Cyber Resilience for Canada’s Critical Infrastructure Organizations

CRATOS CAN connects strategic advisory, managed security operations, proven technology solutions and compliance support to help organizations reduce cyber risk and stay operational.

Service Areas
  • Advisory & Consulting
  • Managed Security Services
  • Technology Partners & Solutions
  • Compliance

From strategy to operations

Resilience across people, process and technology.

CRATOS CAN helps organizations understand cyber risk, strengthen security controls, improve detection and response, deploy suitable technologies and build evidence for governance and compliance. The result is a connected cyber-resilience program rather than isolated security projects.

Selected Cyber Security Projects

MANAGED SOC · FEDERAL CRITICAL INFRASTRUCTURE

A sovereign SOC for a federal infrastructure company

A federally owned company with a nationwide, safety-critical mandate needed full security monitoring without any security data leaving its control. We led the introduction of a SIEM on a sovereign, fully on-premises stack across its sites, steered vendors and stakeholders, and now run the SOC around the clock across IT and OT, including incident response, forensics, penetration testing and security assessments.

  • 3,500 endpoints plus third-party log sources
  • 24/7 monitoring across IT and OT
  • 100% on-premises, full data sovereignty
MANAGED SOC · MUNICIPAL UTILITY

24/7 SOC for a multi-service municipal utility

One organisation supplying several critical services means every incident is a potential multi-service outage. Monitoring covers the utility's hybrid cloud and on-premises estate end to end, with incident response and forensics built around continuity of supply.

  • ~750 endpoints and log sources
  • Multiple critical supply services under one SOC
  • < 1 h to containment of critical alerts
ISMS · ELECTRICITY GRID OPERATOR

Information security management from build-up to operation

For a regional electricity distribution network operator, we supported the build-up of the ISMS, including targeted support in audited areas, and continue as its extended information security team: risk treatment, evidence management and regulatory compliance.

  • Build → run one continuous engagement
  • ISO/IEC 27001 certification maintained under sector regulation
  • 75 major audit findings
ISMS · WATER UTILITY

ISMS rebuilt and extended to the whole company

A regional water supplier's existing ISMS was assessed, then rebuilt and extended from a partial scope to the entire company, using a service-oriented approach that organises security around the services the utility actually delivers.

  • Partial → 100% of the company in scope
  • Service-oriented security model
  • BSIG (BSI-Gesetz - Act on the Federal Office for Information Security) aligned management system
OT OPERATIONS · WATER UTILITY

Operations baseline for a process control system

For a water utility's SCADA-based process control system, we created best-practice operations documentation that became the foundation for day-to-day operation: the groundwork every OT security measure depends on.

  • 1 documented operations baseline for the control system
  • 100% † of critical operating procedures documented
  • IEC 62443 aligned documentation structure
INFRASTRUCTURE HARDENING · ENERGY UTILITY

Hardening IT infrastructure to critical-infrastructure requirements

A municipal energy utility's IT infrastructure was examined against critical-infrastructure requirements. Network traffic and server infrastructure were analysed for weaknesses and vulnerabilities, and results were turned into prioritised recommendations for action.

  • 2 layers analysed: network and servers
  • 1 prioritised action plan
  • −99% critical vulnerabilities after remediation
INTERIM CISO · WASTE-TO-ENERGY

Security leadership through a full IT outsourcing

As interim CISO for a waste-to-energy operator, we built the ISMS and information security risk management on top of corporate risk management, embedded security into ITIL processes and launched an awareness portal. We advised on the full-scope IT outsourcing tender, led the security sub-project for migrating the entire IT to the new provider, and selected and onboarded a SOC provider, including use cases, playbooks and SOC performance metrics.

  • 100% of IT migrated to a new provider under security lead
  • 1 SOC provider selected and onboarded
  • MITRE ATT&CK mapped detection use cases
M&A SUPPORT · ENERGY GROUP

Data discovery ahead of a transaction

For a major European energy company, we planned a data discovery project within an M&A process: knowing where sensitive data lives before it changes hands.

  • Day 1 data inventory ready before closing
  • 100% of in-scope systems classified
  • 0 unplanned data transfers at separation
MANAGED SOC · MUNICIPAL ADMINISTRATION

Cloud-based SOC for a city administration

A city administration running a hybrid cloud and on-premises estate gained 24/7 security monitoring without building its own SOC. A cloud-based monitoring platform brings endpoint and third-party telemetry together, with incident response and forensics on call.

  • ~1,000 endpoints and log sources
  • 24/7 monitoring and incident response
  • < 15 min alert triage
PROGRAMME ADVISORY · HEALTH INSURANCE

Critical-infrastructure programme for a statutory health insurer

Strategic advice structured the insurer's critical-infrastructure programme into work packages and modules, then steered their delivery. The target picture: an ISMS, a business continuity management system and a SOC, delivered as one programme rather than three separate projects.

  • 3 management systems in one programme: ISMS, BCMS, SOC
  • 1 integrated programme structure
  • 18 months roadmap to full operation
PROGRAMME LEAD · MAJOR BANK

Enterprise-wide data loss prevention programme

We led a consulting team designing and steering an enterprise-wide DLP programme in a regulated banking environment: target picture, governance model, control framework, target architecture and minimum standards. Gap analyses and risk assessments were consolidated across business units into a risk-based programme, reported to the steering committee and documented to audit standard. The existing governance framework was also mapped into Microsoft Purview.

  • Enterprise-wide across business units and international entities
  • 100% audit-proof evidence and closure documentation
  • All related audit findings closed
THREAT ASSESSMENT · MAJOR BANK

Testing security controls against real attacker behaviour

Existing security controls for in-scope target systems were identified and their effectiveness assessed against the MITRE ATT&CK framework. In a separate engagement, we analysed the market for a successor to the bank's email encryption gateway.

  • MITRE ATT&CK technique coverage mapped
  • Top 15 control gaps prioritised
  • 1 evaluated successor for email encryption
SOC / SIEM · MORTGAGE BANK

SOC and SIEM for regulatory readiness

For a specialist mortgage bank, we designed the target picture for SOC and SIEM operations in line with German banking supervisory requirements, created the RFP, supported provider selection, and implemented, operationalised and documented the solution.

  • Concept → operation end to end
  • 1 RFP and provider selection
  • 100% supervisory requirements traced to controls
DATA LOSS PREVENTION · REINSURANCE

DLP selection and rollout for a global reinsurer

We managed the selection of a data loss prevention solution and its introduction across the organisation.

  • 1 solution selected against defined criteria
  • Global rollout
  • −95% false positives after tuning
PENETRATION TESTING · FINANCIAL SERVICES

Securing a critical customer service platform

A financial services provider relies on us for recurring penetration tests of its critical customer service platform, complemented by a security assessment of its Active Directory environment.

  • Multiple penetration tests of the customer platform
  • 1 Active Directory security assessment
  • 100% critical findings remediated and retested
PENETRATION TESTING · RETAIL

Long-term security testing partner for a drugstore chain

A national drugstore chain has worked with us for years on penetration testing and security consulting: internal and external web and mobile applications, cloud and on-premises infrastructure, and governance and compliance.

  • Multi-year partnership
  • 4 test domains: web, mobile, cloud, on-premises
  • 100% critical findings retested
INCIDENT RESPONSE · Utility infrastructure contractor

Rapid response to an identity and mailbox compromise

After user identities and mailboxes were compromised, our team delivered first analysis within two hours, followed by forensic investigation, containment and recovery.

  • < 2 h to first analysis
  • Identity + mailbox forensics
  • < 5 days to full recovery
PENETRATION TESTING · MANUFACTURING

Protecting a sportswear brand's customer application

A sportswear manufacturer commissioned multiple penetration tests of a critical customer-facing application.

  • Multiple penetration tests
  • 1 critical customer application
  • 0 critical findings open at release

Advisory & Consulting

Cybersecurity strategy, assessments, penetration testing and risk & compliance guidance.

Explore advisory services

Managed Security Services

24/7 SOC, MDR, incident response, vulnerability management, firewall, EDR and cloud security monitoring.

Explore managed services

Why CRATOS CAN

Security expertise shaped for Canadian organizations.

We connect strategy, implementation and operations so cybersecurity improvements are practical, measurable and aligned with the realities of regulated and mission-critical environments.

Let’s connect Have a project or question in mind? Choose a time that works for you.