British Columbia, Canada · Est. 2026

Governance.
Risk. Assurance.
Built for Growth.

Proxim Advisory Group brings enterprise-grade cybersecurity GRC and business strategy to startups and SMBs — the organizations that need it most, and deserve it most.

DBADoctoral Credential
4+Frameworks Covered
SMBFocused Practice

ISO 27001 & SOC 2

Readiness assessments and gap analysis aligned to international standards.

HIPAA & PIPEDA

Privacy and healthcare assurance guidance for regulated industries.

Business Advisory

Strategy, operations, and governance for founders navigating growth.

BC-Based. Global Reach.

Founded in British Columbia, Canada — advising clients across Canada and beyond.

Advisory services built
around your scale

We don't retrofit enterprise frameworks onto small teams. We design assurance and advisory programmes that fit where you are — and where you're going.

01

Cybersecurity GRC Consulting

Governance frameworks, risk assessments, AI/automation governance, and assurance roadmaps aligned to SOC 2, ISO 27001, NIST CSF, HIPAA, and PIPEDA.

Learn more →
02

Assurance Readiness & Audit Prep

Gap assessments, policy development, contract reviews, security questionnaire support, and evidence preparation to position your business for audit success.

Learn more →
03

Business Advisory & Strategy

Operational strategy, business model analysis, and governance structures for founders and leadership teams at every stage.

Learn more →
04

Risk Management Programmes

Tailored risk registers, control libraries, and continuous monitoring frameworks that scale with your organization.

Learn more →

Turn assurance into a competitive advantage.

Proximity to your business
is everything.

Proxim Advisory Group was founded on a single conviction: that small and growing businesses deserve the same quality of governance and security advisory traditionally reserved for large enterprises.

Why Proxim?

The word proxim derives from the Latin for closeness — and that's precisely what distinguishes our practice. We don't parachute in with a generic framework and leave. We sit alongside your leadership team, understand your context, and build programmes that actually work for your size, your sector, and your risk appetite.

Founded in British Columbia, Canada, Proxim Advisory Group serves startups and small-to-medium businesses across Canada. Our practice spans cybersecurity governance, risk and assurance (GRC) consulting, and strategic business advisory — delivered by an advisor with doctoral-level academic credentials and hands-on operational experience.

Whether you're preparing for your first security audit, building investor-ready governance, or navigating a regulated industry, Proxim brings the rigour, clarity, and conviction to guide you through.

Proximity

We engage as a true partner — close to your team, your decisions, and your outcomes.

Precision

Every recommendation is grounded in evidence, frameworks, and academic rigour.

Practicality

Assurance programmes that fit your business — not the other way around.

Trust

We earn it through transparency, consistency, and delivering on every commitment.

PA

Principal Advisor

Founder & Lead Consultant

The principal advisor holds a Doctor of Business Administration (DBA) in Information Systems and Enterprise Resource Management, is a Certified Information Systems Security Professional (CISSP), and brings deep experience in global GRC, cloud security assurance, and strategic risk management across operational and leadership roles.

Doctoral scholarship, hands-on security practice, and business advisory judgment inform every engagement in Proxim's advisory model.

  • DBA — Information Systems & Enterprise Resource Management
  • CISSP — Certified Information Systems Security Professional
  • Global GRC, assurance, and cloud-scale customer security experience
  • SOC 2, ISO 27001, NIST CSF, HIPAA, PIPEDA, GDPR / CCPA-aligned work

Ready to bring your governance and security posture up to standard?

Book a free 30-minute discovery call to discuss where your business stands and what Proxim can do for you.

Assurance & advisory without the
enterprise price tag.

Every Proxim engagement is scoped to your business. We combine frameworks that matter with advice that translates — practical, actionable, and built to last.

01

Cybersecurity GRC Consulting

Core Service

Governance, Risk, and Assurance is no longer optional — it's a business enabler. Customers, investors, and regulators increasingly demand demonstrable security posture. Proxim helps you build it systematically, without the overhead of a full enterprise security team.

We work with you to assess your current state, identify gaps against applicable frameworks, design appropriate controls (including for AI and automation where relevant), and support you through to audit readiness or certification.

  • Current-state security posture assessment
  • Gap analysis against your target framework
  • AI / automation governance (use cases, controls, and oversight)
  • Risk register development and maintenance
  • Security policy and procedure authoring
  • Control implementation guidance and oversight
  • Audit evidence preparation and readiness review
  • Ongoing advisory retainer engagements
SOC 2 Type I & II ISO 27001 NIST CSF HIPAA PIPEDA / Law 25 GDPR (Cross-border) AI / Automation Governance
02

Assurance Readiness & Audit Prep

Assurance

Facing an audit, a customer security questionnaire, or a regulatory review? Proxim's assurance readiness service prepares your organization to perform confidently — not just pass, but demonstrate a mature, sustainable assurance posture that wins customer trust and opens enterprise doors.

We specialize in helping SMBs achieve the certifications and assurance status that expand market access. This includes deep support for the commercial moments that matter most — contract reviews and security questionnaires that directly affect your ability to close deals.

  • Pre-audit gap assessment and remediation roadmap
  • Policy suite development (information security, acceptable use, privacy)
  • Evidence collection and documentation organization
  • Security awareness training programme design
  • Cloud security posture review (AWS, Azure, GCP)
  • Continuous controls monitoring (CCM) programme design
📄 Contract & Security Reviews
  • Review customer and vendor agreements for hidden security obligations
  • Identify privacy and security risks before you sign
  • Strengthen your negotiation position with informed security language
📋 Security Questionnaires & RFPs
  • Complete client security questionnaires accurately and efficiently
  • Respond to enterprise due diligence requests with confidence
  • Improve win rates with enterprise customers through assurance credibility
SOC 2 ISO 27001 HIPAA Cloud-Native Assurance-as-Code Contract Review Security RFPs
03

Business Advisory & Strategy

Advisory

Behind every assurance challenge is a business challenge. Proxim's advisory practice goes beyond security frameworks to address the strategic and operational questions that founders and leadership teams face at every stage of growth.

Drawing on doctoral-level business administration training and extensive executive experience, the principal advisor brings an evidence-based approach to strategy, governance, and operations for growing businesses.

  • Business model review and strategic planning
  • Corporate governance structure and board-readiness
  • Operational risk identification and mitigation
  • Investor-readiness and due diligence preparation
  • Technology strategy and digital transformation advisory
  • Fractional advisor / virtual CISO engagements
DBA-Grounded Startup & SMB Focus BC Business Law Healthcare Sector Technology Industry
04

Risk Management Programmes

Risk

Risk management is the backbone of a resilient organization. Without a structured programme, risk decisions are made ad hoc, inconsistently, and often too late. Proxim designs pragmatic risk management programmes that give your leadership team visibility and control.

We build risk frameworks that are proportionate to your size — rigorous enough to satisfy external scrutiny, practical enough for a lean team to maintain.

  • Enterprise risk register design and population
  • Information security risk assessments (qualitative & quantitative)
  • Third-party / vendor risk programme design
  • Business continuity and disaster recovery planning
  • Incident response plan development
  • Risk reporting dashboards and executive communication
ISO 31000 NIST RMF FAIR Model MITRE ATT&CK

Engagement models

Every business is different. Choose the engagement model that fits your needs and budget — or combine them.

Project

Fixed-Scope Engagements

Defined deliverable, timeline, and fee. Ideal for gap assessments, policy suites, and audit prep projects.

Retainer

Ongoing Advisory

Monthly advisory hours for businesses that need consistent access to a trusted GRC and assurance advisor.

vCISO

Virtual CISO

Fractional Chief Information Security Officer — strategic security leadership without a full-time hire.

Not sure which service you need?

Book a free 30-minute discovery call. We'll listen, ask the right questions, and tell you plainly what will move the needle for your business.

Proxim AI Advisor

Answers to the questions we hear most — covering our services, the frameworks we work with, AI governance, and how Proxim approaches GRC for startups and SMBs. Don't see your question? Get in touch and we'll answer it directly.

Our Services

Proxim offers four core service lines, each designed to scale with your business:

  • Cybersecurity GRC Consulting — governance frameworks, risk assessments, AI/automation governance, and assurance roadmaps aligned to SOC 2, ISO 27001, NIST CSF, HIPAA, and PIPEDA.
  • Assurance Readiness & Audit Prep — gap assessments, policy development, contract reviews, security questionnaire support, and evidence preparation.
  • Business Advisory & Strategy — operational strategy, governance structures, investor-readiness, and digital transformation advisory.
  • Risk Management Programmes — risk registers, third-party risk, business continuity, and incident response planning.

Every engagement is scoped to your business — we don't retrofit enterprise frameworks onto small teams.

A virtual CISO (vCISO) is a fractional Chief Information Security Officer — an experienced security leader who works with your business part-time, providing strategic security leadership without the cost of a full-time executive hire.

You likely benefit from a vCISO if your business is scaling, facing increased customer security expectations, preparing for a certification like SOC 2 or ISO 27001, or simply needs senior security guidance for board reporting and strategic decisions — but isn't yet at the size to justify a full-time CISO.

Proxim's vCISO engagements are flexible — typically a set number of advisory hours per month, covering security strategy, policy oversight, audit liaison, and executive reporting.

Enterprise customer security questionnaires can be one of the biggest hidden time costs for growing businesses — and getting them wrong can stall or lose deals. As part of our Assurance Readiness & Audit Prep service, Proxim helps you:

  • Complete client security questionnaires accurately and efficiently
  • Respond to enterprise due diligence requests with confidence
  • Review customer and vendor agreements for hidden security obligations before you sign
  • Build a reusable knowledge base of your security posture for future questionnaires

This directly improves win rates with enterprise customers by demonstrating credible, well-documented assurance.

Proxim offers three flexible engagement models so you only pay for what your business needs:

  • Fixed-Scope Engagements — a defined deliverable, timeline, and fee. Ideal for gap assessments, policy suites, and audit prep projects.
  • Ongoing Advisory (Retainer) — monthly advisory hours for businesses that need consistent access to a trusted GRC and assurance advisor.
  • Virtual CISO (vCISO) — fractional security leadership for businesses that need strategic oversight without a full-time hire.

Many clients start with a fixed-scope project (such as a gap assessment) and transition into a retainer once priorities are clear.

Compliance Frameworks

SOC 2 is an attestation report (Type I or Type II) commonly required by North American customers, particularly SaaS companies. It evaluates your controls against the Trust Service Criteria — security, availability, processing integrity, confidentiality, and privacy — over a period of time (Type II) or at a point in time (Type I).

ISO 27001 is an internationally recognised certification for an Information Security Management System (ISMS). It's broader in scope, covering organisational risk management processes, and is often expected by customers in Europe, the Middle East, and global enterprises.

Many growing businesses pursue SOC 2 first (faster, lower cost, satisfies most North American enterprise customers) and add ISO 27001 later as they expand internationally. Proxim can help determine which — or both — your customer base actually requires before you invest.

SOC 2 Type I & IIISO 27001:2022

HIPAA (Health Insurance Portability and Accountability Act) applies if your business creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of, or in connection with, US healthcare providers, health plans, or their business associates — even if your company is based in Canada.

If you're a Canadian healthtech company serving US clients, or a vendor to a US healthcare organisation, HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule likely apply to you as a "business associate."

Proxim helps healthtech and adjacent businesses determine HIPAA applicability, implement required administrative, physical, and technical safeguards, and prepare Business Associate Agreements (BAAs).

HIPAA Privacy RuleHIPAA Security RuleBusiness Associate Agreements

PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada's federal private-sector privacy law, governing how organisations collect, use, and disclose personal information in commercial activity. Quebec's Law 25 introduces stricter requirements similar to GDPR for businesses operating in or serving Quebec residents.

GDPR (EU) and CCPA (California) impose additional, often stricter obligations — including data subject access rights, breach notification timelines, and in GDPR's case, requirements around international data transfers.

If your business has any EU or California customers, users, or website visitors, GDPR/CCPA considerations likely apply in addition to PIPEDA — they aren't mutually exclusive. Proxim helps map your data flows against all applicable regimes and builds a single, unified privacy programme rather than separate compliance silos.

PIPEDALaw 25 (Quebec)GDPRCCPA

The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary framework — not a certification — organised around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It provides a common language for describing and improving your cybersecurity posture.

Unlike SOC 2 or ISO 27001, there's no formal "NIST CSF certificate" to obtain. Instead, organisations use it as a maturity model — assessing current state against target state across the six functions, then prioritising investment accordingly.

NIST CSF is particularly useful as a foundational layer before pursuing SOC 2 or ISO 27001, since its functions map cleanly onto the control families those frameworks expect.

NIST CSF 2.0Maturity Modelling

Audit preparation typically follows this path:

  • Gap assessment — comparing your current controls against the target framework's requirements
  • Policy & procedure development — documenting information security, acceptable use, access control, incident response, and related policies
  • Control implementation — closing identified gaps (e.g. MFA enforcement, access reviews, vendor risk assessments)
  • Evidence collection — gathering proof that controls have been operating (especially critical for SOC 2 Type II, which covers a period of time, not a point in time)
  • Readiness review — a final check before engaging an external auditor

For SOC 2 Type II, expect an observation period of 3–12 months where controls must demonstrably operate before the audit can be completed. ISO 27001 timelines vary similarly depending on organisational maturity. Proxim manages this entire process end-to-end — including liaising with your external auditor.

AI & Automation Governance

Yes — AI and automation governance is part of our Cybersecurity GRC Consulting service. As businesses adopt AI tools (from internal copilots to customer-facing AI features), they introduce new categories of risk: data leakage to third-party models, unvetted AI use cases, lack of human oversight on automated decisions, and emerging regulatory expectations.

Proxim helps you build an AI governance programme that includes:

  • An inventory of AI use cases and tools currently in use across your organisation
  • Risk classification of each use case (e.g. low-risk internal productivity vs. high-risk customer-facing decisions)
  • Acceptable Use policies for AI tools, including data handling rules
  • Human oversight and review controls for AI-assisted decisions
  • Vendor due diligence for third-party AI tools and model providers

This positions your organisation to respond confidently to customer questions about AI use — increasingly a standard part of security questionnaires — and prepares you for emerging regulation.

AI / Automation GovernanceUse Case Risk Classification

AI governance isn't a separate silo — it integrates into your existing GRC structure. For example:

  • Risk management — AI use cases are added to your risk register, with appropriate treatment plans
  • Vendor / third-party risk — AI model providers (OpenAI, Anthropic, Google, etc.) go through the same vendor due diligence as any other processor of your data
  • Access control & data classification — existing policies are extended to cover what data can be input into AI tools
  • Change management — deploying new AI-driven features follows the same change control process as other system changes

SOC 2 and ISO 27001 auditors are increasingly asking about AI tool usage as part of standard control testing — having a documented AI governance approach demonstrates maturity and reduces audit friction.

Enterprise customers are increasingly including questions such as:

  • "Do you use AI/ML in your product, and if so, how is customer data used in model training?"
  • "What third-party AI tools do your employees have access to, and what data can be shared with them?"
  • "Is there human review of any automated or AI-driven decisions affecting our data or account?"
  • "Do you have an AI usage policy, and how is it enforced?"

If you can't answer these clearly and consistently, it can stall enterprise deals — exactly the kind of gap our Assurance Readiness & Audit Prep service is designed to close, working hand-in-hand with AI governance policy development.

Getting Started with Proxim

Most startups don't need to "boil the ocean" — the right starting point depends on what's driving the need. Common triggers include an enterprise customer requiring SOC 2, a healthcare client requiring HIPAA alignment, or simply wanting to build good governance habits early before they become expensive to retrofit.

A typical first step is a lightweight current-state assessment — understanding what data you handle, what tools and vendors you use, and what your customers or industry actually require. From there, Proxim recommends a prioritised roadmap rather than attempting every framework at once.

Book a free 30-minute discovery call and we'll give you a clear, honest read on what matters most for your situation — no obligation.

It depends on scope and your starting maturity:

  • Gap assessment — typically 2–4 weeks
  • Policy suite development — typically 4–8 weeks
  • SOC 2 Type II readiness (including the observation period before audit) — typically 3–6 months to readiness, plus a 3–12 month observation window
  • ISO 27001 readiness — typically 3–9 months depending on organisational complexity
  • Ongoing retainer / vCISO — open-ended, reviewed quarterly

We'll give you a realistic timeline during your discovery call based on your specific situation — not a generic estimate.

Booking is simple — head to our Contact page and fill in the discovery call form, or email us directly at hello@proximadvisory.ca or call 250-258-7187.

Your free 30-minute discovery call includes a review of your current assurance and risk posture, identification of your most pressing gaps, and recommended next steps — with absolutely no obligation. We typically respond within 1 business day.

Let's talk it through together.

Let's talk about your business.

Every engagement starts with a conversation. Book a free 30-minute discovery call — no obligation, no sales pitch. Just an honest conversation about where you are and where you want to be.

Location

British Columbia, Canada

Email

hello@proximadvisory.ca

Service Area

Canada-wide · Remote & in-person (British Columbia)

Response Time

Within 1 business day

Discovery Call Includes
  • Review of your current assurance & risk posture
  • Identification of your most pressing gaps
  • Recommended next steps — no obligation
  • 30 minutes, fully confidential, free of charge
Book a Discovery Call

Your information is kept strictly confidential. We will respond within 1 business day.

✦ Message received — we'll be in touch within 1 business day.