Security Strategy & Assessment
Know where you stand. Strengthen your defenses.
.png)
Security tools don’t add up to a security program
Most organizations have invested in security, including point tools, controls, and scattered policies. What’s often missing is clarity about where the program stands and how to ensure it aligns with the business. Meanwhile, pressures are compounding: Identity and access management has grown fragmented across cloud, SaaS, and remote work. Zero Trust is widely accepted in principle but unevenly implemented in practice. Software vulnerabilities have become the most common breach vector even as defenses mature. And AI adoption is racing ahead of the policies, controls, and governance models needed to support it safely.
.png)
Securing clarity for your enterprise
A security strategy engagement with OnX provides a structured evaluation of your unique environment, business drivers, and risk profile. We use a four-step methodology refined across hundreds of engagements:
1. Identify. Map your current security program against business goals, regulatory obligations, and threat landscape.
2. Develop. Build a strategy tied to your risk priorities and compliance requirements.
3. Apply. Deploy best practices from globally recognized frameworks to protect data and assets.
4. Mature. Establish the practices, oversight, and review cycles that move your program forward year after year.
Security Strategy & Assessment capabilities
We offer four assessment-driven engagements that establish your foundation
for a mature, business-aligned security program.
Security Strategy & Assessment
Security Program & Governance Assessment
Structured analysis and recommendations for programs and practices to protect the confidentiality, integrity and availability of your information and environment.
Read More ➜
Security Policy Review and Authoring
Evaluation, creation, and/or refinement of security policies, resulting in an audit-ready policy library aligned to business drivers and regulatory obligations.
Read More ➜
Zero Trust Services
Pragmatic assessment and roadmap for moving toward a “never trust, always verify” architecture, including a multi-year plan to mature your Zero Trust posture.
Read More ➜
Social Engineering Simulation
Targeted phishing, voice, and physical security simulations that test employees’ responses to deception.
Read More ➜
Advisory engagements
A OnX advisory is a time-bound, fixed-fee engagement designed to give you a clear answer to a specific strategic question — fast.
Cybersecurity Maturity Assessment
Duration: 1 to 2 weeks
Best for: Organizations that want a clear, third-party read on where they stand on AI and security readiness and where to focus first.
You walk away with:
-
An AI threat surface map specific to your environment
-
An assessment of SOC scope and coverage against AI-related risk
-
A prioritized roadmap aligned to frameworks, including the NIST AI Risk Management Framework and the EU AI Act
-
Recommendations that connect directly to subsequent governance, prevention, detection, and response work
%20(1).png)
What success looks like
A well-built security strategy creates measurable improvements across three of the six outcomes that anchor every OnX engagement.
Reduced risk
Identify and govern risk against your organization’s unique tolerance. Know which exposures matter, which controls work, and where to invest next.
Operational excellence
Replace ad hoc, reactive security work with a governed, repeatable program. Build the policies, processes, and review cycles that move security from project to program.
Business agility
Move faster on AI, cloud, and digital initiatives with security designed in from the start.
“Being a steward of security for an enterprise, the standard you hold yourself to is not ‘I’ve come in and fixed everything in three months.’ It’s year-over-year, dedicated and steady progress.”

Ryan Hamrick
Director, Security Practice, CBTS
Don’t take our word for it
“OnX continues to be a reliable and trusted partner, consistently providing support whenever we have questions or encounter issues. Doug's proactive engagement—regular attendance at our meetings and close alignment with our roadmap—demonstrates a genuine commitment to understanding our priorities and aligning with our operational needs. A key factor in OnX's successful relationship with the City of Edmonton is its deliberate focus on understanding our environment, our challenges, and the business outcomes we are working toward. Their highly skilled technical team further strengthens this partnership, enabling us to confidently tackle complex initiatives and advance critical projects with greater speed and assurance."
“OnX has been an incredible partner and really takes the time to understand our needs and our culture. Elias and Gabriel have been fantastic throughout and represent OnX professionally and with curiosity about our technology landscape.”
“The OnX account team consistently demonstrates a high level of professionalism and expertise. They are not only a pleasure to collaborate with, but also excel at understanding and translating customer requirements into practical, cost-effective solutions. Their ability to balance client needs with budgetary constraints ensures that projects are both feasible and aligned with business objectives. Overall, their commitment to service and depth of knowledge make them a valuable partner in achieving successful outcomes.”
“The commitment and dedication by OnX is second to none. We truly do feel that OnX is simply more than a vendor—rather a valuable partner in Sask Polytech's overall success. We truly value the insight that Mark T, Tuyet L, Marcel M, Ali S and various others have guided us within our value streams. Cannot say enough good things about OnX.”
“OnX's core competency in professional services, staffing and procurement services have been integral to the success of assisting the operations staff for the Canadian Blood Services. The OnX team have proved themselves to be more than a vendor but a partner in enabling the reliability for the services The Canadian Blood Services provides.”
Don’t take our word for it
“I love the creative, tailored solutions that are delivered in a consistent and reliable way while always doing what it takes to make things right.”
“My team at CBTS have been trusted partners for a long time. They provide excellent technical support and pre-sales work. Their breadth of knowledge and ability to bring in the right resources have helped us steer our technology into the future.”
“CBTS treats us like a partner and not just a customer. The technical expertise is next to none and the relationship management is some of the best I have experienced.”
Explore the full Cybersecurity portfolio
A connected set of services across the Prevent, Detect, Respond, and Assure lifecycle, designed to work together as your security program matures.
Threat & Vulnerability Management
From penetration testing and AI threat modeling to vulnerability scanning and patch management, OnX helps you reduce your attack surface.
Find out more ➜
Managed Detection & Response
Get continuous monitoring backed by senior analysts who understand your environment, your business, and the threats most likely to target you.
Find out more ➜
Incident Response & Recovery
CBTS delivers incident response retainers, managed backup, and disaster recovery services that limit downtime, contain damage, and get your business back online quickly after an incident.
Find out more ➜
Governance, Risk & Compliance
From virtual CISO services and AI risk assessments to compliance evaluations and tabletop exercises, OnX helps you govern security as a business discipline.
Find out more ➜
Related insights
Frequently asked questions
Shape a more secure future
Build the security program your business needs.