Skip to content

Security Audits

Find your security holes — before someone else does.

A senior-led, non-destructive audit of your websites, servers, network, email, and accounts — with a clear, prioritized report and a plan to fix what matters. Start free.

43–46%of cyberattacks target businesses with fewer than 1,000 employees
88%of small-business breaches now involve ransomware
1 in 5attacks exploit a known, fixable vulnerability

Source: Verizon 2025 Data Breach Investigations Report (DBIR).

Sound familiar?

Signs it’s time for a security audit

  • You’ve never had an independent security review
  • You handle customer data, logins, or payments
  • Staff share logins or don’t all use MFA
  • You’re not sure your servers and site are patched
  • A client, insurer, or investor is asking about your security
  • You had a scare — phishing, a suspicious login, a near-miss
  • You don’t know if your backups actually work

If you nodded at even one — start with a free Security Health Check.

What we check

A full picture — not just your website

Websites & Web Apps

Exposed data, weak authentication, injection, missing security headers, and misconfigurations.

Servers & Infrastructure

Patch levels, hardening, exposed services, and configuration across on-prem and cloud servers.

Networks

Firewall rules, segmentation, VPN, and Wi-Fi — reviewed for gaps attackers look for.

Cloud, Microsoft 365 & Google

M365 / Workspace security posture, permissions, sharing, and admin configuration.

Email & Identity

SPF, DKIM, DMARC, MFA coverage, credential hygiene, and account access.

Backups & Recovery

Whether backups exist, are secured, and can actually be restored when it matters.

How it works

Start free. Pay for what you need.

A no-cost health check first — then only go as far as your risk requires.

Security Health Check

Free

Same week

A senior engineer reviews your setup and runs automated checks, then gives you a red / yellow / green snapshot of where you stand — no commitment.

  • Quick external review + automated scan
  • Your top exposure risks
  • Honest “how bad is it?” answer
Start free

Remediation & Hardening

from $6,000 CAD

1–3 weeks

We don’t just find the holes — we close them: patching, security headers, MFA, backups, monitoring, and access clean-up.

  • Fix criticals & high-risk items
  • MFA, backups & monitoring
  • Verified, documented hardening
Start here

Ongoing Security

from $2,500 CAD / mo

Monthly

Security isn’t a one-time project. Continuous review, patching, and fractional security support so you stay protected as you grow.

  • Continuous review & patching
  • Fractional security engineering
  • Quarterly re-audits
Start here

Prices in CAD. The audit is credited toward remediation — the health check and audit pay for themselves.

Why IT-TECH

The team you want reviewing your security

We audit and harden for a living

This is our craft, not a checkbox. Our own systems ship locked down (HSTS, CSP, MFA) — we hold yours to the same standard.

Non-destructive and safe

Authorized, read-first testing that won’t disrupt your business — no reckless “break it to prove it”.

Findings you can act on

Not a 90-page scanner dump. A clear, prioritized report a human can read — and a fixed-scope plan to fix it.

Confidential & senior-led

NDA-backed, least-privilege access, run by senior engineers with 15+ years — your data and findings stay yours.

FAQ

Questions before you book

Is the audit safe — will it break anything?

No. Our audits are authorized and non-destructive: we review configuration, access, and exposure without disruptive or damaging testing. We don’t take systems down to prove a point.

What do I actually get?

A clear, prioritized findings report (by severity) with plain-language explanations and a fixed-scope remediation plan — the same format behind our own hardened stack. Not a raw scanner dump.

How much does it cost?

The Security Health Check is free. A full Security Audit starts at $1,500 CAD and is credited toward any remediation. Fixes are quoted as fixed scope after the audit.

How fast can you start?

The Health Check happens the same week. A full audit typically takes 3–5 business days; remediation runs 1–3 weeks depending on findings.

Is everything kept confidential?

Yes — we work under NDA on request, use least-privilege access, and your systems, data, and findings remain entirely yours.

Do you fix what you find, or just report it?

Both options. We can remediate and harden directly, or hand your team a clear plan to do it — your call.

Free Security Health Check

Find out where you stand — before an attacker does.

Tell us what you run — website, servers, email, cloud. A senior engineer reviews it and sends back a clear risk snapshot. No cost, no obligation.

  • A red / yellow / green risk snapshot
  • The top exposures we spot
  • An honest “how urgent is this?” answer + next steps

Tip: tell us your website, what servers/cloud you use (e.g. Microsoft 365, Google Workspace, AWS), and anything you’re worried about.

🔒 NDA on request · non-destructive · reply within 1 business day

Hear From Our Clients

We value our partnerships and showcase the success we played a role in:

“
IT-TECH successfully launched our new website, incorporating all our requested features and quickly responding to feedback.
Barton Tabah
“
IT-TECH has been instrumental in launching and supporting our websites, including cadrail.ca, cadrailfleetservices.ca, and the redesign of primerailway.com.
Danielle Lajoie
“
IT-TECH has been invaluable in launching the AppliedLMS MVP. Their ongoing support and responsiveness, has been crucial to the project’s continued progress.
Emma Chille