Governance. Risk.
Compliance.

Protecting your business isn't just about firewalls. ETS GRC helps Manitoba organizations build the policies, frameworks, and audit-readiness they need to operate confidently - and stay that way.

+ Risk Assessments

+ SOC 2 & ISO 27001

+ PIPEDA Compliance

+ Policy Development

+ Vendor Risk Management

What is GRC

Three Pillars.
One Program.

GRC isn't a single product - it's a structured approach to running your business securely, responsibly, and in line with the rules that govern your industry.

G

Governance

The policies, accountability structures, and decision-making frameworks that ensure your organization uses technology and data responsibly - and that everyone knows the rules.

R

risk

Identifying, measuring, and prioritizing the threats to your operations - from cybersecurity vulnerabilities to third-party vendor exposure - so you can act before something goes wrong.

C

Compliance

Demonstrating to clients, insurers, regulators, and auditors that your organization meets the standards required in your industry - whether that's PIPEDA, SOC 2, or ISO 27001.

What We Deliver.

Practical GRC programs built for Manitoba businesses - not boilerplate checklists from a national consulting firm.

CoAudit Readiness

Compliance Audits

Prepare for - and pass - SOC 2 Type I/II, ISO 27001, and other formal audits. We guide you through evidence collection, control mapping, and remediation before the auditors arrive.

SOC 2 Type I/II

ISO 27001

CIS Controls

Evidence Collection

Ongoing Support

Privacy & Regulatory

PIPEDA Compliance

Ensure your organization handles personal information in line with Canadian privacy law. We assess your data flows, consent practices, and breach response procedures.

Data Flow Mapping

Consent Management

Breach Response

Privacy Policies

Manitoba Focus

Foundation

Policy & Framework Development

We build the written policies, standards, and procedures your organization needs - acceptable use, incident response, data classification, access control, and more.

Acceptable Use Policy

Incident Response

Data Classification

Access Control

Custom Deliverables

Third-Party Risk

Vendor Risk Management

Your risk doesn't stop at your perimeter. We assess the security posture of your key vendors and suppliers - and help you build a repeatable third-party review process.

Vendor Questionnaires

Supply Chain Risk

Contract Review

Ongoing Monitoring

On-Site · Remote

Add-On

GRC Program Management

Don't have an internal compliance team? We act as your outsourced GRC function - maintaining your program, tracking controls, and keeping you audit-ready year-round.

vCISO Support

Control Tracking

Board Reporting

Annual Review

Retainer Available

We Speak Your
Auditor's Language.

Our GRC team works across the major frameworks used in Canada and North America - so you're covered no matter what your clients, insurers, or regulators require.

SOC 2 Type I & II

ISO 27001

PIPEDA / Bill C-11

NIST CSF

CIS Controls v8

Cyber Essentials

HIPAA (Cross-Border)

PCI-DSS

Manitoba PHIA

Cyber Insurance Requirements

From Discovery
to Defended.

01

Discovery Call

We learn about your business, your industry, your current controls, and what's driving the need for GRC - compliance deadline, cyber insurance, client requirement, or proactive planning.

02

Assessment & Gap Analysis

We evaluate your environment against the relevant framework or standard, document your current state, and identify the gaps between where you are and where you need to be

03

Roadmap & Remediation

You receive a prioritized remediation plan with clear ownership, timelines, and effort estimates. We can execute alongside you or hand off to your internal team.

04

Ongoing Management

GRC isn't a one-time project. We offer retainer-based program management to keep your controls current, your policies updated, and your team audit-ready all year.

Compliance Backed
By Your IT Team.

Most GRC consultants hand you a report and leave. ETS manages your IT environment - so we can actually implement what we recommend.

Context

We Know Your Environment

As your managed IT partner, we already understand your Microsoft 365 tenant, your network, your vendors, and your workflows. GRC assessments built on real knowledge - not a questionnaire.

Local

Manitoba-Specific Expertise

We understand the compliance landscape for Winnipeg and Manitoba businesses - PIPEDA, PHIA, cyber insurance requirements, and the specific industries that dominate our local economy.

End-to-End

Assess, Remediate, Maintain

We don't just write reports. Our team can close the gaps we identify - through our managed IT, SOC, and training services - so recommendations actually get implemented.

Insurable

Built for Cyber Insurance

Cyber insurance underwriters increasingly require documented controls and evidence of compliance. Our GRC programs are designed to satisfy insurer requirements and reduce your premium exposure.

Get Started

Ready to get
compliant?

Tell us what's driving your GRC need - audit deadline, insurance requirement, or building from scratch. We'll recommend the right starting point.

Book a grc Assessment

Explore Our SOC →