Resources

Field-tested guides. Free.

Playbooks and checklists drawn from active engagement work — written for the operator running the environment, not the auditor signing off on it. Sourced from public standards — NIST, OPC, CCCS, ISED — and updated when the standard changes.

3 LIVE

The guides.

  1. compliance

    Charity Cybersecurity Posture Checklist

    A 30-item, plain-English self-assessment for a Canadian charity with no dedicated security headcount. Identity, email, backup, vendor, governance — covered in an afternoon.

    • 7 pp · PDF
    Get the PDF
  2. email security

    DMARC Configuration Guide for Canadian SMBs

    Step-by-step DMARC, SPF, and DKIM configuration for a Canadian SMB on Microsoft 365 or Google Workspace. The reject-policy ramp, the report-aggregator setup, and the seven recurring mistakes.

    • 8 pp · PDF
    Get the PDF
  3. compliance

    PIPEDA Breach Response Playbook

    The hour-by-hour Canadian-context runbook for the first 72 hours of a personal-information breach. Notification thresholds, OPC reporting template, individual-notice template, post-incident review checklist.

    • 8 pp · PDF
    Get the PDF
IN PROGRESS

More on the way.

Drafts in progress: NIST CSF 2.0 implementation checklist for charities, Quebec Law 25 readiness self-assessment, and a venue-IT segmentation reference architecture.

BEYOND THE DOCUMENTS

Need help applying any of this?

A senior engineer can walk through your environment in 30 minutes, no charge. The conversation often reveals more than the documents.