Proxim Advisory Group brings enterprise-grade cybersecurity GRC and business strategy to startups and SMBs — the organizations that need it most, and deserve it most.
We don't retrofit enterprise frameworks onto small teams. We design assurance and advisory programmes that fit where you are — and where you're going.
Governance frameworks, risk assessments, AI/automation governance, and assurance roadmaps aligned to SOC 2, ISO 27001, NIST CSF, HIPAA, and PIPEDA.
Gap assessments, policy development, contract reviews, security questionnaire support, and evidence preparation to position your business for audit success.
Operational strategy, business model analysis, and governance structures for founders and leadership teams at every stage.
Tailored risk registers, control libraries, and continuous monitoring frameworks that scale with your organization.
Proxim Advisory Group was founded on a single conviction: that small and growing businesses deserve the same quality of governance and security advisory traditionally reserved for large enterprises.
The word proxim derives from the Latin for closeness — and that's precisely what distinguishes our practice. We don't parachute in with a generic framework and leave. We sit alongside your leadership team, understand your context, and build programmes that actually work for your size, your sector, and your risk appetite.
Founded in British Columbia, Canada, Proxim Advisory Group serves startups and small-to-medium businesses across Canada. Our practice spans cybersecurity governance, risk and assurance (GRC) consulting, and strategic business advisory — delivered by an advisor with doctoral-level academic credentials and hands-on operational experience.
Whether you're preparing for your first security audit, building investor-ready governance, or navigating a regulated industry, Proxim brings the rigour, clarity, and conviction to guide you through.
We engage as a true partner — close to your team, your decisions, and your outcomes.
Every recommendation is grounded in evidence, frameworks, and academic rigour.
Assurance programmes that fit your business — not the other way around.
We earn it through transparency, consistency, and delivering on every commitment.
The principal advisor holds a Doctor of Business Administration (DBA) in Information Systems and Enterprise Resource Management, is a Certified Information Systems Security Professional (CISSP), and brings deep experience in global GRC, cloud security assurance, and strategic risk management across operational and leadership roles.
Doctoral scholarship, hands-on security practice, and business advisory judgment inform every engagement in Proxim's advisory model.
Book a free 30-minute discovery call to discuss where your business stands and what Proxim can do for you.
Every Proxim engagement is scoped to your business. We combine frameworks that matter with advice that translates — practical, actionable, and built to last.
Governance, Risk, and Assurance is no longer optional — it's a business enabler. Customers, investors, and regulators increasingly demand demonstrable security posture. Proxim helps you build it systematically, without the overhead of a full enterprise security team.
We work with you to assess your current state, identify gaps against applicable frameworks, design appropriate controls (including for AI and automation where relevant), and support you through to audit readiness or certification.
Facing an audit, a customer security questionnaire, or a regulatory review? Proxim's assurance readiness service prepares your organization to perform confidently — not just pass, but demonstrate a mature, sustainable assurance posture that wins customer trust and opens enterprise doors.
We specialize in helping SMBs achieve the certifications and assurance status that expand market access. This includes deep support for the commercial moments that matter most — contract reviews and security questionnaires that directly affect your ability to close deals.
Behind every assurance challenge is a business challenge. Proxim's advisory practice goes beyond security frameworks to address the strategic and operational questions that founders and leadership teams face at every stage of growth.
Drawing on doctoral-level business administration training and extensive executive experience, the principal advisor brings an evidence-based approach to strategy, governance, and operations for growing businesses.
Risk management is the backbone of a resilient organization. Without a structured programme, risk decisions are made ad hoc, inconsistently, and often too late. Proxim designs pragmatic risk management programmes that give your leadership team visibility and control.
We build risk frameworks that are proportionate to your size — rigorous enough to satisfy external scrutiny, practical enough for a lean team to maintain.
Every business is different. Choose the engagement model that fits your needs and budget — or combine them.
Defined deliverable, timeline, and fee. Ideal for gap assessments, policy suites, and audit prep projects.
Monthly advisory hours for businesses that need consistent access to a trusted GRC and assurance advisor.
Fractional Chief Information Security Officer — strategic security leadership without a full-time hire.
Book a free 30-minute discovery call. We'll listen, ask the right questions, and tell you plainly what will move the needle for your business.
Answers to the questions we hear most — covering our services, the frameworks we work with, AI governance, and how Proxim approaches GRC for startups and SMBs. Don't see your question? Get in touch and we'll answer it directly.
Proxim offers four core service lines, each designed to scale with your business:
Every engagement is scoped to your business — we don't retrofit enterprise frameworks onto small teams.
A virtual CISO (vCISO) is a fractional Chief Information Security Officer — an experienced security leader who works with your business part-time, providing strategic security leadership without the cost of a full-time executive hire.
You likely benefit from a vCISO if your business is scaling, facing increased customer security expectations, preparing for a certification like SOC 2 or ISO 27001, or simply needs senior security guidance for board reporting and strategic decisions — but isn't yet at the size to justify a full-time CISO.
Proxim's vCISO engagements are flexible — typically a set number of advisory hours per month, covering security strategy, policy oversight, audit liaison, and executive reporting.
Enterprise customer security questionnaires can be one of the biggest hidden time costs for growing businesses — and getting them wrong can stall or lose deals. As part of our Assurance Readiness & Audit Prep service, Proxim helps you:
This directly improves win rates with enterprise customers by demonstrating credible, well-documented assurance.
Proxim offers three flexible engagement models so you only pay for what your business needs:
Many clients start with a fixed-scope project (such as a gap assessment) and transition into a retainer once priorities are clear.
SOC 2 is an attestation report (Type I or Type II) commonly required by North American customers, particularly SaaS companies. It evaluates your controls against the Trust Service Criteria — security, availability, processing integrity, confidentiality, and privacy — over a period of time (Type II) or at a point in time (Type I).
ISO 27001 is an internationally recognised certification for an Information Security Management System (ISMS). It's broader in scope, covering organisational risk management processes, and is often expected by customers in Europe, the Middle East, and global enterprises.
Many growing businesses pursue SOC 2 first (faster, lower cost, satisfies most North American enterprise customers) and add ISO 27001 later as they expand internationally. Proxim can help determine which — or both — your customer base actually requires before you invest.
HIPAA (Health Insurance Portability and Accountability Act) applies if your business creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of, or in connection with, US healthcare providers, health plans, or their business associates — even if your company is based in Canada.
If you're a Canadian healthtech company serving US clients, or a vendor to a US healthcare organisation, HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule likely apply to you as a "business associate."
Proxim helps healthtech and adjacent businesses determine HIPAA applicability, implement required administrative, physical, and technical safeguards, and prepare Business Associate Agreements (BAAs).
PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada's federal private-sector privacy law, governing how organisations collect, use, and disclose personal information in commercial activity. Quebec's Law 25 introduces stricter requirements similar to GDPR for businesses operating in or serving Quebec residents.
GDPR (EU) and CCPA (California) impose additional, often stricter obligations — including data subject access rights, breach notification timelines, and in GDPR's case, requirements around international data transfers.
If your business has any EU or California customers, users, or website visitors, GDPR/CCPA considerations likely apply in addition to PIPEDA — they aren't mutually exclusive. Proxim helps map your data flows against all applicable regimes and builds a single, unified privacy programme rather than separate compliance silos.
The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary framework — not a certification — organised around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It provides a common language for describing and improving your cybersecurity posture.
Unlike SOC 2 or ISO 27001, there's no formal "NIST CSF certificate" to obtain. Instead, organisations use it as a maturity model — assessing current state against target state across the six functions, then prioritising investment accordingly.
NIST CSF is particularly useful as a foundational layer before pursuing SOC 2 or ISO 27001, since its functions map cleanly onto the control families those frameworks expect.
Audit preparation typically follows this path:
For SOC 2 Type II, expect an observation period of 3–12 months where controls must demonstrably operate before the audit can be completed. ISO 27001 timelines vary similarly depending on organisational maturity. Proxim manages this entire process end-to-end — including liaising with your external auditor.
Yes — AI and automation governance is part of our Cybersecurity GRC Consulting service. As businesses adopt AI tools (from internal copilots to customer-facing AI features), they introduce new categories of risk: data leakage to third-party models, unvetted AI use cases, lack of human oversight on automated decisions, and emerging regulatory expectations.
Proxim helps you build an AI governance programme that includes:
This positions your organisation to respond confidently to customer questions about AI use — increasingly a standard part of security questionnaires — and prepares you for emerging regulation.
AI governance isn't a separate silo — it integrates into your existing GRC structure. For example:
SOC 2 and ISO 27001 auditors are increasingly asking about AI tool usage as part of standard control testing — having a documented AI governance approach demonstrates maturity and reduces audit friction.
Enterprise customers are increasingly including questions such as:
If you can't answer these clearly and consistently, it can stall enterprise deals — exactly the kind of gap our Assurance Readiness & Audit Prep service is designed to close, working hand-in-hand with AI governance policy development.
Most startups don't need to "boil the ocean" — the right starting point depends on what's driving the need. Common triggers include an enterprise customer requiring SOC 2, a healthcare client requiring HIPAA alignment, or simply wanting to build good governance habits early before they become expensive to retrofit.
A typical first step is a lightweight current-state assessment — understanding what data you handle, what tools and vendors you use, and what your customers or industry actually require. From there, Proxim recommends a prioritised roadmap rather than attempting every framework at once.
Book a free 30-minute discovery call and we'll give you a clear, honest read on what matters most for your situation — no obligation.
It depends on scope and your starting maturity:
We'll give you a realistic timeline during your discovery call based on your specific situation — not a generic estimate.
Booking is simple — head to our Contact page and fill in the discovery call form, or email us directly at hello@proximadvisory.ca or call 250-258-7187.
Your free 30-minute discovery call includes a review of your current assurance and risk posture, identification of your most pressing gaps, and recommended next steps — with absolutely no obligation. We typically respond within 1 business day.
Every engagement starts with a conversation. Book a free 30-minute discovery call — no obligation, no sales pitch. Just an honest conversation about where you are and where you want to be.
British Columbia, Canada
hello@proximadvisory.ca
Canada-wide · Remote & in-person (British Columbia)
Within 1 business day
Your information is kept strictly confidential. We will respond within 1 business day.