20+ Years in Cybersecurity

20+ Years in Cybersecurity

20+ Years in Cybersecurity

CISSP Certified

20+ Years in Cybersecurity

20+ Years in Cybersecurity

ISO/IEC 27001 Lead Auditor

ISO/IEC 27001 Lead Auditor

ISO/IEC 27001 Lead Auditor

NERC CIP Audit Experience

ISO/IEC 27001 Lead Auditor

ISO/IEC 27001 Lead Auditor

What We Do

Governance, Risk & Compliance

Governance, Risk & Compliance

Governance, Risk & Compliance

ISO/IEC 27001, NERC CIP, ITSG-33 and PCI-DSS readiness, threat and risk assessments, privacy impact assessments and security policy.

OT & Critical Infrastructure

Governance, Risk & Compliance

Governance, Risk & Compliance

Security for industrial control systems, SCADA, smart grid and distributed energy resources, designed around safety and availability.

PKI & Trust Services

Governance, Risk & Compliance

Assessments & Testing

Vendor-independent public key infrastructure design, migration and certificate management, plus strong authentication.

Assessments & Testing

Training & Security Talent

Assessments & Testing

Vulnerability assessments, penetration testing and mobile application security assessments with prioritized remediation.

Architecture & Advisory

Training & Security Talent

Training & Security Talent

Zero Trust, identity and access management, cloud security and virtual CISO advisory for leadership teams.

Training & Security Talent

Training & Security Talent

Training & Security Talent

Hands-on courses, awareness programs and CISSP preparation, plus access to specialized cybersecurity professionals.

Training Built by Practitioners Who Teach

Our courses are designed and delivered by working cybersecurity professionals who also teach IT and OT security in higher education, so every module is grounded in real audits, real incidents and current standards.

Latest Insights

Beyond the Checklist

Establish Your Trust Center

Beyond the Checklist

Why compliance should be the by-product of a well-architected security program, not the goal.

ICS Security

Establish Your Trust Center

Beyond the Checklist

How manipulated sensor readings and controller commands can hide an attack from operators.

Establish Your Trust Center

Establish Your Trust Center

Establish Your Trust Center

What it takes to design, operate and migrate a vendor-independent public key infrastructure.

Frequently Asked Questions

Please reach us at info@csmic.ca if you cannot find an answer to your question.

CSMIC is a privately owned Canadian cybersecurity consulting firm, founded in 2017 and based in Toronto, Ontario. It is a company, not a government program, product or certification. Our practitioners and educators provide IT and OT security consulting, compliance and audit readiness, PKI services, cybersecurity training and specialized security talent.

Governance, risk and compliance (ISO/IEC 27001, NERC CIP, ITSG-33 and PCI-DSS), OT and critical-infrastructure security, PKI and trust services, vulnerability assessments and penetration testing, security architecture and virtual CISO advisory, and hands-on cybersecurity training.

Yes. Our Essential Security Assessment package is designed for small businesses that want a clear picture of their security posture. The Advanced Cyber Defense and Premium Cybersecurity Assurance packages scale up for medium-sized businesses and complex environments.

We are based in Toronto, Ontario, and work with organizations across the Greater Toronto Area, Ontario and Canada, on-site or remotely. Email info@csmic.ca or use our contact form to start a conversation.

Look for certified practitioners (such as CISSP or ISO/IEC 27001 Lead Auditor), experience in your sector and with the standards you must meet, vendor independence, a clearly scoped proposal with defined deliverables, and references. Ask how findings will be prioritized and how knowledge will be transferred to your team.

Start with the controls that stop most attacks: multi-factor authentication, timely patching, tested offline backups, phishing awareness training, least-privilege access and an incident response plan. The Canadian Centre for Cyber Security's baseline controls for small and medium organizations are a good starting point.

Yes. We run gap assessments, readiness reviews and internal audits against standards such as ISO/IEC 27001, NERC CIP, ITSG-33 and PCI-DSS, and help you build the evidence and practices auditors look for.

Yes. We deliver instructor-led workshops, hands-on labs, security awareness sessions and CISSP exam preparation, on-site or online, designed by practitioners who teach cybersecurity at Ontario colleges.

Yes. We start from your risks, regulatory obligations and operations, not from a template. We design a security framework and methodology tailored to your organization, map it to the standards you need to meet, such as ISO/IEC 27001, the NIST Cybersecurity Framework, ITSG-33 or NERC CIP, and phase the roadmap to fit your budget and team.

A practical four-step approach. Identify: critical assets, systems and their dependencies. Assess: threats and risks across IT and OT. Plan: a prioritized, phased roadmap against your requirements and risk. Implement: hands-on support for implementation, testing and evidence, so improvements last. We scale the depth of each step to the size and complexity of your organization.