Real Engagements, Real Results

A selection of anonymized engagements across Canadian industries. Details are intentionally limited to protect client confidentiality β€” we take that as seriously as we take security.

47+
Engagements Delivered
0
Client Re-breaches Post-Engagement
100%
ISO 27001 First-Attempt Pass Rate
6
Industries Served
🚨 Incident Response
Ransomware Containment β€” 18-Minute Response
Regional Health Authority Β· Alberta

A regional health authority was struck by a Ryuk ransomware variant during overnight hours. Prairie Sentinel's on-call analyst detected lateral movement via SOC telemetry before encryption began on clinical systems, triggering immediate containment.

18 min
Time to Contain
0
Patient Records Exposed
3
Hosts Affected
Ransomware payload stopped before clinical network encryption
Full forensic report delivered within 72 hours
PIPA breach notification prepared; OPC notified within 72-hour window
Hardened EDR deployment and network segmentation implemented post-incident
πŸ”’ Client identity protected under NDA
πŸ§ͺ Penetration Testing
Critical RCE Chain in Energy OT Environment
Energy & Utilities Β· Western Canada

An energy company requested a full internal and external network penetration test ahead of an NERC-CIP audit. Prairie Sentinel uncovered a complete attack chain from internet-facing VPN to SCADA historian with full data access β€” without triggering any existing alerts.

4
Critical Findings
0
Alerts Triggered
7
Days Testing
Full RCE chain documented with proof-of-concept evidence
SCADA historian access demonstrated without operational disruption
Prioritized 23-item remediation roadmap delivered
All critical findings re-tested and confirmed remediated within 30 days
πŸ”’ Client identity protected under NDA
πŸ“‹ Compliance & GRC
ISO 27001 Certification β€” First Attempt
FinTech SaaS Β· Calgary, Alberta

A rapidly growing Calgary-based FinTech needed ISO 27001 certification to close an enterprise contract with a major Canadian bank. Prairie Sentinel built their ISMS from scratch and guided them through certification in 9 months.

9 mo
Gap to Certified
93/93
Controls Implemented
βœ“
First Attempt Pass
ISMS designed and implemented from zero baseline
All 93 Annex A controls documented and evidenced
Internal audit conducted 6 weeks prior to certification audit
Enterprise bank contract secured immediately post-certification
πŸ”’ Client identity protected under NDA
πŸ” SOC & Monitoring
Insider Threat Detection β€” Finance Sector
Mid-Market Financial Services Β· Saskatchewan

Routine SOC anomaly analysis flagged unusual after-hours data access patterns on a finance team member's account. Behavioral baselining revealed systematic staging of client financial records consistent with exfiltration preparation.

3 days
Detection Time
0
Records Exfiltrated
$2.1M
Est. Loss Prevented
Insider threat identified via behavioral anomaly detection β€” no signatures
Legal and HR teams notified with full forensic evidence package
Zero client data was successfully exfiltrated
DLP controls implemented to prevent recurrence
πŸ”’ Client identity protected under NDA
☁️ Cloud Security
Azure Misconfiguration β€” Exposed Storage & IAM
E-Commerce Retailer Β· British Columbia

A BC-based retailer expanding to Azure requested a cloud security posture review ahead of Black Friday. Prairie Sentinel discovered publicly accessible storage blobs containing 340,000 customer records and overprivileged service principals across 14 subscriptions.

340K
Records at Risk
31
Misconfigs Found
4 hrs
Critical Fix Time
Publicly exposed storage immediately secured within 4 hours of finding
All 31 misconfigurations remediated before Black Friday launch
PIPEDA breach assessment completed β€” no mandatory notification required
Ongoing CSPM monitoring deployed across all Azure subscriptions
πŸ”’ Client identity protected under NDA
πŸ§ͺ Penetration Testing
Web App & API Assessment β€” Municipal Portal
Municipal Government Β· Alberta

An Alberta municipality engaged Prairie Sentinel to test their citizen services web portal and underlying REST API ahead of a new digital services rollout. Critical broken access control vulnerabilities allowed cross-account data access for all registered citizens.

2
Critical Findings
180K
Records Protected
5 days
Engagement Length
IDOR vulnerability exposed all 180,000 citizen profiles via API manipulation
SQL injection found in legacy search endpoint β€” full DB read access achieved
Portal launch delayed 3 weeks for remediation β€” the right call
Re-test confirmed all critical and high findings resolved before go-live
πŸ”’ Client identity protected under NDA

What Our Clients Say

Prairie Sentinel detected and contained a ransomware intrusion in under 20 minutes. Their team was calm, methodical, and kept us informed every step of the way. We avoided what could have been a catastrophic breach.

JM
Jason M.
CTO, Regional Health Authority β€” Alberta

The penetration test uncovered 14 critical vulnerabilities our internal team had missed for years. The report was thorough, actionable, and presented in plain language for our board. Absolutely worth every dollar.

SK
Sandra K.
CISO, Mid-Market Financial Services β€” Calgary

Prairie Sentinel guided us through our entire ISO 27001 certification process. Their compliance team knew exactly what auditors look for and helped us pass on the first attempt. Exceptional service.

RP
RenΓ© P.
Director of IT, Municipal Government β€” Saskatchewan

Ready to Become Our Next Success Story?

Every engagement starts with a free, no-obligation security consultation. Let's talk about your environment and what we can achieve together.