Skip to content

Services · Cybersecurity Services

Cybersecurity Services for Applications and Business

We secure the software you run and the accounts that reach it. OlDevs works from threat modelling through code review, identity, hardening and incident readiness, so security is part of the build rather than a scramble after launch.

You own the code and IP Weekly demos Reply within one business day

Search members, roles or centres
Single sign-on
MemberRoleLive
Admin
Member
Board
Member

1,284

Members

99.9%

Uptime

0

Access issues

Cybersecurity Services, in short

OlDevs is a full-stack technology studio in Vancouver, British Columbia that secures applications and the business systems around them.The work covers secure development practices, threat modelling, code and dependency review, OWASP alignment, penetration test coordination and remediation, identity and access with single sign on, multi factor authentication and passkeys, secrets and encryption, and hardening for WordPress and other content management systems. Teams are also prepared for security questionnaires of the SOC 2 or ISO 27001 kind, with incident response planning and awareness sessions for staff. The studio is an engineering partner rather than an accredited audit firm, so it does not issue certifications.

Key facts

01Service
Application and business cybersecurity
02Studio
OlDevs, Vancouver, British Columbia, since 2014
03Coverage
Secure development, identity, hardening, response
04Standards referenced
OWASP Top 10 and ASVS, plus NIST guidance
05Scope note
Engineering partner, not an accredited audit firm
06Engagement
Scoped and quoted per project. Request a quote

Application and business security

What we secure

01

Secure development and threat modelling

Security starts at design time. We run threat modelling on the features that matter, agree trust boundaries and abuse cases, then write the controls into the backlog so they ship with the feature instead of arriving as a patch later.

Threat modelling · Abuse cases · Secure by default

02

Code and dependency review

We read the code paths that handle authentication, payments, uploads and admin actions, then audit third party packages for known vulnerabilities, abandoned maintainers and licence risk. Findings arrive with fixes attached, not just a list.

Code review · Supply chain · Patching

03

OWASP alignment and testing

We check builds against the OWASP Top 10 and the Application Security Verification Standard, add automated scanning to the pipeline, and keep a written record of what was verified so the next review starts from evidence rather than memory.

OWASP Top 10 · ASVS · Pipeline scanning

04

Identity, SSO, MFA and passkeys

Single sign on through providers such as Microsoft Entra ID, Okta or Google Workspace, multi factor authentication, and passkeys built on the WebAuthn standard. Roles follow least privilege, and joiner, mover and leaver steps are documented.

Single sign on · Passkeys · Least privilege

05

Secrets, encryption and keys

Credentials move out of code and into a managed vault such as AWS Secrets Manager, Azure Key Vault or HashiCorp Vault. We configure TLS properly, encrypt data at rest, plan key rotation, and confirm that backups are encrypted and restorable.

Secrets management · Encryption · Key rotation

06

WordPress and CMS hardening

WordPress, Drupal and headless stacks get the same treatment: least privilege accounts, plugin and theme review, an update and file permission policy, a web application firewall, security headers, useful logging and a tested restore path.

WordPress · Hardening · Backups

Process

How the work runs

  1. Scope

    We learn what you run, who touches it and what would hurt most if it failed. No scanning theatre, just a clear picture of systems, data and the people with access.

  2. Assess

    Threat model, code and dependency review, configuration and identity checks against the OWASP Top 10 and ASVS, with every finding written up so it can be reproduced.

  3. Prioritise

    Findings are ranked by likelihood and business impact, not by scanner colour. You get a remediation plan with owners, effort and the order in which we will work.

  4. Remediate

    We fix the code, tighten identity and permissions, harden the platform, move secrets into a vault and put the checks into your pipeline so regressions get caught.

  5. Verify and hand over

    Retest the closed findings, document what changed, train the team, and leave you with the runbooks, policies and evidence. You own all code, configuration and accounts.

How we work

What an engagement includes

01

A threat model before code

We map what an attacker would want, where it lives and how they would reach it, then agree the controls worth building. The model is written down and revisited as the product changes.

02

Penetration test coordination

We scope the engagement, brief an independent tester, triage the report by real risk, fix the findings, and arrange a retest so the closing evidence matches the system you actually run.

03

Incident response planning

Runbooks, on call roles, contact trees, isolation steps and communication templates, rehearsed in a tabletop exercise so the first real incident is not the first time anyone reads the plan.

04

Security awareness for staff

Short, practical sessions on phishing, password and passkey habits, device basics and safe handling of client data, written for the people doing the job rather than for a compliance binder.

05

Questionnaire and audit readiness

We help you answer SOC 2 or ISO 27001 style questionnaires honestly: gather evidence, close the gaps that are genuinely open, and write the policies your reviewers will ask to see.

06

Monitoring, logging and patching

Logs that answer questions, alerts that mean something, and a scheduled rhythm for dependency updates and platform patches so known issues do not sit open for months.

Who it's for

Cybersecurity Services for organisations that have to get it right.

Corporations

Security leads and IT teams who need application level work that fits existing policy, change control and vendor review, with documentation their auditors will accept.

Associations and government

Public bodies and member organisations handling personal data, with procurement rules, WCAG 2.2 AA accessibility duties and bilingual EN and FR requirements to satisfy.

Franchises

Multi location brands where head office sets the standard and franchisees run the sites. We harden the template, lock down roles and keep updates consistent everywhere.

Entrepreneurs and startups

Founders who need to pass a customer security review without stalling the roadmap. We fix what matters first and leave you with practices a small team can actually keep.

Since 2014

Building and securing software

1 business day

Reply to every enquiry

OWASP ASVS

Standard we review against

FAQ

Cybersecurity Services — questions we hear first.

No. OlDevs is an engineering studio, not an accredited audit firm, so we do not issue SOC 2 reports or ISO 27001 certificates. What we do is the work those reviews look for: access controls, evidence, written policies and remediation. When a formal audit is required we prepare you for it and work alongside the auditor you appoint.

Yes, and that is most of the work. We start with a review of the running site or application: accounts and roles, plugins and packages, hosting configuration, backups, logging and anything exposed to the internet. You get a prioritised list of findings, then we fix them in order of real risk rather than alphabetical severity.

We coordinate them rather than mark our own homework. We help scope the test, brief an independent tester, then take the report and turn it into a remediation plan: reproduce each finding, fix it, document the change and arrange a retest so the closing letter reflects the state of the system today.

Usually single sign on against your existing identity provider, multi factor authentication for anyone with elevated access, and passkeys where a phishing resistant login makes sense. We also tidy roles and permissions, remove dormant accounts and document how access is granted and revoked.

WordPress deserves care rather than fear. We reduce administrator accounts, review every plugin and theme for maintenance and known issues, set an update and staging policy, add a web application firewall and security headers, move secrets out of wp-config edits, and test that a restore actually works before you need it.

Yes. Security drifts the moment nobody is watching, so we offer ongoing patching, dependency updates, log review and periodic re-testing. We also write the incident response plan: who is called, what is isolated, how customers and regulators are told, and how the post incident review feeds back into the backlog.

Tell us what you run, who uses it and what worries you, and we will scope the work in plain language before anything starts. Every engagement is quoted, never billed against a template. Request a quote and you will hear back within one business day, from the same people who will do the work.

Still have a question? Ask us when you request a quote

Let’s connect

Let’s scope your cybersecurity services project.

Tell us what you’re building. We’ll reply within one business day with next steps and a tailored quote — no obligation.

We’ll only use your details to prepare your quote. No lists, no spam.

Call us Request a quote