Cybersecurity Services

Security that feels safe.

happier IT's cybersecurity services put the practical controls in place that protect a Canadian organization of 15 to 200 people: multi-factor authentication, endpoint protection, email defence, patching, backup you have tested, and staff training. Designed around how your team actually works, so people do not route around it.

Who it's for

Security work usually starts for one of three reasons.

Almost never because someone woke up wanting better security. Usually because someone outside the building asked a question.

An insurer or a client asked. A renewal questionnaire, an audit, or a contract with a security schedule attached. Suddenly you need to evidence things you assumed were fine.

Something happened: to you, or to somebody you know. A supplier got their email taken over, an invoice went to the wrong account, or a laptop went missing. It concentrates the mind.

You have grown past informal. Forty people, three offices, contractors coming and going, and no defined way of granting or removing access.

We do not do the third one, the fear version. There is no countdown clock on this page and no statistic about how many businesses close after a breach. The work is worth doing on its own merits.

A word on tone

The brand rule here is no fear-based messaging, and we mean it as a working constraint, not a slogan. If a recommendation only makes sense when you are frightened, it is a bad recommendation.

What's included

The controls that do most of the work.

Ordered roughly by how much risk each removes per dollar. The first four cover the overwhelming majority of how organizations of this size actually get hurt.

  • Multi-factor authentication, everywhere

    A second check before a login is accepted, including on administrator accounts, shared mailboxes and the executive who finds it annoying. Coverage matters more than strength.

  • Endpoint detection and response (EDR)

    Software on every laptop and server that watches for suspicious behaviour rather than just known-bad files, and can cut a machine off the network on its own.

  • Email security and payment verification

    Authentication so your domain cannot be spoofed, filtering for what gets through, and a defined process for verifying any change to payment details.

  • Patching and vulnerability management

    Knowing what software you run, what is out of support, and closing the gaps on a schedule instead of when someone remembers.

  • Identity and access management

    One defined way to grant access when someone joins and remove it the day they leave. Most organizations have the first half.

  • Backup you have restored from

    Tested restores on a schedule, and backups an attacker cannot reach from inside your network.

  • Security awareness training

    Short, human, and not designed to embarrass anyone. People who feel blamed stop reporting things, which is the opposite of what you want.

  • Written policies you can actually hand over

    The acceptable-use, access and incident-response documents that auditors, insurers and clients ask to see.

How it works

How a security engagement runs.

Assessment first, then the cheap high-value fixes, then the rest in an order you agreed to.

  1. Assess

    We look at what is actually in place: accounts, devices, email, backups, and who has access to what. You get a written picture with the gaps ranked by risk and by cost to close. That document is yours regardless.

  2. Close the obvious gaps

    Multi-factor authentication, endpoint protection, unsupported software, dormant accounts, backup verification. Usually a few weeks, usually not disruptive, and it is most of the risk reduction.

  3. Then keep going

    Monitoring, patch cycles, quarterly access reviews, training, and the annual paperwork for insurers and clients. Security is a maintained state, not a project you finish.

What it costs

Included in managed IT, or priced on its own.

Two ways to buy this, and which one is right depends on whether we run your IT.

If happier IT runs your managed IT, the controls above are inside the monthly fee. They are not a security tier you upgrade to.

If someone else runs your IT and you want the security layer from us, it is priced separately, based on the number of people and devices and how much monitoring you want.

The initial assessment is fixed-price and quoted before it starts. There is no situation in which you get a surprise number from us.

What this is worth on a renewal

Cyber-insurance questionnaires now decide premium and sometimes eligibility, and the questions are largely the list above. Getting them answerable is often a few weeks of work with a directly measurable return.

We will not put a percentage on that, because we do not have a sourced one.

Go deeper

Specialisms under this service

Each of these is a distinct piece of work with its own page. Most clients need some of them, not all of them.

Penetration Testing

A test, not a surprise.

Scoped, authorised penetration testing for Canadian organizations of 15 to 200 people: a readable report, a retest included, and advice on when to wait.

Ransomware Protection

Recoverable, by design.

Layered ransomware protection for Canadian organizations: strong sign-in, endpoint isolation, immutable backups, segmentation and a tested recovery plan.

Endpoint Protection (EDR)

Someone reads the alerts.

Endpoint detection and response deployed, tuned and watched by our own Canadian security team, for organizations of 15 to 200 people in AB, BC and Ontario.

Phishing Prevention & Training

Hard to fake. Easy to report.

Email authentication, tuned filtering, a one-click report button and non-punitive simulations. Phishing prevention for Canadian teams of 15 to 200 people.

Dark Web Monitoring

Useful. Just not first.

Credential monitoring for your domains and staff, with a defined action for every hit, and an honest account of what it can and cannot do for you.

Microsoft 365 Security

The settings nobody turned on.

A review and hardening of your Microsoft 365 tenancy: conditional access, legacy sign-in, admin separation, audit logging and guest access. Mostly settings.

Vulnerability Management

Know what you run.

Asset inventory, authenticated scanning, an agreed patch cadence and an exception register, the monthly practice behind every good security answer.

Identity & Access Management

In on day one. Out the same day.

Joiners, movers and leavers done properly: least privilege, separate admin accounts, single sign-on and quarterly access reviews. AB, BC and Ontario.

Intrusion Detection & Response

The part after the alert.

Detection is easy to buy; response is the hard part. Log collection, human triage and agreed containment authority from our own Canadian security centre.

Security Awareness Training

Training nobody dreads.

Short, plain-language security training for Canadian teams of 15 to 200 people: role-specific for finance, never punitive, measured by reporting rate.

Why us for this

Detection is easy to sell. Response is the hard part.

Any provider can install security software. The question that separates them is what happens between an alert firing and someone phoning you, and at 3am, most of this market has no good answer, because the watching has been subcontracted to a platform somewhere else.

happier IT runs its own security operations centre in Canada, staffed by our own people, including Certified Ethical Hackers on the security team. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.

The incident process we use is the standard one, and we will walk you through it before anything happens rather than during: identify, contain, remove, restore, report.

Go deeper

Questions

What people ask before they sign anything.

Where should we start if we have nothing?

Multi-factor authentication on email, then endpoint protection on every device, then a tested backup. Those three, done properly, remove most of the realistic risk to an organization of this size, and none of them takes long. Everything else is worth doing after them, not before.

Do we need penetration testing?

Probably not first. A penetration test tells you how someone could get in; it is money well spent once the basics are in place, and money largely wasted before that, you will pay a specialist to tell you that multi-factor authentication is missing. If a client or a regulator requires one, that is a different conversation and we will arrange it.

Will this slow our team down?

Slightly, in a couple of places, and we would rather say so. A second login step costs a few seconds. Access reviews cost a manager an hour a quarter. Controls that cost more than that get worked around by staff, which makes them worse than useless, so we design for what people will actually tolerate.

What happens if something does go wrong?

We follow a defined process: identify what happened, contain it, remove it, restore what was affected, and report properly, including to you, in plain English, and to a regulator or insurer where required. You will have seen that process written down before you need it.

Do you do security awareness training?

Yes, and we keep it short and non-punitive. Simulated phishing is useful as a measure; it is not useful as a way to make people feel stupid. Staff who are afraid of being blamed hide their mistakes, and a hidden mistake is the expensive kind.

Is our data staying in Canada?

For the parts we run, yes, our security operations centre is in Canada. Where a third-party platform you already use stores data elsewhere, we will tell you which ones rather than implying we control it.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.