Compliance & Risk Management

Audit-ready, minus the acronym soup.

Compliance and risk management means putting the right security controls in place and being able to prove they are working. happier IT does that for Canadian organizations of roughly 15 to 200 people facing privacy law, insurance renewals or client security requirements. Most have more controls than they can evidence.

Who it's for

The requirement almost always arrives from outside.

It starts because somebody asks a question with a deadline attached.

The cyber-insurance renewal landed. A questionnaire, due in three weeks, asking whether MFA (multi-factor authentication: a second check, usually on a phone, before a login is accepted) is enforced on email, remote access and administrator accounts. Someone has to sign it.

A client sent a security schedule. Attached to a contract you want: encryption requirements, breach notification within a fixed window, a named security contact, and a question about where data is stored.

You handle information the law treats carefully. Personal information, health records, or cardholder data because you take payments.

The board asked a reasonable question. What are our top risks, who owns them, and what are we doing about them. No document answers it.

This is not legal advice

happier IT is an IT and security provider, not a law firm. Nothing here is legal advice.

Whether a law applies to you is a question for your lawyer. We make the technical controls real and the evidence producible, alongside your counsel rather than in place of them.

What's included

What happier IT does, and what it does not.

The line matters more than a longer list would.

  • A control register and an evidence pack

    One document listing each control, who owns it, how it is enforced and what proves it. That turns a questionnaire from a week of chasing into an afternoon.

  • Cyber-insurance questionnaire support

    We work through the questions with you, gather the evidence behind each yes, and flag anything not yet true so it can be fixed before you sign.

  • Client and prime-contractor security schedules

    Someone reads the whole schedule, maps each clause to what you actually do, and gives you a gap list with costs. The sticking points are usually data location, notification windows and subcontractor disclosure.

  • Privacy-law groundwork

    PIPEDA is the federal Personal Information Protection and Electronic Documents Act. Alberta and British Columbia each have their own PIPA, or Personal Information Protection Act. Ontario’s PHIPA covers personal health information. We map what you hold and who can reach it.

  • PCI-DSS scope reduction

    PCI-DSS is the Payment Card Industry Data Security Standard, which applies wherever cards are taken. The valuable work is reducing scope, arranging things so cardholder data never touches your network, so most of the standard stops applying.

  • A risk register with owners and dates

    Risks in business language, rated, assigned to a person, given a review date. Not a heat map for its own sake, a short list of what is most likely to cost money.

  • Policies people can actually read

    Acceptable use, access control, incident response, devices and remote work, vendor management. Plain English, signed at onboarding, reviewed annually. A policy nobody has read is not evidence.

  • An incident runbook, rehearsed

    Who declares an incident, who they call, what gets recorded, and when a privacy commissioner and affected individuals must be told. Then we walk your leadership through a scenario.

How it works

From “we think so” to “here is the file”.

The scaffolding we use is public and free to read: the CIS Critical Security Controls, the NIST Cybersecurity Framework, and the Canadian Centre for Cyber Security’s baseline controls.

  1. Find out what you already do

    A structured review of your controls against a baseline, plus an inventory of what regulated information you hold and where it lives. Most organizations score better than expected on controls and worse on records.

  2. Close the real gaps

    We separate the gaps that matter from those that only matter on paper, then fix them in the order a renewal will ask about. MFA coverage, offboarding records and tested backups are almost always first.

  3. Build the evidence pack, then keep it current

    Control register, policies, risk register, incident plan, restore-test results and access reviews, in one file. Refreshed quarterly, so the next questionnaire is a retrieval job.

What it costs

Scoped work, not a percentage of your anxiety.

Compliance is quoted on what is being prepared for, because “audit-ready” means very different amounts of work depending on the audience.

Ongoing support normally sits inside a managed IT agreement Standalone work is fixed-price, and the scope differs at each level:

  • An insurance renewal. Gathering evidence for a questionnaire and fixing the answers not yet true. Short, with a hard deadline.
  • A client security schedule. Reading the clauses, mapping them, closing the gaps the contract requires. Sized by how demanding it is.
  • A full control baseline with quarterly evidence. The register, policies, risk process and review cadence. This is what makes everything afterwards cheap.

Timelines follow how much already exists: three to six months is the usual range, depending on the framework and on how much of it you can already evidence.

What we will not do

We do not issue certifications, and we cannot audit our own work and give you an independent opinion on it. No honest provider can.

A SOC 2 report, the service organization control report clients sometimes demand, comes from a CPA firm. An ISO/IEC 27001 certificate comes from an accredited body.

Why us for this

Evidence is easier when the same team runs the systems.

Most of the proof an insurer or a client asks for is generated by the systems themselves: MFA coverage, patch status, restore results, alert history, account changes. happier IT runs its own security operations centre in Canada, staffed by our own employees, so that history can be retrieved rather than reconstructed from memory.

That is the practical reason compliance work goes faster here. Not a framework, somebody kept the records. The centre is staffed 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific, and our certifications are listed on our awards and certifications page.

Go deeper

Questions

What people ask before they sign anything.

Does PIPEDA apply to us?

It applies to private-sector organizations handling personal information in the course of commercial activity, but in Alberta and British Columbia a provincial law called PIPA usually applies instead. PIPEDA still governs federally regulated businesses and information crossing borders. Which applies is a question for your lawyer.

What do we have to do if we have a data breach?

Under PIPEDA, a breach of security safeguards creating a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada, and the affected individuals notified. You must also keep a record of every breach for 24 months, reportable or not, which is what an incident runbook is for.

Our cyber-insurance renewal asks about MFA and EDR. Can you help?

Yes, this is the most common reason people call this page. EDR means endpoint detection and response: software on laptops and servers that watches for suspicious behaviour rather than only matching known bad files. We check what is deployed, produce the coverage reports the insurer wants, and tell you plainly if an answer you were about to give is not yet accurate.

Can happier IT make us SOC 2 or ISO 27001 certified?

No, and neither can any IT provider, that is rather the point of both. A SOC 2 report is issued by a CPA firm after an examination; an ISO/IEC 27001 certificate comes from an accredited certification body. What we do is the preparation: controls, documentation, evidence and a readiness review, so the auditor finds no surprises.

A client sent us a 40-page security schedule. What now?

Send it to us before you sign it. Someone needs to read every clause and map it to what your organization actually does, because these schedules are usually written for much larger suppliers. You get a gap list with a cost against each item, and a view on which clauses to push back on.

We are 40 people. Is this overkill?

The controls are not, most are things a 40-person organization should have anyway, and several sit inside a decent managed IT agreement already. The documentation is where it can tip into overkill. If nobody is asking for evidence, a lighter baseline is a legitimate choice.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.