Senior expertise, delivered remotely, on access that stays yours
Every engagement runs remotely, inside your own admin portals, on access you grant and can withdraw whenever you choose. Here is what actually happens, from the first email through to the report — and who does what at each step.
You write, Patrick answers
Your message goes straight to Patrick Sincennes, not into a queue. You’ll hear back within 48 hours, usually sooner, from [email protected]. A first message sometimes lands in Junk, so it’s worth adding that address as a safe sender. Nothing at this stage commits you to anything.
- Three ways in. The form, the phone, or a slot booked straight into Patrick’s calendar.
- 48 hours. The reply window, whichever channel you use.
- One person. Whoever answers is who does the work.
Scope first, price second
One call is usually enough to establish what’s at stake: what you run, what worries you, and what an insurer, client or auditor is asking of you. The price comes after that, once we both understand the mandate — and once it’s set, it holds. A firm that quotes you a firm number without asking questions is selling you a template.
- Fixed fee. Where a service page publishes a range, that range is real; the final number is set after scoping.
- Agreed timeline. Dates are set during scoping, with known absences planned around.
- Third-party costs named. A certification body or CPA firm bills you directly for its own fees, and we say so up front.
You grant the access, and you take it back
This is where remote delivery is actually decided. You grant us a least-privilege account in your environment, or granular delegated admin (GDAP) over your Microsoft 365 tenant. What we get, how far it reaches and how long it lasts are yours to set — and you can change or withdraw any of it at any time, without going through us.
For an assessment, that access exists to read configurations and nothing more. For a penetration test, it’s set up before testing starts, with rules of engagement and testing windows written down in advance.
- Revocable at any time. You decide when the access starts and when it ends.
- Your rules. We work within your security policy rather than around it.
- A scope you set. A least-privilege account or granular delegated admin — your call which.
- Meetings on Teams. Scoping, questions along the way, and walking through the report.
While the work runs
An assessment rests on reading your configurations and interviewing your people, scheduled around their availability: nothing is exploited and nothing goes down. A penetration test goes further, so techniques that could cause an outage are left out, and the most intrusive work runs outside peak hours or in a staging environment.
In both cases you can reach us throughout, and any activity can be stopped on the spot. And confirming something critical means telling you at that point; the report documents it afterwards.
What you get
A prioritized, plain-language plan your team can act on without an interpreter. Findings are ranked by the impact they actually carry for your organization, and the report is written to be read by leadership and your insurer as much as by IT. A penetration test includes an executive summary and a retest of the fixes.
- Usable as evidence. Sized for a cyber-insurance application or a client security questionnaire.
- Bilingual when needed. Sessions in French, an English version for the board or head office.
- The decisions stay yours. You choose what to fix, when, and with whom.
Nothing we do needs someone in your building
Hardware ordered as part of a managed-IT engagement arrives preconfigured and ready to plug in — your people handle that, and we stay on the line with them for as long as it takes. Equipment that dies goes through vendor warranty or RMA, a process we run on your behalf. And where physical work is unavoidable, it belongs to your own local resources.
We don’t provide in-place IT support, and we’d rather put that in writing than let you discover it partway through.
Frequently asked questions
Do you ever come on site?
No. The work happens in your admin portals rather than your boardroom — scoping, testing, advisory and reporting all run over access agreed in advance, and meetings run on Teams. No site visit is needed, wherever you are in Canada.
How do you get access to our environment?
You grant us a least-privilege account in your own environment, or granular delegated admin (GDAP) into your Microsoft 365 tenant. You decide what type of access is granted, and you can change or withdraw it at any time. We fit your security requirements rather than asking you to fit ours.
What if something needs to be physically plugged in or replaced?
Hardware arrives preconfigured and ready to plug in, so your own people handle that part while we guide them remotely. Failed equipment goes through vendor warranty or RMA, which we coordinate for you. Anything else physical is handled by your own local resources. We don’t do in-place IT support.
What happens if you find something critical mid-engagement?
You hear about it as soon as we confirm it, rather than waiting for the final report. We stay reachable throughout testing and can pause any activity immediately if you need us to.
You’re a small firm — what does that mean for my timeline?
Timelines are agreed when we scope the work, and known absences are planned around before dates are set. We don’t take on an engagement we can’t see through within the schedule we’ve committed to.
What language do the deliverables come in?
Whichever one suits you. Working sessions and the report itself can run in French, with an English version when your board or head office needs one — and the same the other way round.
Not sure where to start? A cybersecurity assessment is the usual starting point — it measures risk before anything gets bought or deployed.
Questions about how this would run?
Tell us what you have in mind. A reply within 48 hours, straight from Patrick.
Get in touch