Managed Cybersecurity
For Businesses

<
Managed Cybersecurity for Small and Medium-Sized Businesses in Quebec

Managed cybersecurity combines technology, human monitoring, and procedures to protect small and medium-sized businesses from ransomware, Microsoft 365 credential theft, and email fraud. At Arkys, we operate a multi-layered, vendor-agnostic, and scalable architecture: we select the best solutions on the market and replace them without hesitation when a better option emerges. Your protection continuously improves, without requiring any overhaul on your part.

We work with leaders of Quebec SMEs who view technology as a driver of performance and who choose to delegate its management to specialists so they can focus on their core business. Our role: to transform cybersecurity into an operational advantage and provide clear solutions to meet the requirements of Bill 25, cyberinsurance questionnaires, and your customers’ expectations.

Our approach:

Layered, Scalable Defense

An attack involves several stages: email phishing, theft of a Microsoft 365 password, bypassing MFA, lateral movement, data exfiltration, and a ransom demand. Each layer of our architecture is designed to block or slow down the attacker at a specific stage, and each layer is selected from among the best solutions on the market, which are reevaluated annually.

Architecture de cybersécurité en profondeur comprenant EDR, ITDR, SIEM, sauvegarde et protection Microsoft 365

The Arkys architecture includes:

A core architecture, tailored to your specific needs

Our core architecture meets the fundamental requirements of a Quebec-based small and medium-sized enterprise in the current context.

Building on this foundation, we enhance protection at multiple levels based on the sensitivity of your data, your regulatory requirements, your industry, and your investment capacity. During the assessment, we present the available modules and levels and tailor the configuration precisely to your profile.

You pay for what serves your reality—nothing more.

Endpoint
Protection:

EDR + MDR 24/7

Behavioral detection on your Windows workstations and servers, with our Security Operations Center (SOC) that filters alerts and responds 24 hours a day, 7 days a week.

Why Choose an EDR Over Antivirus Software

Key Capabilities

Protection
Of Identity

Microsoft 365

ITDR (Identity Threat Detection and Response) detects credential theft and unauthorized access to your Microsoft 365 environment (Entra ID).

Why Choose an EDR Over Antivirus Software

Key Capabilities

Why a Business Manager?

Key Capabilities

Password Management

And sensitive information

An enterprise password vault eliminates the main cause of security breaches: passwords that are reused, weak, or shared via messaging.

Why Should an SME Use a SIEM?

Key Capabilities

Monitoring and Correlation

24/7 Managed SIEM

The SIEM (Security Information and Event Management system) centralizes and correlates logs from all your systems to detect complex attacks and document incidents.

Web Security

And navigation

DNS filtering, browser sandboxing, and download control. Today, the browser is the primary entry point for attacks.

Three levels of protection to be applied by user group based on risk profile, ranging from the broadest (all employees) to the most targeted (managers and customer access).

Level

Basic
Protection

Protection
Advanced

Remote Browser Isolation (RBI)

Who is it for?

All employees
(universal base)

SMEs that handle sensitive data, finance and administration teams

Executives, finance, HR, privileged accounts, customer access

Key Capabilities

All of the above, plus:

All of the above, plus:

Why Should an SME Use a SIEM?

Email Protection

And collaboration

Advanced protection for Microsoft 365 against phishing, business email compromise (BEC), and ransomware delivered via email.

Why, in addition to Microsoft's built-in protections,

Key Capabilities

Find out more

Maintenant!

Schedule your appointment with a specialist

Backup,

Disaster Recovery and Business Continuity (BCDR)

Your data remains recoverable—even in the event of a ransomware attack—thanks to immutable backups that are regularly tested and can be restored within clear recovery time objectives (RTO) and recovery point objectives (RPO).

Why This Layer Is Critical

Key Capabilities

Awareness and

Training

The human factor remains the most exploited weak link. Our programs provide ongoing training for your employees through micro-lessons and phishing simulations tailored to the Canadian context.

Why Choose an EDR Over Antivirus Software

Key Capabilities

FAQ

What are the main cyber risks for an SME?

The main risks currently facing Quebec SMEs: ransomware that encrypts data and backups, theft of Microsoft 365 credentials (often through phishing that bypasses MFA), email fraud (BEC) involving diverted wire transfers or fake invoices, the exfiltration of personal information that triggers the obligations under Bill 25, and supply chain attacks where a compromised supplier serves as an entry point. Multi-layered protection covers these vectors. Our initial assessment identifies those that pose the greatest risk to your business.

Traditional antivirus software detects known malicious files using signatures. An EDR (Endpoint Detection and Response) system continuously monitors the behavior of workstations and servers—including the execution of suspicious scripts, unusual connections, mass file encryption, and privilege escalation. It blocks new attacks that antivirus software cannot recognize and preserves actionable evidence
for investigations. For an SMB, EDR is now the minimum level of protection required by cyber insurers.

No. Microsoft 365 offers a limited native retention period (typically 30 days for deleted items) and follows the shared responsibility model: service availability is their responsibility, while the long-term protection of your data remains your responsibility. A third-party backup solution designed specifically for Microsoft 365 is necessary to comply with Law 25, meet insurers’ requirements, and recover from a ransomware attack.

Bill 25 requires the implementation of reasonable security measures, access logging, an incident response plan, and the reporting of privacy-related incidents to the Commission d’accès à l’information (CAI) when there is a risk of serious harm. It also requires the ability to restore access to personal information following an incident, including backup and restoration. Our architecture addresses these requirements, and our team monitors incident reports.

Our infrastructure meets the standard requirements of Canadian cyber insurers: 24/7 EDR/MDR,
conditional multi-factor authentication (MFA) via Entra ID, immutable backups,
password management, and ongoing training. We also provide the certificates and documents required for
underwriting or renewal.

Browser managers are designed for personal use: they do not allow for secure sharing within a team, do not provide separation of administrator access, do not offer centralized auditing or dark web monitoring, and do not enforce corporate policies. For an SME, this is insufficient in light of Bill 25 and insurance questionnaires.

<

Evaluate the suite of tools
that protects
your small business

Request a free 30-minute video conference to discuss your current cybersecurity posture and identify critical gaps in your ideal protection.