▸ Service · GLOBAL

Cybersecurity & ISO/IEC 27001 readiness

We find and close security gaps in the websites, servers and office IT of small and mid-sized businesses: audit, penetration test, post-breach clean-up, hardening, and preparation for ISO/IEC 27001 and CyberSecure Canada. You get a plain-language report, the fixes and a re-test.

PricingFixed quote once the scope is agreed
▸ Service
Sections
5
Pricing
Fixed quote once the scope is agreed
Tags
Security audit · Pentest · ISO/IEC 27001 · CyberSecure Canada

What’s included in cybersecurity & ISO/IEC 27001 readiness

  • Audit: a written report — what we found, how serious it is, what to fix today, this month or later — plus a short plain-language version for the owner
  • Pentest: a report with reproducible findings and evidence, a remediation plan, and a re-test of the fixes within the same scope at no extra charge
  • After a breach: the site or server is clean, the way in is closed, passwords and keys are rotated, the backup is proven by a restore; a report on how they got in, what was affected and what was done
  • Hardening: a completed checklist of measures, a tested restore from backup, MFA switched on, alerts configured
  • ISO/IEC 27001 and CyberSecure Canada: a document set (policies, risk register, SoA), an internal audit, and a list of what remains before the certification audit

Standard process

01
Scope the task
A short exchange on what we check and the result you need
call or form
02
Authorisation and scope
Written authorisation (scope letter): targets, dates, contacts, what is off-limits. Testing starts only once it is signed
before any test
03
Test and report
A plain-language report for the owner, with the technical detail as an appendix. A person checks every finding
after signature
04
Remediation
We fix it ourselves or together with your contractor
per the report
05
Re-test
We confirm that what we found is closed
after the fixes

We do the work and hand you the result. The team relies on its own experience and strong tooling to find problems faster; every finding is checked by a person before it reaches your report, and we fix what we find. We run our own information security management system built on ISO/IEC 27001:2022. INNOVA CONSULT LTD has been approved for Anthropic's Cyber Verification Program (CVP), which lets verified organizations use Claude models for defensive cybersecurity work.

Related practice areas