Endpoints, email, identities, firewalls, cloud - attackers only need one gap. ETS closes every layer with managed cybersecurity backed by the only 24/7 Security Operations Centre in Manitoba.
24/7
SOC Monitoring
<15M
Mean Detection Time
100%
manitoba Engineers
Only
SOC in Manitoba
+ 24/7 SOC with Human Analysts
+ EDR / XDR Protection
+ Firewall Management
+ Penetration Testing
+ Email Security & DMARC
+ Vulnerability Management
+ Identity & Zero Trust
+ Dark Web Monitoring
The Reality
The average breach goes undetected for 207 days. By the time you know something happened, the damage is done. These are the gaps we close..
01
Modern attacks live in memory, mimic legitimate processes, and use your own OS tools against you. Signature-based antivirus misses the majority of advanced threats deployed by criminal groups today.
97% of malware uses unique file signatures — bypassing traditional AV
02
Over 90% of breaches begin with a phishing email or business email compromise. Attackers don't need to hack your systems when they can simply trick your people into handing over access.
BEC losses now exceed ransomware losses globally — most go unreported
03
Billions of credentials from third-party breaches are actively traded on criminal marketplaces. The odds that at least one employee in your organization has reused a compromised password are extremely high.
24 billion credentials currently circulating on the dark web
04
Modern attacks live in memory, mimic legitimate processes, and use your own OS tools against you. Signature-based antivirus misses the majority of advanced threats deployed by criminal groups today.Tools alone don't stop attacks - analysts do. Without a Security Operations Centre reviewing alerts around the clock, threats sit undetected while attackers move laterally through your environment at their own pace.
Mean time to detect a breach without a SOC: 207 days
24/7
SOC Monitoring
365 Days a Year
<15M
Mean Time
to Detect
Only
SOC Provider
in Manitoba
100%
Winnipeg-Based
Engineering Team
Our Cybersecurity Services
Click any service to see exactly what's included, what tools we deploy, and how we've implemented it for Manitoba businesses like yours.
01
Next-generation EDR and XDR deployed across every device - detecting, isolating, and neutralising threats that bypass traditional antivirus before they spread through your environment.
→
24/7 endpoint monitoring & alerting
→
Behavioural threat detection (AI-driven)
→
Automatic threat containment & isolation
→
Fileless & memory-based attack protection
→
Ransomware detection & file rollback
→
Proactive threat hunting by SOC analysts
→
CrowdStrike Falcon
→
SentinelOne Singularity
→
Microsoft Defender for Endpoint
→
Windows, macOS & Linux
→
Virtual & cloud workloads
→
Servers & workstations
→
Real-time incident dashboards
→
Monthly executive threat summary
→
Full incident timeline & forensics
→
SOC analyst triage on every alert
→
Post-incident remediation guidance
→
Ticketing system integration
Antivirus misses modern attacks. EDR detects threats by behaviour - not just known signatures - catching what traditional tools never see.
02
Winnipeg's only 24/7 SOC - certified analysts monitoring your entire environment around the clock, triaging every alert, and responding to incidents before they become disasters.
→
24/7/365 analyst-monitored alerting
→
SIEM log ingestion & correlation
→
Cross-source detection (endpoint, email, network, identity)
→
Real-time threat intelligence feeds
→
Anomaly detection & environment baselining
→
Incident escalation & containment
→
Only SOC physically based in Manitoba
→
No offshore alert routing - ever
→
Senior analysts on every shift
→
Mean detection time under 15 minutes
→
Dedicated client Slack / Teams channel
→
Named analyst - not a call centre
→
Defined IR playbooks per threat type
→
Immediate containment on confirmed threats
→
Evidence preservation & chain of custody
→
PIPEDA breach notification support
→
Cyber insurance claim documentation
→
Post-incident root cause analysis
Tools without analysts are just noise. Our SOC turns security alerts into human-reviewed, actioned responses - not a dashboard nobody watches at 3am.
03
Enterprise-grade firewall deployment, configuration, and ongoing management. We harden your network perimeter, enforce segmentation, and keep rule sets current as your environment changes.
→
Next-gen firewall (NGFW) deployment
→
Rule set design & ongoing management
→
Intrusion prevention system (IPS/IDS)
→
Application-layer traffic inspection
→
Network segmentation & VLAN policy
→
SSL/TLS deep packet inspection
→
Fortinet FortiGate
→
Palo Alto Networks
→
Cisco Firepower / ASA
→
Meraki MX series
→
Sophos XGS
→
Azure & AWS network policies
→
24/7 firewall health monitoring via SOC
→
Firmware & threat signature updates
→
Quarterly rule set reviews & cleanup
→
Geo-blocking & threat intelligence feeds
→
Policy violation alerting
→
Traffic & anomaly reporting
A misconfigured firewall is as dangerous as no firewall. Rule sets accumulate exceptions over years - we review and harden them on a regular cadence.
04
Phishing, business email compromise, and malicious attachments remain the #1 breach vector. We layer advanced filtering, anti-spoofing controls, and simulated training to close that door permanently.
→
Advanced anti-phishing & BEC detection
→
Malicious attachment sandboxing
→
URL rewriting & real-time link scanning
→
Executive impersonation protection
→
Spam & bulk mail filtering
→
Quarantine management & reporting
→
DMARC policy deployment & enforcement
→
DKIM signing & SPF alignment
→
Domain spoofing prevention
→
Lookalike domain monitoring
→
Third-party sender verification
→
DMARC aggregate reporting dashboard
→
Monthly simulated phishing campaigns
→
Targeted spear-phishing scenarios
→
Click rate tracking & trend reporting
→
Automatic micro-training on failure
→
Department-level risk scoring
→
Executive board reporting
Over 90% of breaches start with an email. Advanced filtering combined with regular staff simulations is the highest-ROI security control you can deploy.
05
Continuous scanning of your internal and external attack surface - identifying, prioritising, and tracking vulnerabilities so your team always knows what to fix first and why it matters.
→
Continuous internal network scanning
→
External attack surface monitoring
→
Web application vulnerability scanning
→
Cloud configuration assessment (CIS Benchmarks)
→
Active Directory security auditingn
→
Credential exposure scanning
→
CVSS & exploit probability (EPSS) scoring
→
Asset-based risk context (crown jewels first)
→
Patch prioritisation recommendations
→
Automated patch deployment for endpoints
→
Exception management & remediation tracking
→
SLA-driven timelines
→
Tenable.io / Nessus
→
Qualys VMDR
→
Microsoft Defender Vulnerability Mgmt
→
Weekly vulnerability digest
→
Executive risk posture score
→
Compliance evidence exports (PIPEDA, ISO)
You can't fix what you can't see. Continuous vulnerability management cuts your exposure window from months to days.
06
Real-world attacks against your network, applications, and people - by OSCP-certified testers, not just automated scanners. We find what attackers would find, then show you exactly how to close it.
→
External network penetration test
→
Internal network penetration test
→
Web application penetration test
→
Social engineering & phishing simulation
→
Wireless security assessment
→
Active Directory attack path testing
→
PTES & OWASP methodologies
→
OSCP-certified testers on every engagement
→
Manual exploitation - not just automated scans
→
Scoped rules of engagement, zero production risk
→
Black box, grey box, or white box options
→
Post-test debrief with your technical team
→
Executive summary (board-ready)
→
Technical findings with CVSS risk scores
→
Step-by-step remediation roadmap
→
Exploitation evidence (screenshots/video)
→
Free re-test after remediation
→
Cyber insurance evidence package
Find your gaps before attackers do. Annual penetration testing is required by most cyber insurers - and is the only way to truly validate your security posture.
07
Compromised credentials are behind the majority of breaches. We harden your identity layer with MFA enforcement, Zero Trust architecture, privileged access management, and continuous identity threat detection.
→
MFA enforcement across all accounts
→
Phishing-resistant MFA (FIDO2 / passkeys)
→
Conditional access policy design
→
Privileged access management (PAM)
→
Just-in-time admin access
→
Service account hardening & monitoring
→
Zero Trust network access (ZTNA)
→
Device compliance enforcement (Intune)
→
Entra ID / Azure AD hardening
→
Active Directory security baseline
→
Legacy authentication blocking)
→
Sign-in risk & user risk policies
→
Executive & board-level reportingIdentity threat detection & response (ITDR)
→
Impossible travel & anomaly alerting
→
Compromised credential monitoring
→
Privileged account activity auditing
→
SOC-backed identity alert triage
→
Dark web credential exposure alerts
Identity is the new perimeter. With remote work and cloud-first operations, strong identity controls matter more than any single tool or firewall.
08
Continuously scan criminal forums, paste sites, and underground marketplaces for your company's credentials, data, and brand - get alerted before attackers act on what they've found.
→
Employee credential exposure
→
Corporate email & domain mentions
→
Sensitive data leakage (PII, financial records)
→
Source code & IP exposure
→
Third-party breach notifications
→
Criminal forum chatter about your organization
→
Dark web forums & marketplaces
→
Paste sites (Pastebin & equivalents)
→
Telegram hacker channels
→
Ransomware group leak sites
→
Public breach databases
→
Underground credential markets
→
Real-time alerts on new exposures
→
Credential reset recommendations
→
SOC analyst review on critical findings
→
Monthly dark web posture report
→
PIPEDA breach notification support
→
Integration with identity security controls
Your credentials may already be for sale. Most businesses only find out during a breach - dark web monitoring gives you the early warning to act first.
Why ETS
There's no shortage of IT companies claiming to do cybersecurity. Here's what actually separates us from a typical MSP or in-house team.
Capability
✦ ETS
Typical MSP
In-House IT Team
24/7 SOC with human analysts
✓ Only SOC in Manitoba
✗ Alerts go unreviewed overnight
✗ Cost-prohibitive to staff
Mean time to detect threats
✓ Under 15 minutes
Hours to days
207-day industry average
Penetration testing (in-house, certified)
✓ OSCP-certified testers
✗ Outsourced or skipped entirely
✗ Rarely resourced
Engineers based in Winnipeg
✓ 100% local team
Often offshore or remote
✓ Yes
PIPEDA & PHIA compliance support
✓ Full framework coverage
Basic awareness only
Limited expertise
Identity threat detection (ITDR)
✓ Included with SOC
✗ Not offered
✗ Requires dedicated tooling & staff
Dark web credential monitoring
✓ Continuous, SOC-reviewed
Basic automated scan only
✗ Not typically in scope
Named security engineer relationship
✓ Dedicated named contact
✗ Shared support pool
✓ Yes (if properly staffed)
Flat-rate predictable pricing
✓ Per-user monthly
Variable add-ons & overages
✗ Salary + tooling + overhead
Compliance Frameworks Supported
PIPEDA
PHIA Manitoba
NIST CSF 2.0
ISO 27001
Training & Enablement
Client Success
Project Management
Operations & Admin
The Threat Landscape
Attackers don't discriminate by size or geography. Mid-market and small businesses are often preferred targets precisely because their defences are weaker - and they're far less likely to detect an intrusion quickly.
ETS was built for this reality. Our Security Operations Centre operates around the clock from Winnipeg, staffed by certified analysts who understand the specific threat landscape facing Prairie businesses - not a generic global feed.
●
Ransomware-as-a-Service
has lowered the barrier to entry - criminal groups rent sophisticated attack toolkits for a cut of the ransom, making attacks accessible to anyone
●
Business Email Compromise
losses now exceed ransomware losses globally, and the majority of incidents go unreported because they don't involve malware
●
Supply chain attacks
compromise trusted software vendors to reach thousands of downstream businesses at once - your tools can become your vulnerability
●
Credential stuffing
uses leaked passwords from unrelated breaches to silently access accounts - no malware, no alerts, no forensic trail
●
Living-off-the-land attacks
weaponise built-in OS tools like PowerShell and WMI to evade detection by traditional antivirus entirely
●
Without a SOC,
the mean time to detect a breach is 207 days - by then attackers have mapped your environment and exfiltrated everything of value
●
Cyber insurance carriers
are now requiring demonstrable controls - EDR, MFA, annual pen testing - or declining to issue policies at any price
How We Work
Most clients go from first conversation to fully managed in under 30 days. No rip-and-replace. No disruption to your team.
01
We assess your current environment - endpoints, email, network, identity, and cloud - and produce a prioritised risk report. No cost, no obligation, no sales pressure. Just an honest picture of where you stand.
02
Based on your risk profile, industry, and budget, we propose a tailored security program. You choose what to deploy - we don't sell you tools or services you don't need.
03
Our engineers deploy EDR, configure email security, harden your firewall, and activate SOC monitoring. Most clients achieve full coverage within 2–3 weeks with zero downtime.
04
Monthly security reviews, quarterly vulnerability scans, annual penetration tests, and a named analyst who knows your environment. We evolve your posture as threats and your business change.
Common Questions
Small businesses are disproportionately targeted precisely because attackers assume defences are weak. A ransomware event or BEC fraud can be existential for a 20-person company in a way it isn't for a large enterprise. The risk is real - and managed security costs a fraction of what a single breach does.
Not in today's threat landscape. Modern attacks bypass traditional antivirus, and firewalls don't protect against phishing, compromised credentials, or insider threats. Managed cybersecurity layers detection, response, and continuous monitoring on top of perimeter tools - closing the gaps basic controls leave open.
It means a certified analyst reviews every security alert generated across your environment around the clock - weekends and holidays included. When something looks suspicious, they investigate in real time and call you if action is needed. You're not just getting tools; you're getting people watching your back while you sleep.
Most IT companies configure a few security tools and call it managed security. ETS operates the only SOC in Manitoba - actual certified analysts monitoring your environment continuously. We also offer penetration testing, dark web monitoring, and identity threat detection that most IT companies simply don't provide or outsource to third parties.
Our mean time to detect is under 15 minutes. For confirmed incidents, SOC analysts begin containment immediately and contact your designated point of contact directly - day or night. Critical incidents get a phone call, not just a ticket in a queue.
Yes - and we actively help clients reduce premiums. We provide documentation of your security controls, annual penetration test reports, and compliance evidence that insurers look for. Several clients have had premiums reduced 20–40% at renewal after deploying our program. We'll also review your policy and identify coverage gaps.
Book a free security audit. Our engineers will assess your current controls, identify your highest-risk exposures, and show you exactly what needs to change - with no obligation to engage us.