Government and public sector
Cybersecurity built around public-sector realities.
Government environments require strong security, clear accountability and solutions that work across complex technology, operational and regulatory environments. Frank Dolphins brings practical cybersecurity expertise to these challenges.
Security practices we work within
Familiar ground for public-sector security teams
Security assessment and authorization
Structuring control evidence, threat and risk assessments and residual risk statements so an authorizer can make an informed decision.
ITSG-33 control profiles
Tailoring control profiles to the sensitivity of the system rather than applying an untailored catalogue.
Zero Trust and identity protection
Applying NIST SP 800-207 principles to identity, device and network access decisions in mixed on-premises and cloud estates.
Cloud security
Securing Azure and Microsoft 365 workloads with configuration baselines, logging coverage and clear ownership of shared responsibility.
Threat detection
Building detection coverage mapped to MITRE ATT&CK, with the log sources and response procedures that make it usable.
Vulnerability and control assurance
Turning findings into an owned, verified remediation cycle instead of a recurring backlog.
Frank Dolphins is an independent company. Nothing on this page should be read as certification, approval, accreditation or endorsement under any framework, or by any department, agency or Crown corporation.
Who we support
The organizations and teams we work alongside
Government and public-sector organizations
Departments, agencies and public bodies that need qualified cybersecurity expertise delivered against defined requirements and reporting expectations.
Prime contractors
Primes assembling qualified cybersecurity teams who need a dependable Canadian partner for defined scopes of work and subcontracted deliverables.
Security and IT leadership
CISOs, security directors and IT executives who need architecture, operations and risk decisions made with clear technical reasoning.
Technology and delivery partners
Firms and independent professionals who team with us so a requirement is covered end to end rather than in part.
Sector experience
Environments our leadership has worked in
Experience is described at the sector level. We do not publish contract names, departmental relationships or project detail.
- Government of Canada and public sector
- Security assessment, advisory and control assurance support for federal organizations, delivered through professional-services engagements.
- Central banking and financial services
- Control assessment and security monitoring experience in high-sensitivity financial environments.
- Global technology and professional services
- Cloud, identity and cyber risk consulting delivered through Microsoft and Deloitte to their public-sector clients.
- Critical infrastructure
- Enterprise and operational technology security experience across energy operations with high availability constraints.
- Not-for-profit and healthcare
- Security and privacy support for organizations handling sensitive personal and clinical information.
Engage
Strengthen your next cybersecurity initiative.
Connect with Frank Dolphins regarding cybersecurity requirements, subcontracting, teaming arrangements and professional-services opportunities.