A five-tier practice for the Canadian nonprofit sector.
Tight budgets. Donor-data sensitivity. Board oversight. PIPEDA, Quebec Law 25, and PHIPA. The work is packaged into five board-defensible tiers — from a one-week posture snapshot to embedded leadership.
THE FIT
-
Tiers right-sized to charity budgets and risk profiles.
-
Board-ready output. Plain-language reports trustees and funders can act on, delivered as the Sentinel Brief™.
-
Compliance fluency. PIPEDA, Quebec Law 25, PHIPA, CyberSecure Canada.
-
Donor-data first. Privacy sits at the centre of every recommendation.
From posture snapshot to continuous guardian.
-
TIER 0: Posture Snapshot
A one-week exposure assessment with board-ready output and a prioritized remediation roadmap.
Fixed-fee · one week · Identity & access review · endpoint baseline · email security posture · donor-data flow map · board-ready summary
-
TIER 1: Stabilisation
The highest-risk findings from the snapshot, closed first.
Project · MFA rollout · endpoint hardening · identity cleanup · phishing-resistant authentication · 30-day stabilisation report
-
TIER 2: Essentials
Foundational managed controls with quarterly reporting.
Monthly retainer · EDR & endpoint management · email & phishing controls · quarterly posture reviews · annual tabletop exercise · direct senior contact
-
TIER 3: Secure
A mature programme with continuous monitoring and full policy infrastructure.
Monthly retainer · Sentinel Watch™ monitoring & alerting · Exposure Intelligence (vulnerability management) · policy library & review · vendor risk reviews · compliance documentation
-
TIER 4: Guardian
Continuous protection with embedded leadership and active board engagement.
Monthly retainer · Embedded vCISO via Sentinel Advisory™ · 24/7 monitoring & response · quarterly board reporting · annual Exposure Validation (penetration testing) · insurance & audit liaison
Compliance, written in.
- PIPEDA
- Quebec Law 25
- PHIPA
- CyberSecure Canada