Managed Security

Cybersecurity for businesses that can't afford a breach.

A practical security baseline - not a checkbox exercise. MFA, conditional access, email security, endpoint protection, monitoring, and a plan for when something goes wrong.

Security baseline checklist

Every managed security engagement reaches this baseline. These aren't optional extras - they are the minimum acceptable posture for a business operating in 2025.

  • MFA enforced on all accounts - Microsoft 365, email, VPN, and line-of-business apps
  • Conditional access policies configured by user role, device state, and location
  • Endpoint protection deployed and managed - not just installed and forgotten
  • Backup and disaster recovery built on Veeam or Datto - tested restores, documented procedures, off-site retention
  • Email security: anti-phishing, anti-spoofing, attachment sandboxing, DKIM/DMARC/SPF configured
  • Azure AD / Entra ID hardened - legacy auth blocked, sign-in risk policies active
  • Privileged access reviewed and minimized - no stale admin accounts
  • Security alerts routed to a monitored destination, not an inbox nobody checks
  • Offboarding process verified - departed staff access fully revoked on day one

Why most SMB security fails

Security tools are installed without being configured. MFA is turned on for some accounts but not others. Nobody owns the monitoring inbox. Offboarded staff still have access weeks later.

TechHouseCA treats security as a set of operational controls, not a product sale. We configure, validate, document, and review - not just deploy and move on.

Serving companies in Calgary, AB and Kelowna, BC.

Vendor Flexibility

Entry level to enterprise. We deploy the full stack.

TechHouseCA is vendor-flexible. We deploy security stacks from entry level to enterprise - UniFi and Sophos for lean teams, Fortinet and Aruba for growing networks, CrowdStrike, SentinelOne, and Palo Alto Networks for enterprise-grade protection.

We recommend what fits your size, risk, and budget - not whatever we happen to resell. No mystery bundles, no inflated invoices.

Lean teams

  • UniFi
  • Sophos

Growing networks

  • Fortinet
  • Aruba

Enterprise

  • CrowdStrike
  • SentinelOne
  • Palo Alto Networks

The right tool for your environment - sized and scoped honestly.

What we cover

MFA & Conditional Access

Multi-factor authentication deployed across every entry point. Conditional access policies enforced based on device compliance, location, and sign-in risk - not just a blanket on/off toggle.

Monitoring Strategy

Security alerts configured, routed, and reviewed. Log retention set appropriately. You know what's happening in your environment, and anomalies surface before they become breaches.

Email Security

Anti-phishing, anti-spoofing, attachment analysis, and link scanning. DKIM, DMARC, and SPF configured correctly. Impersonation attempts blocked before they reach staff inboxes.

Incident Response Planning

A documented plan for what happens when something goes wrong - who does what, in what order, with what tools. Tested, not theoretical.

Compliance Readiness

Controls and documentation aligned to common frameworks. Evidence of security posture available when insurers, auditors, or enterprise clients ask for it.

Endpoint Protection

Business-grade endpoint detection and response - not consumer antivirus. Managed, monitored, and kept current across every device in your fleet.