SYS::STATUS SOC · ONLINE
FR / EN
cl
CostLink Systems
v.2026.05 · soc·mtl
~ / services
[ROOT] · FULL CATALOG

Six disciplines.
One team.
Operated from Montréal.

No enterprise overhead. No under-equipped SMB toolset. Every engagement is calibrated for Quebec organizations between 50 and 2,000 employees — and delivers the documentary evidence you'll present to your auditor, regulator, or cyber insurer.

[01] · MDR — MANAGED DETECTION & RESPONSE

The centre. Always on.

Continuous monitoring by bilingual analysts in Montréal. Detection across the full signal set — endpoint, network, cloud, identity. When a signal becomes an alert, a human is at the keyboard in under 15 minutes median (22 minutes at the 95th percentile).

The centre isn't a dashboard. It's a human engagement. Monthly reports document what was seen, contained, and learned — not a raw alert count. Every organization gets two dedicated analysts plus an escalation team.

// THREATS TYPICALLY DETECTED
RANSOMWAREAkira, LockBit, Royal families — behavioral detection before impact, automatic endpoint isolation.P1
PHISHING + BECExecutive mailbox compromise, payment redirection, wire fraud. M365 triage + sequence interceptor.P1
EXFILTRATIONAnomalous cloud uploads, mass file share access, DNS tunneling.P2
AD PRIVILEGESKerberoasting, DCSync, lateral movement. Identity signal correlation.P2
NATION-STATEAttributed TTPs (APT29, APT41), sophisticated persistence. CCCS escalation mandate if confirmed.P3
// TECHNICAL STACK
CrowdStrike Falcon SentinelOne Microsoft Defender XDR Splunk Enterprise Elastic SIEM Microsoft Sentinel Velociraptor (DFIR) YARA · Sigma · ATT&CK
// WHAT'S INCLUDED
  • 24/7/365 monitoring by bilingual analysts
  • Triage and escalation under 15 minutes median
  • Active containment (endpoint isolation, identity blocking)
  • Signed monthly report, audit-ready
  • Tenant portal with ticketing, alert journal, posture
  • Quarterly review with the operations director
  • BYOK integration of existing client tools
contract.spec · mdrstandard
OPERATIONAL PARAMETERS
MTTR — detection< 15 min
MTTR — escalation< 22 min (P95)
Coverage24/7/365
Dedicated analysts2 + escalation
Signals correlatedEDR · log · cloud · ID
Reportsmonthly signed
Commitment12-month min.
Data residencyQuébec
Law 25compliant
[02] · IR — INCIDENT RESPONSE

When the event happens.

Four hours on-site, or immediately remote. A dedicated incident response team takes the helm: containment, digital forensics, threat actor negotiation if required, regulator and insurer communication, phased remediation plan.

Available as one-off engagement or as an annual retainer (40 hours blocked · fixed rate · trigger SLA < 2 h). The retainer eliminates rate negotiation mid-crisis — the invoice is known in advance.

// PHASES
T+00 — T+02hMobilization. Client briefing, remote deployment, first indicators of compromise, perimeter established.phase 1
T+02 — T+24hContainment. Isolation of affected assets, access revocation, targeted network blocking, evidence preservation.phase 2
T+24 — T+96hInvestigation. Endpoint and network forensics, attack chain reconstruction, initial vector identification.phase 3
T+96h — T+14dRemediation. Eradication, controlled restoration, hardening of identified weak points, graduated return to operations.phase 4
T+14d — T+45dReport and lessons. Complete dossier, regulator communication (Law 25, AMF, OSFI if applicable), post-incident roadmap.phase 5
// AVAILABLE EXPERTISE
Endpoint forensics Network forensics Cloud forensics (Azure · AWS · GCP) M365 · Google Workspace forensics Reverse engineering · malware Ransom negotiation Regulator comms (Law 25 · AMF) Cyber insurer liaison Expert testimony
contract.spec · ir · retainerurgent
RESPONSE PARAMETERS
Trigger SLA< 2 h
On-site (GTA-equivalent)< 4 h · MTL
Minimum team3 responders
Incident leadCISSP · GCFA
Forensics includedendpoint · network · cloud
Annual retainer40 blocked hours
Off-retainer hourlypremium ×1.8
Law 25 notificationhandled
// EMERGENCY HOTLINE
opt. 1 · human response < 2 min · 24/7/365
[03] · PENTEST — OFFENSIVE ASSESSMENT

Find the holes
before adversaries do.

Penetration tests executed by our in-house red team. No subcontracting. The engagement covers the agreed surface — external, internal, application, cloud, social — with a report delivered to the client within 14 days of the final execution.

Three formats. The fixed-depth test (predictable scoping), the objective red team (free infiltration target chosen by CostLink), and the continuous program (rolling waves over 12 months — equivalent to a private bug bounty program).

// SURFACES COVERED
EXTERNALOSINT reconnaissance, exploitation of public services, WAF bypass, initial foothold.2 weeks
INTERNALOnce on the LAN — Active Directory elevation, lateral movement, access to critical data.3 weeks
APPLICATIONWeb and API testing per OWASP Top 10 + ASVS Level 2. Source or black box.2 weeks
CLOUDPosture assessment for Azure, AWS, GCP, M365 — misconfigurations, IAM, privilege escalation.2 weeks
SOCIALTargeted phishing, voice pretexting, physical access. Separate engagement, strict conditions.on call
RED TEAMOpen objective — access to most sensitive data. No detailed rules of engagement up front.4 — 8 weeks
// TEAM CERTIFICATIONS
OSCP × 5 OSCE × 2 OSEP × 2 CRTO GPEN GWAPT GXPN
contract.spec · pentestred team
STANDARD SCOPING
Fixed depth — external2 weeks
Fixed depth — internal3 weeks
Red team objective4 — 8 weeks
Continuous program12 months
Report delivery< 14 days
Retest of fixesincluded · 60 d
Subcontractingnever
Audit attestationsigned
[04] · COMPLIANCE EVIDENCE

The proof. Signed. Dated.

Five frameworks covered in regular practice: Quebec's Law 25, ISO 27001, SOC 2 Type II, PCI-DSS v4, NIST CSF 2.0. Every engagement delivers the documentary dossier that passes the audit — policies, procedures, registries, operational evidence, gap remediation plan.

Law 25
active

Privacy officer designation, governance policy, incident registry, PIA template, training program.

ISO 27001
active

Certification readiness, Statement of Applicability, risk assessment, treatment plan, internal audits.

SOC 2 II
active

Trust Service Criteria scoping, continuous evidence collection, observation period, CPA auditor liaison.

PCI-DSS v4
v4.0.1

Multi-site retailers, e-commerce, franchised restaurants. SAQ, AOC, scope analysis, segmentation.

NIST CSF 2.0
framework

Posture measurement across six functions (govern, identify, protect, detect, respond, recover).

CMMC 2.0
on demand

For Defense (CA/US) subcontractors. Levels 1 and 2 covered. Available on specific engagement.

contract.spec · compliance
TYPICAL PARAMETERS
Initial scoping3 — 6 weeks
First certification6 — 12 months
Maintenance cadencequarterly
Internal auditannual included
Simultaneous frameworksup to 4
Active engagements (network)44
Audit success rate100 %
[05] · ENDPOINT PROTECTION

EDR · XDR ·
deployed. Maintained.

Deployment and continuous operation of the EDR layer across the entire fleet — workstations, servers, mobile devices. Calibrated prevention policies, updates validated within maintenance windows, automatic isolation on confirmed compromise.

Three models: we operate your existing license (BYOL), we provide the license under our tenant (managed), or we co-administer with your internal team. No engagement forces an editor change without clear operational benefit.

// SUPPORTED PLATFORMS
CrowdStrike Falcon SentinelOne Singularity Microsoft Defender for Endpoint Palo Alto Cortex XDR Sophos Intercept X Bitdefender GravityZone
contract.spec · endpoint
Coverage target≥ 99.2 %
Drift tolerance< 0.8 %
False positives (target)< 0.4 %
Update SLA< 7 d (validated)
Auto-isolationenabled
Supported modelsBYOL · managed · hybrid
[06] · TRAINING & SIMULATION

The human. The firewall
we train.

Continuous training calibrated by role. Phishing simulation campaigns with measured learning curves. Tabletop exercises for executive committees. Everything delivered in Quebec French — not a rough translation of an American program.

Measure what matters: not module completion rates, but the actual reporting rate for a suspicious email, the reporting delay, and the click rate reduction quarter over quarter.

contract.spec · training
Microlearning cadencemonthly
Sim. campaign cadencemonthly
Executive workshopsquarterly
Annual tabletopincluded
LanguagesFR-QC · EN-CA
LMS platformincluded
Annual reportLaw 25 ready
[07] · NEXT STEP

One assessment. Four weeks.
No commitment.

A director walks through your current posture — governance, technical, human — and hands you a report and a roadmap. If we work together afterwards, the report is credited against the first engagement. If not, keep it.