
Most Waterloo companies call us on a date they can name — the week a customer's security review landed, or the week the co-op intake arrived. We are ten minutes away in downtown Kitchener, not an hour up the 401.
Ongoing managed IT or a one-off problem — tell us which and we'll respond accordingly.
We won't sell your data or send you marketing you didn't ask for.
Trusted by businesses in Waterloo Region and across North America
Most Waterloo companies do not go looking for an IT provider. They get pushed into one, and usually on a date they can point to in a calendar.
A software company signs its first enterprise customer — a bank, an insurer, a hospital network. Somewhere between the term sheet and the signature, that customer's procurement team sends over a vendor security review. It asks who holds administrative access, how accounts are removed when somebody leaves, where backups are held and in whose jurisdiction, whether multi-factor is enforced on everything or only on email, and when a restore was last actually performed. The answers exist. They live in three people's heads and one internal wiki page that has not been touched since the Series A.
That is the point at which the IT setup that got a company to thirty staff stops being enough. Not because it was bad — it was appropriate for what it was for — but because it was never built to be evidenced to somebody else.
We do that work. To be plain about what it is and is not: we cannot make you SOC 2 compliant, and you should be wary of any IT provider that says it can. An attestation comes from an auditor. What we can do is run the environment so the answers are true and can be produced on demand — conditional access actually enforced rather than configured, a joiner and leaver record with dates against it, patch compliance you can export, backups with restore evidence rather than a green tick on a dashboard. We hold a SOC 2 Type 2 attestation for our own operations, which mostly means we have sat on the answering side of the same spreadsheet.
If a customer's review is due in four weeks, say so on the first call. It changes the order we do things in, and it changes what is worth doing at all before the deadline.
Three times a year, a large number of Waterloo Region employers replace a meaningful share of their staff in the same fortnight. Co-op terms end and begin together. For a company running twelve students, that is twelve accounts to build, twelve machines to hand over and twelve sets of access to take away again — four months later, every year, for as long as the company keeps hiring that way.
Handled casually, this is where an environment quietly rots. What a first audit turns up is consistent enough to predict: licensed accounts belonging to people who left two intakes ago, a repository that a student still has access to, a personal laptop added to the network in a rush during onboarding week and never removed, and one shared credential for a tool that only one team uses — now known to a rolling cast of people, none of whom still work there.
We treat this as a scheduled operation rather than a run of unrelated tickets. Your intake dates are known in advance. Machines are imaged and accounts provisioned from a standard build before the first day, and the offboarding list runs on the last day of the term whether or not anybody remembers to raise it. Licences come back. Access ends on the date, not on the day someone notices. When a student returns for a second term in September, that is a restore rather than a rebuild.
The same discipline is what makes the security questionnaire in the section above answerable, which is not a coincidence — offboarding is the question every reviewer asks and the one most companies answer worst.
The clients below agreed to be named, so we can describe what we actually built rather than paraphrasing a compliment.
For the Ontario Soil and Crop Improvement Association we retired a failing on-premises server, moved the association onto our private cloud and swapped its VPN for zero trust network access, so that trust is decided per user, per device and per resource instead of by whether someone reached the network. The full migration is in our cloud migration case study for an agricultural association.
For Tube-Mac Industries we designed a VMware and Nimble storage platform that keeps manufacturing running when a component fails, and built JobSight, a job management application tied into Sage 300 so that job data is entered once rather than keyed into separate systems. That build is covered in our manufacturer high availability case study.
A lot of Waterloo companies have head office, engineering and sales in Waterloo, and production or the warehouse twenty minutes down the 401 in Cambridge. The office is a current Microsoft 365 environment. The plant is a machine of uncertain vintage bolted to equipment that cost six figures and is not being replaced to satisfy a patch policy.
Most providers price the office and the plant as two engagements. We put them on one, because the split is what creates the gap — the incident lands on the plant and the credentials came from the office. In practice the plant network is segmented from the office network, the controllers are inventoried with their supported operating system and their vendor's actual written position on patching, and the shift pattern is known so nobody schedules a firewall reboot at the start of an afternoon shift.
The environment that worked at fifteen people fails differently at sixty. Not dramatically — an SSO configuration that only half the applications use, a shared drive nobody can now audit, four different laptop models bought from four suppliers. It is a slow problem, which is why it is usually addressed under deadline pressure.
The co-op cycle above is the biggest driver, and it appears in nearly every environment we take over here: licences still assigned, access still live, and nobody able to say when it should have ended.
Staff living in Elmira, St. Jacobs, Wellesley, Baden and New Hamburg are on connections that are not what the office has. When a call drops or a file sync stalls, the laptop is usually not the problem, and diagnosing that correctly the first time saves a wasted afternoon.
Waterloo has a high rate of technical people who set up their employer's infrastructure competently and then went to work somewhere else. It is documented in their head. We write it down, which is dull work and the thing most worth paying for in the first ninety days.
Waterloo is about an hour from Toronto on the 401, and rather more between three and seven. That is the practical reason most GTA-based providers serve Waterloo remotely and quote a visit separately — an onsite call costs them a technician's entire afternoon in each direction.
We do not have a Waterloo office and are not going to claim one. Ours is at 22 Frederick St, Suite 700 in downtown Kitchener: about ten minutes from uptown Waterloo, about twenty from Cambridge. That is the honest version and it is also the one that matters, because what determines whether somebody can be at your building this afternoon is the distance from the office to you, not the address printed on a website.
What follows from it: onsite attendance is part of the agreement rather than an event that triggers a separate quote. A hardware swap, a cabling job or a fault that turns out to be physical does not wait for a scheduled visit from a provider driving up the 401.
Waterloo's tech ecosystem is anchored by the University of Waterloo, the Velocity accelerator, and the R+T Park cluster of research-driven companies. Research-adjacent SaaS companies scaling from campus spinouts to enterprise sales frequently face vendor security review at the exact moment they are trying to hire their first security lead. The SOC 2 attested MSP is often the first practical answer to that gap.
A Velocity graduate scaling to Series A does not have the security team to answer a SOC 2 vendor questionnaire from a Fortune 500 customer. Working with a SOC 2 Type II attested MSP means the questionnaire has a real answer without the delay of running the founder's own audit before the sale closes.
Companies spun out of University of Waterloo research groups often inherit an ad-hoc IT environment configured for a small research team. Scaling to enterprise-grade security controls without disrupting product development is a specific engineering problem NFD's engineers know well. The transition into the SOC 2-audited baseline is documented and reversible.
The vendor security review is one of the top two stall points in enterprise SaaS sales, alongside procurement legal review. A SOC 2 attested MSP moves the vendor review from an open-ended discovery conversation to a document handoff under NDA. Enterprise deal cycles measurably shorten.
For Waterloo companies that have already achieved their own SOC 2 Type II, working with a SOC 2 attested MSP is a vendor management control that satisfies the auditor's testing. The MSP's report is workpaper-grade evidence for the vendor management control objective.
Waterloo's operating environment covers tech, insurance, healthcare, and professional services — each with a compliance overlay that touches IT.
The Personal Information Protection and Electronic Documents Act is the federal baseline for handling personal information across Canada. For most Waterloo businesses, PIPEDA is the operative statute. Its safeguards principle expects access controls, encryption, incident response, and breach notification — the same categories the SOC 2 audit reviews.
Waterloo's medical practices, dental groups, physiotherapy clinics, and mental health providers are health information custodians under PHIPA. The Ontario Information and Privacy Commissioner publishes guidance that reaches through the custodian to the IT provider.
Waterloo has a long insurance industry legacy. Brokers, MGAs, and insurtech platforms operate under FSRA and, for federally regulated insurers, OSFI. Both require documented IT controls, tested incident response, and vendor risk management.
Cyber-insurance renewals increasingly require documented controls — MFA, EDR, immutable backups, incident response planning, named vendor accountability. NFD's operating baseline meets those requirements as the default posture.
US customer contracts increasingly reference SOC 2 as a required standard for the seller's infrastructure providers. Waterloo SaaS companies selling to Canadian federal and provincial government customers face data-residency requirements. Backups and monitoring data reside in Canadian-region infrastructure at NFD by default.
NFD serves Waterloo from the Kitchener office at 22 Frederick Street, a short drive from uptown Waterloo, the University of Waterloo research parks, R+T Park, Velocity, and the King-Belmont corridor. That geography is fifteen minutes on the ION or in a car, which is well inside NFD's same-day onsite window.
The University of Waterloo research parks host a concentration of research-driven and product-driven companies. The specific challenges of research-adjacent computing environments — GPU workstations, research data storage, mixed academic and commercial workflows — are inside our team's operating experience.
Waterloo's accelerator ecosystem produces companies that scale quickly. NFD's operating baseline is designed for growth-stage teams that need enterprise-grade IT and security controls before they can staff the internal team. The SOC 2 attestation and the named engineer model translate directly to the pressures of a fast-growing SaaS company.
The Waterloo insurance sector clustered around uptown and central Waterloo is one of the oldest continuously operating industries in the region. NFD's operating baseline covers the compliance overlay these firms carry — FSRA, OSFI where applicable, cybersecurity underwriting requirements.
An engineer dispatched from 22 Frederick Street can be in uptown Waterloo in under twenty minutes and at the UW campuses or R+T Park in under thirty. For critical onsite work, that geography is a same-day guarantee — not a scheduled visit.
NFD's Waterloo book is weighted toward technology, insurance, healthcare, professional services, and research-adjacent computing.
Waterloo SaaS companies from Velocity graduates to established late-stage firms use NFD for 24/7 monitoring, cybersecurity, backup, and SOC 2 vendor evidence. The engagement scales with the company: what starts as core managed IT expands into co-managed depth as the company builds its own security team.
Waterloo's insurance industry — carriers, brokers, MGAs, and insurtech platforms — carries a compliance profile that intersects FSRA, OSFI (for federally regulated insurers), cybersecurity underwriting scrutiny, and customer expectations around data residency.
Companies operating in University of Waterloo research parks, R+T Park, and adjacent environments have mixed academic and commercial computing needs. NFD's engineers routinely support environments that include research computing infrastructure alongside standard endpoints.
Uptown Waterloo and downtown Waterloo's medical practices, dental groups, physiotherapy chains, and mental health providers operate under PHIPA. NFD's privacy and confidentiality controls align with the safeguards custodians are expected to have in place.
Waterloo accounting firms and financial advisory practices carry the same regulatory overlay as their counterparts in Toronto and Kitchener — busy-season load, confidentiality expectations, CIRO or OSC oversight where applicable, and client vendor reviews.
Waterloo's engineering and architectural practices manage large project files, client-sensitive drawings, and multi-vendor collaboration workflows. NFD's operating baseline covers the security, confidentiality, and reliability requirements those workflows carry.
Waterloo Region manufacturing serves domestic and export customers. Export customers routinely send security questionnaires that ask about IT controls. NFD's audit closes those. Waterloo non-profits and foundations face donor privacy expectations that mirror the private sector — same audited operating baseline applies.
Yes, and the first thing we do is read it. Most of these ask the same nine or ten things: who holds administrative access, how accounts are removed when somebody leaves, multi-factor coverage, where backups sit and in whose jurisdiction, patch compliance, when a restore was last tested, logging, and who your subprocessors are. We work through them in the order of what can be made both true and evidenceable inside four weeks, and we tell you which answers will have to be honest rather than flattering. A reviewer will accept a dated remediation plan. They will not accept a claim that falls apart on the follow-up question.
No, and be wary of any IT provider that says it can. An auditor issues the report, and SOC 2 is an attestation rather than a certification. What we do is run the environment so the controls behind that report are genuinely in place and can be produced on demand — conditional access enforced rather than merely configured, a joiner and leaver record with dates against it, patch compliance you can export, backups with restore evidence rather than a green tick. We hold a SOC 2 Type 2 attestation for our own operations, which mostly means we have sat on the answering side of the same spreadsheet.
As a scheduled operation rather than a run of unrelated tickets. You give us the intake dates in advance; machines are imaged and accounts provisioned from a standard build before the first day, and the offboarding list runs on the last day of the term whether or not anybody remembers to raise it. Licences come back. Access ends on the date, not on the day someone notices. A student returning for a second term in September is a restore rather than a rebuild.
One. Most providers price them as two, and that split is exactly what creates the gap — the incident lands on the plant and the credentials came from the office. Under one agreement the plant network is segmented from the office network, the controllers are inventoried with their supported operating system and their vendor's written position on patching, and your shift pattern is known so nobody schedules a firewall reboot at the start of an afternoon shift.
About ten minutes from 22 Frederick St, Suite 700 to uptown Waterloo, and about twenty to Cambridge. We do not have a Waterloo office and are not going to claim one. Onsite attendance is part of the agreement rather than an event that triggers a separate quote, emergencies are same day, and everything else is scheduled.
With an inventory and administrative access, in that order. We document what actually exists — tenants, domains, certificates, licences, backup jobs, and the services billed to somebody's personal card — and take ownership of the accounts that control them. It is dull work and it is the single most valuable thing in the first ninety days, because until it is written down every decision you make about the environment is a guess.
One specific problem: their connection is not the office connection, so a dropped call or a stalled file sync is usually the link rather than the laptop. We test from the user's end before touching the machine, because diagnosing that correctly the first time saves a wasted afternoon and an unnecessary drive into the office.
Tell us what's not working. We'll be honest about whether we're the right fit and what it would realistically involve.