The doors (identity & access)
MFA on email, banking and payroll · shared “Nursing2” logins inventoried · admin accounts separated · departures losing access same-day.
Client portal’s on the way
No login needed to get your files.
Already working with us? Call or email and we’ll send your reports and certificates the same business day.
Questions? Contact your team →It’s 3 a.m. and the med cart won’t sign in - that is the night every administrator quietly dreads, and it usually starts weeks earlier with one fake pharmacy invoice on a shared workstation. Care homes run on thin IT and full trust; we audit the systems your care actually runs on, fix the basics, train every shift, and stay on as your IT and security person.
Free, no obligation. We work around shift changes - evenings included.
Care homes are a rising target for a simple reason: resident records are sensitive, care cannot pause, and a small office pays pharmacies, food services and staffing agencies every week. Here is the path it actually takes.
A believable email lands in the office - a pharmacy “statement,” a staffing-agency “timesheet.” One click on a shared workstation runs the attacker’s code. No alarm rings.
From that one login it reads everything: who pays vendors, how approvals work, which generic accounts every shift shares. Nothing looks wrong on any screen.
Charts, schedules and the medication record encrypt mid-shift. The night team is on paper, families start calling at 8, and the vendor owed Friday has “new banking details.”
Beyond days of disrupted care, resident health records mean PHIPA duties: assessing the breach, notifying residents and families, the privacy commissioner where required. In a sector built on family trust, the reputational bill outlasts the technical one.
Almost every care-home incident starts with one email, one shared password, or one convincing phone call - not a master hacker. The strongest defence is boring: audited basics, separated networks, tested backups, trained shifts, and a first hour everyone has rehearsed. That is exactly what we build - and it starts with knowing where you stand.
24 controls, scored 0–2, on-site in a day for most homes. Read-only - nothing is changed without a separate authorized engagement, and your incumbent IT provider gets a copy of everything if you want them to.
MFA on email, banking and payroll · shared “Nursing2” logins inventoried · admin accounts separated · departures losing access same-day.
Resident and guest Wi-Fi separated from the network the med carts live on · firewall supported and updated · remote access inventoried.
Backups for the systems care runs on - and a restore that has been watched to succeed, not assumed. Copies that survive ransomware.
Mail authentication configured · the vendor bank-change callback rule written down · a two-person rule on new payees and payroll changes.
Training in the last 12 months including nights · a no-shame reporting path · a first-hour plan posted, insurer’s breach line first.
PHIPA privacy contact named · verified vendor contacts · the after-hours “IT support” call script at the nursing station · agency staff under the same rules.
Every step is priced before you commit: the written proposal states the hourly rate and the estimated hours, and the invoice reflects actual hours - with a heads-up before any material overrun.
24 controls checked on-site, scored, in plain language. Your top five risks, the PHIPA page, the insurer page, and a 30-day plan with owners - delivered in three business days. If your home is in good shape, the report says so, and that’s the outcome.
Book the fit call →The audit’s findings, closed: MFA enforced, backups restore-tested, the guest network separated from the med carts - and the Cyber Security Hygiene curriculum run shift by shift, nights included. Phishing practice under your signed authorization, reported in aggregate, nobody named.
See the training →Monthly check-ins with a live scorecard, every new hire trained (turnover stops being a security reset), quarterly phishing practice, and your insurer answers kept true year-round. If you’d rather hand the whole IT stack to one accountable partner, ask on the call.
See the Partner Plan →No 80-page PDF nobody opens. One page up front with the score and the top five risks in order, then the plan. Every recommendation comes with a do-it-yourself route too - honesty is what sells the next engagement, and if your home is in good shape, the report says so.
Live, chapter by chapter, in the staff room between shift changes. New hires catch the next session, so turnover becomes a training cadence instead of a security reset. Certificates and a dated completion record issue every session - the evidence your insurance renewal asks about.
Why the password reused since 2019 is the way in, passphrases that stick, and retiring the shared “Nursing2” logins without slowing care.
Your home keeps: A passphrase card for every attendee and a generic-login retirement checklist for the administrator.
The tells that survive AI-written email (pressure + payment + new channel), the burst attack that hits every department at 8 a.m., and reporting fast without shame.
Your home keeps: The report-fast path posted at the station, plus your team’s spot-the-phish scorecard.
What the second lock actually does, MFA-fatigue calls (“the burglar ringing the doorbell”), and live enrollment in the room.
Your home keeps: Office team enrolled on the spot and an enrollment plan for everyone else.
What the tunnel does, when it matters for remote admin and head-office access, and the install on your own pattern.
Your home keeps: One office laptop connected live and a one-page remote-work rule.
The front desk for network traffic, why residents and visitors never share the med-cart network, and what good looks like for a home your size.
Your home keeps: A network walk-through with whoever owns IT - findings feed your audit score.
Locking in two seconds, why your login is your signature, and a handoff that covers screens, keys and tailgating.
Your home keeps: The shift-handoff security checklist, posted at the station.
Vendor bank-change fraud, payroll diversion, the executive-voice call - and the two-person rule that stops all of it.
Your home keeps: The callback card by the phone and a two-person payment rule, written and signed that afternoon.
What counts as resident PHI, the five ways it leaks, and the first hour of a suspected breach - tell, don’t hide.
Your home keeps: The PHIPA first-hour card and a no-shame reporting path your policy actually states.
Each chapter runs 25–40 minutes in your staff room, from $1,800+ per session - or the whole rhythm runs inside the Partner Plan, where every new hire catches the next chapter. Per-person certificates and the dated completion record issue every session: the credential your insurer and inspectors actually recognize. We schedule a limited number of program starts each month; dates are set on the fit call.
Completely. We never open resident records, run no malware, and harvest no credentials. Demo data is synthetic, every simulation is authorized by you in writing first, and if a screen with resident information needs looking at, your person drives.
Keep them. They run the systems; we check them and train your people - the things that are nobody’s job today: whether backups actually restore, whether the guest Wi-Fi can see the med carts, whether the ex-employee’s login still works. Your provider gets a copy of everything we find, and the to-do list usually makes their job easier.
Turnover is exactly why one-off training fails - so ours doesn’t work that way. The hygiene curriculum runs chapter by chapter, new hires catch the next session, and on the Partner Plan every new hire is trained as part of the monthly rhythm. Your staffing churn becomes a training cadence, not a security reset.
Starting prices are published on this page and on the pricing page: the audit from $750+ (from $1,500+ at 51–150 staff), training from $1,800+ a session, ongoing coverage from $349/mo. Your written proposal states the hourly rate and the estimated hours before you commit, and the invoice reflects actual hours - with a heads-up before any material overrun, not after.
One name. We send a single page - not a deck - to whoever signs at the group level, and we scope one home first so the decision is small. Operators with several homes usually roll the audit across the group after the first report.
Call your insurer’s cyber breach line first - that’s our standing advice to every client, because calling vendors first can jeopardize coverage. Our incident-readiness package rehearses exactly that first hour with your real names and numbers, in business hours, before you ever need it.
Read a complete audit report on the samples page before you pay a dollar.
The controls we score against are on this site - check yourself first, free.
Scope, rate, estimated hours and what’s not included - in the proposal, before you commit.
No simulation, test or change happens without your signed authorization. Ever.
If the honest answer is “someone fixes it, nobody checks it,” start with the audit. Twenty minutes with us is enough to scope it, and the report tells you the truth either way.
Audit from $750+ · 51–150 staff from $1,500+ · CAD plus HST · starting prices published