Cybersecurity // Logins, Two-Factor & Single Sign-On

Most break-ins start with a real login.

Attackers don't usually break the lock — they get the key. Stolen passwords, fake login pages, and old accounts that nobody removed when someone left the company. We tighten up how your team signs in, make those logins phishing-proof, and shut down access the same day someone walks out the door.

8 in 10
Of break-ins came from a stolen or weak password
Person holding a giant key in front of a secure lock
fig.01
Toronto
Delivered locally across the Greater Toronto Area (GTA). PHIPA (Ontario Health) & OSFI Financial Regulations Aligned.
2-Hour On-Site Dispatch
Senator Networks has been an essential partner in managing our regulatory requirements. Their Toronto-based dispatch was on-site in under an hour during our office expansion, ensuring zero operational downtime.
Marcus Vance, Vance Financial Advisory, Bay St.
Compare

The MFA factor honest matrix.

All of these technically count as 'MFA' for an auditor. They are not equivalent in the field.

SMS codeTOTP appPush approvalPasskey (FIDO2)Hardware token
Phishing-resistantNoNoNoYesYes
MFA-fatigue resistantN/AYesNoYesYes
SIM-swap resistantNoYesYesYesYes
User experience costLowMediumLowLow (after setup)Medium
Recovery / lost-factor costLowMediumMediumMediumHigh
Regulatory acceptanceYes (declining)YesYesYes (preferred)Yes
What you get

What's included.

  • 01

    Entra ID or Okta deployment

    Tenant configuration, app integration plan, conditional access policy set tuned to your industry's risk profile.

  • 02

    Conditional access policy suite

    Risk-based, location-aware, device-aware. Compliant mobile + managed device required for sensitive apps. Block-by-default with exceptions you can audit.

  • 03

    MFA rollout plan

    No-disruption pilot, then broaden. Passkeys first for admins, then privileged users, then everyone — over 90 days, not 90 minutes.

  • 04

    Group + role taxonomy cleanup

    Most environments have 800 groups and 12 that are actually used. We rebuild the model around your real org chart.

  • 05

    Automated offboarding

    Termination in your HRIS triggers access revocation within 15 minutes — across every SSO-connected app and most of the SaaS that isn't.

  • 06

    Break-glass procedure

    Documented, drilled emergency accounts that work when Entra ID itself is down. Auditors check for this; most firms don't have it.

How it works

The no-lockout rollout.

MFA rollouts go wrong when they move fast. We measure twice.

  1. 01

    Discovery sweep

    Inventory every account, every app, every authentication path. Find the service accounts using NTLM nobody remembers creating.

  2. 02

    Pilot — 10 power users

    Two weeks with a hand-picked group. Document every confusion, every recovery scenario. Update training before the broad rollout.

  3. 03

    Conditional access (log-only)

    Policies enforce nothing yet — they just log what they would have blocked. Two weeks of report-only mode catches edge cases.

  4. 04

    Enforce, broaden, repeat

    Move from log-only to enforce in tranches. Admins get passkey-mandated first. Standard users next.

  5. 05

    Quarterly access reviews

    Every group, every privileged role, every external collaborator gets re-justified by an owner. Stale access decays by default.

Regulatory map

Where IAM controls satisfy your auditor.

Identity is the highest-density control area in every framework. The same program checks every box.

HIPAA
§164.312(a)(1) Access control, §164.312(d) Authentication
Pair with logged access auditing.
SOC 2
CC6.1, CC6.2, CC6.3, CC6.6, CC6.7, CC6.8 (logical access)
Largest control family in SOC 2 Type II.
ISO 27001:2022
A.5.15 Access control, A.5.16 Identity management, A.5.17 Authentication, A.5.18 Access rights
PCI-DSS 4.0
Requirement 8 (Identify users and authenticate access)
Phishing-resistant MFA explicitly preferred.
NIST 800-171
3.5.1–3.5.11 (Identification & Authentication)
Required for DoD-adjacent contracts.
By the numbers

What we measure (and send you every month).

100
%
Phishing-proof login for admins

Goal: every admin uses a sign-in method that can't be tricked, like a passkey.

<15
min
Access removed after firing

From the moment HR marks someone as terminated, all their access is gone.

<5
%
Unused accounts

Accounts no one has signed into for 90+ days. We chase them down.

<3
%
Admin accounts

What share of your staff have admin powers. Most firms have too many.

Who needs this

Who needs this.

  • Anyone whose cyber-insurance application asks 'is MFA enforced on all accounts including admins?' — universal in 2026 underwriting.
  • Firms preparing for SOC 2, HIPAA, ISO 27001, or PCI-DSS audit (the access-control section is always the most evidence-heavy).
  • Anyone who's had a terminated employee retain access for more than 24 hours.
  • Firms with shared service accounts, group mailboxes, or 'one Excel file with all the admin passwords.'
FAQ
Q01

We already have MFA. Isn't that enough?

It depends on the factor. SMS MFA and push approvals are routinely bypassed in 2026 — by SIM-swap, by fatigue, by adversary-in-the-middle proxies. Phishing-resistant MFA (passkeys, FIDO2) is the only factor class that resists modern phishing kits.

Q02

What's a passkey and why do you keep mentioning it?

A passkey is a FIDO2 credential bound to a device (or a hardware key). It can't be phished because the user never sees a secret to type. It's the most significant authentication improvement in a decade and works everywhere modern.

Q03

What happens to access when someone leaves?

With us: termination in your HRIS triggers automated revocation in Entra/Okta within 15 minutes. Every SSO-connected app instantly. Non-SSO apps via SCIM where supported, runbook where not.

Q04

Can we keep our existing Active Directory?

Yes. Most clients run hybrid — on-prem AD synchronized to Entra ID via Entra Connect. We harden both sides and add conditional access on top.

Q05

How do we avoid breaking everything during rollout?

Log-only conditional access first. We watch what would have broken for two weeks, fix it, then enforce. Pilot groups before broad rollout. We've done this enough times to know what surprises happen.

Next step

Free 30-minute identity posture review.

Bring us your Entra/Okta tenant for read-only review and we'll map your current state against phishing-resistance, account hygiene, and conditional-access maturity.