Cybersecurity consulting for Canadian startups.
I help Canadian startups and SMBs get secure, get compliant, and prove it to customers and partners. I've built a 76-control SOC 2 program from scratch, run 20+ client engagements, and published a CVSS 9.1 CVE. Pick the engagement that fits where you are.
76control SOC 2 Type II program built at Humera
20+client security & compliance engagements
9.1CVSS, CVE-2024-45163, Mirai kill switch
5,000+users on a live platform I secured
Four ways to work with me.
SOC 2 Readiness Consulting
Zero to audit-ready SOC 2 Type I and Type II for Canadian startups, gap analysis through attestation, tooling included.
Learn more →
Penetration Testing
Manual pentesting for web apps, APIs, and cloud. Reports and attestation letters your customers' security teams will accept.
Learn more →
ISO 27001 Readiness
A right-sized ISMS that's certification-ready, with SOC 2 and ISO 42001 mapped once so you collect evidence a single time.
Learn more →
Fractional CISO / vCISO
Senior security leadership a few days a month, strategy, compliance ownership, questionnaires, and incident readiness.
Learn more →
Local cybersecurity consulting.
Canada-based and remote-first, with on-site time when it helps. Popular locations:
Not sure which one you need?
Tell me what's driving the timeline, a stalled deal, an upcoming audit, or a customer asking hard security questions, and I'll point you to the right starting place.