Security Insights
Expert perspectives, buyer playbooks, and technical analysis from the Lorikeet Security Canada team in Calgary and Toronto.
All Articles
14 articlesA Customer Wants Proof of a Penetration Test: What Enterprise Buyers Will (and Won't) Accept
Learn what enterprise procurement teams accept as proof of a penetration test, why sending a raw report is dangerous, and how an Attestation Letter unblocks deals.
How to Vet a Penetration Testing Firm Before You Buy: 5 Questions That Expose an Automated Scanner Reseller
How to differentiate genuine offensive security practitioners from automated scanner resellers. 5 essential questions to ask before signing a pentest SOW.
Your Cyber Insurer Is Asking About Security Controls: How Canadian Underwriters Actually Evaluate MFA, EDR, and Pentests
Canadian cyber insurers are tightening underwriting standards. Learn what controls are non-negotiable for policy renewal and how to avoid claim denials.
A Customer Sent You a 150-Question Security Questionnaire and You Have Nothing Prepared: The 48-Hour Playbook
What to do when an enterprise prospect sends a massive vendor security questionnaire and you have no SOC 2 or formal policies. A 48-hour survival guide.
The Hidden Costs of SOC 2 Nobody Quotes You (and How Canadian SaaS Companies Avoid Them)
The CPA audit fee is only half the expense. Discover the five hidden costs of SOC 2 compliance for Canadian SaaS companies and how to budget accurately.
What a Penetration Testing Deliverable Actually Looks Like: Dissecting an Executive Attestation vs Vulnerability Dump
Inspect the anatomy of an audit-ready penetration test deliverable. What belongs in an executive summary, technical vulnerability proof, and attestation.
PHIPA vs HIPAA: Navigating Cross-Border Health Data Compliance for Canadian Digital Health Companies
A comparative compliance guide for Canadian digital health companies in Calgary & Toronto navigating Ontario PHIPA, Alberta HIA, and US HIPAA regulations.
Quebec Law 25, Alberta PIPA, and Federal PIPEDA: The Canadian Privacy Stack Requirements Enterprise Buyers Demand
Understand the modern Canadian privacy compliance stack. Learn why enterprise procurement teams mandate Law 25, PIPA, and PIPEDA alignment before signing.
SOC 2 Type I vs Type II for Canadian Tech Companies: When to Trigger Your Observation Window Without Losing Deals
Should your Canadian SaaS company pursue SOC 2 Type I or go directly to Type II? Compare timelines, costs, and buyer expectations to make the right move.
Securing AI and RAG Architectures: The Vulnerabilities Enterprise Buyers and Auditors Test for Before Production
A technical guide for Canadian engineering teams deploying Generative AI and RAG. Learn how to secure vector stores, prevent prompt injection, and pass enterprise reviews.
Top 10 Cybersecurity Companies in Canada: 2026 Industry Guide
Explore the top 10 cybersecurity companies in Canada for penetration testing, fractional CISO advisory, MDR, and compliance, featuring Lorikeet Security Canada, Traztech, and more.
Web Application Penetration Testing in Canada: Scoping, Pricing, and What Tech Buyers Must Know
The definitive 2026 buyer guide to web application and API penetration testing in Canada. Benchmark CAD pricing, avoid scoping pitfalls, and unblock enterprise sales.
Cross-Border Penetration Testing: How Canadian Tech Companies Satisfy US Enterprise Vendor Risk Reviews
How Canadian SaaS companies satisfy US enterprise security reviews, SOC 2 vendor requirements, and HIPAA procurement audits with sovereign Canadian penetration testing.
Financial & Critical Infrastructure Penetration Testing in Canada: Meeting OSFI B-13, CIRO, and Enterprise Assurance Mandates
A regulatory guide to penetration testing for Canadian fintechs, payment processors, credit unions, and financial institutions under OSFI Guideline B-13 and CIRO.