Public sector and municipalities.
Municipalities and public agencies carry broad service obligations on constrained budgets, increasingly on infrastructure that was never designed to be internet facing. An assessment here has to speak to council and to the people running the systems in the same document.
Regulatory anchor. Ontario's Bill 194 and its cyber security directives place explicit expectations on public sector entities to assess and report on risk.
What we assess that is specific to it.
The method does not change. What changes is what we look hardest at, and what counts as a serious result.
Legacy operational technology. Systems that predate the internet, now connected to modern service delivery and exposed in ways their designers never anticipated.
Shared services and third parties. Platforms and providers carrying resident data across multiple departments and agencies.
Assessments that survive council. Findings framed to support a budget request and to withstand the audit that follows it.
What counts as severe here.
Impact is calibrated to the sector. The same threat carries a different weight depending on what it would actually cost.
| Rating | What it means in this sector |
|---|---|
| Severe | Sustained loss of a resident-facing service, or exposure of resident data at scale, with statutory reporting triggered. |
| Major | Disruption to internal operations requiring council involvement and public communication. |
| Moderate | Contained service degradation absorbed within existing resources. |
What the report has to survive.
A public sector report is read by people who did not commission it, in a council chamber and later in an audit. It has to be defensible line by line, tied to the directives that apply, and free of the inflated severity that erodes trust the first time it is questioned.
Working in public sector?
Tell us what you run and what you need to decide. We will tell you plainly whether we are the right people for it.