Vanguard Ontario Group

Line 03 · Defensive security

Findings you can act on, not a posture score.

A law firm, accounting practice or clinic carries an obligation over client data that can't be handed to an IT helpdesk. The helpdesk keeps things running. This decides what risk you're carrying, what gets fixed first, and what you tell a client who asks.

Offers

Start outside, with nothing touched

Exposure Snapshot

Free

2 business days · public records only · one line of written authorization from the domain owner

  • Email spoofing protection: SPF, DKIM and DMARC as published in public DNS
  • Your public website certificate: validity, expiry, protocol versions
  • Whether your domain appears in known public credential-breach datasets
  • Services already listed for your domain in public datasets
  • One page, red / yellow / green, in plain language
What it deliberately isn't

No scanning, probing or testing of your systems. No severity scores, no fix plan, no access to any account. It tells you that something is exposed; the paid assessment tells you what to do about it, and the upgrade price is printed on the sheet so there's no bait and switch.

Leaky Roof Risk Assessment

$450 + HST

5 business days · signed authorization required first · a stop contact who can halt work in 15 minutes

  • Authorized external assessment of the hosts you name
  • Services and versions discovered, TLS configuration, email authentication
  • Known vulnerabilities mapped to what was found
  • Every finding scored with CVSS v3.1, with evidence
  • A fix plan in priority order, each item with an owner and an effort estimate
  • Written report and a walkthrough call
Guarantee

Late and it's free. Every finding carries a score, a named owner and a concrete fix — no "consider reviewing your posture" filler. And if nothing above Low severity is found, you pay half, because a clean result is worth less to you than a problem found.

Cloud / Microsoft 365 Hardening

$1,500 + HST

Scoped per environment · read-only review first, change access only for the change window

  • Identity and tenant configuration hardened against a defined checklist
  • Before-and-after evidence for every setting changed
  • A rollback note for each change
  • A written summary of what was deliberately left alone, and why
Guarantee

Nothing is changed without your written approval of that specific change. Every change has evidence and a rollback. My access is read-only except during the agreed change window, and it's revoked and confirmed in writing afterwards.

Comprehensive Environment Audit

$4,500 + HST

10 business days · authorization and named scope required

  • Identity and access, data locations, backups, external exposure, vendors, continuity
  • Every finding with a severity, an owner, an effort estimate and a fix
  • A prioritized 90-day plan, ordered by what actually reduces risk
  • Written report and a walkthrough with whoever has to act on it
Guarantee

Late and it's free. A free re-check of the fixes within 60 days is included, so you find out whether the work landed instead of hoping. Every finding is actionable by a named owner, or it doesn't go in the report.

Fractional Security Lead (vCISO)

$3,500 / month + HST

30 days notice either side · no auto-renewal trap

  • Your risk register, owned and carried forward month to month
  • A monthly decisions memo: what changed, what needs your decision, what I recommend
  • Vendor security questionnaires answered
  • Incident-readiness steps maintained, with the notification obligations and who decides
  • Every accepted risk recorded with who accepted it and when
Guarantee

The register and the memo arrive every month, or that month is free. Next-business-day first response. You end up with a defensible record of the decisions you made and when — which is what someone asks for after an incident.

The boundary

Written authorization, every time

Testing systems without permission isn't a paperwork problem, it's a legal one. This is the part of the engagement I don't flex on, and you should be wary of anyone who does.

Before anything runs

  • A signed form naming the exact domains, hosts or tenants in scope. No wildcards.
  • Confirmation you own them, or your hosting provider's own authorization attached.
  • A testing window with a start and an end.
  • A stop contact who can halt the work in fifteen minutes, by any channel.

Never, at any price

  • Exploiting a vulnerability, cracking passwords, or denial-of-service testing.
  • Phishing or social-engineering your staff.
  • Testing anything you don't own.
  • Claiming a certification, a compliance sign-off, or that anything is unhackable. Nobody can promise that, and I won't.

Access for an authenticated review is a read-only account you create in your own console, with multi-factor authentication on, used only during the window, then deleted — confirmed in writing. No password of yours is ever shared with me, and I'll decline access that's broader than the job needs.

Start

The free snapshot is the easy first step

Send your domain and one line confirming you're authorized to ask for the check. Two business days later you get the one-page sheet. Nothing is touched on your systems, and there's no obligation of any kind.

saman@vanguardontario.ca

Saman Ghabcheloo · Vanguard Apex Systems, a division of Vanguard Ontario Group · Ontario · No compliance certification, regulatory sign-off or security guarantee is offered or implied.