Cybersecurity and continuity

Cybersecurity Calgary: protection, backup, and tested recovery.

CoreData is a Calgary cybersecurity company combining cybersecurity consulting, network security, preventative protection, recoverable data, tested procedures, and practical guidance so one incident does not become a business-ending event.

Layered protection

Security is strongest when protection and recovery are designed together.

CoreData helps organizations reduce preventable exposure while ensuring that important systems and information can be recovered when something still goes wrong.

Endpoint & network security

Use modern endpoint security, network security, managed configuration, monitoring, and response practices to protect user devices, servers, and the network they run on.

Backup and immutable storage

Design off-site and on-premise backup around business priorities, useful retention periods, and recovery requirements.

Disaster recovery

Document recovery procedures, identify dependencies, and conduct periodic testing before a real recovery event.

Cybersecurity consulting & assessment

Assess external and internal exposure, document findings, and turn technical risk into a prioritized remediation plan through hands-on cybersecurity consulting.

Monitoring and alerting

Watch critical infrastructure and services for availability, unexpected change, and conditions requiring attention.

Practical improvement

Strengthen the highest-value controls first and continue improving without overwhelming the organization.

Business continuity

Recovery has to work under pressure.

A backup is only one part of continuity. CoreData helps identify critical services, recovery order, people, credentials, dependencies, and the decisions that need to be made during an outage.

  • Recovery objectives tied to business operations
  • Documented responsibilities and escalation paths
  • Backup retention matched to actual needs
  • Periodic recovery exercises and lessons learned
IT security analyst monitoring systems for threats

What actually happens

How Calgary businesses actually get compromised.

Almost none of it looks like the movies. These are the routes that account for most incidents we are called about, and each one has a boring, affordable control that blocks it.

A convincing email

Phishing remains the most common entry point: a fake login page, an invoice that looks routine, a message that appears to come from a colleague. Multi-factor authentication and email filtering stop the overwhelming majority.

Payment redirection

An attacker sits quietly in a mailbox, learns your billing cycle, then emails a client new banking details. Businesses lose real money to this without any malware involved. Mailbox rule monitoring and out-of-band payment verification catch it.

An unpatched edge device

Firewalls, VPN appliances, and remote access tools are scanned constantly for known vulnerabilities. Keeping edge firmware current is unglamorous and closes a door that gets tried every day.

Reused or leaked credentials

A password reused from a breached personal service works on a business account with no MFA. Enforced MFA plus disabled accounts for departed staff removes this entirely.

Ransomware through a supplier

Compromise arrives through a vendor's remote-access tooling rather than your perimeter. Segmentation and least-privilege vendor access limit how far it can travel.

Backups that were never tested

Not an entry point but the reason incidents become disasters. Attackers target backups first, which is why immutable copies and tested restores matter more than backup software brand.

The bar to clear

The security baseline every Alberta business should meet.

Cyber-insurance renewals and enterprise client security reviews now ask for evidence of these specific controls. If any line below is uncertain, that is the gap to close first, and closing it is usually cheaper than the questionnaire suggests.

  • Multi-factor authentication everywhere, especially email, VPN, and remote access, with no shared accounts and no exceptions for executives
  • Managed endpoint protection on every machine, monitored centrally rather than installed and forgotten
  • Patching on a schedule for operating systems, browsers, and edge devices, with nothing running past its end-of-support date
  • Backups with an immutable or offline copy, so an attacker with domain access cannot delete your ability to recover
  • A tested restore, done at least annually, with the recovery time written down and proven rather than estimated
  • Documented onboarding and offboarding, so access ends the day employment does
  • Least-privilege access, including for vendors, so one compromised account does not reach everything
  • An incident plan people can actually follow: who is called, in what order, and who can authorize decisions at 2am

Backup as a service

Managed backup and recovery for Calgary businesses.

Backup as a service means the backup is designed, monitored, and verified by someone whose job it is, instead of being software your team installed once and now assumes is working. The distinction only becomes visible on the day you need a restore.

Designed around recovery, not storage

The starting question is not how much data you have but how long the business can be without each system, and how much recent work it can afford to lose. Those two answers, recovery time and recovery point objectives, drive the design and the cost.

On-site, off-site, and immutable

Local copies for speed, off-site copies for site loss, and an immutable or air-gapped copy so ransomware with administrator access still cannot delete your way back. CoreData works with Datto, Veeam, and AhSay depending on whether the workload is physical, virtual, or cloud.

Monitored every day

Failed and partial backups generate tickets automatically. The most common backup failure we inherit is not a missing product, it is a job that has been quietly erroring for months with nobody watching the report.

Microsoft 365 included

Microsoft protects its infrastructure, not your data from your own users. Deleted mail, purged SharePoint files, and departed-staff mailboxes are your responsibility, and retention defaults are shorter than most businesses assume.

Restores actually tested

A backup job reporting success is not evidence that recovery works. Periodic test restores prove the data is usable and reveal the dependencies that turn a two-hour recovery into a two-day one.

Documented and handed over

What is backed up, how often, where copies live, who can authorize a restore, and how long recovery takes. Written down, so recovery does not depend on one person being reachable.

When something happens

What the first 48 hours look like.

Most organizations discover during an incident that the plan lived in one person's head. The sequence below is what a documented response looks like, and it is written before anything goes wrong, not during.

  1. Contain

    Isolate affected machines and accounts, preserve evidence rather than wiping it, and stop the spread before diagnosing the cause.

  2. Assess

    Establish what was reached, what was taken, and whether personal information is involved, since that determines your legal obligations.

  3. Notify

    Insurer, legal counsel, and where privacy legislation requires it, affected individuals and regulators. Timelines here are legislated, not optional.

  4. Recover

    Restore from clean, verified backups in the order the business actually needs services back, rather than the order they happen to restore fastest.

  5. Learn

    Close the specific gap that was used, and revisit the controls that would have caught it earlier. Every incident should make the next one less likely.

Paperwork that has teeth

Cyber insurance and client security questionnaires.

Two things changed in the last few years. Cyber-insurance underwriters stopped accepting checkbox answers and now ask for evidence of MFA, endpoint protection, patch currency, and tested backup, sometimes with a technical review attached. And enterprise clients increasingly send their own security questionnaire before signing, which can stall a deal for weeks if nobody can answer it.

Both are far easier when documentation has been maintained from the start of the engagement rather than assembled in a panic. CoreData supports clients through these reviews: mapping the questions to what is actually deployed, closing the gaps that matter, and producing the evidence in the format the reviewer expects. It is also worth saying plainly that misrepresenting controls on an insurance application can void the policy at the exact moment you need it, so the honest answer, plus a remediation plan, beats the optimistic one.

Who this is for

Security scaled to the business, not to the fear.

CoreData works with Calgary and Alberta organizations where downtime has operational consequences: energy operators with field and well-site systems, industrial firms where plant and office networks meet, healthcare providers with privacy obligations, and professional services firms holding client data they are contractually responsible for.

The approach is deliberately unfashionable: close the common entry points first, make recovery genuinely work, then improve. Most Alberta businesses do not need a security operations centre. They need MFA fully deployed, patching that actually happens, a backup someone has restored from, and a plan that names people. That foundation is where nearly all of the real risk reduction lives, and it is what our managed IT service maintains day to day rather than treating security as an annual project.

Common questions

What's the difference between backup and business continuity?

A backup protects your data. Business continuity is the full plan around it: recovery objectives, who is responsible, escalation paths, and tested procedures so critical services come back online in the right order during an outage.

Do you test recovery plans, or just document them?

Both. CoreData documents recovery procedures and dependencies, then runs periodic recovery exercises so the plan is proven before it's needed for real.

What does a vulnerability assessment involve?

Assessing external and internal exposure, documenting findings, and turning technical risk into a prioritized remediation plan, strongest controls first.

Is this only for organizations that had an incident?

No. Most engagements start proactively, reducing preventable exposure and building tested recovery plans before an incident happens.

How much does cybersecurity cost for a Calgary business?

The foundational controls, MFA, managed endpoint protection, patching, and monitored backup, are usually part of a managed IT agreement priced per user and device. Assessments and remediation projects are quoted separately as fixed scopes. Call (403) 450-3438.

Do we need a SOC or 24/7 threat hunting?

Most Alberta small and mid-sized businesses do not. The honest answer is that MFA, patching, managed endpoint protection, and tested backups eliminate far more real risk per dollar. We will tell you when you have genuinely outgrown that baseline.

Can you help with a cyber-insurance application or client questionnaire?

Yes, and it is a common reason clients call. We map the questions to what is actually deployed, close the gaps that matter, and produce the evidence in the format the reviewer expects.

What happens if we are breached right now?

Contain first, then assess scope, then meet notification obligations, then recover from verified clean backups. If you are in an active incident, call (403) 450-3438 rather than reading further.

How often should disaster recovery be tested?

At least annually, and after any material change to systems or staff. A recovery plan that has never been executed is a document, not a plan, and the gap usually shows up in dependencies nobody mapped.

More on backup, recovery, and business continuity is coming soon to the CoreData blog.

Know where you stand

Start with the risks that matter to the business.

Talk with CoreData about endpoint security, backup, recovery testing, or a broader security assessment.

Start a security conversation