Skip to content
Crimson Security — Practical Information Security

Find the gaps before they find you.

Canadian cybersecurity assessments and consulting — penetration testing, compliance, monitoring and incident response, delivered by CISSP- and GIAC-certified technicians.

Thorough by policy, practical by design.

01/ 03

No Limit Policy

Full coverage, with no meter running.

  • Internal and external scanning, using multiple tools
  • Every scan result verified by hand
  • Penetration tests run with full knowledge of your systems
02/ 03

No Hacker Policy

Only certified professionals work on your systems.

  • Technicians hold CISSP and GIAC credentials
  • The owner is present on assessments whenever possible
  • Client references available in similar verticals
03/ 03

Detailed Reporting

Reports that tell you what to fix first.

  • Comprehensive breach and leak reporting
  • Remediation assistance to close the gaps we find
  • Technical support Monday to Friday, 9am–5pm
assessment.report
ExecutiveIT detail

Prioritized checklist

  • Critical

    Mandate immediate deployment of Multi-Factor Authentication (MFA) across all administrative and remote-access accounts to mitigate active breach risks.

  • High

    Approve the requested capital expenditure budget to replace unsupported, end-of-life legacy servers housing sensitive data.

  • High

    Authorize mandatory company-wide phishing and security awareness training to address vulnerabilities discovered in the detailed IT audit.

  • Medium

    Review and officially sign off on the updated quarterly Disaster Recovery and Business Continuity policy.

Assess, test, monitor and respond.

Eight services covering compliance, testing, monitoring and incident response — delivered by certified technicians.

  • Assess

    Compliance Assessments & Reports

    Framework-based assessments and reports against the standards your business answers to.

    • PCI
    • ISO 27002 / GLBA / HIPAA
    • NIST 800-53
    • FERC / NERC
    • BITS / COBRA
  • Test

    Penetration Testing

    Hands-on testing of your infrastructure with full knowledge of the environment.

    • Full-knowledge penetration tests
    • Comprehensive breach and leak reporting
  • Assess

    SSAE 16 / SOC Audits

    SOC audits, delivered through our partner accounting firms.

    • SSAE 16 / SOC audits
    • Partner accounting firms
  • Test

    Vulnerability Scanning

    Scanning from the inside and the outside, with results checked by a person.

    • Internal and external scanning
    • Multi-tool coverage
    • Manual verification
  • Monitor

    Vendor Security Management

    Know how secure your vendors and partners really are — and keep them accountable.

    • Evaluate and rate vendors
    • Manage vendor and partner remediation
  • Respond

    Incident Response Services

    Be ready before an incident, and supported through it.

    • IR planning
    • Training and testing
    • Containment and recovery support
  • Respond

    Forensic Analysis Services

    Get answers when something looks wrong.

    • Comprehensive analysis on suspected incidents
  • Monitor

    Security Monitoring / SIEM

    Monitoring you can stand up, staff and trust to escalate.

    • SIEM implementation
    • Staff training
    • Alert escalation
    • Log, IDS / IPS and antivirus monitoring

From first assessment to incident response.

Pick a discipline to see how we approach it.

Know where you stand against the standards that matter.

We assess your controls against the frameworks you answer to and deliver reports written for both executives and IT. Remote pre-audit preparation gets you ready before the formal assessment begins, and SOC audits are delivered through our partner accounting firms.

  • Remote pre-audit preparation
  • Executive and IT-level reports
  • Remediation assistance
Compliance Assessments & ReportsPCI · ISO 27002 / GLBA / HIPAA · NIST 800-53 · FERC / NERC · BITS / COBRA
SSAE 16 / SOC AuditsSSAE 16 / SOC audits · Partner accounting firms
Customers satisfied
10,000+
Years of experience
18+
Availability & support
24/7
ROI delivered for clients
$100M+

Nine commitments behind every engagement.

  • Remote Pre-Audit Preparation

    Prepare for your audit remotely, so the formal assessment runs smoothly.

  • Remediation Assistance

    Help closing the gaps we find — not just a list of them.

  • No Limit Policy

    Full-coverage assessment with no device or scan limits.

  • Detailed Reporting

    Executive-level and IT-level reports with prioritized checklists.

  • Flexibility

    Off-hours and weekend assessments at no extra cost.

  • No Hacker Policy

    CISSP- and GIAC-certified technicians only.

  • Ongoing Technical Support

    Technical support Monday to Friday, 9am⁠–⁠5pm.

  • Owner Accessibility

    The owner is present on assessments whenever possible.

  • Real World References

    Client references in verticals similar to yours.

Let's talk about your security.

Tell us about your environment and what you need assessed. We'll follow up by email.

Call us now
1-800-123-4567
Address
325 Front St. W., 4th Floor
Toronto, Ontario, Canada M5V 2Y1
Locations
  • Virginia, USA
  • Reykjavik, Iceland
  • Frankfurt, Germany
  • Cebu, Philippines

We use your details only to respond to your enquiry. See our Privacy Policy.