Your business is a target. Here is where to start.
My name is Elie Catafago. I help SMBs in Beauce and across Quebec understand their real risks, comply with Law 25 and put in place the protections that actually matter - no jargon, and no enterprise budget required.
- 30-minute call, free and with no strings attached
- Reply within one business day, from me directly
- NDA signed before any information is shared
Seven ways to reduce your exposure
Every engagement starts with the same question: what would hurt the most if it happened tomorrow? The answer decides where we begin - and what we deliberately leave for later.
Security audits & penetration testing
"We think we are fine, but we have never actually checked."
I test your systems the way someone trying to get in would: what is exposed on the internet, what is reachable from the inside, and what your employees would do with a well-crafted email. You get the list of what I found, ranked by real severity, with what to do about each item and how long it takes.
Compliance & governance
"Our biggest client is asking for evidence and we do not know what to say."
I take you from an initial assessment all the way to the documents you have to produce: personal information register, retention policy, incident procedure, designated privacy officer. All aligned with Law 25 - and with ISO 27001, NIST CSF or the CIS Controls when your client requires it.
Training & awareness
"One of our employees clicked. That was close."
Short, practical workshops for your teams: spotting a fraudulent email, managing passwords without making life difficult, and knowing what to do in the ten minutes after something feels wrong. On site or online.
Incident response
"Our files are encrypted. What do we do, right now?"
Before: a written plan that says who does what, who we call and in what order. During: contain, understand what happened, restore operations. After: findings, fixes and what has to be reported - including under Law 25.
Virtual CISO (vCISO)
"We could use someone, but not full time."
An agreed number of days per month: steering your security plan, reviewing incidents, supporting technology decisions, handling your clients' security questionnaires and dealing with your cyber insurer.
Cloud security
"We moved to the cloud, but nobody has reviewed the settings since."
A review of your Microsoft 365 and Azure environments: who holds administrative rights, which accounts have no multi-factor authentication, what is publicly shared without your knowledge, and what your logs would actually let you reconstruct after an incident.
Cybersecurity for young people
"Our students live online, and we do not know how to talk to them about it."
Workshops for high school students, CEGEP students and their parents: protecting your identity online, phishing, cyberbullying, digital footprints and good habits. Adapted to the age of the group, and free of moralizing.
Integrating AI, securely
"Our employees already use AI. We have no idea what they put into it."
Two parts. First, setting boundaries: which data must never leave, which tools are acceptable, what policy to write. Then building: assistants shaped around your processes, hosted where you decide, on your data and by your rules. That expertise is what gave rise to CyberIA.
What I do not do
I do not sell software, antivirus or firewalls, and I take no vendor commission. When I recommend a product, it is because it solves your problem.
I do not run your day-to-day IT. That is not my trade, and your current provider probably does it better than I would.
I do not take on work I cannot deliver alone. If you need a team for six months, I will tell you on the first call and point you toward someone reliable.
I do not sell fear. A good share of my recommendations cost nothing, and I sometimes end an assessment by saying the rest can wait until next year.
What I see in SMBs across the region
Twenty years in cybersecurity, the last four inside a large organization where I saw just about everything that can go wrong. Since I started working in Beauce, three situations keep coming back among the businesses here.
These are not engagements I have carried out. They are situations I observe, from conversations with business owners here and from patterns I know well. If you recognize yourself in one of them, it is probably time we talked.
"Our IT guy takes care of that"
The business has an IT provider, often an excellent one, who keeps the systems running. Nobody ever asked whether "keeping the systems running" and "protecting the business" are the same thing. They are not the same trade, and not the same instincts.
What that looks like in practice: backups that have been running for years without ever being tested through an actual restore, former employees whose accounts are still active, and a shared administrator password nobody can account for anymore.
Do this week: ask your provider when they last restored a full backup for real - not merely confirmed that it ran. The answer will tell you a lot.
"Our biggest client sent us a security questionnaire"
This is the number one trigger today. A manufacturing or services SMB receives a sixty-question form from a major customer or from its insurer. Nobody in-house knows how to answer. You tick what you can, hope it goes through - and sometimes it does not.
The questionnaire is not the real problem: it simply reveals that none of these things was ever put in place or written down. The good news is that most of the expected answers cost time rather than money.
Do this week: pull out the last questionnaire you received and highlight the questions you could not answer. That is your work plan.
"We hold client data, but we have never looked at Law 25"
The business collects names, addresses, sometimes social insurance numbers for payroll or employee medical files. There is no register, no designated officer, no retention policy. Often nobody knows exactly where all that data sits, or how many copies are sleeping in mailboxes and USB keys.
Law 25 has been in force since 2022 and its final provisions have applied since 2024. Many businesses here learned about it when a client asked, not by reading the act.
Do this week: write down the five places where information about people is held in your business. If you hesitate at the third one, you have your answer.
Recognize yourself? The 30-minute call is exactly for this: putting words on your situation and figuring out whether there is something to work on together. It is free, and it sometimes ends with "you are in better shape than you thought, here are the two things to fix".
Book a 30-minute callHow we can work together
Three formats, from the lightest to the most committed. You get a firm written price before anything starts.
Initial assessment
Half a day to go through your situation: your systems, your sensitive data, your legal obligations and your most obvious exposure. You leave with a prioritized list of 10 to 15 actions, sized by effort, that you can hand to anyone - including your current IT provider.
- Written report of 8 to 12 pages
- One-hour debrief meeting
- Timeline: one week
- Fixed fee, given before we start
Law 25 compliance engagement
Taking you from an initial assessment to the documents you must produce: personal information register, retention policy, privacy incident procedure, designation of the responsible person, and training for your team.
- The full file, ready to present
- Training session for your team
- Timeline: 4 to 8 weeks depending on size
- Fee set after the assessment
vCISO - ongoing support
An agreed number of days per month: steering the security plan, reviewing incidents, supporting technology decisions, preparing your clients' audits and dealing with your cyber insurer.
- Quarterly dashboard
- Availability during an incident
- Six-month minimum commitment
- Fixed monthly fee, no surprises
In every case. The first 30-minute call is free. You get a firm written price before anything starts. No engagement begins on an open-ended estimate, and I will tell you on the call if your need goes beyond what I can deliver alone.
CyberIA
Five AI tools I built for Quebec SMBs. You do not need to be technical to use them - and they come with my support.
Describe a situation in plain language - a suspicious email, unusual sign-ins, a former employee who still has access - and get an analysis of the risk and the steps to take, with a PDF report.
Straight talk: CyberIA is a young product that I improve continuously. The tools above are live today, not mockups. Ask me for a demo and I will show you the platform as it is.
Elie Catafago
Consultant in cybersecurity, Law 25 compliance and AI integration
I have been supporting organizations in cybersecurity for more than 20 years, in Canada and internationally. I spent the last four years inside a large Canadian organization, where I led operational security, compliance and risk management work at enterprise scale.
I founded Catafago Services to make that level of support available to SMBs in Beauce and across Quebec - the ones with no internal security team and no budget for a large firm, but with exactly the same legal obligations and the same attackers on the other side.
My approach combines technical expertise, governance and responsible AI integration - including through CyberIA, the platform I am building to make cybersecurity more concrete for Quebec SMBs.
Strategic view
Aligning security with your business goals and your real budget
Technical expertise
Penetration testing, forensics, architecture, cloud security
Governance and compliance
Law 25, ISO/IEC 27001, NIST CSF, CIS Controls
My values
Like a solid firewall, my approach rests on three layers. Each one holds because of the one beneath it.
Ethics - The foundation
I do not resell software and I take no vendor commission. When I recommend a tool, it is because it solves your problem. And I tell you what you need to hear rather than what you want to hear - including when the answer is "that can wait until next year".
The commitment: no commissions, no reselling, no conflict of interest.
Expertise - The protection
Twenty years in cybersecurity, in Canada and internationally, including four inside a large organization. No SMB can fix everything at once: my work starts by sorting what really exposes you, what can wait, and what is not worth the investment in your situation.
The commitment: prioritized actions sized by effort, never a list of 200 items.
Innovation - The advantage
I bring artificial intelligence into SMB cybersecurity - that is what CyberIA is for. But innovation is worthless if it makes you dependent: I document and I train your people so the day-to-day belongs to you.
The commitment: by the end of an engagement, you no longer need me for routine work.
From assessment to follow-up, with no surprises
Four steps to understand your risks, prioritize the work and measure progress.
Assessment
A picture of your current posture, your critical assets and the risks to address first.
Plan
A realistic plan aligned with your goals, your budget and your legal obligations. Priced before we start.
Implementation
Carrying out the priority actions, with named deliverables, clear responsibilities and written follow-up.
Follow-up
Regular check-ins, progress indicators and continuous improvement of your security posture.
Let's talk about your priority risks
A 30-minute call, free and with no strings attached, to clarify your situation and identify the first priorities. If I am not the right person for your need, I will say so during the call.
Incident in progress? Do not write - call 418-313-3457. The first few hours matter.
Send a message
The questions people actually ask me
Direct answers about how I work, timelines, confidentiality and cost.
I work alone, and that is a deliberate choice. You speak with the person doing the work, from the first call to the final report - not with a salesperson who then hands it off to someone else. When an engagement goes beyond what I can deliver alone, I say so from the start and point you toward someone qualified.
Yes, though rarely in a targeted way. Most attacks on SMBs are automated sweeps looking for known weaknesses, with no idea and no interest in who is behind them. A 20-person business with an unpatched server gets found as fast as a large enterprise - often faster, because nobody is watching.
Law 25 is Quebec's legislation on the protection of personal information. It applies to any business that collects information about people - customers, employees, suppliers. So yes, it applies to you. In practice it requires designating a responsible person, keeping an incident register, telling people what you do with their data, and being able to answer their requests.
No, and that is not the goal. Your provider keeps your systems running; my role is to look at those same systems through the lens of risk and compliance. In most cases I work with the provider already in place, not against them. I can also help you frame what you should be asking of them.
It is a methodical review of your systems, your access and your working practices, to find what exposes you before someone else does. You receive a written report with what was found, ranked by real severity, and for each item what needs doing and the effort it takes.
I call you the same day, before finishing anything else. Then we decide together what comes next: what gets patched immediately, what can wait, and whether someone else needs to be brought in. Nothing is disclosed to anyone without your agreement.
Yes. I sign a non-disclosure agreement before any information is shared, including before the discovery call if you prefer. I never name a client without written permission, and the reports belong to you.
Yes, and that is why I always start with a fixed-price assessment rather than a large project. A good share of what I recommend costs nothing to put in place - settings, procedures and habits. You know the cost from the start, and you decide what comes next.
The initial assessment takes a week and you leave with a prioritized list of actions. Several of them take a few hours and no budget. You do not wait for the end of a long engagement for your situation to improve.
It is free and lasts 30 minutes, by phone or video. We go through your situation, what worries you and your obligations. By the end you know whether there is something to work on together - and if the answer is no, I will say so.
CyberIA is the artificial intelligence platform I built for SMB cybersecurity. It brings together five tools: a threat analyzer, a phishing detector, a security posture assessment, QR code analysis, and PDF reports you can hand to a client or an insurer. It is online and usable today, the data is hosted in Canada, and it keeps evolving from what I see in the field.
Yes. I run awareness workshops for high school students, CEGEP students and parents: protecting your identity online, phishing, cyberbullying and good digital habits. Write to me to schedule a session at your institution.
Yes. I design AI tools suited to your sector - healthcare, retail, education, finance, manufacturing. The approach is always the same: understand how you work, then build a tool that saves you time or reduces errors, without exposing your data. No jargon, just something that works where you are.
One hour to know where you stand
Free 30-minute call - Clear priorities when you hang up - Reply within one business day
Book a 30-minute call