Integrated coverage
Architecture, operations and offensive testing under one banner, with methodological consistency.
HM-DJANTA SÉCURITÉ designs, operates and tests your defenses in a continuous improvement loop. Offensive, operational and architectural cybersecurity — under a single banner.
A Québec firm operating across Canada, HM-DJANTA SÉCURITÉ covers the entire lifecycle of information security.
Offensive cybersecurity, operational security and architecture : we design the controls, we operate them and we test them. A continuous improvement loop rarely offered by a single provider in the SME segment.
Architecture, operations and offensive testing under one banner, with methodological consistency.
Team certified OSCP, OSWE, OSEP, CRTL, CRTO, CISSP, CISM, ISO 27001 LA/LI and more.
NIST, OWASP, PTES, MITRE ATT&CK, ISO/IEC 27001 — combined to fit your context.
Executive summary for leadership, technical detail for operational teams.
Professional liability (E&O) and cyber insurance from the very first engagement.
Canadian Criminal Code, Law 25, PIPEDA — written authorizations as standard.
Every engagement is carried out following recognized methodologies and undergoes an internal review by a second consultant before delivery.
Our reports honestly describe what was tested, designed or operated, as well as the limits of each assessment.
We translate technical complexity into business risks that decision-makers can understand.
Strict respect for the legal framework and confidentiality guides all of our work.
We invest in training, certifications and technology watch to stay at the cutting edge.
Proactively identifying and demonstrating exploitable vulnerabilities before an attacker discovers them.
Active defense, continuous monitoring, incident response and day-to-day support of your security posture.
Designing secure architectures, frameworks and policies aligned with the world's best standards.
Our engagements follow recognized frameworks combined to fit your maturity and context. Select a stream to explore the services.
From validated vulnerability scans to multi-vector Red Team engagements, we emulate real tactics to reveal your blind spots.
Assessment of the Internet-facing infrastructure, black-box or grey-box.
Active Directory, segmentation, lateral movement, simulated exfiltration.
OWASP WSTG, ASVS and MASVS — Top 10 and business logic.
AWS, Azure/Entra ID and GCP following the CSA Cloud Pentest Playbook.
WPA2/WPA3/802.1X, Evil Twin, guest/corporate isolation.
Multi-vector simulation over 3 to 8 weeks with a defined objective.
Pro tools + manual review to eliminate false positives.
Scheduled tests, unlimited re-tests, dashboard and dedicated consultant.
Managed SOC, incident response and continuous vulnerability management following NIST SP 800-61 and MITRE ATT&CK.
Analysts for monitoring, triage and investigation — block of hours or one-off.
Extended monitoring 5–7 days/week, SIEM integration, continuously tuned rules.
NIST 800-61 r2 cycle — containment, forensics, eradication, post-mortem.
CVSS + EPSS + impact prioritization, remediation tracking, dashboards.
Dark web, compromised credentials, typosquatting, applicable CVEs.
Simulated phishing, workshops, e-learning, developer training.
SIEM, EDR, firewall, IAM, M365 and Workspace per CIS Benchmarks.
Target architectures, documentation frameworks, Zero Trust, ISO 27001 and SOC 2 — security planned upstream, aligned with ISO/IEC 27005 and NIST CSF.
Network, application, cloud, identity, data, logging.
Gap analysis vs NIST CSF, CIS Controls and ISO 27002.
ISO/IEC 27005 — assets, threats, impacts, register, action plan.
Corpus aligned with ISO 27001 Annex A, NIST CSF or CIS Controls.
NIST SP 800-207 roadmap over 12 to 36 months.
BIA, scenarios, RTO/RPO, table-top exercises and simulations.
End-to-end support: gap → compliance → audit.
Part-time virtual security chief — 2 to 8 days/month.
Our delivery process is standardized to guarantee consistency, quality and traceability across all three streams.
Scoping workshop, perimeter definition, objectives and intervention window.
→ Statement of Work (SOW)Signing of the contract, NDA and — for offensive work — Rules of Engagement.
→ Signed contract fileTool configuration, perimeter validation, coordination checkpoint.
→ Execution planDelivery per methodology, regular communication, immediate alerts on critical findings.
→ Progress notesManual validation of findings, CVSS + business context prioritization.
→ Preliminary reportExecutive summary + technical detail, internal review by a second consultant.
→ Final reportOral presentation, knowledge transfer, Q&A session and prioritized action plan.
→ Action plan30-day support, satisfaction survey, proposal for a recurring engagement.
→ Closing letterQuébec's Law modernizing legislative provisions on the protection of personal information is fully in force. We combine our three streams to achieve operational and lasting compliance.
Mapping of personal information, assessment of current practices, gap identification and prioritized action plan.
Appointment of the privacy officer, governance policies, incident management process, PIAs and out-of-Québec transfers.
Encryption, access controls, logging, anonymization, penetration testing and continuous monitoring.
Training tailored to each role (leadership, HR, marketing, IT) and preparation for handling requests.
Have a project, a question or an emergency? Our team responds quickly and confidentially.