Industries

Government Cybersecurity

Security assessment built for public sector accountability.

Sherlock Forensics provides cybersecurity assessment and incident response for Canadian government organizations. Services cover ITSG-33 compliance assessment, TBS policy alignment, Protected B system testing, supply chain security for government contractors and public sector incident response. We work with federal departments, provincial agencies, municipalities and government contractors.

Compliance Framework

ITSG-33 Compliance Assessment

ITSG-33 is the Government of Canada's IT security risk management framework, published by the Canadian Centre for Cyber Security. It defines security control profiles based on the confidentiality, integrity and availability requirements of the information system. Federal departments must implement ITSG-33 controls. Contractors handling government data are typically required to meet the same standards through their contract security clauses.

We assess your systems against the applicable ITSG-33 control profile. The assessment identifies which controls are implemented, which are partially implemented and which are missing entirely. Our report maps each finding to the specific ITSG-33 control identifier so your team can prioritize remediation. We also test whether implemented controls actually work as intended, not just whether they exist on paper.

Policy Alignment

Treasury Board Policies

Treasury Board Secretariat (TBS) policies set the governance framework for IT security across the Government of Canada. The Policy on Government Security and the Directive on Security Management require departments to implement security programs that protect government information and assets. These policies mandate security assessments, vulnerability management and incident reporting.

Key TBS requirements we assess:

Security Assessment and Authorization (SA&A)
Formal evaluation of a system's security controls before it is authorized to operate.
Vulnerability Management
Ongoing identification and remediation of security vulnerabilities in government systems.
Incident Management
Processes for detecting, responding to and recovering from security incidents.
Supply Chain Security
Controls ensuring that third-party products and services do not introduce unacceptable risk.

Data Classification

Protected B System Assessment

Protected B is the Government of Canada classification for information that could cause serious injury if compromised. This includes personal tax records, medical files, immigration records, financial data and law enforcement information. Systems processing Protected B data require a specific set of security controls covering encryption, access control, audit logging, network segmentation and physical security.

Our Protected B assessment verifies that your systems meet the required security posture. We test encryption implementation (both at rest and in transit), access control configurations, audit log completeness, network segmentation effectiveness and administrative access procedures. For cloud-hosted systems, we assess against the Canadian Centre for Cyber Security's cloud security guidance and the applicable Protected B cloud security profile.

Contractors

Supply Chain Security for Government Contractors

Government contractors are increasingly required to demonstrate security compliance as a condition of procurement. The Industrial Security Program, managed by Public Services and Procurement Canada (PSPC), sets baseline security requirements. Many Request for Proposals (RFPs) now include specific cybersecurity requirements including penetration testing, vulnerability assessment and security control implementation evidence.

We help contractors prepare for government security requirements before they become barriers to winning or retaining contracts. Our assessment identifies gaps between your current security posture and the requirements specified in government contracts. We provide a prioritized remediation plan and a formal assessment report that can be submitted as evidence of due diligence during procurement processes.

Incident Response

Public Sector Incident Response

Government organizations face unique constraints during security incidents. Public accountability, mandatory reporting to the Canadian Centre for Cyber Security, privacy breach notification obligations and the potential impact on public services all add complexity. Our incident response process accounts for these requirements from the first call. We coordinate with your internal teams, legal counsel and any mandatory reporting bodies.

Municipal governments are frequent targets of ransomware attacks. City systems, utility SCADA networks, public transit operations and citizen-facing services all present attack surfaces. We have responded to incidents across municipal infrastructure including compromised email systems, encrypted file servers, breached citizen databases and ransomware affecting public-facing services. Our priority is always restoring operations while preserving forensic evidence for investigation and potential prosecution.

Get Started

Ready to meet government security requirements?

Order a security assessment online or call for a scoping consultation. ITSG-33 assessments from $12,000 CAD.

Since 20064.8/5 ratingCISSP, ISSAP, ISSMP certified
Order Online

Questions

Frequently Asked

What is ITSG-33 and why does it matter for government systems?
ITSG-33 is the IT Security Risk Management framework published by the Canadian Centre for Cyber Security (CCCS). It defines security controls for federal government information systems based on the sensitivity of the data they process. Compliance with ITSG-33 is mandatory for federal departments and expected for contractors handling government data.
What is Protected B and what security does it require?
Protected B is a Government of Canada information sensitivity classification for data that could cause serious injury to an individual or organization if compromised. Examples include tax records, medical files and financial data. Protected B systems require specific security controls including encryption, access controls, audit logging and regular security assessments.
Can government contractors use your security assessment services?
Yes. Government contractors handling sensitive data are required to meet security standards defined in their contracts, often including ITSG-33 controls. We assess contractor environments against these requirements and identify gaps before they become procurement disqualifiers or audit findings.
Do you provide incident response for public sector organizations?
Yes. We provide incident response for municipal governments, provincial agencies and federal contractors. Our response process is designed to work alongside the Canadian Centre for Cyber Security reporting requirements and any applicable privacy breach notification obligations under PIPEDA or provincial legislation.
How much does a government security assessment cost?
Government security assessments start at $12,000 CAD for focused network penetration testing. Full ITSG-33 compliance assessments range from $20,000-$50,000 CAD depending on system scope, classification level and the number of security controls in the assessment profile. We provide fixed-price quotes after a scoping call.