Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Incident Response Readiness Score

Fourteen questions on the things that decide how the first day of an incident goes. You get a readiness score by area and the gaps to close first.

Four areas, fourteen questions

Answer for how things would work tonight, not how they are meant to work.

Incident response readiness
0%
Not started
By area
Suggested next step

Priority gaps
    Tabletop exercise, From $3,000 CAD
    Self-reported, so treat it as a starting point. Each question is weighted by how much it tends to matter on the first day of an incident. Partly counts as half.

    Questions

    What matters most in the first hours of an incident?

    Knowing who is in charge, who to call and how to reach them when email is down, and being able to cut off access quickly. Most of the questions here are about those basics, because they are what goes wrong first.

    Why does the score ask about breach counsel and insurance?

    Insurers often require you to report quickly and use approved firms, and legal advice early shapes what you write down and who you notify. Finding out those terms mid-incident costs time you do not have.

    What is a tabletop exercise?

    A walk-through of a realistic scenario with the people who would handle it, in a room or on a call, with no systems touched. It finds the gaps in the plan, the contact list and the decision rights before a real incident does.

    Do frameworks require a tested plan?

    PCI DSS requires the plan to be tested at least every 12 months, and SOC 2, ISO 27001 and CyberSecure Canada auditors look for evidence that it has been exercised. A tabletop record is usually that evidence.

    Is this score free?

    Yes, free and no signup. Your answers stay in your browser.

    Not ready for a call yet?

    Get your readiness score by email

    Your score and priority gaps to keep, then a few short notes from Jacob on getting incident response ready before you need it. Unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    Incident response tabletop

    A realistic scenario run with your team, with a written record of the gaps and fixes.

    Explore Incident response tabletop →

    Find the gaps in a room, not in an incident.

    A tabletop exercise walks your team through a realistic scenario and gives you a written record of what broke and how to fix it, which is also the evidence auditors ask for. From $3,000 CAD.

    See the tabletop exercise Talk about incident readiness

    Want the full picture?

    This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

    Start your free assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.