BadgerAuditPremium · on-site

A complete security audit, on-site and in person.

A scanner sees your tech. BadgerAudit is a consultant-led, on-site review of your physical security, document handling, network, policies, and staff practices, mapped to NIST CSF / CIS Controls and PIPEDA, delivered as a board-ready risk report and remediation roadmap.

Fixed-fee, from C$3,500 CAD. Scoped to your organization on a discovery call.

Online vs. on-site

Free external scan

Everything an anonymous visitor can see online.

  • DNS, SPF/DMARC, TLS
  • HTTP security headers
  • Public files & fingerprint
  • Subdomains & known CVEs

The front door: useful, but it stops at the perimeter.

BadgerAudit · on-site

Your whole organization: physical, people, policy, systems.

  • Physical & building security: access, server room, cameras, visitors
  • Documents & data: storage, retention, shredding, backups
  • Network & systems: segmentation, firewall, Wi-Fi, access, credentialed scan
  • People & process: staff interviews, awareness, incident response
  • Vendor & third-party risk
  • Every finding mapped to NIST CSF / CIS Controls / PIPEDA

The whole building: where breaches actually happen.

What we assess on-site

Building & server-room accessBadges, cameras, visitor managementClean-desk & shreddingDocument & records storage / retentionBackups & data handlingNetwork architecture & segmentationFirewall & Wi-FiCredentialed vulnerability scanAccess managementIncident-response planVendor / third-party riskSecurity-awareness trainingStaff interviews

How it works

1

Discovery call & scope

We confirm your sites, systems, and staff count, agree the scope, and give you a fixed fee. No surprises.

2

On-site assessment

A consultant comes to you and reviews physical security, network, document handling, and policies on location.

3

Interviews & technical scan

Staff interviews to see how security works in practice, plus a credentialed vulnerability scan of your authorized systems.

4

Report & roadmap

A board-ready risk report mapped to NIST CSF / CIS / PIPEDA, plus a remediation roadmap and a walkthrough with your team.

DONE RIGHT

A serious audit, handled professionally.

We're in your building and your systems, so trust is the whole job, not a footnote.

✓
Authorized & scoped
We assess only what you approve in the engagement letter, nothing outside it.
✓
No disruption
We review and verify. We don't attack, brute-force, or take systems down.
✓
Confidential
NDA by default. Findings go to you and your leadership, never a marketing deck.
✓
Standards-mapped
Every finding ties to NIST CSF, CIS Controls, and PIPEDA. Defensible, not hand-wavy.
✓
Board-ready
A prioritized risk report and remediation roadmap your leadership can act on.

Fixed-fee, by organization size

OrganizationEffortFixed fee (CAD)
Micro
Single site · 1 to 20 staff
2 to 4 days$3,500 to $6,000
Small
1 to 2 sites · 20 to 100 staff
5 to 8 days$7,500 to $15,000
Mid-size
Multi-site · 100 to 500 staff
10 to 20 days$18,000 to $40,000
Enterprise
Many sites · 500+ staff
20+ daysfrom $45,000

Effort and fees scale with sites, systems, and staff count; final scope is confirmed after the discovery call. Well below the $8k to $25k of a typical manual pen-test, because our own tooling does the technical heavy lifting.

Add-ons

  • ISO 27001 / NIST CSF maturity readiness+$2,000 to $8,000
  • Annual re-assessment (baseline exists)60 to 70% of fee

Terms

  • Deposit / on delivery50% / 50%
  • Travel & expenses (out-of-region)billed at cost
  • All feesplus GST/HST

See your whole security picture.

A discovery call takes 20 minutes and gives you a fixed scope and price, no obligation.

Just want your website checked? See BadgerScan Pro →