Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Threat and Risk Assessment (TRA)

A Threat and Risk Assessment (TRA) is a formal cybersecurity document used to identify, evaluate, and mitigate the security risks to an organization's digital assets, infrastructure, and sensitive data. It names the realistic threats to your systems, rates each risk by likelihood and impact, and documents the mitigations you have in place. In Canada it is common vocabulary in government procurement, in regulated sectors, and in enterprise vendor reviews.

In practice

People rarely read about TRAs out of curiosity. The ask usually arrives in a Government of Canada solicitation, from an enterprise procurement or vendor-risk team, from a federally regulated financial institution flowing its third-party requirements down, or from an insurer assessing a cyber policy. If you are looking one up, something in a contract or a review has asked for it.

A TRA is not a pen test and not a vulnerability scan, and the three get used interchangeably in procurement emails. A scan is automated and flags known issues; a pen test is human-led and proves what an attacker could actually do; the TRA puts those facts in business terms, covering threats, likelihood, impact, and mitigations. A TRA with no testing behind it is a guess in a nice template, so the assessment should be backed by hands-on testing of your environment.

// how traztech helps

traztech delivers Threat and Risk Assessments backed by real testing for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

A TRA is usually requested by a procurement team, a government buyer or an insurer who wants a formal, documented view of what could go wrong and what you have done about it.

It is distinct from a penetration test. A test finds specific weaknesses in a specific target. A TRA reasons about assets, threats, likelihood and impact across the whole environment, and produces a prioritised risk picture rather than a finding list.

Threat and Risk Assessment (TRA): common questions

Is a TRA the same as a risk assessment?

A TRA is a particular form of risk assessment, structured around threats to identified assets, and it is the form Canadian public sector and financial buyers most often ask for by name.

Do we need a TRA and a penetration test?

They answer different questions and are frequently requested together. The TRA sets priorities; the test verifies whether specific controls hold.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.