Business cybersecurity

Cybersecurity services in Calgary, starting with the controls that stop most attacks.

Most businesses that get breached were not singled out by anyone clever. They had an email account without multi-factor authentication, a firewall nobody had patched, or a backup that had never been restored. CoreData's cyber security work for Calgary businesses starts there: close the common entry points, prove recovery works, then keep improving.

What it covers

Cybersecurity services that close the doors attackers actually use.

Each service below maps to a way businesses really get breached. None of it needs a security operations centre. All of it needs someone checking that it stays in place.

01

Multi-factor authentication and access

MFA on email, VPN, and remote access, with no shared accounts and no exceptions for executives. Access for departed staff and vendors ends the day it should, not the next time someone notices.

02

Managed endpoint protection

Modern endpoint protection on every laptop and server, monitored centrally, so an alert reaches a person instead of a console nobody opens.

03

Email security

Filtering against phishing and fake invoices, plus monitoring for the forwarding rules attackers set up in a mailbox before a payment-redirection fraud.

04

Patching and vulnerability management

Operating systems, browsers, firewalls, and VPN appliances patched on a schedule, with nothing left running past its end-of-support date.

05

Firewall and network security

Firewall policy, segmentation, and remote access rules, handled together with our network support team so one compromised laptop cannot reach everything.

06

Security assessments

External and internal exposure reviewed, findings written down, and a remediation plan ranked by consequence rather than by product margin.

What actually happens

How Calgary businesses actually get compromised.

Almost none of it looks like the movies. These are the routes that account for most incidents we are called about, and each one has a boring, affordable control that blocks it.

A convincing email

Phishing remains the most common entry point: a fake login page, an invoice that looks routine, a message that appears to come from a colleague. Multi-factor authentication and email filtering stop the overwhelming majority.

Payment redirection

An attacker sits quietly in a mailbox, learns your billing cycle, then emails a client new banking details. Businesses lose real money to this without any malware involved. Mailbox rule monitoring and out-of-band payment verification catch it.

An unpatched edge device

Firewalls, VPN appliances, and remote access tools are scanned constantly for known vulnerabilities. Keeping edge firmware current is unglamorous and closes a door that gets tried every day.

Reused or leaked credentials

A password reused from a breached personal service works on a business account with no MFA. Enforced MFA plus disabled accounts for departed staff removes this entirely.

Ransomware through a supplier

Compromise arrives through a vendor's remote-access tooling rather than your perimeter. Segmentation and least-privilege vendor access limit how far it can travel.

Backups that were never tested

Not an entry point but the reason incidents become disasters. Attackers target backups first, which is why immutable copies and tested restores matter more than backup software brand.

Backup and business continuity →

The bar to clear

The security baseline every Calgary business should meet.

Cyber-insurance renewals and enterprise client security reviews now ask for evidence of these specific controls. If any line below is uncertain, that is the gap to close first, and closing it is usually cheaper than the questionnaire suggests.

  • Multi-factor authentication everywhere, especially email, VPN, and remote access, with no shared accounts and no exceptions for executives
  • Managed endpoint protection on every machine, monitored centrally rather than installed and forgotten
  • Patching on a schedule for operating systems, browsers, and edge devices, with nothing running past its end-of-support date
  • Backups with an immutable or offline copy, so an attacker with domain access cannot delete your ability to recover
  • A tested restore, done at least annually, with the recovery time written down and proven rather than estimated
  • Documented onboarding and offboarding, so access ends the day employment does
  • Least-privilege access, including for vendors, so one compromised account does not reach everything
  • An incident plan people can actually follow: who is called, in what order, and who can authorize decisions at 2am

Paperwork that has teeth

Cyber insurance and client security questionnaires.

Two things changed in the last few years. Cyber-insurance underwriters stopped accepting checkbox answers and now ask for evidence of MFA, endpoint protection, patch currency, and tested backup, sometimes with a technical review attached. And enterprise clients increasingly send their own security questionnaire before signing, which can stall a deal for weeks if nobody can answer it.

Both are far easier when documentation has been maintained from the start of the engagement rather than assembled in a panic. CoreData supports clients through these reviews: mapping the questions to what is actually deployed, closing the gaps that matter, and producing the evidence in the format the reviewer expects. It is also worth saying plainly that misrepresenting controls on an insurance application can void the policy at the exact moment you need it, so the honest answer, plus a remediation plan, beats the optimistic one.

Security analyst reviewing monitoring alerts for a Calgary business

Where it starts

How a cybersecurity engagement runs.

Whether the environment was set up by us, by a previous provider, or by whoever was handy at the time, the order of work is the same.

  1. Assess

    Review identity, endpoints, patching, email, the network perimeter, and backup against the baseline above, and write down what is actually deployed.

  2. Prioritize

    Rank the gaps by consequence. Missing MFA on email and an untested backup come before anything that needs a new product.

  3. Close

    Fix the common entry points first, scheduled around your operations, with every change documented.

  4. Prove

    Run a test restore, so recovery is demonstrated rather than assumed. That half of the work is covered under backup and business continuity.

  5. Operate

    Keep the controls current under managed IT, or hand them back to your team with the documentation to run them.

Who this is for

Security scaled to the business, not to the fear.

CoreData works with Calgary and Alberta organizations where downtime has operational consequences: energy operators with field and well-site systems, industrial firms where plant and office networks meet, healthcare providers with privacy obligations, and professional services firms holding client data they are contractually responsible for.

The approach is deliberately unfashionable: close the common entry points first, make recovery genuinely work, then improve. Most Calgary businesses do not need a security operations centre. They need MFA fully deployed, patching that actually happens, a backup someone has restored from, and a plan that names people. That foundation is where nearly all of the real risk reduction lives, and it is what our managed IT service maintains day to day rather than treating security as an annual project.

Common questions

How much does cybersecurity cost for a Calgary business?

The foundational controls, MFA, managed endpoint protection, patching, and monitored backup, are usually part of a managed IT agreement priced per user and device. Assessments and remediation projects are quoted separately as fixed scopes once we know what is actually deployed.

Do we need a SOC or 24/7 threat hunting?

Most Calgary small and mid-sized businesses do not. The honest answer is that MFA, patching, managed endpoint protection, and tested backups eliminate far more real risk per dollar. We will tell you when you have genuinely outgrown that baseline.

Can you help with a cyber-insurance application or client questionnaire?

Yes, and it is a common reason clients call. We map the questions to what is actually deployed, close the gaps that matter, and produce the evidence in the format the reviewer expects.

What does a security assessment involve?

A review of external and internal exposure covering identity, endpoints, patching, email, the network perimeter, and backup, written up as a prioritized remediation plan with the highest-value controls first.

Is cybersecurity included in managed IT?

The foundation is. Assurance+ managed IT includes 24/7 monitoring, managed endpoint protection, patch management, and backup. Assessments, remediation projects, and questionnaire support are scoped separately.

Managed IT services →

Can this be co-managed with our IT person?

Yes. Endpoint monitoring and patching are often the first layers a business hands over, while its own IT person keeps projects and day-to-day requests.

Co-managed IT in Calgary →

Are you tied to one security vendor?

No. CoreData is independent, so tools are chosen to fit the requirement rather than a resale agreement, and the reasoning behind each recommendation is written down for you.

Talk with our team

Which of your accounts still work without MFA?

If nobody can answer that quickly, a security assessment is the place to start.

Request A Security Assessment