Contact
Let’s talk about your infrastructure
The first conversation is free and without commitment. You leave with a written summary of your primary exposure.
Office
Montréal, Québec, Canada
Write to us
[email protected]Technical support
[email protected]Careers
[email protected]What a first conversation looks like
The first call runs 30 to 60 minutes. We aim to understand your context: size, sector, regulatory obligations, past incidents, the state of your infrastructure and leadership priorities. No sales pitch at this stage.
We then send you a written summary of your primary exposure and, if an engagement makes sense, a costed proposal with scope, milestones and deliverables. If you do not proceed, the summary is yours to keep.
Key points
- A 30 to 60 minute conversation, with no commitment and no sales pitch.
- You leave with a written summary of your principal exposure.
- Incident in progress: say so in your message and it goes ahead of everything else.
- The first contact is with a consultant, not a sales desk.
How does a first conversation work?
In 30 to 60 minutes, by phone or video. We aim to understand your context: size, sector, regulatory obligations, past incidents, the state of your infrastructure and leadership priorities. No sales presentation at this stage.
The format is deliberately short and informal. Its purpose is not to sell you something but to establish whether your need matches what we know how to do, and which of our engagement types would deliver the most value in your situation. Sometimes the conclusion is that you do not need us, and that is an acceptable conclusion.
- What we try to understand. What would stop you tomorrow, what you already pay for without using, and who holds you to account: a client, an insurer, a regulator. Those three answers shape almost everything that follows.
- What you receive next. A written summary of your principal exposure and, if an engagement makes sense, a proposal with scope, milestones and deliverables. If you do not proceed, the summary is yours to keep.
What should you do in the first sixty minutes of an incident?
Four reflexes, in this order. Do not power off the affected machines. Isolate from the network rather than shutting down. Write down the time and nature of what you observe. Then alert someone authorised to decide, before acting on the systems.
These four steps require no technical skill and change a great deal afterwards. They are useful whether or not you have support in place, and we publish them here because the first hours almost always unfold without us.
If personal information is affected, Law 25 additionally requires you to record the incident in your register, assess the risk of serious injury, and notify the Commission d'accès à l'information and the individuals concerned where that risk exists.
- Do not power off. A machine that is shut down loses evidence in memory that often determines what happened and how far it went. Unplug the network, yes; cut the power, no.
- Isolate rather than shut down. Removing suspicious endpoints and servers from the network limits spread while preserving state.
- Document as you go. Time, symptom, action taken, by whom. That record serves the qualification of the incident, the regulatory notification and your insurer.
- Do not pay, do not respond alone. Where a ransom is demanded, the Canadian authorities' position is consistent: payment is not recommended. Report the incident to the Canadian Centre for Cyber Security and the Canadian Anti-Fraud Centre.
How do you handle inbound requests?
Every request is read by a consultant, not by an automated system nor by a sales qualification desk. We come back to you as soon as we have something useful to say, and reports of an incident in progress go ahead of everything else.
We do not publish a response-time commitment. That is a deliberate choice: a posted timeline is only worth having if it holds in every case, including during an emergency engagement at another client, and we prefer not to promise what we do not fully control. What we do guarantee is the nature of the reply: it comes from a person who has read your context.
If your request concerns an incident in progress, say so explicitly in the first paragraph of your message or call directly. That is the only prioritisation criterion we apply.
Where are you based and where do you work?
RISS Canada Inc. is headquartered in Montérégie and works in Greater Montreal, Montérégie and throughout Quebec, on site and remotely. Full contact details appear in the legal notice.
Three distinct destinations exist depending on your request: commercial enquiries and assessment requests, technical support for clients under engagement, and applications, handled through the careers page.
- On-site work. Physical infrastructure surveys, wireless coverage studies, cutover windows, awareness workshops. Mainly in Greater Montreal and Montérégie, elsewhere in Quebec depending on the engagement.
- Remote work. Technical reviews, governance and compliance work, monitoring, training. This is the majority of the work, and it covers the rest of Canada.
- Europe. Engagements are run with our partner RISS Consulting in France, which allows us to support an organization subject to both the European and Quebec frameworks.
Sources
- Canadian Centre for Cyber Security · incident reporting and recommended measures
- Canadian Anti-Fraud Centre · reporting fraud and ransom demands
- Commission d'accès à l'information du Québec · confidentiality incident register and notification
- Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1) · obligations in the event of a confidentiality incident
The steps described for the first minutes of an incident are general preservation measures. They do not replace the intervention of a response team nor legal advice on your notification obligations, which depend on the data affected and the law applicable to your organization.
Frequently asked questions
It runs 30 to 60 minutes, by phone or video, with a consultant. We ask questions about your context rather than presenting our offers: what would stop you tomorrow, what your licences already cover, and who holds you to account. You then receive a written summary of your principal exposure. There is no sales presentation and no pricing proposal at this stage, because putting a number on it before surveying the environment would produce a wrong number.
Yes, and the written summary stays yours even if you do not proceed. That is a deliberate position: an organization that leaves with a clear view of its risks and decides to handle them itself has still gained something. We prefer that to an engagement sold before it was understood, which generally ends badly for both parties. No clause binds you at the end of that conversation.
Reports of an incident in progress are prioritised above all other requests. Say so explicitly in the first paragraph of your message, or call. We do not publish a guaranteed response time, because a commitment of that nature is only worth having if it holds in every case, including when we are already engaged elsewhere. The Protection and 360 levels of RISS 360 do, however, include contractually defined on-call coverage.
No. The first conversation and the written summary that follows it are free. What is billed begins with the in-depth technical review, and that is then set out in a written proposal with scope, milestones and deliverables, accepted before any work starts. You will not receive an invoice for something you have not agreed to in writing.
Yes, that is the most common case. We are not a managed IT services provider and we are not looking to replace yours: our role is analysis, advice and oversight. That includes helping you frame the technical questions you lack the means to ask, particularly about their patching timelines, the scope their contract actually covers, and their obligation to notify you of an incident at their end.
Is your infrastructure ready for the next threat?
An initial assessment, free and without commitment, to evaluate your security posture.