Sentrix

Services

Cybersecurity and compliance services

Posture assessment, ISO 27001, TGV, CPCSC and CAN/DGSI 104 certification support, control implementation and managed services. We prepare; we do not certify.

Assessments

Cybersecurity Posture Assessment

Interviews and technical validation, mapped to ISO 27001, NIST CSF or CIS v8.1, for an objective baseline and a phased roadmap before you spend a dollar on remediation.

Compliance

TGV certification

Support for certification under the Trousse globale de vérification, the gateway for technology products and services into Quebec's health and social services network.

CPCSC certification

Preparation for Levels 1, 2 and 3 of the Canadian Program for Cyber Security Certification: self-assessment, the 13 Level 1 controls, technical remediation and evidence collection.

CAN/DGSI 104 certification

The Canadian standard built for SMEs (CyberSecure Canada): choosing Level 1 or 2, closing the gaps and preparing for the audit, with effort proportional to your size.

ISO 27001 certification

From gap analysis to the certification body's audits, an ISMS sized for your organization and a verification that stays independent of the preparation.

Implementation

Identity and access

MFA, conditional access and privileged accounts deployed on Microsoft Entra ID, Okta or your identity provider, then validated: enabled is not the same as enforced.

Endpoint and server protection

EDR and hardening baselines deployed, then tested per endpoint: tamper protection, policy coverage and an isolation response that actually works.

Network security

Firewalls, segmentation and remote access (VPN, ZTNA), with a review of the full rule set for least privilege, not just the rules that were added.

Cloud security

CSPM, guardrails and configuration baselines on Azure, AWS and Google Cloud, then a validation of the real configuration against a hardening benchmark.

Data protection

Classification, DLP, encryption and backups, with a restore test actually performed and timed instead of a green checkmark on a dashboard.

Vulnerability and patch management

Scanning, prioritization by current exploitability and patch deployment, with an independent re-scan before any ticket is closed.

Managed services

Incident response

A line answered by an analyst, available around the clock, with a scope defined up front: containment and eradication, forensic investigation, post-incident report.

Darkweb and threat intelligence monitoring

Compromised credentials, brand mentions and infrastructure monitored continuously, every alert reviewed by an analyst and paired with a recommended action.

Managed security operations

A periodic check framework, weekly to annual, with a buildbook and a runbook for every activity and documented evidence at every cadence.

Security governance and reporting

KPIs and KRIs reported on a fixed cadence, a risk register kept current and audit evidence always ready, not assembled the week before.

How we work

Measure before you spend. You cannot fix what you have not measured. The posture assessment gives you an objective, technically validated baseline and a sequenced roadmap: quick wins, then foundational controls, then advanced maturity.

Implement, then go back and validate. An EDR agent installed is not an EDR agent working; MFA enabled is not MFA enforced; a closed ticket is not a closed vulnerability. Every implementation engagement ends with a validation of the real configuration and a specific action for each gap.

Prepare without certifying. Whoever supports you must not be the one who certifies you. We structure the process, build the management system and run the internal audit; the certification body remains an accredited third party, chosen by you, with no commercial ties to us.

Keep it effective over time. Controls that were implemented correctly still drift. Managed services keep them effective with checks on a fixed cadence, analyst-reviewed alerts and reporting your leadership actually reads.

Let's talk about what applies to you.

A first conversation helps scope the perimeter and estimate an achievable effort. No commitment.

Contact us

Frequently asked questions

Where should we start?
With a cybersecurity posture assessment if you have no objective baseline: it gives you a score by domain, a prioritized risk register and a phased roadmap before you spend a dollar on remediation. If you already know what needs fixing, we can scope an implementation engagement or a certification support project directly, without an assessment first.
Do you issue ISO 27001, TGV, CPCSC or CAN/DGSI 104 certifications?
No, and that is deliberate. Certification is issued by a third party: an accredited certification body for ISO 27001 and CAN/DGSI 104, the Certification and Homologation Bureau for TGV, the government tool or an accredited body for CPCSC. We structure the process, implement the controls and prepare you for the audits, but we are never judge and jury.
Do you work with the tools we already have?
In most cases, yes. We tune and extend your EDR, identity provider, firewall or CSPM tool before recommending a replacement. Every implementation engagement ends with a validation of the real configuration, with a specific action for each gap we find, rather than an installation report that says everything is deployed.
What happens after an implementation engagement ends?
An implementation engagement is a defined project with a start and an end. If you want the controls to stay effective over time, Managed Security Operations takes over with checks on a fixed cadence, tracked remediation and documented evidence; Security Governance and Reporting adds the layer of reporting to leadership, auditors and customers.

Let's talk about your compliance program.

Last updated: 2026-09-17