Cybersecurity
Architecture, testing and remediation under one roof.
Certified depth across security architecture, penetration testing, vulnerability management and incident readiness—turning findings into fixes your team can act on.
We help Canadian small and mid-sized businesses save time with AI, prevent costly technology surprises and keep work moving—without making you learn the jargon.
A focused first look at the controls that matter most—followed by clear priorities you can act on.
Book a free reviewCanlus brings certified, hands-on practitioners across cybersecurity, cloud, identity, networks, AI and data. You work directly with experienced specialists who can assess, design and implement—not a sales layer or junior delivery bench.
Architecture, testing and remediation under one roof.
Certified depth across security architecture, penetration testing, vulnerability management and incident readiness—turning findings into fixes your team can act on.
Microsoft security expertise from strategy through implementation.
Proven architecture and implementation capability across Microsoft cloud security, modern identity, privileged access and zero-trust programs at enterprise scale.
Enterprise network depth for complex, real-world environments.
Hands-on capability across enterprise firewalls, secure network design, SD-WAN and Azure hybrid connectivity—from architecture decisions to practical implementation.
Production-minded AI backed by strong data engineering.
Advanced AI and data capability for LLM and RAG solutions, automation and reliable data pipelines—built to move from promising prototype to usable production system.
A Calgary-based team that understands how Canadian small businesses operate, communicates in English or Chinese and stays accountable from the first conversation through delivery.
Every service starts with the worry or bottleneck on your desk, then works backward to a clear outcome your team can see and use.
On-site across Calgary and surrounding communities, with remote delivery available across Canada.
Tired of AI demos that never help the day-to-day? We find the repetitive work worth fixing, build a useful solution and make sure your team can run it safely after launch.
Discuss an AI opportunityWorried that one missed setting could expose email, files or customer data? We review the environment, close the gaps that matter and give your team a simpler way to stay on top of security.
Book an M365 health checkUnsure who can still reach sensitive systems—or whether a stolen password is enough to get in? We simplify sign-in, remove unnecessary access and make joining, changing roles and leaving safer.
Review identity securityNew laptops should not take days to set up, and lost devices should not create panic. We make company devices consistent, protected and easier to support wherever your team works.
Assess endpoint securityConcerned that customer, employee or financial data is being shared too widely? We help you see where sensitive information lives, set practical rules and reduce accidental exposure without blocking normal work.
Plan data protectionWhen an alert arrives at the worst possible time, your team should not be deciding from scratch. We clarify who acts, what happens first and how the business keeps moving.
Review incident readinessA long list of possible flaws does not tell you what could really hurt the business. We safely test realistic paths, show what matters and give your team a prioritized fix plan.
Scope a penetration testIf every new office, cloud service or remote worker adds another workaround, the network becomes fragile. We simplify the design so people connect reliably and problems are easier to contain.
Review network architectureSecurity questionnaires, insurance renewals and privacy obligations can become last-minute fire drills. We show what evidence you have, what is missing and what to fix first so the next request is easier.
Assess compliance readinessNot sure which AI idea deserves budget—or whether your data is ready? We compare the opportunities, surface the risks and give you a phased plan built around value, effort and safe adoption.
Start an AI readiness reviewA straightforward four-step process keeps scope, cost, delivery and next actions clear.
We clarify your priorities, current environment and the outcome you want—at no cost and with no obligation.
We review the relevant environment, provide a written scope and estimate, and proceed once the agreement is signed.
We complete the work, communicate progress and provide clear findings, recommendations and documentation.
We help with remediation, handover and follow-up support so improvements continue after delivery.
Focused safeguards for sectors where trust, confidentiality and lean teams make practical execution especially important.
Healthcare clinics
Protect patient information without slowing clinical work. We review Microsoft 365, endpoints, vendor access, backups and incident readiness, then map practical controls to PIPEDA and applicable provincial privacy obligations, including PHIPA considerations for Ontario operations.
Professional services
Client confidentiality depends on more than antivirus. We strengthen email authentication, identity, document sharing, administrator access, retention and recovery so sensitive matters remain controlled across employees, contractors and clients.
For organizations that need someone to own the follow-through without hiring a full-time security leader. We set priorities, check progress every month and keep leadership clear on what needs attention.
Our first verified client reviews will appear here as they are approved for publication.
Only genuine feedback from completed engagements will be published.
Only genuine feedback from completed engagements will be published.
The framework below illustrates how we communicate an engagement. It is not presented as a client claim; real case studies will be published only after details are anonymized and approved.
A growing professional-services firm has inconsistent MFA, broad file permissions and no tested recovery procedure. Leadership needs priorities without interrupting client work.
Review identities, sharing, administrator roles and backups; validate the highest-risk gaps; sequence remediation around business operations.
Clear ownership, stronger sign-in controls, reduced unnecessary access, tested recovery evidence and a practical 90-day improvement plan.
Illustrative engagement framework · Real outcomes will be published after client approval and anonymization.
Clear, actionable perspectives for owners and technology leaders—written in English and Chinese.
Password reuse, missing MFA, untested backups, active former-employee accounts and flat Wi-Fi networks—and one practical action for each.
A practical review of MFA, Conditional Access, external sharing, DLP and administrator accounts for business owners.
The differences, the right use cases and the typical process—so you can choose the right depth of testing.
How part-time security leadership creates ownership, priorities and follow-through without a full-time executive hire.
The first hour, the first day and the recovery decisions that help a team respond without making the situation worse.
What accountability, appropriate purpose, safeguards, access and breach readiness mean in everyday operations.
Most small and mid-sized businesses do not ignore cybersecurity. The more common problem is that day-to-day growth changes the environment faster than controls are updated. New cloud tools appear, employees change roles, contractors come and go, and a network that once served ten people now supports fifty. The result is rarely one dramatic failure. It is a handful of ordinary gaps that quietly increase exposure.
For Calgary businesses, the right response is not to copy an enterprise security program. It is to identify the few controls that reduce the most practical risk, assign clear ownership and verify that they work. These five blind spots are a useful place to begin.
When an employee reuses the same password for email, accounting, a vendor portal and a personal service, one unrelated breach can become a business incident. A strong-looking password does not solve the problem if it is used in several places. Shared team passwords create an additional issue: nobody can reliably tell who used the account, and access is difficult to remove when responsibilities change.
Action: Provide a business password manager, require a unique password for every account and replace shared credentials with named user access wherever the system allows it. Start with email, finance, remote access and administrator accounts. These systems have the highest potential impact and give the team a manageable first phase.
Many cloud services offer multi-factor authentication, but “available” is not the same as “required.” Optional enrollment usually leaves a group of users unprotected. SMS verification is better than a password alone, but an authenticator app, passkey or hardware security key offers stronger protection. Administrator accounts deserve the strictest method because they can change security settings for everyone else.
Action: Review actual MFA registration and sign-in policies, not just the licence features. Enforce MFA for all users, block legacy authentication where possible and use phishing-resistant methods for privileged roles. Keep a controlled emergency-access account and test its monitoring and recovery procedure.
A dashboard showing “backup successful” proves that a job ran; it does not prove that the right data can be restored within the time the business needs. Backups can be incomplete, dependent on the same compromised administrator account or stored in a location that ransomware can also reach. Cloud platforms may protect service availability while leaving file deletion, retention and application-level recovery to the customer.
Action: Choose one critical workload and perform a documented restore test this month. Record what was restored, how long it took, who approved the result and what failed. Then schedule tests for the remaining priority systems. Keep at least one protected copy separated from normal production access.
Offboarding often focuses on returning a laptop and forwarding email. Access to SaaS applications, VPNs, file shares, shared mailboxes and vendor portals can remain active because no single person owns the full list. Dormant accounts are easy to overlook and may retain permissions that are no longer visible in normal operations.
Action: Use one offboarding checklist triggered by the confirmed departure time. Disable the primary identity first, revoke active sessions, remove group and application access, rotate any shared secrets and transfer business data through an approved process. Review inactive accounts quarterly to catch what the workflow missed.
A single flat network is convenient, but it allows an unmanaged visitor device, smart television, camera or printer to sit close to employee computers and business systems. If one device is compromised, broad internal access can make the next step easier. Network segmentation does not need to be complicated to be useful.
Action: Create separate networks for managed business devices, guests and internet-connected equipment. Use different credentials, prevent guest traffic from reaching internal resources and restrict device networks to only the services they need. Document who manages the firewall and wireless equipment so future changes do not undo the separation.
These controls are not one-time purchases. Assign an owner, a review frequency and a simple piece of evidence for each one: an MFA coverage report, a restore-test record, an offboarding ticket or a network diagram. That makes security visible without creating unnecessary bureaucracy.
A short assessment can help separate urgent gaps from acceptable risk. Canlus offers a free initial consultation to review your current environment and identify a practical first step. The goal is not to sell a large program—it is to make the next decision clear.
多数中小企业并非不重视网络安全,真正的问题往往是:业务变化比安全控制更新得更快。团队扩大、云服务增加、员工转岗、外包人员进出,原本适合十个人的环境逐渐支撑五十个人,却没有同步调整权限、备份和网络设计。风险通常不是来自某个“惊天漏洞”,而是几个看似普通的缺口叠加在一起。
对 Calgary 的中小企业来说,正确做法不是照搬大型企业的复杂体系,而是先抓住最能降低实际风险的控制,明确负责人,并验证它们真的有效。以下五个盲区最值得优先检查。
同一个密码同时用于邮箱、财务系统、供应商门户和个人网站时,任何一处泄露都可能演变成企业事件。密码再复杂,只要重复使用,风险仍然存在。多人共用同一个账号还会导致操作无法追溯,人员变动时也难以及时撤销权限。
可执行建议:为员工提供企业密码管理器,要求每个系统使用独立密码,并尽量把共享账号改为实名账号。第一阶段先覆盖邮箱、财务、远程访问和管理员账号,因为这些系统的影响最大,也最适合快速落地。
很多云服务支持多因素认证,但“可以开启”不等于“所有人必须使用”。依赖员工自愿注册,通常会留下未保护账户。短信验证比单一密码更好,但身份验证器、Passkey 或硬件安全密钥更可靠;管理员账号应采用更严格的方法,因为它们能够修改全公司的安全设置。
可执行建议:检查真实注册率和登录策略,而不是只看许可证功能。对所有用户强制 MFA,在条件允许时关闭旧式身份验证,并优先为高权限角色部署抗钓鱼认证。保留受控的紧急访问账号,同时测试监控和恢复流程。
控制台显示“备份成功”,只说明任务运行过,并不能证明关键数据能在业务要求的时间内恢复。备份可能不完整、依赖同一个已被入侵的管理员账号,或存放在勒索软件同样能够访问的位置。云平台保障服务可用性,不代表自动承担所有文件删除、保留和应用恢复责任。
可执行建议:本月选一个关键系统做一次正式恢复演练,记录恢复了什么、耗时多久、由谁验收、哪里失败。然后按优先级安排其他系统。至少保留一份与生产权限隔离、不能被日常账号直接修改的受保护副本。
离职流程常常只关注收回电脑和转发邮箱,却遗漏 SaaS、VPN、共享文件、共享邮箱和供应商门户。没有人掌握完整权限清单时,休眠账号会长期保留,而且过去授予的权限很难在日常工作中被发现。
可执行建议:建立由确认离职时间触发的统一清单:先停用主身份,撤销所有活动会话,再移除群组和应用权限,轮换共享密钥,并通过批准流程移交业务数据。每季度检查不活跃账号,发现流程遗漏。
单一网络管理方便,却让访客手机、摄像头、打印机或智能电视与员工电脑和业务系统处在相近的信任范围。一台设备被攻破后,扁平网络会让攻击者更容易横向移动。有效隔离不一定复杂。
可执行建议:至少划分办公设备、访客和物联网设备三个网络,使用不同凭据,禁止访客访问内部资源,并让设备网络只能连接必要服务。同时记录谁负责防火墙和无线设备,避免后续变更破坏隔离。
这些控制不是一次性采购。为每项控制指定负责人、复查频率和简单证据,例如 MFA 覆盖报告、恢复演练记录、离职工单或网络图。这样既能持续改进,也不会制造不必要的流程负担。
如果不确定先做哪一项,Canlus 可通过免费初步咨询了解现状,帮助区分紧急缺口与可接受风险,并明确一个现实的第一步。重点不是把项目做大,而是先把下一项决策做对。
Microsoft 365 gives a small business professional email, collaboration and identity services without building its own infrastructure. That convenience can create a dangerous assumption: if the service is reputable and the licence is active, the environment must already be secure. In practice, the platform provides many security capabilities, but the business still has to decide how identities, devices, sharing and data should be controlled.
The purpose of this checklist is not to turn an owner into a Microsoft 365 administrator. It is to help leadership ask for clear evidence. Each item should produce an answer that can be verified, not “we think it is enabled.”
Owner’s question: “Can you show me the users who could still sign in with only a password?”
Owner’s question: “Which sign-ins would we block today, and who reviews the exceptions?”
Owner’s question: “Can we list every external party with access to our sensitive sites, and when that access was last reviewed?”
Owner’s question: “What sensitive information are we trying to protect, and what happens when someone attempts to send it outside the company?”
Owner’s question: “How many people can make tenant-wide changes right now, and why does each person need that access?”
Do not attempt every improvement at once. Ask for evidence, record the gap, assign risk and agree on the next action. A practical first phase often secures administrator accounts, enforces MFA, reduces risky sharing and confirms who receives security alerts. Conditional Access and data protection can then be expanded with careful testing.
Canlus offers a free initial consultation for businesses that want an independent view of their Microsoft 365 posture. We can help translate technical configuration into clear business priorities and a realistic remediation sequence—without turning the review into a fear-based sales exercise.
Microsoft 365 让中小企业无需自建基础设施,就能获得企业邮箱、协作和身份服务。但这种便利容易带来一个误区:平台知名、许可证正常,环境就应该已经安全。实际上,Microsoft 提供了大量安全能力,但身份、设备、共享和数据如何控制,仍然需要企业主动配置和持续管理。
这份清单不是要让老板变成管理员,而是帮助管理层要求团队提供可以验证的证据。每一项都应有明确答案,而不是“应该已经开了”。
老板要问:“能否列出目前仍可能只用密码登录的用户?”
老板要问:“今天哪些登录会被阻止?谁负责审查例外?”
老板要问:“能否列出所有能够访问敏感站点的外部人员,以及上次复查时间?”
老板要问:“我们要保护哪些敏感信息?员工试图把它发到公司外部时会发生什么?”
老板要问:“现在有多少人能修改整个租户?每个人为什么需要这项权限?”
不要一次完成所有改进。先要求证据、记录缺口、评估风险并确认下一步。务实的第一阶段通常是保护管理员账号、强制 MFA、减少高风险共享,并确认安全告警由谁接收;随后再通过测试逐步扩展条件访问和数据保护。
如果需要独立视角,Canlus 可通过免费初步咨询了解 Microsoft 365 现状,把技术配置翻译成清晰的业务优先级和可执行的修复顺序,不用恐惧式营销推动不必要的项目。
“Vulnerability scan” and “penetration test” are often used as if they describe the same service. They do not. Both can identify security weaknesses, but they answer different questions, use different levels of human judgement and produce different evidence. Choosing the wrong one can either leave important risk unexplored or spend money on depth the business does not yet need.
A vulnerability scan uses automated tools to inspect systems, applications or cloud assets for known weaknesses. It may identify missing patches, outdated software, insecure services, weak encryption, exposed ports and configuration patterns associated with published vulnerabilities. Authenticated scans can log into systems with controlled credentials and see more than an external scan.
Scanning is broad, repeatable and relatively efficient. That makes it well suited to routine hygiene: checking a changing environment, measuring whether patching is improving, supporting a vulnerability-management program and finding obvious exposure before a deeper test. Its limitation is context. A scanner can report that a condition exists, but it may not understand whether the finding is reachable, exploitable or meaningful to your specific business. False positives and duplicate findings require review.
A penetration test is a controlled, time-bounded assessment performed by a security professional under an agreed scope and rules of engagement. The tester combines tools with manual analysis to determine whether weaknesses can be used to achieve a realistic objective: access sensitive data, move from one system to another, bypass a control or obtain a higher level of privilege.
The purpose is not to “hack everything.” It is to safely demonstrate credible attack paths and explain their business impact. A penetration test can connect several moderate issues that would look unrelated in a scan. It also tests assumptions: whether segmentation works, whether permissions contain an account compromise and whether an application’s business logic can be abused. Because it requires human judgement, it is narrower, more expensive and less suitable as a constant monitoring tool.
Scanning should not be a one-time report. A useful process assigns each finding an owner, validates severity in business context, tracks remediation and rescans to confirm closure.
A penetration test is strongest when the scope is tied to a decision. “Test our external environment” is less useful than “determine whether an unauthenticated attacker can reach customer information through these applications and supporting services.”
For many small and mid-sized businesses, the practical model is recurring vulnerability scanning for broad visibility and a focused penetration test at key moments: before a major launch, after significant architectural change or on a risk-based schedule. Scanning finds known weaknesses at scale; penetration testing shows how selected weaknesses behave in the context of your environment.
If you are unsure which level of testing is justified, Canlus offers a free initial consultation. We can help define the business question, identify an appropriate scope and recommend scanning, penetration testing or a phased combination—without selling depth that will not change a decision.
“漏洞扫描”和“渗透测试”经常被当成同一种服务,其实两者回答的问题不同,依赖人工判断的程度不同,最终提供的证据也不同。选错方案,可能导致关键风险没有被验证,也可能在基础工作尚未完成时,为不必要的深度投入预算。
漏洞扫描使用自动化工具检查系统、应用和云资产中的已知弱点,例如缺失补丁、过期软件、不安全服务、弱加密、暴露端口,以及与公开漏洞相关的配置。经过授权的认证扫描还可以使用受控账号登录系统,从内部看到比外部扫描更多的信息。
扫描覆盖广、可重复、效率较高,适合日常安全卫生:定期检查变化中的环境、衡量补丁工作是否改善、支撑漏洞管理,并在深入测试前发现明显暴露。它的局限是缺少业务上下文。工具能报告某个条件存在,却未必能判断它在本环境中是否可达、可利用或真正重要,因此需要人工排除误报、合并重复项并重新评估优先级。
渗透测试是在约定范围和交战规则下,由安全专业人员进行的受控、限时评估。测试人员结合工具和手工分析,判断弱点能否被利用来实现现实目标,例如访问敏感数据、从一台系统移动到另一台、绕过控制或提升权限。
它的目的不是“把所有系统都黑一遍”,而是在安全前提下证明可信攻击路径,并解释业务影响。渗透测试可以把扫描中几个看似无关的中等问题连接成一条实际路径,也能验证网络隔离、权限边界和应用业务逻辑是否真正有效。由于高度依赖人工判断,它范围更聚焦、成本更高,也不适合作为持续监控手段。
扫描不应止于一次报告。有效流程要为发现指定负责人,结合业务背景确认严重性,跟踪修复,并通过重新扫描验证关闭。
渗透测试的范围最好与决策直接相关。“测试外部环境”过于宽泛;“判断未登录攻击者能否通过这些应用及其支撑服务访问客户数据”更容易形成有价值的结论。
对多数中小企业,实用模式是用周期性漏洞扫描保持广泛可见性,再在关键时点做聚焦渗透测试,例如重要系统上线前、重大架构变更后,或按风险制定周期。扫描擅长大范围发现已知弱点;渗透测试则说明这些弱点在具体环境中能产生什么后果。
如果不确定该选择哪种深度,Canlus 可通过免费初步咨询帮助明确业务问题、确定合理范围,并建议扫描、渗透测试或分阶段组合方案,不会为了扩大项目而出售对决策没有帮助的深度。
A virtual Chief Information Security Officer, or vCISO, gives an organization experienced security leadership on a part-time or retained basis. The role is not simply another monitoring service. A good vCISO helps leadership decide what matters, assigns ownership, connects technical work to business risk and keeps improvement moving after the initial assessment.
Small businesses often reach a point where security work is spread across an owner, an IT provider and several vendors. Each party handles a piece, but nobody owns the whole picture. Important questions remain open: Who accepts a risk? Who checks that a critical patch was completed? Who explains a customer security questionnaire? Who coordinates when an incident crosses email, endpoints, insurance and legal obligations?
The engagement usually begins with a current-state review. The vCISO identifies critical systems and data, documents major risks and agrees on a practical plan with leadership. Monthly work may include identity and Microsoft 365 reviews, vulnerability and patch follow-up, policy updates, tabletop exercises, vendor-risk decisions and a concise report for management.
The vCISO also creates a decision process. Not every finding deserves an urgent project. Risks should be explained in business terms, assigned to an owner and either mitigated, transferred, avoided or formally accepted. This discipline prevents security from becoming an endless list of tools.
A vCISO should not replace hands-on IT operations, legal advice or a 24×7 security operations centre. The role must have clear boundaries and escalation paths. If the same provider recommends and sells every product, leadership should also understand how conflicts are managed. Useful reporting is specific: what changed, what is overdue, which decision is needed and what evidence supports the conclusion.
It may be too early when basic IT ownership is still unclear, assets are not inventoried or the organization only needs one focused project. In that case, begin with a bounded assessment and establish the operational foundation first.
Ask who will actually deliver the service, what is included each month, how urgent incidents are handled, which reports leadership receives and whether implementation work is separate from governance. Agree on measurable outcomes for the first 90 days rather than buying an undefined block of hours.
Canlus offers a free initial consultation to determine whether a focused project, a monthly security program or a vCISO relationship is the right next step. The answer should match your operating needs—not a predetermined package.
虚拟首席信息安全官(vCISO)是以兼职或长期顾问方式,为企业提供资深安全领导力。它不是另一项单纯的监控服务。合格的 vCISO 要帮助管理层判断重点、明确负责人、把技术工作连接到业务风险,并在首次评估后持续推动改进。
很多中小企业发展到一定阶段后,安全责任分散在老板、IT 服务商和多个供应商之间。每一方负责一部分,却没有人掌握全局:谁接受某项风险?谁确认关键补丁真正完成?谁回答客户的安全问卷?当事件同时涉及邮箱、终端、保险和法律义务时,谁负责协调?
合作通常从现状评估开始。vCISO 识别关键系统和数据,记录主要风险,并与管理层确定务实计划。月度工作可包括身份与 Microsoft 365 检查、漏洞和补丁跟进、政策更新、桌面演练、供应商风险决策,以及面向管理层的简明报告。
更重要的是建立决策机制。并非每个发现都值得紧急立项。风险应以业务语言解释,分配负责人,并选择降低、转移、避免或正式接受。这样才能避免安全工作变成无止境的工具采购清单。
vCISO 不替代日常 IT 运维、法律意见或 7×24 安全运营中心。服务边界和升级路径必须明确。如果同一服务商既提出建议又销售所有产品,管理层也应了解如何处理利益冲突。有效报告要具体说明:发生了什么变化、哪些事项逾期、需要什么决策、结论有什么证据。
如果基础 IT 责任尚未明确、资产没有清单,或当前只需要完成一个专项项目,那么引入 vCISO 可能过早。此时应先做有边界的评估,建立运营基础。
确认由谁实际交付、每月包含哪些内容、紧急事件如何支持、管理层收到什么报告,以及实施与治理是否分别计费。第一阶段应约定 90 天内的可衡量结果,而不是购买一块定义模糊的时间。
Canlus 可通过免费初步咨询帮助判断:当前更适合专项项目、月度安全代维,还是 vCISO 合作。答案应匹配真实运营需求,而不是预设套餐。
Ransomware response is a coordination problem before it is a technical problem. The first decisions affect evidence, recovery, insurance, legal obligations and business continuity. A short plan with named contacts is more useful during an incident than a long policy nobody has practised.
Determine which systems, locations, identities and data are affected. Preserve logs, ransom notes, suspicious emails and forensic images when appropriate. Check whether attackers gained access before encryption and whether data may have been removed. Extortion involving stolen information can create different notification and legal considerations from operational disruption alone.
Confirm the status of backups without connecting protected copies to the compromised environment. Identify the last known clean point, the dependencies between systems and the minimum services needed to operate safely. Communicate internally using verified facts. Avoid promising a restoration time or stating that no data was taken before evidence supports the claim.
Recovery should use clean systems, known-good credentials and a prioritized sequence. Restore the identity and management layers carefully because they control everything else. Patch or remove the entry path before reconnecting systems. Validate restored data and application behaviour with business owners, then increase monitoring for repeated access.
Whether to pay a ransom is a legal, financial, operational and ethical decision—not a purely technical recommendation. Payment does not guarantee decryption, deletion of stolen data or protection from future targeting. Engage counsel, the insurer and appropriate authorities, and check sanctions implications before any negotiation.
Canlus can review an existing response plan or facilitate a focused readiness session. A free initial consultation can identify the most important preparation gap without turning the conversation into a fear-based sale.
勒索软件响应首先是协调问题,其次才是技术问题。最初几个决定会影响证据、恢复、保险、法律义务和业务连续性。真正发生事件时,一份明确联系人和权限的短计划,往往比没人演练过的长政策更有用。
确认哪些系统、地点、身份和数据受到影响。保存日志、勒索信、可疑邮件,并在适当情况下制作取证镜像。调查攻击者是否在加密前已经获得访问,以及数据是否可能被带走。涉及数据窃取的勒索,与单纯业务中断在通知和法律义务上可能不同。
在不把受保护副本接入受损环境的情况下确认备份状态,确定最后一个可信恢复点、系统依赖关系,以及安全维持运营所需的最小服务。内部沟通只使用已经验证的事实。在没有证据前,不承诺恢复时间,也不要断言“没有数据泄露”。
使用干净系统、可信凭据和明确优先顺序恢复。身份与管理层控制其他系统,应谨慎恢复。重新联网前修补或移除入侵路径,由业务负责人验证数据和应用行为,并加强对重复访问的监控。
是否支付赎金涉及法律、财务、运营和伦理,不是纯技术决定。付款不能保证解密、删除被盗数据或避免再次被攻击。任何谈判前应咨询法律顾问、保险机构和适当执法部门,并检查制裁风险。
Canlus 可检查现有响应计划,或组织聚焦的准备度会议。免费初步咨询可以先找出最重要的准备缺口,不用恐惧式营销推动不必要的项目。
PIPEDA is Canada’s federal private-sector privacy law governing how covered organizations collect, use and disclose personal information in commercial activities. Provincial laws may apply instead of, or alongside, federal requirements in particular circumstances. This introduction is operational guidance, not legal advice; confirm the obligations that apply to your organization with qualified counsel.
Privacy is not only a policy on a website. Someone must be accountable for the organization’s privacy practices, understand where personal information is held and coordinate requests or incidents. A small business does not need a large privacy office, but it does need a named owner, documented responsibilities and a path for employees to raise questions.
Before collecting personal information, identify why it is needed and whether a reasonable person would consider that purpose appropriate. Tell the individual in understandable language. Avoid collecting information “just in case.” Extra data increases breach impact, access-request effort and retention obligations without necessarily creating value.
Consent must be meaningful for the context. The form of consent can depend on sensitivity and reasonable expectations. Do not hide important uses in a long general statement. If the purpose changes materially, reassess whether new consent or another lawful basis is required.
Use information for the identified purpose and disclose it only as permitted. Vendors that process information should be selected and governed with care; outsourcing a service does not outsource accountability. Contracts should address safeguards, access, incidents, deletion and any cross-border processing relevant to the service.
Define retention periods. Information should not remain forever because storage is inexpensive. Keep it long enough for legitimate operational, contractual or legal needs, then dispose of it securely. Apply the rule to email, shared drives, SaaS tools and backups—not only the primary database.
Safeguards should reflect the sensitivity, amount, format and distribution of the information. Practical controls often include MFA, role-based access, secure sharing, endpoint management, encryption, tested backups, logging, employee awareness and timely offboarding. Protect administrator accounts more strongly because they can bypass other controls.
Individuals may request access to personal information and ask for corrections, subject to applicable limits. The business needs a repeatable way to verify identity, search relevant systems, review information, respond within required timelines and record the outcome. An incomplete system inventory makes these requests difficult.
Organizations subject to PIPEDA must assess breaches of security safeguards and follow reporting, notification and record-keeping requirements where applicable, including the “real risk of significant harm” threshold. A response plan should identify who assesses harm, who obtains legal advice, how affected records and people are identified and how decisions are documented.
Canlus can help assess technical and operational privacy readiness and organize remediation evidence. A free initial consultation can clarify whether your first need is an inventory, a safeguards review or a broader compliance-readiness assessment.
PIPEDA 是加拿大联邦私营部门隐私法,规范适用组织在商业活动中如何收集、使用和披露个人信息。在某些情况下,省级法律可能取代或与联邦要求同时适用。本文提供运营层面的入门说明,不构成法律意见;企业应与合格法律顾问确认自身适用义务。
隐私不只是网站上的一份政策。企业必须有人对隐私实践负责,了解个人信息存放在哪里,并协调访问请求或事件。小企业不需要庞大隐私部门,但需要明确负责人、书面职责,以及员工提出问题的路径。
收集个人信息前,先明确为什么需要,以及合理的人是否会认为目的适当,并用容易理解的语言告知个人。不要为了“以后可能用到”而过度收集。额外数据会增加泄露影响、访问请求工作量和保留责任,却未必创造价值。
同意必须在具体场景中具有真实意义,形式会随信息敏感度和合理预期变化。重要用途不应隐藏在冗长通用声明中。如果目的发生重大变化,应重新判断是否需要新的同意或其他合法依据。
信息只能用于已经说明的目的,并在允许范围内披露。选择和管理处理个人信息的供应商时要谨慎;外包服务不等于外包问责。合同应明确安全措施、访问、事件、删除,以及与服务相关的跨境处理。
建立保留期限。不能因为存储便宜就永久保存。信息应在合法运营、合同或法律需要期间保留,之后安全销毁。规则应覆盖邮箱、共享盘、SaaS 工具和备份,而不只是主数据库。
保护措施应考虑信息的敏感度、数量、格式和分布。常见实用控制包括 MFA、基于角色的访问、安全共享、终端管理、加密、已测试备份、日志、员工意识和及时离职处理。管理员账号能够绕过其他控制,应采用更严格保护。
个人可以在适用限制下请求访问并更正自己的信息。企业需要一套可重复流程来验证身份、搜索相关系统、审查信息、在要求时间内回应并记录结果。如果没有完整系统清单,这类请求会很困难。
受 PIPEDA 约束的组织必须评估安全保护措施泄露,并在适用时遵守报告、通知和记录要求,包括“造成重大伤害的真实风险”门槛。响应计划应明确谁评估伤害、谁取得法律意见、如何识别受影响记录和个人,以及如何记录决策。
Canlus 可协助评估技术和运营层面的隐私准备度,并整理修复证据。免费初步咨询可以帮助判断第一步是数据盘点、安全措施检查,还是更完整的合规就绪评估。
What you receive, what is included, how the process works and how pricing is structured—the buyer questions worth answering up front.
A plain-language conversation about the problem, what may be causing it and the most sensible next step. If Canlus is a fit, we explain what a scoped engagement could look like; if not, we will say so.
Before work begins, you receive a written scope that lists the outcome, activities, deliverables, timeline, responsibilities and assumptions. Depending on the project, deliverables may include findings, a prioritized plan, implementation, documentation and a review session.
We start with a free consultation, assess only what is relevant, agree on scope and cost, complete the work with regular updates, then review the results and next actions with you. You always know what stage the work is in.
Defined projects are normally quoted for an agreed scope or professional time. Ongoing advisory and managed support use a predictable monthly fee. We do not publish one-size-fits-all prices because the right scope depends on your environment; you approve the written cost before work begins.
Because prevention is the service. A fixed monthly fee keeps our incentive aligned with yours: maintain the basics, follow up on risks and reduce incidents instead of earning more when something fails.
That depends on urgency, access and scope. A focused review may take a few business days, while implementation can take several weeks. The proposal sets a realistic start window, milestones and any decisions needed from your team.
We can sign an NDA before sensitive information is shared. The engagement agreement also defines access, confidentiality and data-handling expectations, and we request only the access needed for the work.
Yes. We are based in Calgary, provide on-site support in the region and work remotely across Canada. Consultations and working sessions are available in English or Chinese; formal technical reports are normally delivered in English with Chinese review available.
We are a strong fit when you want senior, practical help with a clear business outcome—not a large team or a product-first sales pitch. Start with the free consultation and we will recommend a focused project, monthly support or another path.
Share your name, contact details and what is weighing on your mind. We’ll review the situation and outline practical options—no pressure and no jargon.
We reply within 24 hours.