Cybersecurity for SMEs — clear defense, verifiable results

Your data is not negotiable.

Cyber attacks are expensive for small businesses: data loss, operational downtime, reputation damage. NEXUS AGENCE helps you identify vulnerabilities, harden your defenses, and train your team so everyone understands real risks — no jargon.

Audit in 4–6 weeks · detailed report · priority action plan · follow-up included

Full auditAnalysis of entry points, passwords, backups, access and logs.
Clear reportExecutive summary in plain English, no unnecessary jargon.
Action planPrioritized steps, estimated costs and realistic timelines for each fix.
Team trainingHalf-day workshop: phishing, passwords, backups and best practices.
6-month follow-upPeriodic checks that corrections have been properly implemented.
100% confidentialData covered by professional secrecy, no third-party sharing.

Three levels of engagement

Every SME has different needs.

You can start small (quick audit) and scale up to more robust protection. The key is identifying your real risks and putting in place what matters for your business.

Quick audit

For an SME wanting a first overview without long-term commitment.

  • On-site visit, 4 hours.
  • Team questionnaire, 30 min.
  • Summary report with top 5 recommendations.
  • Q&A after report delivery.

Starting at $800

Full audit

For an SME wanting to understand all risks and get a real action plan.

  • Two visits: assessment (6 h) and debrief (2 h).
  • Backup and recovery verification.
  • Testing of existing security measures.
  • Detailed report with prioritization and budgets.
  • Half-day team training workshop.

Starting at $2,000

Ongoing monitoring

For an SME wanting regular vigilance and guided corrections.

  • Full audit + quick audit every 3 months.
  • Correction tracking (shared checklist).
  • Alert if anomalies detected (logs, access).
  • Quarterly action plan updates.
  • Annual guided password overhaul.

Starting at $400/month

Frequently asked

What SMEs often ask.

How long does an audit take?

Quick audit: 4–6 hours on-site, report in 1 week. Full audit: 2 visits of 6–8 hours each, detailed report in 2 weeks. Ongoing monitoring takes a few hours per quarter.

What's the actual cost?

Quick audit starts at $800. Full audit ranges from $2,000 to $3,500 depending on size. Ongoing monitoring varies from $300 to $500 per month. Prices include report, debrief and implementation advice.

What do you do with my data?

Nothing. Your data stays with you. The audit report is covered by professional confidentiality. NEXUS AGENCE doesn't share it with anyone, doesn't send copies to vendors or insurers, and deletes it after two years.

Do we close during the audit?

No. The audit happens during normal hours. We want to see how things really work. Your team continues their tasks while we observe and ask questions.

Who needs to be there?

At minimum, the IT manager (or whoever handles computers), a manager, and a few team members. Not everyone needs to be present—just enough to understand real practices.

What comes next?

You get a report with a prioritized action plan. NEXUS AGENCE can help implement fixes (web, infrastructure) or recommend a trusted local IT vendor for the rest.

The real landscape

An SME is never too small to be attacked. It is often the most profitable target.

An attacker doesn't pick the largest company: they pick the easiest. Without unique passwords, a tested backup and a response plan, an SME recovers more slowly — and pays more. These are the six scenarios seen most often in Quebec.

Ransomware in an attachment

An invoice, a résumé, a delivery notice: the file looks ordinary and encrypts the files within minutes. The ransom demanded is rarely the real loss — the shutdown is.

CEO fraud

An email impersonates a manager and requests a transfer. The money leaves before anyone calls to double-check. A phone confirmation almost always stops it.

Reused passwords

The same password opens the email, the accounting software and the bank. A leak at any supplier becomes a key to everything else.

Backups never tested

The backup file exists — but nobody has ever tried to restore it. On incident day, it turns out to be incomplete, encrypted, or stored on the same disk as the original.

Compromised supplier or software

The flaw isn't yours: it arrives through an update, a module or a subcontractor. Access granted "just for the trial" stays open months after.

Staff departures, forgotten access

The email account, the cloud access and the router password stay active after the departure. It isn't malice: it's an oversight, and it costs.

The method

Five steps, from the first call to verifying the fixes.

An audit isn't a report you hand over and forget. It's a short loop: understand, test, explain, fix, re-verify.

Step 130 min

Scoping

A 30-minute call to set the perimeter: number of workstations, servers, business software, key people. Together we decide what is included and what is not.

Step 2D+0 to D+5

Collection

Workstations, accounts, backups, network, email, websites. Collection happens during normal hours, without closing the business, with the people who actually use the tools.

Step 3controlled

Verifications

We test what must be tested, with written authorisation and without disrupting operations: restoring a backup, password strength, exposure of remote access.

Step 41 to 2 weeks

Report and debrief

An executive summary in plain language for management, then technical detail for whoever runs IT. Every finding carries its priority, estimated cost and deadline.

Step 5follow-up

Fix and re-verify

A shared checklist tracks every fix, from "to do" to "verified". Corrected items are retested — not just ticked on trust.

And thenongoing

Vigilance

Depending on the chosen package, the agency returns each quarter for a quick audit, updates the action plan and flags what has changed in the environment.

The scope

What the audit covers, concretely.

Eight areas are reviewed in every full audit. They cover the essentials of what brings an SME down — and each produces verifiable findings, not impressions.

Identities and passwords

Shared accounts, weak or reused passwords, missing two-factor authentication on email and sensitive access. It's the most common way in.

Backups and restore

Frequency, location, the 3-2-1 rule, encryption and above all a real restore test. A backup never restored is not a backup.

Workstations

System and software updates, active antivirus, administrator accounts kept separate from daily accounts, personal devices connected to the network.

Accounts and permissions

Who has access to what, and who should. Former employees, interns and subcontractors are the most often forgotten.

Network and Wi-Fi

Guest network separated from the work network, router password, remote access left open without need, equipment left on defaults.

Email and phishing

Filtering, domain authentication (SPF, DKIM, DMARC), a reporting procedure for the team. Most incidents start with an email.

Websites and hosting

Certificate, CMS updates, administrator accounts, site backups. What the agency hosts, it also checks.

Incident response

Who calls whom, in what order, with which offline numbers. A one-page written plan beats good intentions in a panic.

Compliance · Quebec Law 25

Law 25 doesn't demand perfection. It demands written decisions.

Quebec's Act to modernise legislative provisions on the protection of personal information imposes concrete obligations on businesses. Most are simple — provided they are done before the incident, not after.

Designated officer

Someone must be appointed responsible for the protection of personal information, with contact details published. Often it's the owner — which is perfectly acceptable.

Incident register

Any incident presenting a risk of serious harm must be recorded, and affected people informed. The register is kept calmly, not in an emergency.

Policies and consent

Why each piece of information is collected, how long it is kept, who it is shared with. A clear policy avoids vague promises.

Individuals' rights

Access, correction, withdrawal of consent: these requests must be handled within the prescribed timeframes. A written process beats memory.

NEXUS AGENCE is not a law firm and does not replace legal advice. What the audit provides: a map of the data actually held, the access points that expose it, and the technical fixes that make those decisions enforceable.

The limits

What a NEXUS AGENCE audit does not do.

An honest audit also states what it leaves aside. Here are the four limits, set out in advance — to avoid misunderstandings and billing surprises.

No unauthorised penetration test

Verifications are done with written authorisation, on your infrastructure. An intrusive test on a third-party service (host, business software) requires a separate mandate and the supplier's agreement.

No proprietary code review without access

A closed business application cannot be audited from the inside without the supplier's access. In that case, the audit checks configuration, accounts and updates — not the code.

No real-time monitoring without a 24/7 contract

An audit is a dated snapshot. Continuous detection, alerts and uptime reports belong to the 24/7 monitoring service, separate and optional.

No legal advice

Support covers technical and organisational aspects. For an interpretation of Law 25 or contract drafting, the agency refers you to a lawyer — and provides the necessary technical material.

Glossary

The words we use, explained simply.

A report is only worth what it is understood to be worth. Here are the terms that come up most often, translated into plain language.

Ransomware

Software that encrypts files and demands a ransom to decrypt them. The real defence isn't payment: it's a backup restored successfully.

Two-factor authentication (MFA)

A password plus a second factor (app, key, code). Even if the password leaks, access stays closed. It's the most cost-effective security gain.

Phishing

A message impersonating a trusted sender to get a click, a password or a transfer. Training the team is the best defence.

RPO / RTO

RPO: how much data you accept losing (say 24 h). RTO: how long you accept the business staying down. Two numbers to decide in advance.

Least privilege

Each person holds only the access their work requires, nothing more. A sales account doesn't need to be network administrator.

The 3-2-1 rule

Three copies of the data, on two different media, one of them off-site. The modern version adds an immutable copy, which ransomware cannot encrypt.

Next steps

Ready to verify your defenses?

Contact NEXUS AGENCE for a free 20-minute discussion. We'll understand your situation and suggest the right audit for you, no pressure.

FR