Quick audit
For an SME wanting a first overview without long-term commitment.
- On-site visit, 4 hours.
- Team questionnaire, 30 min.
- Summary report with top 5 recommendations.
- Q&A after report delivery.
Starting at $800
Cybersecurity for SMEs — clear defense, verifiable results
Cyber attacks are expensive for small businesses: data loss, operational downtime, reputation damage. NEXUS AGENCE helps you identify vulnerabilities, harden your defenses, and train your team so everyone understands real risks — no jargon.
Audit in 4–6 weeks · detailed report · priority action plan · follow-up included
Three levels of engagement
You can start small (quick audit) and scale up to more robust protection. The key is identifying your real risks and putting in place what matters for your business.
For an SME wanting a first overview without long-term commitment.
Starting at $800
For an SME wanting to understand all risks and get a real action plan.
Starting at $2,000
For an SME wanting regular vigilance and guided corrections.
Starting at $400/month
Frequently asked
Quick audit: 4–6 hours on-site, report in 1 week. Full audit: 2 visits of 6–8 hours each, detailed report in 2 weeks. Ongoing monitoring takes a few hours per quarter.
Quick audit starts at $800. Full audit ranges from $2,000 to $3,500 depending on size. Ongoing monitoring varies from $300 to $500 per month. Prices include report, debrief and implementation advice.
Nothing. Your data stays with you. The audit report is covered by professional confidentiality. NEXUS AGENCE doesn't share it with anyone, doesn't send copies to vendors or insurers, and deletes it after two years.
No. The audit happens during normal hours. We want to see how things really work. Your team continues their tasks while we observe and ask questions.
At minimum, the IT manager (or whoever handles computers), a manager, and a few team members. Not everyone needs to be present—just enough to understand real practices.
You get a report with a prioritized action plan. NEXUS AGENCE can help implement fixes (web, infrastructure) or recommend a trusted local IT vendor for the rest.
The real landscape
An attacker doesn't pick the largest company: they pick the easiest. Without unique passwords, a tested backup and a response plan, an SME recovers more slowly — and pays more. These are the six scenarios seen most often in Quebec.
An invoice, a résumé, a delivery notice: the file looks ordinary and encrypts the files within minutes. The ransom demanded is rarely the real loss — the shutdown is.
An email impersonates a manager and requests a transfer. The money leaves before anyone calls to double-check. A phone confirmation almost always stops it.
The same password opens the email, the accounting software and the bank. A leak at any supplier becomes a key to everything else.
The backup file exists — but nobody has ever tried to restore it. On incident day, it turns out to be incomplete, encrypted, or stored on the same disk as the original.
The flaw isn't yours: it arrives through an update, a module or a subcontractor. Access granted "just for the trial" stays open months after.
The email account, the cloud access and the router password stay active after the departure. It isn't malice: it's an oversight, and it costs.
The method
An audit isn't a report you hand over and forget. It's a short loop: understand, test, explain, fix, re-verify.
A 30-minute call to set the perimeter: number of workstations, servers, business software, key people. Together we decide what is included and what is not.
Workstations, accounts, backups, network, email, websites. Collection happens during normal hours, without closing the business, with the people who actually use the tools.
We test what must be tested, with written authorisation and without disrupting operations: restoring a backup, password strength, exposure of remote access.
An executive summary in plain language for management, then technical detail for whoever runs IT. Every finding carries its priority, estimated cost and deadline.
A shared checklist tracks every fix, from "to do" to "verified". Corrected items are retested — not just ticked on trust.
Depending on the chosen package, the agency returns each quarter for a quick audit, updates the action plan and flags what has changed in the environment.
The scope
Eight areas are reviewed in every full audit. They cover the essentials of what brings an SME down — and each produces verifiable findings, not impressions.
Shared accounts, weak or reused passwords, missing two-factor authentication on email and sensitive access. It's the most common way in.
Frequency, location, the 3-2-1 rule, encryption and above all a real restore test. A backup never restored is not a backup.
System and software updates, active antivirus, administrator accounts kept separate from daily accounts, personal devices connected to the network.
Who has access to what, and who should. Former employees, interns and subcontractors are the most often forgotten.
Guest network separated from the work network, router password, remote access left open without need, equipment left on defaults.
Filtering, domain authentication (SPF, DKIM, DMARC), a reporting procedure for the team. Most incidents start with an email.
Certificate, CMS updates, administrator accounts, site backups. What the agency hosts, it also checks.
Who calls whom, in what order, with which offline numbers. A one-page written plan beats good intentions in a panic.
Compliance · Quebec Law 25
Quebec's Act to modernise legislative provisions on the protection of personal information imposes concrete obligations on businesses. Most are simple — provided they are done before the incident, not after.
Someone must be appointed responsible for the protection of personal information, with contact details published. Often it's the owner — which is perfectly acceptable.
Any incident presenting a risk of serious harm must be recorded, and affected people informed. The register is kept calmly, not in an emergency.
Why each piece of information is collected, how long it is kept, who it is shared with. A clear policy avoids vague promises.
Access, correction, withdrawal of consent: these requests must be handled within the prescribed timeframes. A written process beats memory.
NEXUS AGENCE is not a law firm and does not replace legal advice. What the audit provides: a map of the data actually held, the access points that expose it, and the technical fixes that make those decisions enforceable.
The limits
An honest audit also states what it leaves aside. Here are the four limits, set out in advance — to avoid misunderstandings and billing surprises.
Verifications are done with written authorisation, on your infrastructure. An intrusive test on a third-party service (host, business software) requires a separate mandate and the supplier's agreement.
A closed business application cannot be audited from the inside without the supplier's access. In that case, the audit checks configuration, accounts and updates — not the code.
An audit is a dated snapshot. Continuous detection, alerts and uptime reports belong to the 24/7 monitoring service, separate and optional.
Support covers technical and organisational aspects. For an interpretation of Law 25 or contract drafting, the agency refers you to a lawyer — and provides the necessary technical material.
Glossary
A report is only worth what it is understood to be worth. Here are the terms that come up most often, translated into plain language.
Software that encrypts files and demands a ransom to decrypt them. The real defence isn't payment: it's a backup restored successfully.
A password plus a second factor (app, key, code). Even if the password leaks, access stays closed. It's the most cost-effective security gain.
A message impersonating a trusted sender to get a click, a password or a transfer. Training the team is the best defence.
RPO: how much data you accept losing (say 24 h). RTO: how long you accept the business staying down. Two numbers to decide in advance.
Each person holds only the access their work requires, nothing more. A sales account doesn't need to be network administrator.
Three copies of the data, on two different media, one of them off-site. The modern version adds an immutable copy, which ransomware cannot encrypt.
Next steps
Contact NEXUS AGENCE for a free 20-minute discussion. We'll understand your situation and suggest the right audit for you, no pressure.
Related services
Recovery plans and fast recovery in case of incident. Make sure your backups actually work.
Read more →
Managed servers, current SSL, automatic updates and 24/7 monitoring. Simple infrastructure, no headaches.
Read more →
Continuous monitoring, real-time alerts and uptime reports. Be the first to know if something goes wrong.
Read more →