How we protect the environments we manage
An IT provider holds keys to your business. This page describes the controls we actually apply — and is deliberately clear about what we do not claim.
Security controls we apply
Multi-factor authentication on management tools
Every administrative tool we use to reach client environments — remote monitoring, remote access, Microsoft 365 and Google Workspace administration, and our documentation platform — requires multi-factor authentication. There are no shared logins without MFA, and no exceptions for convenience.
Least-privilege access
Technicians hold the access their role requires and no more. Elevated and administrative access is granted for the work at hand rather than kept permanently open, and access is reviewed when roles change.
Encrypted credential storage
Client credentials are stored in an encrypted password management system with access controls and audit history. Credentials are never kept in spreadsheets, email, chat messages, or personal notes.
Monitored endpoints and logged remote sessions
Devices under management report health and security state continuously. Remote control sessions are consent-based on managed devices and are logged with the time, the technician, and the work performed.
Backup verification
Backup jobs on managed systems are monitored, and failures are treated as alerts rather than being quietly retried. Restore testing is performed for clients whose plan includes it, and results are reported.
Documented offboarding
When a staff member leaves your organization, we follow a documented offboarding process: account disable, session revocation, MFA method removal, mailbox handling, device retrieval or wipe, and licence reclamation — with a record of what was done.
Segmentation and firewall standards
Where we design or manage the network, guest, payment, operational, and staff traffic are separated, firewall rules are documented, and management interfaces are not exposed to the public internet.
Incident handling
Security incidents follow a defined path: contain, investigate, communicate, recover, and review. Clients receive a written summary of what happened and what changed afterwards.
Shared responsibility
Security is not delivered by one party alone. Here is how responsibility is split between us, the platforms we manage, and your organization.
What Nickel City Tech Solutions does
- Applies and maintains the technical controls described on this page across managed environments
- Monitors managed devices, patches them on schedule, and surfaces failures
- Maintains documentation of your environment and the changes we make to it
- Reports monthly on device health, patching, security posture, and backups
- Coordinates with your other vendors on security-relevant issues
What the platforms and vendors do
- Microsoft, Google, and other cloud providers operate their own platform security and availability
- Security vendors maintain detection content and threat intelligence in their products
- Hardware vendors supply firmware and security updates for their devices
- Certifications held by those vendors belong to those vendors, not to us
What your organization is responsible for
- Deciding who should have access to what, and telling us when that changes
- Approving security recommendations and funding the controls you accept
- Staff behaviour — reporting suspicious email, not sharing credentials, following your own policies
- Regulatory and contractual compliance obligations that apply to your business
What we do not claim
We are not SOC 2, ISO 27001, PCI, or HIPAA certified, and we do not certify your business either.
We do not guarantee that a breach, outage, or data loss will never occur. No provider honestly can.
Vendor certifications belong to those vendors — using a certified platform does not make us certified.
Compliance obligations under PHIPA, PIPEDA, or your industry regulator remain with your organization. We build and document the technical controls that support them.
Security questions we get asked
Are you SOC 2 or ISO 27001 certified?
No. Nickel City Tech Solutions does not hold SOC 2, ISO 27001, or any equivalent certification, and we will not imply otherwise. We apply the security practices described on this page, and we help clients prepare for their own audits through our SOC 2 readiness support service. Any certification claims you see about the platforms we use belong to those vendors.
Who at your company can access our systems?
Access is limited to technicians working on your environment, through managed tooling that requires multi-factor authentication and records session activity. Administrative access is granted for the task and reviewed as roles change.
Where are our credentials kept?
In an encrypted password management platform with role-based access and an audit trail. They are not stored in email, chat, spreadsheets, or documents.
Do you keep copies of our data?
We do not take our own copies of your business data. We configure and monitor backup systems that store your data under your own retention settings, and we hold documentation about your environment — configurations, inventory, and procedures — rather than your files.
What happens if you are breached?
We would contain the incident, determine which client environments were affected, notify affected clients directly with what we know, take remediation steps including credential rotation, and follow up with a written review. No provider can promise a breach will never happen; what we can commit to is honest, prompt communication if one does.
Can you complete our security questionnaire?
Yes. We regularly complete client and insurer security questionnaires covering access control, MFA, backup, patching, and incident handling. Ask us and we will work through yours.
Have a security or privacy question?
Ask directly. We will give you a straight answer, including when the answer is "we don't do that."
Security services and platforms
Services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
- Mobile Device Management (MDM)
Enroll, secure, and manage business phones, tablets, and laptops centrally.
- Remote Monitoring & Management (RMM)
24/7 device monitoring, automated patch management, and remote maintenance.
Platforms we manage
Helpful resources
- Why Every Business Needs Multi-Factor Authentication
If you do only one security thing this year, do this. MFA blocks the vast majority of account-takeover atta…
- IT Offboarding Checklist: What to Do When an Employee Leaves
A step-by-step IT offboarding checklist for when an employee leaves — disable sign-in, revoke sessions, ret…
- How to Protect Your Business from Ransomware
Ransomware isn't a Fortune-500 problem. Here's how small and mid-sized businesses in Greater Sudbury and No…
- The Most Common Cybersecurity Threats Facing Small Businesses
Forget nation-state hackers. Here are the threats actually hitting Northern Ontario SMBs today — and the pr…
