Skip to content

Cleared consultant group · Secret Level II

//AI security & governance//NIST AI RMF alignment//ITSG-33 control tailoring//SA&A / ATO evidence//NIST 800-53 rev5//Zero Trust architecture//Sentinel · Defender XDR//Threat & risk assessment//Protected B environments//MITRE ATT&CK mapping//AI security & governance//NIST AI RMF alignment//ITSG-33 control tailoring//SA&A / ATO evidence//NIST 800-53 rev5//Zero Trust architecture//Sentinel · Defender XDR//Threat & risk assessment//Protected B environments//MITRE ATT&CK mapping
Parliament Hill in Ottawa at dusk

SEC-OPS // AI security · Zero Trust · federal cyber assurance

A cleared group of security consultants for the Government of Canada.

Frank Dolphins Group is a team of senior security consultants who are ready to deploy across every province and territory, and each consultant holds an active Secret Level II clearance. Government work is our focus: ITSG-33 assessment and authorization, Zero Trust architecture, threat detection and AI security. The same rigour is also available to select non-government clients in central banking, critical infrastructure, national not-for-profits and healthcare when the mission demands it.

Clearance
Active Secret Level II for every consultant
Team
A group of senior consultants ready to deploy
Experience
More than 15 years in security
Track record
Federal, banking, cloud and critical infrastructure
Coverage
All provinces and territories, Canada
Cleared · Secret Level IIITSG-33 · NIST 800-53 · NIST CSF 2.0 · ISO 27001 · CIS v8 · MITRE ATT&CK · SOC 2

Clearance

A cleared consultant group, with Secret Level II active and verifiable.

Every consultant at Frank Dolphins Group holds an active Secret Level II clearance, which removes the slowest step in federal delivery. Work can begin inside protected environments without waiting on sponsorship, and sensitive findings are handled at the level they belong to.

Level II Secret

Every consultant in the group carries an active Secret clearance, verifiable on request through the contracting authority.

Protected B environments

We are comfortable working inside Protected A and B systems and in classified discussions.

Reliability screening

Reliability status and background screening are already in place across the whole team.

Capabilities

Built for how government buys security work.

Every engagement is scoped to produce the artifacts a departmental security authority actually needs: assessments, evidence, and defensible risk decisions.

Security assessment & authorization

SA&A packages aligned to ITSG-33 control profiles: threat and risk assessments, control traceability, residual risk statements and authority-to-operate support.

  • ITSG-33 tailoring
  • TRA / PIA support
  • ATO documentation

Cyber risk & compliance

Independent evaluation of departmental security posture against federal policy, plus remediation roadmaps that survive audit scrutiny.

  • Policy on Government Security
  • NIST 800-53 mapping
  • Audit readiness

Cloud & identity security

Secure configuration reviews and hardening for Azure and Microsoft 365 estates, Entra ID identity governance and Zero Trust segmentation.

  • Azure / M365 hardening
  • Entra ID governance
  • Zero Trust design

Threat detection & response

Detection engineering, log pipeline design and incident response playbooks that give SOC teams usable signal instead of noise.

  • SIEM use cases
  • IR playbooks
  • Tabletop exercises

Vulnerability & control testing

Recurring vulnerability management programs, configuration baselines and evidence collection tied to real remediation ownership.

  • VM program design
  • CIS baselines
  • Evidence automation

AI security & governance

Security and governance for generative AI and machine learning systems, with every AI specific risk mapped back to Zero Trust principles, the NIST AI Risk Management Framework and ITSG-33 control families.

  • NIST AI RMF
  • Copilot & LLM security
  • AI risk mapping

AI security

AI security is part of every modern assessment.

Departments are adopting AI faster than their existing controls were written for, so we make it measurable. We map every AI specific risk to a Zero Trust principle, a NIST reference and an ITSG-33 control family, so an AI system can be assessed and authorized with the same rigour as any other federal system.

Prompt injection & jailbreaks

Untrusted content steering a model into unintended actions or disclosure.

Assume breach · verify every request

AI RMF Measure · SI-10, SI-4 · SI (system & information integrity)

Data leakage through AI endpoints

Protected information leaving the boundary in prompts, outputs or vendor logs.

Data-centric protection

SC-8, SC-28, AC-4 · SC / MP control families, Protected A/B handling

Oversharing in retrieval and Copilot

Existing permission sprawl amplified the moment a model can search everything a user can.

Least privilege access

AC-3, AC-6, AC-24 · AC (access control) tailoring

Unaccountable model identity

Agents and service principals acting without a verifiable, revocable identity.

Explicit identity verification

IA-2, IA-9, AC-2 · IA (identification & authentication)

Track record

Trusted by institutions that cannot afford a bad security day.

Most of our delivery is for federal government, central banking and the government consulting practices at Microsoft and Deloitte. We also bring the same standard to critical infrastructure, national not-for-profits and healthcare when the mission requires it.

Government of Canada

Administrative Tribunals Support Service of Canada (ATSSC)

Security assessment and authorization support for a federal administrative tribunal agency.

Central banking

Bank of Canada

Security analysis and control assurance in a high-sensitivity financial environment.

Global technology

Microsoft

Consulting delivered to Microsoft public sector and government clients, covering cloud and identity security engineering.

Professional services

Deloitte

Consulting delivered to Deloitte government and public sector clients across risk, audit readiness and security advisory.

Critical infrastructure

Suncor Energy

Operational technology and enterprise IT security across energy operations.

National not-for-profit

Kids Help Phone

Security and privacy support for a national youth crisis service handling highly sensitive personal information.

Healthcare & seniors care

The Brenda Strafford Foundation

Security posture and compliance support across clinical and long-term care environments.

Credentials

Certified across governance, audit and cloud.

Compliance work is judged on credentials and evidence, so these are the ones we bring into every engagement. The full dossier, including framework coverage, sits on the credentials page.

CISMCRISCSecurityXPenTest+CySA+SC-200SC-300AWS SAAMCT

Certifications held

20+

Frameworks in practice

12

Years in security

15+

Availability

Cleared capacity across Canada.

Government contracts, task authorizations and subcontract arrangements are our main focus across every province and territory. We also take select non-government engagements where the same senior team, clearance discipline and federal rigour can add value, and we can send résumés and a capability statement on request.

Start a conversation