Cybersecurity for Small Firms, Metro Vancouver — Seynox IT Solutions
What is included

Controls that survive an audit, not a checklist that survives a meeting.

Everything here produces evidence: a report, a log, a register. If a control cannot be shown to a third party, it is not finished.

From-price
From $38 per user / month, on top of Managed
How pricing works →
01
Multi-factor authentication, everywhere

Email, remote access, banking portals, practice management. Including the shared accounts everyone pretends do not exist.

02
Endpoint detection and response

Managed EDR on every workstation and server, with alerts that reach a human who is on the hook for answering them.

03
Quarterly access reviews

Who can reach what, produced as a signed document each quarter. Leavers are removed before their last day, not months after.

04
Security awareness training

Short, quarterly, and aimed at the attacks that actually hit small firms: invoice fraud, trust-account redirection, and fake partner emails.

05
Written exposure report

Plain-English findings ranked by what it would cost you, with a fixed price to close each gap. Yours whether you hire us or not.

06
Incident response runbook

Who to call, in what order, with what authority — written down before you need it, and rehearsed once a year.

How it runs

01
Exposure review

We look at identity, endpoints, email, backups, and who has access to what. Nothing intrusive, nothing disruptive.

3–5 days
02
Written report

Ranked findings, each with an owner, an effort estimate, and a fixed price to fix.

From $1,800
03
Remediation

MFA, EDR, access cleanup, and email authentication, in the order that reduces the most risk first.

Fixed fee
04
Ongoing posture

Quarterly access reviews, quarterly training, annual runbook rehearsal, and monthly reporting.

From $38/user

What you get in writing

Yours to keep
01
Exposure report

Ranked findings, priced remediation, plain English.

02
Access review

Signed quarterly record of who can reach what.

03
Incident runbook

Call order, authority, and client-notification wording.

04
Training record

Who was trained, on what, and when — for your insurer.

Where small firms actually get hurt

Invoice and trust-account fraud.

Not ransomware. Someone reads a mailbox for three weeks, then emails your client new banking details in your own writing style.

Leavers who never left.

Accounts, mailbox delegations, and VPN profiles that outlive the employment. Most firms find several on the first access review.

Insurance that assumes controls you do not have.

Cyber policies increasingly ask whether MFA is enforced. Answering optimistically is how claims get denied.

Questions about cybersecurity

Do we need this if we are only six people?

Attackers do not filter by headcount, they filter by whether money moves through your inbox. A six-person practice holding client funds is a better target than a large firm with a security team.

Is this enough for PIPA or PIPEDA?

It covers the technical and organisational safeguards those regimes expect, and produces the documentation to demonstrate them. Legal interpretation is your counsel's call, not ours.

Will MFA slow everyone down?

Configured properly, most staff authenticate once per device per fortnight. The friction people complain about is usually a sign it was set up badly.

Can we buy just the exposure report?

Yes. It is a fixed-fee engagement, the findings are yours to keep, and there is no obligation to have us fix anything.

Related

All of what we do →
Service · 01
Managed IT
Read →
Service · 02
Cloud & Microsoft 365
Read →
Industry
Legal practices
Read →
Cybersecurity in Vancouver Burnaby Surrey Coquitlam Langley Chilliwack White Rock Delta