Phishing
An email impersonates a supplier, the bank or a colleague, and harvests a password. It is the most common way in, and the cheapest one for the attacker.
Managed cybersecurity
An attack does not have to target your company to hit it: most phishing and ransomware campaigns cast a wide net and land on whichever organizations are least protected. OKTO Solutions assesses your security posture, fixes what is exposed, then monitors your environment continuously.
Managed cybersecurity for a Quebec small business brings together five layers: multifactor authentication on every account, monitored EDR protection on the workstations, DNS filtering, patches applied without delay, and staff trained to spot a booby-trapped email. An assessment first establishes what is exposed, then continuous monitoring takes over.
What it is
Managed cybersecurity means an outside provider takes charge of protection, detection and response across all of your workstations, your servers and your cloud accounts.
In practice it happens in three stages. A first assessment establishes what is genuinely exposed in your environment. The fixes follow, in an order set by risk rather than by whatever is fashionable this quarter. Then comes the monitoring, which is the part SMBs underestimate the most: a tool that gets installed and never looked at protects nobody. The service is built for Quebec companies that handle client data, payments or employee files and have no security specialist in house. What changes is measured by what stops happening. Accounts are no longer wide open, known attacks get blocked before they land, and you finally know what is going on across your device fleet.
The service adds to what you already have. If someone in-house handles the day-to-day, we agree from the start on who does what, and nothing gets deployed twice. What was blocked, fixed or left pending is written down in language management can read without a translation.
The real threats
The cases we see at our clients almost always come back to the same short list. None of these attacks calls for a sophisticated attacker. They only call for a company that has not yet put the basics in place.
An email impersonates a supplier, the bank or a colleague, and harvests a password. It is the most common way in, and the cheapest one for the attacker.
A password stolen somewhere else gets replayed on your mailbox. With no second factor, nothing stops it, and the intruder reads everything without making a sound.
After reading your email for weeks, the attacker asks for a transfer at the right moment, in the right tone, on the right file. The loss is direct and rarely recoverable.
Files get encrypted, often after being copied first to add pressure. Without an isolated backup that actually restores, the company comes to a full stop.
A flaw published months ago is still open on a server or a firewall nobody updates. The attacker does not even need to be aiming at you.
A forgotten login outlives the person who left, sometimes for years. Nobody looks at it, and it shows up on no report at all.
Our layers of defence
Security that is useful to an SMB is not one product, it is a stack of measures that reinforce each other. We always start with the foundations, because they stop the majority of real attacks for a reasonable effort: multifactor authentication on every account, updates on systems and applications, advanced protection on the workstations, and backups whose restore has been tested. Detection and response measures come next; they cost more and only make sense once the foundations are in place. Training closes the loop. The most-used way in is still email, and no software replaces an employee who gets suspicious at the right moment.
No jargon
The three terms get used a lot and they do not cover the same risk at all. Here is the difference, in plain words.
It compares files against a list of known threats and blocks what it recognizes. That is the floor. It does not see an attack that uses legitimate Windows tools, it alerts nobody outside the machine, and if it gets switched off, nobody notices.
Endpoint detection watches behaviour: a process encrypting files in a row, a script trying to disable the backups, an unusual outbound connection. The important word is "managed". Someone receives the alert, reads it and acts.
It correlates events from workstations, servers and cloud services in one central log. That is what lets you see an attack moving from machine to machine, and reconstruct afterwards what really happened. Offered in the Complet plan.
Level of protection
Three plans: Base, Standard and Complet. The foundations are laid in all three. What changes is the depth of the detection and the speed of the response.
| Security measure | Base | Standard | Complet |
|---|---|---|---|
| Multifactor authentication on accounts | Included | Included | Included |
| Windows and third-party patching | Included | Included | Included |
| Managed EDR on workstations and servers | Included | Included | Included |
| Microsoft 365 hardening, DMARC, encryption | Set up in the initial engagement | Set up in the initial engagement | Set up in the initial engagement |
| Backup and restore testing | Daily monitoring | Restore test twice a year | Restore test twice a year |
| Managed detection and central logging | Not included | Not included | Included |
| Vulnerability management across the fleet | Not included | Not included | Included |
| 24/7 emergency service | Not included | Not included | Included |
| Phishing simulations and awareness training | vCIO module | vCIO module | vCIO module |
Phishing simulations are part of the virtual CIO module, which plans four of them per year. The full breakdown of each level sits on the plans and pricing page.
The first hours
The day something gets through, the difference between an incident and a crisis comes down to two things: do we know what was touched, and do we have a clean copy to restart from. An SMB with no logging and no verified backup finds out how bad it is at the same time as the ransomware does. Here is the order we work in, and it does not change with the mood of the morning.
This is also why the tools are put in place before anything happens. Isolating a workstation remotely, revoking sessions or reading the logs only takes minutes when the agents, the central logging and the access lists already exist. Without them, the first hours go to setting up what should have been there.
Cyber insurance
Cyber insurance questionnaires all look alike, and they no longer ask whether you have antivirus. They ask whether multifactor authentication is active on email and on remote access, whether the workstations carry monitored advanced protection, whether patches are applied and tracked, whether backups are off site and tested, whether employees get training, and whether a written incident procedure exists. Answering yes is not enough: at claim time, the insurer will want proof that the measure was genuinely in place on the date of the incident. That is exactly what a managed security engagement produces. Every change is documented, dated and kept.
The measures asked for are the same ones we deploy anyway: multifactor authentication, offline copies, detection on the workstations and up-to-date systems. A client already covered by our service answers the questionnaire with evidence pulled from the console, not with boxes ticked from memory.
You do not recognize a protected SMB by how many products are installed. You recognize it by what stops happening to it.
What it rests on
No security layer stands up on its own. It assumes workstations kept current, a cloud environment configured properly and copies of your data that have already been proven to restore. That is why cybersecurity is part of a whole here rather than something sold on the side.
Where we work
Our office is in Trois-Rivières and the service is offered across Quebec. Most security work is done remotely, and a technician travels when the job calls for it: replacing a firewall, taking charge of an incident on site, meeting with management.
See the details for IT services in Trois-Rivières, for companies in the Mauricie, for Greater Montreal or for the Quebec City area.
Monitoring, fixes and investigations happen from our console, with the same tools and the same people, whether the client is in Shawinigan or in Longueuil. When a workstation has to be replaced, it is prepared at the office, patched and encrypted, and the trip only serves to plug it in.
Questions and answers
An assessment with no obligation tells you where you are exposed, what has to be fixed first and what that takes. You leave with an ordered list, whether you hand us the rest or not.
We use cookies that are strictly necessary for the site to work. Only with your consent do we add measurement cookies that tell us which pages get read. Refusing costs you nothing, and you can change your mind at any time from the bottom of any page. Cookie details.