Risk means something different in every sector.
The method does not change between engagements. What changes is what counts as a severe impact, which regulator is reading over your shoulder, and what a realistic threat looks like in your environment. These are the sectors where we work most.
Public sector and municipalities
Municipalities and public agencies carry broad service obligations on constrained budgets, and increasingly on infrastructure that was never designed to be internet facing. An assessment here has to speak to council and to the people running the systems in the same document.
Ontario's Bill 194 and the accompanying cyber security directives place explicit expectations on public sector entities to assess and report on risk.
- Legacy operational technology sitting alongside modern service delivery
- Shared services and third-party platforms carrying resident data
- Assessments written to survive a council presentation and a subsequent audit
- Findings framed to support budget requests rather than just record problems
Financial services
Regulated financial institutions face a supervisory expectation that risk is identified, measured and governed continuously, not reviewed once a year. The assessment has to withstand scrutiny from a second line of defence and from the regulator behind it.
OSFI Guideline B-13 sets expectations for technology and cyber risk management at federally regulated financial institutions.
- Third-party and concentration risk across critical service providers
- Control mapping aligned to existing risk taxonomies and registers
- Inherent and residual scoring that fits established governance reporting
- Evidence trails that hold up under internal audit and supervisory review
Healthcare
Health information carries some of the highest impact ratings we assign, because the consequences of exposure are personal, permanent and legally consequential. Clinical continuity raises the stakes further, since a control that disrupts care is not a control anyone will keep.
Ontario's PHIPA imposes duties on custodians of personal health information, including safeguards and breach notification.
- Personal health information across clinical and administrative systems
- Connected medical devices and the networks they depend on
- Availability weighted properly, since downtime is a patient safety issue
- Recommendations tested against clinical workflow before they are made
Technology and SaaS
When your product is the system, your customers inherit your risk, and their procurement teams will ask you to prove you have measured it. An assessment often has to serve two audiences at once, your own engineering roadmap and your customers' due diligence.
Enterprise procurement and assurance programmes routinely request evidence of a structured, framework-aligned risk assessment.
- Application and platform risk assessed against the real deployment
- Supply chain and dependency exposure across the build pipeline
- Findings that map onto an engineering backlog rather than a policy binder
- Documentation your customers' security reviewers will accept
By sector.
What changes when the method meets a specific regulatory world.
Not on this list?
Sector experience shapes how we calibrate impact and which threats we treat as credible, and it is not a prerequisite for good work. The method applies wherever there are assets worth protecting and decisions worth informing.
Tell us what you run and what you are deciding, and we will tell you plainly whether we are the right people for it.