Separate facts from unknowns
Ask what was checked, when, with which access and against which inventory. A system that could not be reviewed is an open question, not a passing result.
Turn a security concern into a defined piece of work. North Star helps Lacombe businesses scope account protection, endpoint controls, monitoring and recovery planning, with clear responsibilities and evidence to review.
A Lacombe business may need help with a client questionnaire, unmanaged laptops, access left behind by a former employee, or an unclear incident plan. Identify the concern and the person authorised to approve changes before choosing tools. An assessment, implementation project and recurring managed service have different deliverables.
For a team split between an office, a shop and mobile work, note where devices connect, who owns them and when staff can test changes. Where a specialist vendor controls business equipment, agree access and responsibility with that vendor. Do not assume a remote technician can change every system or reach an offline device.
North Star serves Lacombe through Canada-wide remote delivery. Physical work is scheduled from Prince George and Grande Prairie, not a Lacombe storefront. Keep site access, travel and hands-on tasks visible in the proposal.
Use these questions to compare proposals. They are planning prompts, not a claim that your systems have been tested or that every item is included in a plan.
| Workstream | Define before work | Evidence to request |
|---|---|---|
| Accounts and MFA | Accounts, administrators, recovery access, legacy exceptions and who approves access changes. | A covered-account list, recorded exceptions and agreed sign-in and recovery checks. |
| Devices and patching | Supported devices, ownership, licensing, vendor restrictions and maintenance windows. | Deployment and update results for the agreed inventory, with failed or unsupported items assigned for follow-up. |
| Email and staff reporting | Mail services, shared inboxes, reporting contacts and any training or simulation scope. | Configuration review and reporting-path checks; training results if a campaign is included. |
| Monitoring and response | Coverage hours, alert sources, escalation contacts and containment authority. | A documented escalation path and a review of an agreed exercise or example alert, not a promise of immediate containment. |
| Backup and recovery | Protected data, retention, recovery priorities and who approves restoration. | Results from agreed restore checks, unresolved exceptions and the next review date. |
Security tools, subscriptions and administration are not interchangeable. Confirm what is already licensed, what needs purchasing, which work is one-time and which work recurs. Review published IT pricing as a starting point, then obtain a quote for the actual scope.
Ask what was checked, when, with which access and against which inventory. A system that could not be reviewed is an open question, not a passing result.
Name an owner and approval point for each action. Record maintenance windows, user preparation, vendor dependencies and any rollback or recovery decision before changes start.
Review agreed checks and exceptions with the business contact. Keep documentation and critical accounts under customer ownership, with a follow-up date for unfinished work.
For ongoing coverage, connect the findings to the agreed support process. A finished assessment does not establish that all fixes are implemented, and a successful check does not guarantee that a future incident cannot occur.
Prepare an authorised technical contact, supported remote access and a suitable way to share evidence. If the work needs someone at a device, in a network room or alongside an equipment vendor, separate that task from remote administration and agree how it will be delivered.
Dispatch from Prince George and Grande Prairie depends on the job and technician availability. Confirm site access, appointment timing, travel charges and any approved local-hands arrangement. Neither a service-area page nor an assessment request promises a local office, immediate arrival or a particular response time.
For general support, use the Lacombe managed IT hub. For deeper workstream detail, review the national cybersecurity service scope and backup and recovery service. A security review does not replace a recovery plan.
Yes. Start by defining the systems to review, the access available and the decision you need to make. An assessment documents findings within that agreed scope. Remediation, ongoing monitoring and managed IT are separate decisions; confirm the deliverables and price before work begins.
List business accounts, supported computers and phones, shared devices, remote access and third-party systems. Identify personally owned or vendor-controlled equipment before approving changes. The proposal should name covered systems, licensing requirements, exclusions and who may authorise work.
Not automatically. Confirm monitoring hours, which alerts are investigated, escalation contacts and authority to contain a suspected incident. Incident response and recovery may need a separate scope. Monitoring does not guarantee that every threat will be detected or that disruption will be prevented.
We can scope a review of the requested controls and supporting evidence. Bring the actual questionnaire and distinguish implemented controls from planned work. Confirm acceptance with the insurer or broker; an assessment does not guarantee insurance approval, claim payment or legal compliance.
North Star does not have a Lacombe office. Canada-wide remote support is backed by scheduled dispatch from Prince George and Grande Prairie. If work needs physical access, agree technician availability, site access, travel charges and any local-hands arrangements before booking.
Use the escalation contacts in your incident plan or support agreement and notify the authorised decision-maker. The assessment form is not a monitored emergency channel. Do not send passwords, recovery codes or sensitive incident exports through it. Confirm authority and a suitable evidence-sharing channel before investigation begins.
Tell us the business concern, approximate user and device counts, main systems and any deadline. We will confirm the assessment scope and next step. This form is not a monitored emergency channel; do not send passwords or sensitive incident evidence.
Discuss your cybersecurity assessmentChoose the exact service