Endpoint & network security
Use modern endpoint security, network security, managed configuration, monitoring, and response practices to protect user devices, servers, and the network they run on.
Cybersecurity and continuity
CoreData is a Calgary cybersecurity company combining cybersecurity consulting, network security, preventative protection, recoverable data, tested procedures, and practical guidance so one incident does not become a business-ending event.
Layered protection
CoreData helps organizations reduce preventable exposure while ensuring that important systems and information can be recovered when something still goes wrong.
Use modern endpoint security, network security, managed configuration, monitoring, and response practices to protect user devices, servers, and the network they run on.
Design off-site and on-premise backup around business priorities, useful retention periods, and recovery requirements.
Document recovery procedures, identify dependencies, and conduct periodic testing before a real recovery event.
Assess external and internal exposure, document findings, and turn technical risk into a prioritized remediation plan through hands-on cybersecurity consulting.
Watch critical infrastructure and services for availability, unexpected change, and conditions requiring attention.
Strengthen the highest-value controls first and continue improving without overwhelming the organization.
Business continuity
A backup is only one part of continuity. CoreData helps identify critical services, recovery order, people, credentials, dependencies, and the decisions that need to be made during an outage.

What actually happens
Almost none of it looks like the movies. These are the routes that account for most incidents we are called about, and each one has a boring, affordable control that blocks it.
Phishing remains the most common entry point: a fake login page, an invoice that looks routine, a message that appears to come from a colleague. Multi-factor authentication and email filtering stop the overwhelming majority.
An attacker sits quietly in a mailbox, learns your billing cycle, then emails a client new banking details. Businesses lose real money to this without any malware involved. Mailbox rule monitoring and out-of-band payment verification catch it.
Firewalls, VPN appliances, and remote access tools are scanned constantly for known vulnerabilities. Keeping edge firmware current is unglamorous and closes a door that gets tried every day.
A password reused from a breached personal service works on a business account with no MFA. Enforced MFA plus disabled accounts for departed staff removes this entirely.
Compromise arrives through a vendor's remote-access tooling rather than your perimeter. Segmentation and least-privilege vendor access limit how far it can travel.
Not an entry point but the reason incidents become disasters. Attackers target backups first, which is why immutable copies and tested restores matter more than backup software brand.
The bar to clear
Cyber-insurance renewals and enterprise client security reviews now ask for evidence of these specific controls. If any line below is uncertain, that is the gap to close first, and closing it is usually cheaper than the questionnaire suggests.
Backup as a service
Backup as a service means the backup is designed, monitored, and verified by someone whose job it is, instead of being software your team installed once and now assumes is working. The distinction only becomes visible on the day you need a restore.
The starting question is not how much data you have but how long the business can be without each system, and how much recent work it can afford to lose. Those two answers, recovery time and recovery point objectives, drive the design and the cost.
Local copies for speed, off-site copies for site loss, and an immutable or air-gapped copy so ransomware with administrator access still cannot delete your way back. CoreData works with Datto, Veeam, and AhSay depending on whether the workload is physical, virtual, or cloud.
Failed and partial backups generate tickets automatically. The most common backup failure we inherit is not a missing product, it is a job that has been quietly erroring for months with nobody watching the report.
Microsoft protects its infrastructure, not your data from your own users. Deleted mail, purged SharePoint files, and departed-staff mailboxes are your responsibility, and retention defaults are shorter than most businesses assume.
A backup job reporting success is not evidence that recovery works. Periodic test restores prove the data is usable and reveal the dependencies that turn a two-hour recovery into a two-day one.
What is backed up, how often, where copies live, who can authorize a restore, and how long recovery takes. Written down, so recovery does not depend on one person being reachable.
When something happens
Most organizations discover during an incident that the plan lived in one person's head. The sequence below is what a documented response looks like, and it is written before anything goes wrong, not during.
Isolate affected machines and accounts, preserve evidence rather than wiping it, and stop the spread before diagnosing the cause.
Establish what was reached, what was taken, and whether personal information is involved, since that determines your legal obligations.
Insurer, legal counsel, and where privacy legislation requires it, affected individuals and regulators. Timelines here are legislated, not optional.
Restore from clean, verified backups in the order the business actually needs services back, rather than the order they happen to restore fastest.
Close the specific gap that was used, and revisit the controls that would have caught it earlier. Every incident should make the next one less likely.
Paperwork that has teeth
Two things changed in the last few years. Cyber-insurance underwriters stopped accepting checkbox answers and now ask for evidence of MFA, endpoint protection, patch currency, and tested backup, sometimes with a technical review attached. And enterprise clients increasingly send their own security questionnaire before signing, which can stall a deal for weeks if nobody can answer it.
Both are far easier when documentation has been maintained from the start of the engagement rather than assembled in a panic. CoreData supports clients through these reviews: mapping the questions to what is actually deployed, closing the gaps that matter, and producing the evidence in the format the reviewer expects. It is also worth saying plainly that misrepresenting controls on an insurance application can void the policy at the exact moment you need it, so the honest answer, plus a remediation plan, beats the optimistic one.
Who this is for
CoreData works with Calgary and Alberta organizations where downtime has operational consequences: energy operators with field and well-site systems, industrial firms where plant and office networks meet, healthcare providers with privacy obligations, and professional services firms holding client data they are contractually responsible for.
The approach is deliberately unfashionable: close the common entry points first, make recovery genuinely work, then improve. Most Alberta businesses do not need a security operations centre. They need MFA fully deployed, patching that actually happens, a backup someone has restored from, and a plan that names people. That foundation is where nearly all of the real risk reduction lives, and it is what our managed IT service maintains day to day rather than treating security as an annual project.
Common questions
A backup protects your data. Business continuity is the full plan around it: recovery objectives, who is responsible, escalation paths, and tested procedures so critical services come back online in the right order during an outage.
Both. CoreData documents recovery procedures and dependencies, then runs periodic recovery exercises so the plan is proven before it's needed for real.
Assessing external and internal exposure, documenting findings, and turning technical risk into a prioritized remediation plan, strongest controls first.
No. Most engagements start proactively, reducing preventable exposure and building tested recovery plans before an incident happens.
The foundational controls, MFA, managed endpoint protection, patching, and monitored backup, are usually part of a managed IT agreement priced per user and device. Assessments and remediation projects are quoted separately as fixed scopes. Call (403) 450-3438.
Most Alberta small and mid-sized businesses do not. The honest answer is that MFA, patching, managed endpoint protection, and tested backups eliminate far more real risk per dollar. We will tell you when you have genuinely outgrown that baseline.
Yes, and it is a common reason clients call. We map the questions to what is actually deployed, close the gaps that matter, and produce the evidence in the format the reviewer expects.
Contain first, then assess scope, then meet notification obligations, then recover from verified clean backups. If you are in an active incident, call (403) 450-3438 rather than reading further.
At least annually, and after any material change to systems or staff. A recovery plan that has never been executed is a document, not a plan, and the gap usually shows up in dependencies nobody mapped.
More on backup, recovery, and business continuity is coming soon to the CoreData blog.
Know where you stand
Talk with CoreData about endpoint security, backup, recovery testing, or a broader security assessment.