Security Intelligence & Monitoring

Security Clarity for Organizations That Can't Afford Ambiguity

Independent security assessments, post-incident validation, and continuous monitoring — grounded in NIST and CIS standards. No vendor agenda. No jargon. A clear, documented picture of where you stand.

"Nothing hidden. Nothing unmeasured."

4
Industry Frameworks
(NIST, CIS, MITRE, ISO)
3
Service Lines
(Post-Incident, Baseline, Periodic)
2–6 wk
Typical Engagement
Duration
100%
Independent — No
Vendor Relationships

The Problem

Most mid-market organizations live in security ambiguity

You've done some security work. You're not sure if it was enough. And if something happens, you can't prove it either way.

After an Incident

A breach happened. You think it's contained — but customers, partners, and regulators want documentation. You need an independent voice saying: "Yes, this is remediated."

No Security Baseline

You've never had a structured assessment. You're operating on instinct and vendor promises, with no documented posture to measure against — or defend.

Drift Between Reviews

Your security posture changes constantly — new staff, new tools, new vendors. Without periodic assessment, last year's clean bill of health is this year's liability.

Services

Three service lines. One clear outcome.

A documented, defensible picture of your security posture — independently verified against recognized standards.

🔍
S1 — Post-Incident

Post-Incident Validation

Independent third-party confirmation that a security incident has been fully contained and remediated. Produces a report suitable for sharing with customers, partners, or regulators.

CAD $8,000 – $18,000 fixed
  • Incident timeline & IoC analysis
  • Control-by-control remediation verification
  • Executive summary — shareable externally
  • Attestation statement for third-party use
  • 2–3 week engagement
📊
S2 — Baseline

Security Baseline Assessment

A comprehensive assessment of your current security posture against NIST CSF 2.0 and CIS Controls v8. Your documented starting point for everything that follows.

CAD $15,000 – $28,000 fixed
  • Identity & access management review
  • Network security posture assessment
  • Endpoint & email security evaluation
  • Incident response readiness review
  • Prioritized findings + remediation roadmap
  • 4–6 week engagement
📡
S3 — Periodic

Periodic Threat Assessment

Quarterly reviews that track your security posture over time — measuring progress against your baseline, identifying new exposures, and keeping your documentation current.

CAD $4,000 – $6,000 / quarter
  • Posture delta vs. prior assessment
  • New threat landscape review
  • Finding closure verification
  • Updated executive security dashboard
  • Ongoing relationship, no surprises

How It Works

From engagement to evidence — in weeks, not months

A structured, standards-based process that produces clear outputs at every stage.

1

Scoping Call

30–60 min to define scope, gather documentation, and align on deliverables and timelines.

2

Evidence Collection

Read-only access to logs, configuration, and audit data. No agents installed. No disruption to operations.

3

Independent Analysis

Findings structured against NIST CSF 2.0 and CIS Controls v8. MITRE ATT&CK mapping for threat validation.

4

Report Delivery

Executive summary for leadership and customers. Technical appendix for your team. Both defensible, both useful.

5

Debrief & Q&A

Live walkthrough of findings. Clear answers on priority, remediation, and next steps.

Standards & Frameworks

Grounded in what the industry trusts

No proprietary scoring systems. No invented maturity models. We assess against established, recognized frameworks.

NIST
CSF 2.0

NIST Cybersecurity Framework 2.0

Govern · Identify · Protect · Detect · Respond · Recover. The foundation for organizational security posture assessment.

NIST
800-61

NIST SP 800-61 Incident Handling

Computer security incident handling guide. Structures our post-incident validation methodology.

CIS
v8

CIS Controls v8

Prioritized, actionable security controls. Used for finding categorization and remediation prioritization.

MITRE
ATT&CK

MITRE ATT&CK Framework

Adversary tactic and technique mapping for incident analysis and threat modeling.

Monitoring & Observability

You can’t secure what you can’t see

Security posture and operational visibility are two sides of the same coin. We help organizations establish the monitoring infrastructure they need — so threats become visible before they become incidents.

M1

Monitoring Infrastructure Setup

Deploy a production-grade observability stack tailored to your environment — metrics collection, log aggregation, and alerting configured from the ground up.

$5,000 – $12,000

M2

Security Dashboard Design

Custom dashboards aligned to your security posture and compliance requirements. Executive views and operational views — always grounded in your actual data.

$3,000 – $8,000

M3

Managed Monitoring

Ongoing visibility as a service. Alert triage, monthly posture reports, and continuous tuning — so your team stays focused on what matters.

$1,500 – $3,000 / month

Part of the XRAY family. XRAY VU Corp operates alongside XRAY Communications, IT Extension, and Audio Extension — a group of independent, employee-owned technology companies serving Canadian businesses. Our monitoring and security practices are built to complement managed IT and communications services for organizations that want a coordinated approach to infrastructure and security.

Get Started

Ready to see your security clearly?

Start with a 30-minute scoping conversation. No obligation. We'll tell you whether an engagement makes sense and what it would look like.

XRAY VU Corp · Canadian Corporation · Independent · No vendor affiliations