vCISO Services
Fractional executive security leadership: strategy, board reporting and program direction, without a full-time hire.
Risk, translated. · Moncton, NB · Serving Canada
Senior-led cybersecurity for small and mid-sized businesses. Most businesses your size don’t need a full-time security team, but they do need to understand their risk. We identify your real-world exposure, respond to customer and cyber-insurance security questionnaires, and test your defences using the same techniques an attacker would.
Built for businesses of 10 to 500 people, with or without an IT team.
Free 45-minute working session with a senior consultant. No obligation.
Senior-led, end to end. Every engagement is delivered by a senior consultant, never handed to a junior. Behind it: 7+ years securing energy, municipal, and retail-payment environments, with hands-on depth in security architecture & design, penetration testing (web, network, mobile), and application security testing (SAST & DAST).
In their words
I put off having our website looked at for two years, assuming a cybersecurity firm meant a hefty retainer and a three-month project. Wrong on both counts. Avertix gave us a fixed price up front, scoped it in one 45-minute call, and hardened our site without disrupting a thing. No retainer, no upsell. If you’re a small business owner avoiding this because you assume you can’t afford it: make the call. It cost less and took less time than I’d budgeted.
The best IT and OT security service in Atlantic Canada. Avertix is a true one-stop partner covering critical infrastructure, IT networks, and compliance across both OT and IT. What sets them apart isn’t only the technical depth. It’s the service: responsive, proactive, and genuinely invested in solving problems before they become issues. We’ve worked with several providers, but Avertix stands out. I’d recommend them without hesitation.
What we do
Most firms do governance or offensive testing. We do both, plus the AI assurance work almost nobody in Atlantic Canada is equipped for yet, scoped to what a business your size actually needs, at a fixed price agreed before any work starts.
Strategy, governance and assurance, including AI.
Fractional executive security leadership: strategy, board reporting and program direction, without a full-time hire.
Governance, risk and compliance programs that satisfy the auditor and genuinely reduce exposure.
Stand up an ISO/IEC 42001 management system and NIST AI RMF controls, then evidence them for audit and the board.
AI risk and impact assessments, responsible-AI policy, and a defensible path through the EU AI Act.
Hands-on assessments and engineering.
Manual, expert-led offensive testing across web, network, cloud, mobile and API attack surfaces.
IEC 62443-aligned assessments for the industrial systems that cannot go down. Safety and uptime come first.
Zero-trust reference architectures and pragmatic roadmaps that scale with cloud and modern work.
Certified media destruction to NIST 800-88, with full chain-of-custody documentation.
Ongoing support
Most small and mid-sized businesses do not need a full-time security hire. They need someone to ask. Keep Avertix on a monthly retainer and you get a direct line for the things that come up between projects.
That is what the first call is for. Bring the audit finding, the security questionnaire you cannot answer, or the AI deployment nobody has governed yet.
The promise
01 · The advantage
At most firms a partner sells the engagement and a graduate delivers it. Here, the person who scopes your work is the person who does it. Every finding is written by someone who has sat on your side of the table.
02 · The wedge
Your organization is already deploying AI. Your policy, your risk register and your regulator are not caught up. We close that gap with a defensible program rather than a statement of intent.
AI system inventories and model cards, risk and impact assessments, human-oversight controls, and independent assurance readiness, all mapped onto the ISO 27001 or SOC 2 program you already run.
03 · Method & materials
Four phases, always in the same order, so you always know where you are and what comes next. The craft is in the precision, not the theatrics.
We map your environment, assets and business context before touching a single control.
We quantify real exposure through hands-on testing and framework-aligned analysis.
We architect resilient, pragmatic solutions with a prioritized remediation roadmap.
We implement, validate and continuously strengthen the controls that matter.
04 · Who we help
You do not have to know what is wrong before you call. Most of these start as one awkward question nobody in the building can answer.
You have an IT person, a managed provider, or neither, and security keeps falling between them. We take ownership of it without you hiring for it.
A security questionnaire, a SOC 2 request, an ISO 27001 clause in a contract. We give you the shortest honest path to the answer they will accept.
Cyber policies now ask exactly which controls you run, and a wrong answer costs you the claim. We get you to a defensible yes, in writing.
New staff, new SaaS, old access nobody revoked, and no map of any of it. We find what you actually have before someone else does.
Testing your defences the way an attacker would is the only honest way to find out. Then we price the risk in operational terms, not scanner output.
The problems change, the method does not. Tell us what is keeping you up and we will scope it on the call.
Industries we know: professional services · financial services · healthcare · energy & utilities · manufacturing · retail & payments · municipal & government · engineering & construction
05 · Credentials
Before you call
Usually yes, and for less than people expect. We scope the work on a single call and agree on a fixed price before anything starts, so there is no open-ended bill. If an ongoing retainer is the better fit, you are charged for the time you actually use rather than a flat managed-service fee. The first consultation is free, and we will tell you if you do not need us yet.
That is the normal case for businesses this size, and it is who this practice is built for. You do not need to speak the language or know what is wrong before you call. We work out what you have, explain it in plain terms, and tell you what to do first. Where you have an IT provider already, we work alongside them rather than replacing them.
Forty-five minutes with a senior consultant, not a salesperson. Bring the audit finding, the questionnaire you cannot answer, the insurance form, or just the thing that is worrying you. You leave with a scoped path forward and a clear idea of cost, whether or not you engage us. There is no obligation and no follow-up sales sequence.
A monthly retainer keeps your line open to a senior consultant, and the work you draw on is billed as time and materials, so you pay for the hours you actually use. It is meant for the things that come up between projects: a vendor questionnaire, a suspicious email, a new system going live, an insurer asking which controls you run. We will tell you on the first call whether it is worth it for a business your size.
Yes. It is one of the most common reasons businesses call us. We work out which of the questions genuinely apply to you, help you answer them accurately, and identify the small number of gaps worth closing before you send it back. Where a customer is asking for SOC 2 or ISO 27001, we will tell you honestly whether you need the certification or just a defensible answer.
Yes. We are based in Moncton, New Brunswick, and work with clients across Canada. Assessments, testing, advisory and governance are all done remotely, and on-site visits are arranged where the work genuinely needs someone in the building, which is most common for industrial and OT environments. Service is available in English and French.
Start here
A working session with a senior consultant, not a sales call. Bring the questionnaire you cannot answer, the insurance form, the audit finding, or just the thing that is worrying you. You will leave with a scoped path forward and a clear idea of cost, whether or not you engage us.
Free consultation
Pick a time that works. 45 minutes with a senior consultant, at no cost and no obligation.
Free consultation
45 minutes with a senior consultant, at no cost. We reply within one business day. Fields marked with an asterisk are required.
A confirmation is on its way to your inbox. A senior consultant will reply within one business day. If it is urgent, call +1 (902) 932-8802.