How a Vancouver occupational therapy practice closed the gaps found in a security review — without disrupting a fully remote contractor team.
The practice relied on a general IT vendor's default Microsoft 365 setup, with no device policy for its remote contractor therapists and no documented breach response plan. A routine security review flagged both as compliance gaps under PIPA.
We audited data flows across every contractor device, rebuilt the Microsoft 365 tenant with Intune and Purview policies suited to a fully remote team, and wrote a breach response plan the practice's admin staff could actually run.
Every contractor device now meets a documented compliance standard. Company intellectual property has been protected and the attack surface area has been reduced. The company now has a set of policies to adhere to and a breach response plan in place in case the unexpected should arise.
Book a free 30-minute consultation. We'll review your current setup and outline where the risks are.
Vancouver, BC, Canada · hello@sitkalabs.ca