Skip to content

Practical protection is a short list of specific layers.

Maintenance and security rhythm names practical security hygiene as part of managed IT without listing what it actually contains. This page names the layers - email filtering, endpoint protection, sign-in habits, and the phishing recognition employees can actually learn - plus the honest line about what still needs a specialist.

Read this page in French

Four ordinary layers

Protection is built from separate, specific pieces of work.

No single tool stops every attack. A realistic security posture layers several ordinary pieces of work on top of each other, so a missed patch, a clicked link, or a reused password does not become the only thing standing between an employee and a serious incident.

The layers, named

What “security basics” is actually built from.

Email filtering

Spam and phishing filtering on the mailbox, plus the domain-level records that make it harder for someone to send email pretending to be your business.

Endpoint protection

Antivirus and malware protection running on every managed laptop and desktop, kept current the same way any other software gets updated.

Phishing recognition

Specific, practical habits employees can actually learn - checking the sender address, hovering before clicking, and knowing the one number to call when something looks wrong - not a generic reminder to “be careful.”

What's real / what is not claimed

A useful line, not a blurred one.

What's realMailbox filtering, endpoint protection, sign-in security, patch discipline, and staff-facing phishing habits, applied consistently across the devices and accounts actually in scope.

What is not claimedA dedicated security operations centre, a guaranteed detection or response time, or a specific compliance certification. Exact tools and coverage are confirmed in writing, not on this page.

A real baseline, tested

A real baseline can answer these questions on request.

  • Which mailboxes and domains are protected, and how the underlying authentication records are set up
  • Which devices run current endpoint protection, and which are explicitly excluded
  • How a reported phishing attempt actually gets handled once someone flags it
  • What happens differently when multi-factor authentication catches a suspicious sign-in
See how this fits the recurring maintenance rhythm

Routine versus urgent

A caught phishing email and a live incident are different conversations.

Catching and cleaning up an ordinary phishing attempt is routine work. A confirmed compromise - an account actively being used by someone else, files already encrypted - needs an incident-response conversation with its own scope and its own urgency, not a ticket in the regular queue. See how incident readiness connects to Law 25 and PIPEDA

Prepare the responsibilities before contacting a provider.

The service map turns your context into a short, copyable list: people, devices, Microsoft 365, vendors, and decisions to clarify.

Build the service map