Security & Trust at MSP Corp
Any provider can list security tools. Fewer can prove they are secure themselves
Most security conversations start with a product list. Ours starts with an audit report. Because the question that actually matters is not which tools we sell. It is whether the organization behind them is secure, and whether the people operating them know what they are doing. We answer both the same way: independently, and on the record.
SOC 2 Type 2
Security & Privacy criteria — no exceptions noted
24x7x365
Canadian Security Operations Centre
30+ Years
Securing Canadian organizations
Proven
We did not grade our own homework
Our security controls are examined and tested by an independent CPA firm under SOC 2 Type 2, covering the Security and Privacy Trust Services Criteria. Every control tested came back clean — no exceptions noted, and no incidents affecting our service commitments.
Why that matters to you: the platform examined is the same one that runs your environment, and the report is yours to read under NDA. It is the level of due diligence most providers cannot survive.
Practiced
Specialists, not generalists stretched thin
Security is not one discipline — it is ten. Identity, endpoint, cloud, email, data governance and network are each owned by people who work in them every day. That depth is deliberate and it is maintained: CISSP-led advisory, Microsoft-certified engineers, competency frameworks, role-specific scorecards and continuous vendor-led training — all examined as part of our SOC 2 control environment.
Certified across: CISSP · CISM · CRISC · CISA · CIPP/C · Microsoft Cybersecurity Architect Expert · Azure Solutions Architect Expert · SC-200, SC-300, SC-400, AZ-500 · Fortinet NSE 7 / 5 / 4 · Cisco CCNP and CCNA.
Recognized
Credentials that are earned, not asserted
Member of the Microsoft Intelligent Security Association. All six Microsoft Solutions Partner designations: Security, Modern Work, Data & AI, Infrastructure, Digital & App Innovation, Business Applications, plus multiple advanced specializations. More than thirty years securing Canadian organizations. These are not logos on a website; each one has a bar, and we cleared it.
Delivered from four regional Centres of Excellence across East, Central, Prairies and West — national consistency with a local team who knows your business.
Ready
We have already run the play
Incident response is where security stops being theoretical. Ours is documented in a Security Incident Response Plan, operated by a 24x7x365 Canadian Security Operations Centre, and rehearsed — a tabletop exercise was completed during our audit period and its findings were used to sharpen how we respond.
The line we hold: our detection partners extend coverage, but response authority, client communication and incident ownership stay with MSP Corp. You are never handed off to a third party in the middle of your worst day.
Depth in Every Domain and the Certifications Behind It
We staff security as the set of specialisms it actually is. Each domain has an owner, a platform they know deeply, and credentials that are externally validated.
| Domain | Platforms We Run | Credentials Held |
|---|---|---|
| Identity & access | Entra ID, Conditional Access, PIM, Delinea PAM | SC-300, AZ-500 |
| Endpoint | Defender, SentinelOne, Intune | Endpoint Administrator |
| Detection & response | Microsoft Sentinel, Guardian Shield MDR / Field Effect | SC-200 |
| Data governance & privacy | Purview, AvePoint, classification and DLP | SC-400, CIPP/C |
| Network & perimeter | Fortinet, WatchGuard, Cloudflare WAF and DNS | NSE 7 / 5 / 4, CCNP |
| Cloud & platform | Azure, Microsoft 365 E5, Defender for Cloud | Azure Solutions Architect Expert |
| Resilience | Veeam, Datto, backup and disaster recovery | AZ-104, ITIL-aligned practice |
| Governance & advisory | vCISO, risk assessments, maturity roadmaps | CISSP, CISM, CRISC, CISA |
When something happens: detection through to controlled return
Most providers stop at detection. The value is in everything that comes after: restoring trusted access, proving containment held, and getting you back to normal without reintroducing the risk.
| Detect | Guardian Shield MDR (powered by Field Effect) and Microsoft Sentinel run continuous detection across identity, endpoint, email and cloud. Coverage is layered, not single-source. |
| Triage | Alerts land in ConnectWise PSA with severity scoring, assignment and escalation — a signal becomes an owned, trackable action, not a notification. |
| Contain | Response playbooks fire predefined actions on known threat patterns, cutting containment time without waiting on manual intervention. |
| Recover | Identity lockdown and access normalization, network segmentation and trusted-path validation, endpoint re-enrolment, and restoration from encrypted local and geographically separate backups. |
| Validate | We confirm containment held and threats are no longer active, harden the gaps the incident exposed, then plan a controlled return to service. |
| Learn | Root cause analysis where the impact warrants it, lessons converted into automated guardrails, and executive reporting that stands up to auditors and insurers. |
Governance your board, regulator and insurer will accept
Technology alone does not satisfy an auditor. Our advisory team builds the governance around it: security assessments and risk analysis, vCISO services, policy and controls development, compliance readiness, privacy guidance aligned to PIPEDA and provincial requirements, and security maturity roadmaps. Our own Information Security Policy is owned and approved annually by the Chief Security Officer, with risk assessment results reported to leadership and the board.
Proven. Practised. Recognised. Ready.
Audited controls, run by certified specialists, backed by earned credentials, and rehearsed before you needed them. That is what security-first means when someone makes you prove it.
Want the evidence? Our full SOC 2 Type 2 report is available under NDA to clients, prospective clients, business partners and regulators