Managed Cybersecurity — Winnipeg

Your Threat Surface Is
Larger Than You Think.

Endpoints, email, identities, firewalls, cloud - attackers only need one gap. ETS closes every layer with managed cybersecurity backed by the only 24/7 Security Operations Centre in Manitoba.

24/7

SOC Monitoring

<15M

Mean Detection Time

100%

manitoba Engineers

Only

SOC in Manitoba

+ 24/7 SOC with Human Analysts

+ EDR / XDR Protection

+ Firewall Management

+ Penetration Testing

+ Email Security & DMARC

+ Vulnerability Management

+ Identity & Zero Trust

+ Dark Web Monitoring

Most Businesses Are
Already Compromised.

The average breach goes undetected for 207 days. By the time you know something happened, the damage is done. These are the gaps we close..

01

Antivirus Isn't Enough

Modern attacks live in memory, mimic legitimate processes, and use your own OS tools against you. Signature-based antivirus misses the majority of advanced threats deployed by criminal groups today.

97% of malware uses unique file signatures — bypassing traditional AV

02

Your Email Is the Front Door

Over 90% of breaches begin with a phishing email or business email compromise. Attackers don't need to hack your systems when they can simply trick your people into handing over access.

BEC losses now exceed ransomware losses globally — most go unreported

03

Your Credentials Are Already Leaked

Billions of credentials from third-party breaches are actively traded on criminal marketplaces. The odds that at least one employee in your organization has reused a compromised password are extremely high.

24 billion credentials currently circulating on the dark web

04

No SOC Means No Visibility

Modern attacks live in memory, mimic legitimate processes, and use your own OS tools against you. Signature-based antivirus misses the majority of advanced threats deployed by criminal groups today.Tools alone don't stop attacks - analysts do. Without a Security Operations Centre reviewing alerts around the clock, threats sit undetected while attackers move laterally through your environment at their own pace.

Mean time to detect a breach without a SOC: 207 days

24/7

SOC Monitoring
365 Days a Year

<15M

Mean Time
to Detect

Only

SOC Provider
in Manitoba

100%

Winnipeg-Based
Engineering Team

Every Layer.
Completely Covered.

Click any service to see exactly what's included, what tools we deploy, and how we've implemented it for Manitoba businesses like yours.

01

Endpoint Detection & Response

Next-generation EDR and XDR deployed across every device - detecting, isolating, and neutralising threats that bypass traditional antivirus before they spread through your environment.

EDR

XDR

Threat Hunting

Auto-Isolation

CrowdStrike

SentinelOne

+

What's Included

24/7 endpoint monitoring & alerting

Behavioural threat detection (AI-driven)

Automatic threat containment & isolation

Fileless & memory-based attack protection

Ransomware detection & file rollback

Proactive threat hunting by SOC analysts

Supported Platforms

CrowdStrike Falcon

SentinelOne Singularity

Microsoft Defender for Endpoint

Windows, macOS & Linux

Virtual & cloud workloads

Servers & workstations

Reporting & Response

Real-time incident dashboards

Monthly executive threat summary

Full incident timeline & forensics

SOC analyst triage on every alert

Post-incident remediation guidance

Ticketing system integration

Antivirus misses modern attacks. EDR detects threats by behaviour - not just known signatures - catching what traditional tools never see.

02

Security Operations Centre (SOC)

Winnipeg's only 24/7 SOC - certified analysts monitoring your entire environment around the clock, triaging every alert, and responding to incidents before they become disasters.

24/7 Monitoring

SIEM

Incident Response

Alert Triage

Threat Intel

Only in Manitoba

+

SOC Coverage

24/7/365 analyst-monitored alerting

SIEM log ingestion & correlation

Cross-source detection (endpoint, email, network, identity)

Real-time threat intelligence feeds

Anomaly detection & environment baselining

Incident escalation & containment

What Makes ETS Different

Only SOC physically based in Manitoba

No offshore alert routing - ever

Senior analysts on every shift

Mean detection time under 15 minutes

Dedicated client Slack / Teams channel

Named analyst - not a call centre

Incident Response

Defined IR playbooks per threat type

Immediate containment on confirmed threats

Evidence preservation & chain of custody

PIPEDA breach notification support

Cyber insurance claim documentation

Post-incident root cause analysis

Tools without analysts are just noise. Our SOC turns security alerts into human-reviewed, actioned responses - not a dashboard nobody watches at 3am.

03

Firewall Management

Enterprise-grade firewall deployment, configuration, and ongoing management. We harden your network perimeter, enforce segmentation, and keep rule sets current as your environment changes.

NGFW

Fortinet

Palo Alto

Segmentation

IPS/IDS

SSL Inspection

+

Firewall Services

Next-gen firewall (NGFW) deployment

Rule set design & ongoing management

Intrusion prevention system (IPS/IDS)

Application-layer traffic inspection

Network segmentation & VLAN policy

SSL/TLS deep packet inspection

Supported Platforms

Fortinet FortiGate

Palo Alto Networks

Cisco Firepower / ASA

Meraki MX series

Sophos XGS

Azure & AWS network policies

Ongoing Management

24/7 firewall health monitoring via SOC

Firmware & threat signature updates

Quarterly rule set reviews & cleanup

Geo-blocking & threat intelligence feeds

Policy violation alerting

Traffic & anomaly reporting

A misconfigured firewall is as dangerous as no firewall. Rule sets accumulate exceptions over years - we review and harden them on a regular cadence.

04

Email Security

Phishing, business email compromise, and malicious attachments remain the #1 breach vector. We layer advanced filtering, anti-spoofing controls, and simulated training to close that door permanently.

Anti-Phishing

BEC Protection

DMARC

Sandboxing

Proofpoint

Phishing Simulations

+

Email Protection

Advanced anti-phishing & BEC detection

Malicious attachment sandboxing

URL rewriting & real-time link scanning

Executive impersonation protection

Spam & bulk mail filtering

Quarantine management & reporting

Email Authentication (DMARC)

DMARC policy deployment & enforcement

DKIM signing & SPF alignment

Domain spoofing prevention

Lookalike domain monitoring

Third-party sender verification

DMARC aggregate reporting dashboard

Phishing Simulations

Monthly simulated phishing campaigns

Targeted spear-phishing scenarios

Click rate tracking & trend reporting

Automatic micro-training on failure

Department-level risk scoring

Executive board reporting

Over 90% of breaches start with an email. Advanced filtering combined with regular staff simulations is the highest-ROI security control you can deploy.

05

Vulnerability Management

Continuous scanning of your internal and external attack surface - identifying, prioritising, and tracking vulnerabilities so your team always knows what to fix first and why it matters.

Continuous Scanning

Patch Priority

Tenable

CVE Tracking

Risk Scoring

Attack Surface Mgmt

+

Scanning Coverage

Continuous internal network scanning

External attack surface monitoring

Web application vulnerability scanning

Cloud configuration assessment (CIS Benchmarks)

Active Directory security auditingn

Credential exposure scanning

Prioritisation & Patching

CVSS & exploit probability (EPSS) scoring

Asset-based risk context (crown jewels first)

Patch prioritisation recommendations

Automated patch deployment for endpoints

Exception management & remediation tracking

SLA-driven timelines

Tools & Reporting

Tenable.io / Nessus

Qualys VMDR

Microsoft Defender Vulnerability Mgmt

Weekly vulnerability digest

Executive risk posture score

Compliance evidence exports (PIPEDA, ISO)

You can't fix what you can't see. Continuous vulnerability management cuts your exposure window from months to days.

06

Penetration Testing

Real-world attacks against your network, applications, and people - by OSCP-certified testers, not just automated scanners. We find what attackers would find, then show you exactly how to close it.

External Test

Internal Test

Social Engineering

Web App

OSCP Certified

Cyber Insurance Docs

+

Test Types

External network penetration test

Internal network penetration test

Web application penetration test

Social engineering & phishing simulation

Wireless security assessment

Active Directory attack path testing

Methodology

PTES & OWASP methodologies

OSCP-certified testers on every engagement

Manual exploitation - not just automated scans

Scoped rules of engagement, zero production risk

Black box, grey box, or white box options

Post-test debrief with your technical team

Deliverables

Executive summary (board-ready)

Technical findings with CVSS risk scores

Step-by-step remediation roadmap

Exploitation evidence (screenshots/video)

Free re-test after remediation

Cyber insurance evidence package

Find your gaps before attackers do. Annual penetration testing is required by most cyber insurers - and is the only way to truly validate your security posture.

07

Identity & Access Security

Compromised credentials are behind the majority of breaches. We harden your identity layer with MFA enforcement, Zero Trust architecture, privileged access management, and continuous identity threat detection.

MFA / FIDO2

Zero Trust

Entra ID

PAM

Conditional Access

ITDR

+

Identity Controls

MFA enforcement across all accounts

Phishing-resistant MFA (FIDO2 / passkeys)

Conditional access policy design

Privileged access management (PAM)

Just-in-time admin access

Service account hardening & monitoring

Zero Trust Architecture

Zero Trust network access (ZTNA)

Device compliance enforcement (Intune)

Entra ID / Azure AD hardening

Active Directory security baseline

Legacy authentication blocking)

Sign-in risk & user risk policies

Identity Threat Detection

Executive & board-level reportingIdentity threat detection & response (ITDR)

Impossible travel & anomaly alerting

Compromised credential monitoring

Privileged account activity auditing

SOC-backed identity alert triage

Dark web credential exposure alerts

Identity is the new perimeter. With remote work and cloud-first operations, strong identity controls matter more than any single tool or firewall.

08

Dark Web Monitoring

Continuously scan criminal forums, paste sites, and underground marketplaces for your company's credentials, data, and brand - get alerted before attackers act on what they've found.

Credential Monitoring

Data Leakage

Breach Detection

Threat Intel

PIPEDA Support

+

What We Monitor

Employee credential exposure

Corporate email & domain mentions

Sensitive data leakage (PII, financial records)

Source code & IP exposure

Third-party breach notifications

Criminal forum chatter about your organization

Sources Covered

Dark web forums & marketplaces

Paste sites (Pastebin & equivalents)

Telegram hacker channels

Ransomware group leak sites

Public breach databases

Underground credential markets

Response & Alerts

Real-time alerts on new exposures

Credential reset recommendations

SOC analyst review on critical findings

Monthly dark web posture report

PIPEDA breach notification support

Integration with identity security controls

Your credentials may already be for sale. Most businesses only find out during a breach - dark web monitoring gives you the early warning to act first.

ETS vs. Every Other
Option in Manitoba.

There's no shortage of IT companies claiming to do cybersecurity. Here's what actually separates us from a typical MSP or in-house team.

Capability

✦ ETS

Typical MSP

In-House IT Team

24/7 SOC with human analysts

Only SOC in Manitoba

Alerts go unreviewed overnight

Cost-prohibitive to staff

Mean time to detect threats

Under 15 minutes

Hours to days

207-day industry average

Penetration testing (in-house, certified)

OSCP-certified testers

Outsourced or skipped entirely

Rarely resourced

Engineers based in Winnipeg

100% local team

Often offshore or remote

Yes

PIPEDA & PHIA compliance support

Full framework coverage

Basic awareness only

Limited expertise

Identity threat detection (ITDR)

Included with SOC

Not offered

Requires dedicated tooling & staff

Dark web credential monitoring

Continuous, SOC-reviewed

Basic automated scan only

Not typically in scope

Named security engineer relationship

Dedicated named contact

Shared support pool

Yes (if properly staffed)

Flat-rate predictable pricing

Per-user monthly

Variable add-ons & overages

Salary + tooling + overhead

Compliance Frameworks Supported

PIPEDA

PHIA Manitoba

NIST CSF 2.0

ISO 27001

Training & Enablement

Client Success

Project Management

Operations & Admin

Manitoba Businesses Are
Active Targets.

Attackers don't discriminate by size or geography. Mid-market and small businesses are often preferred targets precisely because their defences are weaker - and they're far less likely to detect an intrusion quickly.

ETS was built for this reality. Our Security Operations Centre operates around the clock from Winnipeg, staffed by certified analysts who understand the specific threat landscape facing Prairie businesses - not a generic global feed.

Talk to a Security Engineer

Ransomware-as-a-Service

has lowered the barrier to entry - criminal groups rent sophisticated attack toolkits for a cut of the ransom, making attacks accessible to anyone

Business Email Compromise

losses now exceed ransomware losses globally, and the majority of incidents go unreported because they don't involve malware

Supply chain attacks

compromise trusted software vendors to reach thousands of downstream businesses at once - your tools can become your vulnerability

Credential stuffing

uses leaked passwords from unrelated breaches to silently access accounts - no malware, no alerts, no forensic trail

Living-off-the-land attacks

weaponise built-in OS tools like PowerShell and WMI to evade detection by traditional antivirus entirely

Without a SOC,

the mean time to detect a breach is 207 days - by then attackers have mapped your environment and exfiltrated everything of value

Cyber insurance carriers

are now requiring demonstrable controls - EDR, MFA, annual pen testing - or declining to issue policies at any price

From First Call to
Full Coverage.

Most clients go from first conversation to fully managed in under 30 days. No rip-and-replace. No disruption to your team.

01

Free Security Audit

We assess your current environment - endpoints, email, network, identity, and cloud - and produce a prioritised risk report. No cost, no obligation, no sales pressure. Just an honest picture of where you stand.

02

Right-Fit Program

Based on your risk profile, industry, and budget, we propose a tailored security program. You choose what to deploy - we don't sell you tools or services you don't need.

03

Rapid Deployment

Our engineers deploy EDR, configure email security, harden your firewall, and activate SOC monitoring. Most clients achieve full coverage within 2–3 weeks with zero downtime.

04

Ongoing Partnership

Monthly security reviews, quarterly vulnerability scans, annual penetration tests, and a named analyst who knows your environment. We evolve your posture as threats and your business change.

Things Business Owners
Actually Ask Us.

We're a small business. Do we really need this?

Small businesses are disproportionately targeted precisely because attackers assume defences are weak. A ransomware event or BEC fraud can be existential for a 20-person company in a way it isn't for a large enterprise. The risk is real - and managed security costs a fraction of what a single breach does.

We already have antivirus and a firewall. Isn't that enough?

Not in today's threat landscape. Modern attacks bypass traditional antivirus, and firewalls don't protect against phishing, compromised credentials, or insider threats. Managed cybersecurity layers detection, response, and continuous monitoring on top of perimeter tools - closing the gaps basic controls leave open.

What does 24/7 SOC monitoring actually mean day-to-day?

It means a certified analyst reviews every security alert generated across your environment around the clock - weekends and holidays included. When something looks suspicious, they investigate in real time and call you if action is needed. You're not just getting tools; you're getting people watching your back while you sleep.

How is ETS different from our current IT company doing security?

Most IT companies configure a few security tools and call it managed security. ETS operates the only SOC in Manitoba - actual certified analysts monitoring your environment continuously. We also offer penetration testing, dark web monitoring, and identity threat detection that most IT companies simply don't provide or outsource to third parties.

How quickly can you respond to an active incident?

Our mean time to detect is under 15 minutes. For confirmed incidents, SOC analysts begin containment immediately and contact your designated point of contact directly - day or night. Critical incidents get a phone call, not just a ticket in a queue.

Can ETS help us with our cyber insurance requirements?

Yes - and we actively help clients reduce premiums. We provide documentation of your security controls, annual penetration test reports, and compliance evidence that insurers look for. Several clients have had premiums reduced 20–40% at renewal after deploying our program. We'll also review your policy and identify coverage gaps.

Not Sure Where Your
Gaps Are?

Book a free security audit. Our engineers will assess your current controls, identify your highest-risk exposures, and show you exactly what needs to change - with no obligation to engage us.

Book a Free Security Audit

View All Services →