Security Insights
Expert perspectives, buyer playbooks, and technical analysis from the Lorikeet Security Canada team in Calgary and Toronto.
All Articles
11 articlesA Customer Wants Proof of a Penetration Test: What Enterprise Buyers Will (and Won't) Accept
Learn what enterprise procurement teams accept as proof of a penetration test, why sending a raw report is dangerous, and how an Attestation Letter unblocks deals.
How to Vet a Penetration Testing Firm Before You Buy: 5 Questions That Expose an Automated Scanner Reseller
How to differentiate genuine offensive security practitioners from automated scanner resellers. 5 essential questions to ask before signing a pentest SOW.
Your Cyber Insurer Is Asking About Security Controls: How Canadian Underwriters Actually Evaluate MFA, EDR, and Pentests
Canadian cyber insurers are tightening underwriting standards. Learn what controls are non-negotiable for policy renewal and how to avoid claim denials.
A Customer Sent You a 150-Question Security Questionnaire and You Have Nothing Prepared: The 48-Hour Playbook
What to do when an enterprise prospect sends a massive vendor security questionnaire and you have no SOC 2 or formal policies. A 48-hour survival guide.
The Hidden Costs of SOC 2 Nobody Quotes You (and How Canadian SaaS Companies Avoid Them)
The CPA audit fee is only half the expense. Discover the five hidden costs of SOC 2 compliance for Canadian SaaS companies and how to budget accurately.
What a Penetration Testing Deliverable Actually Looks Like: Dissecting an Executive Attestation vs Vulnerability Dump
Inspect the anatomy of an audit-ready penetration test deliverable. What belongs in an executive summary, technical vulnerability proof, and attestation.
PHIPA vs HIPAA: Navigating Cross-Border Health Data Compliance for Canadian Digital Health Companies
A comparative compliance guide for Canadian digital health companies in Calgary & Toronto navigating Ontario PHIPA, Alberta HIA, and US HIPAA regulations.
Quebec Law 25, Alberta PIPA, and Federal PIPEDA: The Canadian Privacy Stack Requirements Enterprise Buyers Demand
Understand the modern Canadian privacy compliance stack. Learn why enterprise procurement teams mandate Law 25, PIPA, and PIPEDA alignment before signing.
SOC 2 Type I vs Type II for Canadian Tech Companies: When to Trigger Your Observation Window Without Losing Deals
Should your Canadian SaaS company pursue SOC 2 Type I or go directly to Type II? Compare timelines, costs, and buyer expectations to make the right move.
Securing AI and RAG Architectures: The Vulnerabilities Enterprise Buyers and Auditors Test for Before Production
A technical guide for Canadian engineering teams deploying Generative AI and RAG. Learn how to secure vector stores, prevent prompt injection, and pass enterprise reviews.
Top 10 Cybersecurity Companies in Canada: 2026 Industry Guide
Explore the top 10 cybersecurity companies in Canada for penetration testing, fractional CISO advisory, MDR, and compliance, featuring Lorikeet Security Canada, Traztech, and more.