Services
Cybersecurity and compliance services
Posture assessment, ISO 27001, TGV, CPCSC and CAN/DGSI 104 certification support, control implementation and managed services. We prepare; we do not certify.
Assessments
Cybersecurity Posture Assessment
Interviews and technical validation, mapped to ISO 27001, NIST CSF or CIS v8.1, for an objective baseline and a phased roadmap before you spend a dollar on remediation.
Compliance
TGV certification
Support for certification under the Trousse globale de vérification, the gateway for technology products and services into Quebec's health and social services network.
CPCSC certification
Preparation for Levels 1, 2 and 3 of the Canadian Program for Cyber Security Certification: self-assessment, the 13 Level 1 controls, technical remediation and evidence collection.
CAN/DGSI 104 certification
The Canadian standard built for SMEs (CyberSecure Canada): choosing Level 1 or 2, closing the gaps and preparing for the audit, with effort proportional to your size.
ISO 27001 certification
From gap analysis to the certification body's audits, an ISMS sized for your organization and a verification that stays independent of the preparation.
Implementation
Identity and access
MFA, conditional access and privileged accounts deployed on Microsoft Entra ID, Okta or your identity provider, then validated: enabled is not the same as enforced.
Endpoint and server protection
EDR and hardening baselines deployed, then tested per endpoint: tamper protection, policy coverage and an isolation response that actually works.
Network security
Firewalls, segmentation and remote access (VPN, ZTNA), with a review of the full rule set for least privilege, not just the rules that were added.
Cloud security
CSPM, guardrails and configuration baselines on Azure, AWS and Google Cloud, then a validation of the real configuration against a hardening benchmark.
Data protection
Classification, DLP, encryption and backups, with a restore test actually performed and timed instead of a green checkmark on a dashboard.
Vulnerability and patch management
Scanning, prioritization by current exploitability and patch deployment, with an independent re-scan before any ticket is closed.
Managed services
Incident response
A line answered by an analyst, available around the clock, with a scope defined up front: containment and eradication, forensic investigation, post-incident report.
Darkweb and threat intelligence monitoring
Compromised credentials, brand mentions and infrastructure monitored continuously, every alert reviewed by an analyst and paired with a recommended action.
Managed security operations
A periodic check framework, weekly to annual, with a buildbook and a runbook for every activity and documented evidence at every cadence.
Security governance and reporting
KPIs and KRIs reported on a fixed cadence, a risk register kept current and audit evidence always ready, not assembled the week before.
How we work
Measure before you spend. You cannot fix what you have not measured. The posture assessment gives you an objective, technically validated baseline and a sequenced roadmap: quick wins, then foundational controls, then advanced maturity.
Implement, then go back and validate. An EDR agent installed is not an EDR agent working; MFA enabled is not MFA enforced; a closed ticket is not a closed vulnerability. Every implementation engagement ends with a validation of the real configuration and a specific action for each gap.
Prepare without certifying. Whoever supports you must not be the one who certifies you. We structure the process, build the management system and run the internal audit; the certification body remains an accredited third party, chosen by you, with no commercial ties to us.
Keep it effective over time. Controls that were implemented correctly still drift. Managed services keep them effective with checks on a fixed cadence, analyst-reviewed alerts and reporting your leadership actually reads.
Let's talk about what applies to you.
A first conversation helps scope the perimeter and estimate an achievable effort. No commitment.
Services · Assessments
Posture assessment: know where your security stands
Interviews and technical validation mapped to ISO 27001, NIST CSF or CIS v8.1: an objective baseline and a phased roadmap before you spend on remediation.
Learn more →
Services · Compliance
ISO/IEC 27001 certification support
From gap analysis to the certification body's audits, Sentrix structures your ISO 27001 journey and keeps the verification independent of the preparation.
Learn more →
Services · Compliance
TGV certification support
Your gateway to Quebec's health and social services network: Sentrix structures your TGV certification journey so your file reaches the BCH solid and ready.
Learn more →
Services · Compliance
CPCSC certification support (Levels 1, 2 and 3)
CPCSC is becoming a contractual requirement for defence suppliers. Sentrix structures your process at Levels 1, 2 and 3, from gap analysis to evidence.
Learn more →
Services · Compliance
CAN/DGSI 104 certification support (CyberSecure Canada)
The Canadian standard built for SMEs (CyberSecure Canada): choosing Level 1 or 2, closing the gaps and preparing for the audit. We prepare; we do not certify.
Learn more →
Services · Implementation
Cloud security: configuration validated, not just guardrails
CSPM, guardrails and configuration baselines deployed on Azure, AWS or Google Cloud, then the real configuration validated against a hardening benchmark.
Learn more →
Services · Implementation
Data protection: we test the restore, not the backup job
Classification, DLP, encryption and backups deployed, then validated end to end: a restore test actually performed and timed instead of a green checkmark.
Learn more →
Services · Implementation
Endpoint and server protection: we test the response
EDR and hardening baselines deployed on SentinelOne, Microsoft Defender or your platform, then validated per endpoint: tamper protection, policies, isolation.
Learn more →
Services · Implementation
Identity and access: enforcement validated, not assumed
MFA, conditional access and privileged accounts deployed on Entra ID, Okta or your identity provider, then tested: enabled is not the same as enforced.
Learn more →
Services · Implementation
Network security: we review every rule, not just new ones
Firewalls, segmentation and remote access (VPN, ZTNA) deployed on the vendor you already have, then the full rule set reviewed for least privilege and tested.
Learn more →
Services · Implementation
Vulnerability and patch management: we re-scan to confirm it
Scanning, prioritization by current exploitability and patch deployment, with an independent re-scan before any ticket is closed: closed is not fixed.
Learn more →
Services · Managed services
Darkweb and threat intelligence monitoring
Compromised credentials, brand mentions and infrastructure monitored continuously; every alert reviewed by an analyst and paired with a recommended action.
Learn more →
Services · Managed services
Security governance and reporting
Prove improvement over time: KPIs and KRIs reported on a fixed cadence, a current risk register and audit evidence always ready, not assembled the week before.
Learn more →
Services · Managed services
Incident response: under attack? We're here, 24/7
Suspect a security incident? Do not wait. A line answered by an analyst, around the clock, with a scope defined up front: containment, investigation, report.
Learn more →
Services · Managed services
Managed security operations: continuous validation
Controls that were implemented correctly still drift. We keep them effective with a periodic check framework, weekly to annual, documented at every cadence.
Learn more →
Frequently asked questions
- Where should we start?
- With a cybersecurity posture assessment if you have no objective baseline: it gives you a score by domain, a prioritized risk register and a phased roadmap before you spend a dollar on remediation. If you already know what needs fixing, we can scope an implementation engagement or a certification support project directly, without an assessment first.
- Do you issue ISO 27001, TGV, CPCSC or CAN/DGSI 104 certifications?
- No, and that is deliberate. Certification is issued by a third party: an accredited certification body for ISO 27001 and CAN/DGSI 104, the Certification and Homologation Bureau for TGV, the government tool or an accredited body for CPCSC. We structure the process, implement the controls and prepare you for the audits, but we are never judge and jury.
- Do you work with the tools we already have?
- In most cases, yes. We tune and extend your EDR, identity provider, firewall or CSPM tool before recommending a replacement. Every implementation engagement ends with a validation of the real configuration, with a specific action for each gap we find, rather than an installation report that says everything is deployed.
- What happens after an implementation engagement ends?
- An implementation engagement is a defined project with a start and an end. If you want the controls to stay effective over time, Managed Security Operations takes over with checks on a fixed cadence, tracked remediation and documented evidence; Security Governance and Reporting adds the layer of reporting to leadership, auditors and customers.
Let's talk about your compliance program.
Last updated: 2026-09-17
