaches from anywhere, with data in Canada.
Also: Azure architecture & advisory · backup & disaster recovery · SIEM & logging · AI enablement
An authorized Drata Alliance Partner
We pair hands-on compliance work with Drata, a compliance-automation platform: it connects to your cloud and SaaS systems, collects evidence automatically, maps it to the SOC 2, ISO 27001 and NIST CSF controls, and flags drift. What it doesn’t do is decide which drift matters — that part of the job is ours.
A local partner that speaks your language
A bilingual cybersecurity firm based in Ottawa and Gatineau, serving businesses coast to coast to coast — with Canadian compliance front of mind.
- Assessment first. We start by measuring risk, not by selling products.
- Bilingual. Full service in both French and English.
- Local. A National Capital Region practice — one senior point of contact from kickoff to handover.
- End to end. From strategy through to delivered, documented projects.
- Canadian-owned. Your data stays in Canada, under Canadian privacy law.
In the region: cybersecurity in Gatineau · cybersecurity in Ottawa · pen testing in the Outaouais · vCISO in the Outaouais · Law 25 in the Outaouais · IT services in Gatineau
We don’t just advise on security — we build it
Cactus Security is our own production security tooling — built, run and given away free by IT Sincennes. Link and email checkers, breach lookups, a Security Checkup and more.
- Link & email checker
- Breached-website lookups
- Security Checkup & Spot-the-Scam quiz
- Scam of the Week & newsletter
Ready to know where you stand?
Start with a no-obligation scoping call — we’ll tell you what an assessment would cover and what it costs.
Get in touch- Canadian-owned
- Microsoft SC-100
- Bilingual
- Straight to the architect
Frequently asked questions
What does a cybersecurity assessment include?
We review your security posture end to end — what’s exposed and what matters most — and hand you a prioritized, plain-language plan your team can act on.
What is penetration testing, and does my business need it?
Penetration testing is authorized, real-world testing of your systems and applications that finds weaknesses before attackers do. Most organizations that handle client data — or are required to by insurance or compliance — benefit from regular testing.
Do you serve both Ottawa and Gatineau, in English and French?
Yes. We’re based in the Ottawa-Gatineau region and serve clients on both sides of the river, fully in English and French, as well as across Canada.
Do you work with small and mid-sized businesses?
Yes — SMBs are who this is built for. We scope the work and right-size the recommendations to your budget and your risk rather than to an enterprise template.
Are you certified?
Yes. Our work is backed by Microsoft expert certifications — Cybersecurity Architect Expert (SC-100), Azure Solutions Architect Expert, and Identity & Access Administrator — plus 20+ years of hands-on experience.
Is IT Sincennes Canadian-owned, and does our data stay in Canada?
Yes. IT Sincennes is a Canadian-owned and operated firm based in Ottawa and Gatineau. We keep client data in Canada — hosted in Canadian cloud regions (Azure Canada Central/East, AWS ca-central-1) — so it stays subject to Canadian privacy law rather than crossing the border. For organizations bound by Quebec’s Law 25 or PIPEDA, that matters twice over: the data sits in Canada, and the firm that controls it answers to Canadian law — which a US-headquartered provider cannot offer, whatever region it hosts in.
How do we get started?
Send us a note through the contact form or email [email protected]. Start with a no-obligation scoping call — we’ll tell you what an assessment would cover and what it costs.
Let’s talk about your project
Your message goes straight to Patrick Sincennes — the Microsoft-certified architect (SC-100) who does the work, not a ticket queue. You’ll hear back within 48 hours, usually sooner.