compliance
Charity Cybersecurity Posture Checklist
A 30-item, plain-English self-assessment for a Canadian charity with no dedicated security headcount. Identity, email, backup, vendor, governance — covered in an afternoon.
Get the PDFPlaybooks and checklists drawn from active engagement work — written for the operator running the environment, not the auditor signing off on it. Sourced from public standards — NIST, OPC, CCCS, ISED — and updated when the standard changes.
compliance
A 30-item, plain-English self-assessment for a Canadian charity with no dedicated security headcount. Identity, email, backup, vendor, governance — covered in an afternoon.
Get the PDFemail security
Step-by-step DMARC, SPF, and DKIM configuration for a Canadian SMB on Microsoft 365 or Google Workspace. The reject-policy ramp, the report-aggregator setup, and the seven recurring mistakes.
Get the PDFcompliance
The hour-by-hour Canadian-context runbook for the first 72 hours of a personal-information breach. Notification thresholds, OPC reporting template, individual-notice template, post-incident review checklist.
Get the PDFDrafts in progress: NIST CSF 2.0 implementation checklist for charities, Quebec Law 25 readiness self-assessment, and a venue-IT segmentation reference architecture.
A senior engineer can walk through your environment in 30 minutes, no charge. The conversation often reveals more than the documents.