Cybersecurity Assurance & Governance

Independent assurance and governance across Information Technology (IT) and Operational Technology (OT) environments, from risk assessment to board-level reporting.

This practice conducts independent cybersecurity risk assessments and governance reviews across Information Technology (IT) and Operational Technology (OT) environments, identifying exposed assets, control gaps, and governance weaknesses, and translating findings into clear, decision-ready reporting for boards, executives, and audit committees.

Serving organizations across Canada and Latin America, engagements combine technical depth with governance fluency, connecting the full risk picture to the people accountable for governing it.

Available on-site, Hybrid, Remote  |  Canada & Latin America  |  English, Spanish, French

What this covers

Cybersecurity Risk & Governance Assessment

Independent assessment of cybersecurity risk and governance across SaaS, IaaS, PaaS, on-premises, network, application, vendor, and organizational environments. Identifies exposed assets, control gaps, governance weaknesses, and unclear accountabilities. Findings are prioritized by business impact and delivered as clear, decision-ready reporting for management, executive, and board audiences.

NIST CSF 2.0, ISO/IEC 27001, NIST SP 800-53, MITRE ATT&CK, CIS Benchmarks

OT & ICS Cybersecurity

Dedicated assessment of operational technology environments, network segmentation, remote access, asset visibility, and patch management, integrated with the enterprise IT risk picture for a single coherent cybersecurity profile. Findings are structured for operational and executive reporting.

IEC 62443, NIST SP 800-82, INL CCE, NERC CIP

Regulatory Alignment & Compliance

Gap assessment and implementation support for organizations navigating cybersecurity regulatory requirements, including ISO/IEC 27001 certification, OSFI B-13, and IEC 62443. Covers gap analysis, action plan development, and implementation support across Canadian and Latin American regulatory contexts.

ISO/IEC 27001, OSFI B-13, IEC 62443

Vendor & Third-Party Cybersecurity Risk

Assessment of cybersecurity risk introduced through technology vendors, cloud service providers, and third-party operational contractors, including SOC report review, ISO certification validation, SLA and contract assessment, and vendor security posture evaluation.

Who this is for

Boards & audit committees

Independent cybersecurity posture reviews reported in terms that support governance decisions, not just technical ones.

CFOs, CISOs & risk officers

Senior advisory support for assessments, governance programs, and regulatory alignment, without adding permanent headcount.

Industrial & extractive operations

Mining, energy, and utilities where IT and OT intersect and cybersecurity must be part of the full operational risk picture.

Organizations across Canada & Latin America

Navigating OSFI B-13, ISO/IEC 27001, IEC 62443, and related frameworks across multiple jurisdictions.

Frameworks applied

NIST CSF 2.0 IEC 62443 NIST SP 800-82 INL CCE ISO/IEC 27001 NIST SP 800-53 OSFI B-13 MITRE ATT&CK for ICS CIS Benchmarks NERC CIP