Frequently Asked Questions
The questions businesses actually ask before signing with an IT and security provider, answered plainly.
What is the minimum contract length, and can I cancel?
All plans are monthly rather than multi-year, with a 30-day notice period to cancel. There is no long lock-in, and the plan can be adjusted up or down as your risk and headcount change. The exact terms are set out in your signed agreement, so you always have them in writing.
We already have an IT person. Do you replace them or work alongside them?
Either. Plenty of engagements are alongside an existing internal person, where CyberConnect covers the security side, the infrastructure they do not have time for, or the work that needs a second set of hands. Replacing an existing provider is also common. What matters is that responsibilities are written down so nothing falls between the two of us.
What actually happens in the first week?
Day one is intake, risk triage, and a priority list of critical systems. The rest of the week covers access hardening and MFA, backup validation with a real restore test, endpoint and patch baselines, email and identity protection, and a written roadmap. It ends with a leadership briefing. The full day-by-day breakdown is on the home page.
What is your emergency response time?
Six hours for active incidents, and 48 hours for general requests. An emergency means an active or suspected compromise: ransomware, an account takeover, data exposure, or systems down in a way that stops you operating. It is not a monitored 24/7 channel, so if something is critical, phone rather than submitting a form.
Do you offer one-off projects, or is it monthly only?
One-off projects are available and are quoted per engagement - network builds, camera systems, migrations, cabling rebuilds, and website or platform builds. Every project starts with a site walkthrough and a written scope, and finishes with documented handover. Moving onto a monthly plan afterwards is optional, not assumed.
We are under 10 people. Is the Foundation tier overkill?
Possibly, and it is worth saying so rather than selling you the bigger number. Cyber Foundation is sized for teams up to 15 users, and IT Core Care for up to 10. For a very small team, a one-time hardening project followed by a lighter ongoing arrangement is often the more honest fit. Ask and we will tell you which of those actually applies.
Do you work with our existing vendors and software?
Yes. Most environments arrive with a POS provider, an accounting package, a booking system, and a line-of-business application that all have to keep working. The job is to secure and stabilise what you already run, not to force a migration. Where something genuinely needs replacing, you get the reasoning and the cost before anything changes.
Where is our data stored, and who can see it?
All client data access is handled directly by Dorian Balogh - no subcontractors, no offshore support, no third-party access. We work inside your systems rather than copying data out. If a copy is approved, it is held for a maximum of 30 days, or 14 in regulated and medically sensitive contexts. The full detail is in the Trust Center and the Privacy Policy.
Do you serve businesses outside Regina?
Yes. Regina is home base, Moose Jaw is a short drive, and Saskatoon and rural Saskatchewan are supported remote-first with planned onsite visits. Response targets do not change with distance because most work is remote. The service areas page sets out what onsite attendance looks like in each.
What happens to our systems if we stop working with you?
You keep everything. You own your admin accounts and infrastructure throughout, and can revoke access at any time without our involvement. Documentation and configurations are yours, so you leave with a working, documented environment that another technician can pick up. There is no lock-in and nothing is held hostage.
Do you handle compliance audits?
We prepare you for them rather than certify you. CyberConnect aligns environments to PIPEDA and PCI DSS baselines, uses CIS Controls as the practical hardening standard, and supports GDPR and HIPAA-conscious workflows where a client's obligations require it. Policy and control mapping to your specific scope is available, as is coordination of an annual penetration test. Formal certification is issued by an accredited auditor, not by us.
How is pricing adjusted as we grow?
Plans are banded by user count, so the tier changes when your headcount does rather than through surprise mid-year increases. Add-ons are priced individually and can be added or removed month to month. If growth means you have outgrown a tier, you will hear it from us before it becomes a problem.
Still have a question?
If it is not answered here, ask directly. Questions before an engagement are free, and a question you asked early is cheaper than an assumption you discover later.
Worked with us already? Leaving a Google review helps other Saskatchewan businesses find us.
Ready to get specific about your environment?
Book a Security Assessment