Multi-factor authentication and access
MFA on email, VPN, and remote access, with no shared accounts and no exceptions for executives. Access for departed staff and vendors ends the day it should, not the next time someone notices.
Business cybersecurity
Most businesses that get breached were not singled out by anyone clever. They had an email account without multi-factor authentication, a firewall nobody had patched, or a backup that had never been restored. CoreData's cyber security work for Calgary businesses starts there: close the common entry points, prove recovery works, then keep improving.
What it covers
Each service below maps to a way businesses really get breached. None of it needs a security operations centre. All of it needs someone checking that it stays in place.
MFA on email, VPN, and remote access, with no shared accounts and no exceptions for executives. Access for departed staff and vendors ends the day it should, not the next time someone notices.
Modern endpoint protection on every laptop and server, monitored centrally, so an alert reaches a person instead of a console nobody opens.
Filtering against phishing and fake invoices, plus monitoring for the forwarding rules attackers set up in a mailbox before a payment-redirection fraud.
Operating systems, browsers, firewalls, and VPN appliances patched on a schedule, with nothing left running past its end-of-support date.
Firewall policy, segmentation, and remote access rules, handled together with our network support team so one compromised laptop cannot reach everything.
External and internal exposure reviewed, findings written down, and a remediation plan ranked by consequence rather than by product margin.
What actually happens
Almost none of it looks like the movies. These are the routes that account for most incidents we are called about, and each one has a boring, affordable control that blocks it.
Phishing remains the most common entry point: a fake login page, an invoice that looks routine, a message that appears to come from a colleague. Multi-factor authentication and email filtering stop the overwhelming majority.
An attacker sits quietly in a mailbox, learns your billing cycle, then emails a client new banking details. Businesses lose real money to this without any malware involved. Mailbox rule monitoring and out-of-band payment verification catch it.
Firewalls, VPN appliances, and remote access tools are scanned constantly for known vulnerabilities. Keeping edge firmware current is unglamorous and closes a door that gets tried every day.
A password reused from a breached personal service works on a business account with no MFA. Enforced MFA plus disabled accounts for departed staff removes this entirely.
Compromise arrives through a vendor's remote-access tooling rather than your perimeter. Segmentation and least-privilege vendor access limit how far it can travel.
Not an entry point but the reason incidents become disasters. Attackers target backups first, which is why immutable copies and tested restores matter more than backup software brand.
Backup and business continuity →The bar to clear
Cyber-insurance renewals and enterprise client security reviews now ask for evidence of these specific controls. If any line below is uncertain, that is the gap to close first, and closing it is usually cheaper than the questionnaire suggests.
Paperwork that has teeth
Two things changed in the last few years. Cyber-insurance underwriters stopped accepting checkbox answers and now ask for evidence of MFA, endpoint protection, patch currency, and tested backup, sometimes with a technical review attached. And enterprise clients increasingly send their own security questionnaire before signing, which can stall a deal for weeks if nobody can answer it.
Both are far easier when documentation has been maintained from the start of the engagement rather than assembled in a panic. CoreData supports clients through these reviews: mapping the questions to what is actually deployed, closing the gaps that matter, and producing the evidence in the format the reviewer expects. It is also worth saying plainly that misrepresenting controls on an insurance application can void the policy at the exact moment you need it, so the honest answer, plus a remediation plan, beats the optimistic one.
Where it starts
Whether the environment was set up by us, by a previous provider, or by whoever was handy at the time, the order of work is the same.
Review identity, endpoints, patching, email, the network perimeter, and backup against the baseline above, and write down what is actually deployed.
Rank the gaps by consequence. Missing MFA on email and an untested backup come before anything that needs a new product.
Fix the common entry points first, scheduled around your operations, with every change documented.
Run a test restore, so recovery is demonstrated rather than assumed. That half of the work is covered under backup and business continuity.
Keep the controls current under managed IT, or hand them back to your team with the documentation to run them.
Who this is for
CoreData works with Calgary and Alberta organizations where downtime has operational consequences: energy operators with field and well-site systems, industrial firms where plant and office networks meet, healthcare providers with privacy obligations, and professional services firms holding client data they are contractually responsible for.
The approach is deliberately unfashionable: close the common entry points first, make recovery genuinely work, then improve. Most Calgary businesses do not need a security operations centre. They need MFA fully deployed, patching that actually happens, a backup someone has restored from, and a plan that names people. That foundation is where nearly all of the real risk reduction lives, and it is what our managed IT service maintains day to day rather than treating security as an annual project.
Common questions
The foundational controls, MFA, managed endpoint protection, patching, and monitored backup, are usually part of a managed IT agreement priced per user and device. Assessments and remediation projects are quoted separately as fixed scopes once we know what is actually deployed.
Most Calgary small and mid-sized businesses do not. The honest answer is that MFA, patching, managed endpoint protection, and tested backups eliminate far more real risk per dollar. We will tell you when you have genuinely outgrown that baseline.
Yes, and it is a common reason clients call. We map the questions to what is actually deployed, close the gaps that matter, and produce the evidence in the format the reviewer expects.
A review of external and internal exposure covering identity, endpoints, patching, email, the network perimeter, and backup, written up as a prioritized remediation plan with the highest-value controls first.
The foundation is. Assurance+ managed IT includes 24/7 monitoring, managed endpoint protection, patch management, and backup. Assessments, remediation projects, and questionnaire support are scoped separately.
Managed IT services →Yes. Endpoint monitoring and patching are often the first layers a business hands over, while its own IT person keeps projects and day-to-day requests.
Co-managed IT in Calgary →No. CoreData is independent, so tools are chosen to fit the requirement rather than a resale agreement, and the reasoning behind each recommendation is written down for you.
Call (403) 450-3438 rather than reading further. The first 48 hours follow a written sequence: contain, assess, notify, recover, and close the gap that was used.
What the first 48 hours look like →Talk with our team
If nobody can answer that quickly, a security assessment is the place to start.