Public issuers face obligations private companies don't: material incidents may need disclosing, financial systems fall under internal controls, and your auditors test whether IT controls actually operate.
Including if you're preparing for an audit or responding to an auditor's finding.
We don't share your data. No spam, ever.
Public companies and subsidiaries we support
Materiality assessment requires facts: what was accessed, when, and whether it affects financial reporting. Without evidence you cannot make that judgement — or defend it afterwards.
An alert, a report, or an anomaly. At this point nobody yet knows scope — and that uncertainty is the problem.
What was accessed, by whom, over what period, and whether financial systems or reporting data were touched.
A judgement for management, counsel, and the audit committee — but it can only be made against evidence.
If material, disclosure follows on your regulator's timeline, and the record of your process gets scrutinised too.
General sequence, not legal or securities advice — your disclosure obligations are for your counsel and audit committee to determine. Our part is making sure the facts exist to inform that decision.
Internal control over financial reporting depends on IT general controls — access management, change management, and operations around the systems that produce your numbers. Auditors don't accept that a control exists; they test whether it operated throughout the period.
Most deficiencies we're brought in to remediate aren't missing controls. They're controls that were real but never evidenced, so there was nothing for the auditor to sample.
Our Compliance ApproachDraft results, transaction models, and board packages are market-moving until released. Leakage isn't only a security incident — it's a regulatory and market-integrity problem, and it usually happens through ordinary carelessness rather than an attack.
The controls that matter here are unglamorous: who can reach the folder, whether access is logged, and whether a departing executive's access actually ended.
Draft results and deal material in access-controlled locations where every open is recorded.
A departing officer's access ends immediately — with a record of what they accessed beforehand.
Deliberate rules about what can leave the tenant, so a convenient link doesn't become a public one.
External counsel and bankers working within a controlled space rather than over unmanaged email.
Public companies have immovable filing deadlines. Change management has to respect them, which means the maintenance calendar is built around your reporting calendar rather than ours.
Upgrades, migrations, and infrastructure changes land when a rollback wouldn't threaten a filing.
No changes to financial reporting systems while the numbers are being assembled.
Response and monitoring, nothing discretionary. Availability matters more than progress.
Control evidence packaged for the period, and the next quarter's change plan agreed.
Identity, privileged access, and periodic reviews run as a documented process — the control auditors sample most often.
Requests, approvals, testing, and deployment recorded in a system rather than in email threads and memory.
Log retention set to the periods agreed with you, protected against alteration.
Recovery objectives agreed with the business, then tested and documented — because an untested RTO is an assumption.
A written plan with defined roles, escalation to the audit committee, and a tabletop exercise so it isn't first used live.
Our SOC 2 report, so your auditors can assess your service provider from documentation rather than a questionnaire.
Usually, and the first step is understanding whether the control is genuinely absent or simply unevidenced — they're very different pieces of work. Most findings we're brought in for are the second: the practice existed but produced nothing an auditor could sample. Send us the finding and we'll tell you which it is.
Likely yes, as a service organization in scope for your ITGCs. That's why we hold a SOC 2 Type 2 report — it's intended for your auditors' use, so they can assess us from documentation rather than interviewing us. Providers without one create work for your finance team every year.
You do — management, counsel, and the audit committee. We're not securities advisers and won't pretend otherwise. Our job is to make sure the factual record exists so that judgement is informed rather than guessed, and defensible if it's later questioned.
Earlier than most companies do. Control environments take a few reporting cycles to produce clean evidence, and auditors want to see controls operating over time rather than implemented last month. Starting a year out is comfortable; three months out is expensive.
Yes, and that's the normal arrangement at this scale — co-managed, with the split written down. Internal audit tests, internal IT owns direction, and we cover specified layers and produce evidence. Ambiguity about who owns what is what causes findings.
Yes. Canadian subsidiaries frequently inherit control requirements from a US or European parent's framework, and the practical challenge is meeting the parent's standard with a smaller local team. That's a good fit for co-managed delivery.
Tell us what your auditors flagged, or what your audit committee is asking. We'll tell you what's a real gap and what just needs evidencing.

A globally recognized IT service provider with clients across North America. We hold a SOC 2 Type 2 report, independently audited.