Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Managed cybersecurity

Cybersecurity for SMBs in Quebec: managed IT security, EDR, MFA and security audits

An attack does not have to target your company to hit it: most phishing and ransomware campaigns cast a wide net and land on whichever organizations are least protected. OKTO Solutions assesses your security posture, fixes what is exposed, then monitors your environment continuously.

Managed cybersecurity for a Quebec small business brings together five layers: multifactor authentication on every account, monitored EDR protection on the workstations, DNS filtering, patches applied without delay, and staff trained to spot a booby-trapped email. An assessment first establishes what is exposed, then continuous monitoring takes over.

What it is

What is managed cybersecurity for an SMB?

Managed cybersecurity means an outside provider takes charge of protection, detection and response across all of your workstations, your servers and your cloud accounts.

In practice it happens in three stages. A first assessment establishes what is genuinely exposed in your environment. The fixes follow, in an order set by risk rather than by whatever is fashionable this quarter. Then comes the monitoring, which is the part SMBs underestimate the most: a tool that gets installed and never looked at protects nobody. The service is built for Quebec companies that handle client data, payments or employee files and have no security specialist in house. What changes is measured by what stops happening. Accounts are no longer wide open, known attacks get blocked before they land, and you finally know what is going on across your device fleet.

  • An assessment that ends in an ordered list, not in a report nobody reads
  • Fixes applied and documented, one at a time
  • Monitoring that alerts a real team, not an inbox

The service adds to what you already have. If someone in-house handles the day-to-day, we agree from the start on who does what, and nothing gets deployed twice. What was blocked, fixed or left pending is written down in language management can read without a translation.

The real threats

Which attacks actually hit Quebec SMBs?

The cases we see at our clients almost always come back to the same short list. None of these attacks calls for a sophisticated attacker. They only call for a company that has not yet put the basics in place.

Phishing

An email impersonates a supplier, the bank or a colleague, and harvests a password. It is the most common way in, and the cheapest one for the attacker.

A compromised Microsoft 365 account

A password stolen somewhere else gets replayed on your mailbox. With no second factor, nothing stops it, and the intruder reads everything without making a sound.

CEO fraud

After reading your email for weeks, the attacker asks for a transfer at the right moment, in the right tone, on the right file. The loss is direct and rarely recoverable.

Ransomware

Files get encrypted, often after being copied first to add pressure. Without an isolated backup that actually restores, the company comes to a full stop.

Unpatched systems

A flaw published months ago is still open on a server or a firewall nobody updates. The attacker does not even need to be aiming at you.

Accounts of former employees

A forgotten login outlives the person who left, sometimes for years. Nobody looks at it, and it shows up on no report at all.

What those six cases have in common. Not one of them needs an unknown flaw or an attacker motivated by your company in particular. A manufacturer in the Mauricie and a professional firm in Laval get caught by the same automated campaign, in the same week, because the same kind of account had no second factor.

Our layers of defence

The layers we deploy, in order

Security that is useful to an SMB is not one product, it is a stack of measures that reinforce each other. We always start with the foundations, because they stop the majority of real attacks for a reasonable effort: multifactor authentication on every account, updates on systems and applications, advanced protection on the workstations, and backups whose restore has been tested. Detection and response measures come next; they cost more and only make sense once the foundations are in place. Training closes the loop. The most-used way in is still email, and no software replaces an employee who gets suspicious at the right moment.

  • Microsoft 365 hardening: shares, mail rules, admin access, DMARC configuration
  • Encryption on laptops and on sensitive data
  • Security awareness training and phishing simulations to measure how staff actually react
  • Multifactor authentication on user accounts and on admin accounts, remote access included
  • Managed EDR on workstations and servers, with the alerts handled by our team
  • Managed detection and central logging to see an attack moving across several machines
  • DNS filtering that blocks the malicious site before it even opens
  • Patch management for Windows and third-party applications, tracked and reported

No jargon

Antivirus, managed EDR or managed detection: what sets them apart

The three terms get used a lot and they do not cover the same risk at all. Here is the difference, in plain words.

Classic antivirus

It compares files against a list of known threats and blocks what it recognizes. That is the floor. It does not see an attack that uses legitimate Windows tools, it alerts nobody outside the machine, and if it gets switched off, nobody notices.

Managed EDR

Endpoint detection watches behaviour: a process encrypting files in a row, a script trying to disable the backups, an unusual outbound connection. The important word is "managed". Someone receives the alert, reads it and acts.

Managed detection

It correlates events from workstations, servers and cloud services in one central log. That is what lets you see an attack moving from machine to machine, and reconstruct afterwards what really happened. Offered in the Complet plan.

Level of protection

What is protected in each plan?

Three plans: Base, Standard and Complet. The foundations are laid in all three. What changes is the depth of the detection and the speed of the response.

Security measureBaseStandardComplet
Multifactor authentication on accountsIncludedIncludedIncluded
Windows and third-party patchingIncludedIncludedIncluded
Managed EDR on workstations and serversIncludedIncludedIncluded
Microsoft 365 hardening, DMARC, encryptionSet up in the initial engagementSet up in the initial engagementSet up in the initial engagement
Backup and restore testingDaily monitoringRestore test twice a yearRestore test twice a year
Managed detection and central loggingNot includedNot includedIncluded
Vulnerability management across the fleetNot includedNot includedIncluded
24/7 emergency serviceNot includedNot includedIncluded
Phishing simulations and awareness trainingvCIO modulevCIO modulevCIO module

Phishing simulations are part of the virtual CIO module, which plans four of them per year. The full breakdown of each level sits on the plans and pricing page.

The first hours

What happens in the first hours of an incident?

The day something gets through, the difference between an incident and a crisis comes down to two things: do we know what was touched, and do we have a clean copy to restart from. An SMB with no logging and no verified backup finds out how bad it is at the same time as the ransomware does. Here is the order we work in, and it does not change with the mood of the morning.

This is also why the tools are put in place before anything happens. Isolating a workstation remotely, revoking sessions or reading the logs only takes minutes when the agents, the central logging and the access lists already exist. Without them, the first hours go to setting up what should have been there.

  1. IsolateThe affected machines get cut off the network remotely, to stop the spread before anyone understands anything.
  2. Close the accessPasswords reset, sessions revoked, tokens invalidated, mail forwarding rules removed.
  3. Establish the scopeThe central logs say what was read, copied or changed, and since when. Without them, you are guessing.
  4. Notify the right peopleManagement, your privacy officer, your insurer. The incident register gets filled in as things unfold.
  5. RestoreFrom a verified, isolated copy, never onto a system that is still compromised. The restart order follows the recovery plan.
  6. Fix the causeThe hole it came in through gets closed, and the missing measure is added to the plan. A written report stays on file.

Cyber insurance

What your insurer will require before covering you

Cyber insurance questionnaires all look alike, and they no longer ask whether you have antivirus. They ask whether multifactor authentication is active on email and on remote access, whether the workstations carry monitored advanced protection, whether patches are applied and tracked, whether backups are off site and tested, whether employees get training, and whether a written incident procedure exists. Answering yes is not enough: at claim time, the insurer will want proof that the measure was genuinely in place on the date of the incident. That is exactly what a managed security engagement produces. Every change is documented, dated and kept.

The measures asked for are the same ones we deploy anyway: multifactor authentication, offline copies, detection on the workstations and up-to-date systems. A client already covered by our service answers the questionnaire with evidence pulled from the console, not with boxes ticked from memory.

The trap in the declaration. Ticking a box when the measure does not really exist can get the claim denied at the worst possible moment. Before you fill out the questionnaire, have the actual state of your environment verified. It takes a few days and it spares you a very bad surprise.

You do not recognize a protected SMB by how many products are installed. You recognize it by what stops happening to it.

Antonio Pazzi, founder of OKTO Solutions

What it rests on

Security leans on the rest of your IT

No security layer stands up on its own. It assumes workstations kept current, a cloud environment configured properly and copies of your data that have already been proven to restore. That is why cybersecurity is part of a whole here rather than something sold on the side.

Where we work

Where we come in

Our office is in Trois-Rivières and the service is offered across Quebec. Most security work is done remotely, and a technician travels when the job calls for it: replacing a firewall, taking charge of an incident on site, meeting with management.

See the details for IT services in Trois-Rivières, for companies in the Mauricie, for Greater Montreal or for the Quebec City area.

Monitoring, fixes and investigations happen from our console, with the same tools and the same people, whether the client is in Shawinigan or in Longueuil. When a workstation has to be replaced, it is prepared at the office, patched and encrypted, and the trip only serves to plug it in.

Our tools are our own. OKTO builds its own monitoring and incident tracking platforms rather than reselling someone else’s. Our applications are signed with a code signing certificate obtained through Microsoft Azure Trusted Signing, under the verified publisher identity OKTO Solutions. OKTO is also a Microsoft Partner.

Questions and answers

Frequently asked questions about SMB cybersecurity

We are a small business. Are we really a target?
Yes, though rarely a chosen one. Phishing and ransomware campaigns are automated and cast a wide net. They find the organizations whose accounts have no multifactor authentication and whose systems are behind on updates. Being small protects you far less than the measures you have in place.
Where do we start if we have never done anything?
With four things, in this order: multifactor authentication on every account, updates on systems and applications, monitored advanced protection on the workstations, and a backup whose restore has already been tested. Those four measures stop the vast majority of real attacks, before any more advanced spending.
What is the difference between antivirus and EDR?
Antivirus recognizes threats that are already known and blocks what it recognizes. EDR watches behaviour on the workstation instead, so it catches attacks that use no identifiable malicious file. More to the point, a managed EDR sends its alerts to a team that acts on them. A tool that gets installed and never watched protects nobody.
How long does a cybersecurity assessment take for an SMB?
The length depends on how many workstations, servers and cloud services have to be reviewed. The assessment runs in four stages: current state, risk ranking, remediation, then continuous monitoring. You get the ordered list of fixes before the work starts, so you know exactly what you are committing to.
Do we have to replace everything to be better protected?
No. Most of the gain comes from configuring what you already own: turning on multifactor authentication, closing shares that are open to the whole company, removing dormant accounts, applying the patches that are overdue. Equipment replacement gets planned afterwards, based on real risk and your budget.
What do you do if an attack succeeds anyway?
We isolate the affected machines, cut off the compromised access, establish the scope from the central logs, then restore from verified backups. The Complet plan includes a 24/7 emergency service. The documentation produced during the engagement feeds straight into this step.
Does this help us get cyber insurance?
Insurer questionnaires keep coming back to the same points: multifactor authentication, advanced protection on the workstations, patching that is tracked, off-site backups that get tested, staff training and a written incident procedure. Those are exactly the measures we put in place, and we keep dated proof of each one.
Does cybersecurity cover our Law 25 obligations?
It is the technical foundation of them. Quebec’s Law 25 requires you to know what data you hold, who reaches it, how it is protected and how an incident would be handled. The measures we put in place are documented, which gives you the proof that gets asked for. The legal reading itself belongs to your own advisor.

Have your security posture assessed

An assessment with no obligation tells you where you are exposed, what has to be fixed first and what that takes. You leave with an ordered list, whether you hand us the rest or not.