SYMATech Book a call

Alberta, Canada · IT & Cybersecurity

Security isn't a phase. It's how we build.

Most shops wire the network first and bolt security on when something breaks. We design it in from the first switch port — so the infrastructure you pay for is the infrastructure that defends you.

25+ years in the field Assessment to incident response One accountable team

We assess and report against

  • NIST CSF 2.0
  • CIS Controls v8.1
  • CIS Benchmarks
  • MITRE ATT&CK Enterprise
  • NIST SP 800-61 Incident Handling
  • SANS PICERL

Services

Four practices, one accountable team

You get the same people from scoping through handover. No reselling the work, no handing you a PDF and disappearing.

01 / Infrastructure

Managed IT, delivered A‑to‑Z

Networks and endpoints built properly the first time, then supported by the team that built them.

  • Office network design and build‑out, 10 to 250 seats
  • Procurement, imaging and deployment — handed over fully configured
  • Microsoft 365 and Entra ID tenancy setup, hardened to baseline
  • Backup and recovery with restores that are actually tested
  • Day‑to‑day helpdesk and endpoint support

02 / Assurance

Assessment & hardening

Find what's exposed, rank it by what it would actually cost you, then close it.

  • Vulnerability assessment with a prioritised remediation roadmap
  • Active Directory and Entra ID review — tiering, delegation, Kerberos
  • Workstation and server hardening against CIS Benchmarks
  • Firewall rule review and network segmentation design
  • Policies, standards and procedures mapped to NIST CSF 2.0

03 / Forensics

Digital forensics & incident response

For when it has already happened. We establish what was touched, how far it went, and when it started — then get you back to operating.

  • Incident response led on your behalf — containment through recovery
  • Host forensics across disk, memory and Windows artifacts
  • Log and network analysis to establish scope and a defensible timeline
  • Ransomware and business email compromise investigations
  • Written findings your insurer, counsel and board can actually use

04 / Readiness

Detection & response readiness

The work that decides whether the next incident is an afternoon or a fortnight.

  • Detection coverage reviewed against MITRE ATT&CK, then tuned
  • Alerting sized so your team can realistically action every one
  • Incident response plans and runbooks written for your environment
  • Tabletop exercises driven by real attack paths, with an after‑action report
  • Retainer arrangements, so you already have our number when it matters

Awareness training

Your staff are the control that runs every day

Technology stops a lot. It doesn't stop someone being talked into a wire transfer. We run short, plain-language sessions built around the things that actually reach your inbox — no fear, no jargon, no hour-long compliance video nobody finishes.

  • Phishing & BEC
  • Password hygiene
  • MFA fatigue
  • Wi‑Fi & travel
  • Data handling
  • Reporting fast
Book a session

Approach

We work outward from what you can't afford to lose

Every engagement starts by naming the thing at the centre — the data, the system, the process that cannot stop. Controls are then justified by how close they sit to it, not by what a vendor is selling this quarter.

Defence in depth, layered from the outside in Five concentric layers. From the outside in: people and process, perimeter and remote access, network, endpoint and identity, and at the centre the crown jewels — the business data and systems that must not stop. PEOPLE & PROCESS Awareness training · runbooks · tabletop exercises PERIMETER & REMOTE ACCESS MFA everywhere · brokered vendor access · egress control NETWORK Segmentation · east–west visibility · traffic capture ENDPOINT & IDENTITY CIS-hardened builds · EDR · AD tiering · least privilege CROWN JEWELS Business data · key systems · what must not stop

How an engagement runs

Five stages, and you always know which one you're in

Fixed scope at every stage. You can stop after any of them and still hold something useful.

  1. 01

    Scope

    A discovery call, an asset and dependency inventory, and an honest read on where the real risk sits. No cost, no obligation.

    1 week
  2. 02

    Assess

    Technical assessment across network, identity and endpoint. Findings rated by exploitability and business consequence — not raw CVSS.

    2–3 weeks
  3. 03

    Roadmap

    A prioritised plan with effort, cost and an owner against every item. Written so your board and your technician both understand it.

    1 week
  4. 04

    Implement

    Hardening, segmentation, tooling and documentation — delivered in change windows that respect your operations.

    4–12 weeks
  5. 05

    Sustain

    Monitoring, patch cadence, quarterly review and an annual tabletop, so the posture you paid for is still there next year.

    Ongoing

Visibility

You can't defend what you can't see

Most environments we walk into are generating plenty of data and almost no answers. We fix that — so when something is wrong, you hear it from your own systems, not from a customer, your bank, or a note demanding payment.

Know the estate

What's actually on the network

A current, accurate picture of the devices, services and accounts you own. Nearly every estate holds more than its owners expect, and the surprises are rarely harmless.

Capture the evidence

What your systems already tell you

The logs almost always exist. We get them collected, retained long enough to investigate with, and put somewhere a person will actually look.

Establish the baseline

What normal looks like here

Alerting tuned to your environment, so what fires is worth attention — and so an investigation starts from evidence instead of guesswork.

We'll recommend whatever genuinely fits your environment, your budget and the size of your team — including telling you when you don't need to buy anything at all.

About

The security engineering big firms sell, sized for the rest of us

SYMATech is a technology consultancy based in Alberta. We were started on a straightforward observation: the security engineering that large enterprises buy isn't complicated — it's just expensive, and it's rarely offered to the organisations that need it most.

So we offer it. The same assessment discipline, the same hardening standards and the same investigative rigour — scoped and priced for a 40-person office, a professional practice or a growing business that has outgrown whoever set up its network five years ago.

Behind that is more than 25 years of hands-on work: building the networks, then breaking them on purpose, then defending them — and, when it comes to it, going through the wreckage afterwards to work out exactly what happened. We put people and the communities they serve first, and we'd rather tell you that you don't need something than sell it to you.

25+Years of hands-on IT and security experience
4Practices under one roof — IT, assurance, forensics, detection
A–ZProcurement through handover, one accountable team
1 dayTypical response to a new enquiry

Get started

Tell us what's keeping you up at night

The first conversation is a scoping call, not a sales call. Come with a problem — an audit you failed, a network nobody documented, an incident you're still piecing together — and you'll leave with a straight answer on what it takes to fix it.

  • Email admin@symatech.ca
  • Service area Alberta and remote across Canada
  • Response time Within one business day

We use what you send here to reply to your enquiry, and nothing else. No list, no resale.