Cyber security risk assessment
Cyber security risk assessment services in Canada
A ranked risk register with owners, decisions and deadlines, built to satisfy PIPEDA, PHIPA, PCI DSS, SOC 2, ISO 27001 and OSFI expectations.
Security budgets get wasted when every risk looks the same size. Canada Create™ ranks them, prices them and gives leadership a plan they can fund.
Get your risk assessment proposal
Tell us what you run and what you must comply with. Fixed price in writing within one business day.
By submitting, you agree that Canada Create™ may contact you about your request. No spam, ever.
What a risk assessment gives you
Risks ranked by real impact
Likelihood and cost scored consistently, so leadership can compare them.
Decisions in writing
Fix, monitor, insure or accept, with an owner and a deadline for each.
Framework evidence
The risk assessment control that PIPEDA, PHIPA, PCI DSS, SOC 2 and ISO 27001 require.
Budget that goes to the right risks
Spend on what would actually hurt, not on what is loudest.
What the risk assessment covers
From inventory to a funded treatment plan.
- Asset and data inventorySystems, data types, credentials and the vendors that touch them.
- Threat analysisRealistic attack scenarios for your sector, from ransomware to insider misuse.
- Likelihood and impact scoringFinancial, operational, legal and reputational impact on a consistent scale.
- Control effectiveness reviewWhether existing controls reduce risk in practice, not just on paper.
- Risk registerRanked, with owner, treatment decision and deadline for every risk.
- Vendor and third-party riskSuppliers rated the same way, with required contract language and evidence.
- Executive presentationResidual risk and the plan, for leadership, the board and your insurer.
- Working sessionPriorities and budget agreed with the people who must act and approve.
Risk assessment pricing
Scope decides price: size, systems, data types, vendors and framework.
Business risk assessment
Quoted in writing
Companies with 5 to 100 staff that need a ranked register and a funded plan
- Asset and data inventory
- Threat and impact analysis
- Risk register with treatment plan
- Executive presentation
Regulated risk assessment
By proposal
Healthcare, finance, legal, public sector and SaaS with framework obligations
- Everything in the business assessment
- Framework-mapped register
- Vendor and third-party risk program
- Optional audit and penetration test in one engagement
- Annual review and update
Annual updates are quoted at a reduced rate for returning clients.
Decide with evidence
Know what would hurt, and what to do first
A cyber security risk assessment that tells leadership what would actually hurt
Security budgets get wasted when every risk looks the same size. A Canada Create™ cyber security risk assessment ranks them. We identify the systems and data your business depends on, the ways each could be compromised, how likely that is and what it would cost, then hand leadership a risk register with clear treatment decisions: fix, monitor, transfer to insurance or accept in writing. It is the document PIPEDA guidance, PHIPA, PCI DSS, SOC 2, ISO 27001 and OSFI expectations all ask for, and it is the fastest way to turn a vague worry into a funded plan.
What the assessment covers
Asset and data inventory
What you run and what you hold: customer records, health information, financial data, intellectual property, credentials, the systems that process them and the vendors that touch them. Most organizations discover data they did not know they were keeping.
Threat and vulnerability analysis
The realistic ways each asset could be compromised, from ransomware and business email compromise to insider misuse, vendor breach, lost devices and web application attacks, informed by the incidents actually hitting Canadian businesses in your sector.
Likelihood and impact scoring
Each risk rated on a consistent scale for likelihood and for financial, operational, legal and reputational impact, including regulator notification, downtime cost and contract exposure.
Control effectiveness
Whether the controls you already have reduce the risk in practice. Backups that have never been restored and MFA that covers half the accounts do not count the way they look on paper.
Risk register and treatment plan
A ranked register with an owner, a decision and a deadline for every risk, plus a summary of residual risk after treatment for the board and your insurer.
Third-party and vendor risk
The suppliers, contractors and cloud services with access to your systems or data, rated the same way, with the contract language and evidence you should require from each.
Who needs a risk assessment
Any organization subject to a framework that requires one, which now includes most regulated industries in Canada. Healthcare providers and health technology companies under PHIPA and provincial law. Financial services firms answering to OSFI, FINTRAC and provincial regulators. Law firms managing client confidentiality. Public sector bodies with procurement and privacy obligations. SaaS companies preparing for SOC 2 or ISO 27001, where the risk assessment is a foundational control. And any business that wants to spend its security budget on the risks that matter rather than the ones that are loudest.
Risk assessment versus audit versus penetration test
A cyber security audit checks whether controls exist and work. A penetration test tries to break through them. A risk assessment decides which failures would matter most and what to do about each. Regulated organizations generally need all three; we run them separately or as one engagement, and the risk register becomes the backbone of your compliance program.
What you receive
An asset and data inventory. A threat analysis specific to your sector. A scored, ranked risk register with owners, treatment decisions and deadlines. A vendor risk summary. An executive presentation for leadership and the board. And a working session to agree on priorities and budget. Everything is written for two audiences: the people who must act, and the people who must approve.
Risk assessment pricing
Pricing depends on organization size, the number of systems and data types, the number of vendors and the framework you are assessing against. Tell us what you run and what you must comply with, and you will have a fixed price in writing within one business day.
Book your risk assessment
Get a proposal in one business day, or call +1 (800) 808-9235 any time. Part of our cyber security services for Canadian businesses.
Talk to a strategist
Ready when you are!
Get a proposal in one business day.
Tell us your goals, budget and timeline. You get a plan, a price and a named strategist, with no long-term contract.
How the risk assessment runs
Three to five weeks from kickoff to an approved treatment plan.
- Kickoff and scoping Day 1 to 3
Business context, framework, systems in scope and stakeholders.
- Inventory and interviews Week 1 to 2
Assets, data flows, vendors and current controls documented.
- Threat and impact analysis Week 2 to 3
Scenarios scored for likelihood and impact against control effectiveness.
- Risk register and plan Week 3 to 4
Ranked register with treatment decisions, owners and deadlines.
- Leadership session Week 4 to 5
Executive presentation and approval of priorities and budget.
What clients say on Google
Reviews pulled live from our Google Business Profile.
Free review, no obligation
Not sure where to start? Send us what you have.
Share your current site, campaign or brief. A strategist reviews it and replies within one business day with a written recommendation and a fixed quote.
Why Canada Create™ for risk assessment
Business-first scoring
Impact measured in downtime, notification, contracts and cost, not scanner scores.
BBB Accredited, A+
An A+ rating with the Better Business Bureau and zero complaints.
Framework-ready
Registers structured for PIPEDA, PHIPA, PCI DSS, SOC 2, ISO 27001 and OSFI.
Quoted in writing
Fixed price before work starts. Get a proposal in one business day.
A plan we can execute
Testing, managed security, compliance and development under one roof.
24/7* support
Call +1 (800) 808-9235 any time, day or night.
Risk assessment questions
What is a cyber security risk assessment?
A structured process that identifies what you depend on, how it could be compromised, how likely and costly that would be, and what to do about each risk, documented in a ranked register.
How is it different from a cyber security audit?
An audit checks whether controls exist and work. A risk assessment decides which failures would matter most and how to treat them. Regulated organizations usually need both.
How much does a risk assessment cost in Canada?
It depends on size, systems, data types, vendors and framework. Every assessment is quoted at a fixed price in writing within one business day.
Which frameworks require a risk assessment?
PIPEDA guidance, PHIPA, PCI DSS, SOC 2, ISO 27001, NIST CSF and OSFI cyber expectations all require or expect a documented, periodic risk assessment.
How long does it take?
Three to five weeks for most organizations, with a few hours of stakeholder interviews.
What is a risk register?
A ranked list of your risks with likelihood, impact, existing controls, a treatment decision, an owner and a deadline for each, updated as risks change.
Do you assess vendor and third-party risk?
Yes. Suppliers and cloud services with access to your data are rated the same way, with the contract terms and evidence you should require.
How often should we update it?
At least annually and after any major change: a new system, a new vendor, an acquisition or an incident.
Does it help with cyber insurance?
Yes. A documented risk assessment with treatment decisions answers most underwriting questions and often improves terms.
What happens after the assessment?
You have a funded plan with owners. We can execute it through testing, managed security, compliance and development, or hand it to your team.


Unranked risks get funded by whoever shouts loudest
A risk register puts the numbers on the table so the budget goes where the damage would be.

