Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A Threat and Risk Assessment (TRA) is a formal cybersecurity document used to identify, evaluate, and mitigate the security risks to an organization's digital assets, infrastructure, and sensitive data. It names the realistic threats to your systems, rates each risk by likelihood and impact, and documents the mitigations you have in place. In Canada it is common vocabulary in government procurement, in regulated sectors, and in enterprise vendor reviews.
People rarely read about TRAs out of curiosity. The ask usually arrives in a Government of Canada solicitation, from an enterprise procurement or vendor-risk team, from a federally regulated financial institution flowing its third-party requirements down, or from an insurer assessing a cyber policy. If you are looking one up, something in a contract or a review has asked for it.
A TRA is not a pen test and not a vulnerability scan, and the three get used interchangeably in procurement emails. A scan is automated and flags known issues; a pen test is human-led and proves what an attacker could actually do; the TRA puts those facts in business terms, covering threats, likelihood, impact, and mitigations. A TRA with no testing behind it is a guess in a nice template, so the assessment should be backed by hands-on testing of your environment.
traztech delivers Threat and Risk Assessments backed by real testing for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
A TRA is usually requested by a procurement team, a government buyer or an insurer who wants a formal, documented view of what could go wrong and what you have done about it.
It is distinct from a penetration test. A test finds specific weaknesses in a specific target. A TRA reasons about assets, threats, likelihood and impact across the whole environment, and produces a prioritised risk picture rather than a finding list.
A TRA is a particular form of risk assessment, structured around threats to identified assets, and it is the form Canadian public sector and financial buyers most often ask for by name.
They answer different questions and are frequently requested together. The TRA sets priorities; the test verifies whether specific controls hold.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.