Skip to content

Secure the mission. Strengthen public trust.

Cybersecurity expertise for Canada's public sector.

Frank Dolphins Group Inc. helps government and public-sector organizations strengthen cyber resilience, modernize security operations and deliver secure digital services.

Security ArchitectureSecurity Architecture, Cloud Security, Threat Detection, Identity Protection, Security Operations, Cyber Risk

Canadian-owned

An independent company owned and operated in Canada.

Cybersecurity focused

Security architecture, cloud security, operations, identity and cyber risk are the whole of our practice.

Public-sector focused

Services shaped around government and public-sector security expectations.

Security-conscious delivery

Work is planned and handled according to the sensitivity of the environment and its information.

Partnership ready

Set up to work alongside government teams, prime contractors and technology partners.

Security operations view

How we look at a protected environment

Identity, cloud workloads, telemetry and control assurance are treated as one connected picture rather than separate projects. The graphics below illustrate that model.

Zero Trust access layers

Access is evaluated at every layer

  1. 01Identity
  2. 02Device
  3. 03Network
  4. 04Workload
  5. 05Data

Identity and device posture inform every access decision, applying NIST SP 800-207 principles to estates that are part on-premises and part cloud.

Threat detection coverage

Detections mapped to real technique

Detection coverage is planned against MITRE ATT&CK techniques, with the log sources and response procedures that make an alert actionable.

Secure cloud architecture

Boundaries that hold as you scale

Azure and Microsoft 365 workloads are designed with configuration baselines, logging coverage and clear ownership of shared responsibility.

Cyber resilience

Recovery expectations, dependencies and response ownership are defined before an incident, not during one.

Identity protection

Privileged access is time-bound, approved and reviewed on a cycle rather than left standing.

Control assurance

Control evidence is structured so an authorizer or auditor can follow it without reconstruction.

Illustrative brand graphics. Not live telemetry or client data.

Cybersecurity capabilities

Six capability areas, built for security-sensitive environments

Each area addresses a specific cybersecurity challenge, the services we provide against it and the security outcome the organization can point to.

Cybersecurity strategy and architecture

The challenge
Security investments are often made tool by tool, which leaves organizations with overlapping controls and no shared view of the target state.
What we provide
We set the security direction and the architecture behind it, from a costed cybersecurity roadmap through Zero Trust strategy and the structure of the security program itself.
The security outcome
A defensible target architecture and sequenced roadmap that security, IT and executive stakeholders can plan and budget against.
  • Cybersecurity roadmaps
  • Security architecture
  • Zero Trust strategy
  • Security program development

Cloud and Microsoft security

The challenge
Cloud and Microsoft 365 estates grow quickly, and configuration decisions made early are difficult and expensive to unwind later.
What we provide
We design and harden cloud security architecture across Azure and Microsoft 365, and engineer the Microsoft security stack, including Microsoft Defender and Microsoft Sentinel, to fit the environment it protects.
The security outcome
A cloud estate with security controls that hold their intended boundaries as the environment scales.
  • Microsoft security technologies
  • Cloud security architecture
  • Microsoft Defender
  • Microsoft Sentinel
  • Azure and Microsoft 365 security

Security operations and threat detection

The challenge
Monitoring platforms produce volume, but teams still lack the specific detections, context and playbooks an incident actually demands.
What we provide
We engineer the SIEM and its data pipelines, build and tune detections, automate repetitive response steps and prepare the incident response procedures that surround them.
The security outcome
Operations teams that see what matters, respond on an agreed sequence and spend less time on manual triage.
  • SIEM engineering
  • Security monitoring
  • Detection engineering
  • Incident response
  • Security automation

Identity and access security

The challenge
Identity has become the primary control plane, yet privileged access and access reviews are frequently the least governed part of the estate.
What we provide
We design identity architecture, tighten privileged access, build Conditional Access and identity governance, and align access controls to Zero Trust principles.
The security outcome
Access that is granted deliberately, reviewed on a cycle and revoked when it is no longer warranted.
  • Identity architecture
  • Privileged access
  • Conditional Access
  • Identity governance
  • Zero Trust access controls

Cyber risk, compliance and assurance

The challenge
Teams are held to security policy expectations without a clear, evidenced picture of where their controls currently stand.
What we provide
We run security assessments, implement and document controls, structure governance and risk management, build vulnerability management into a repeatable cycle and prepare organizations for compliance review.
The security outcome
A defensible view of current risk and a prioritized remediation plan that holds up under audit and executive scrutiny.
  • Security assessments
  • Governance and risk management
  • Control implementation
  • Vulnerability management
  • Compliance readiness

Cybersecurity professional services

The challenge
Requirements arrive with firm dates while the specialized cybersecurity capacity to meet them is not available internally.
What we provide
We provide experienced cybersecurity professionals for technical project delivery, advisory and engineering support, and we support prime contractors through subcontracting and teaming arrangements.
The security outcome
Continuity of delivery through peak periods, without a permanent headcount commitment.
  • Experienced cybersecurity professionals
  • Technical project delivery
  • Advisory and engineering support
  • Subcontracting and teaming support
Explore Our Cyber Capabilities

Public-sector focus

Cybersecurity built around public-sector realities.

Government environments require strong security, clear accountability and solutions that work across complex technology, operational and regulatory environments. Frank Dolphins brings practical cybersecurity expertise to these challenges.

Security assessment and authorization

Structuring control evidence, threat and risk assessments and residual risk statements so an authorizer can make an informed decision.

ITSG-33 control profiles

Tailoring control profiles to the sensitivity of the system rather than applying an untailored catalogue.

Zero Trust and identity protection

Applying NIST SP 800-207 principles to identity, device and network access decisions in mixed on-premises and cloud estates.

Cloud security

Securing Azure and Microsoft 365 workloads with configuration baselines, logging coverage and clear ownership of shared responsibility.

Threat detection

Building detection coverage mapped to MITRE ATT&CK, with the log sources and response procedures that make it usable.

Vulnerability and control assurance

Turning findings into an owned, verified remediation cycle instead of a recurring backlog.

These describe the guidance and practices we work within. Frank Dolphins does not claim certification, approval or endorsement under any framework or by any government organization.

Why Frank Dolphins

Four commitments behind every security engagement

Mission-aware security

Controls are chosen for the service being protected and the people who depend on it, not applied as a uniform template across an estate.

Experienced technical leadership

Engagements are led by practitioners who have built and operated security architecture, cloud security, detection and identity in complex environments.

Accountable execution

Commitments are written down, ownership is named, progress is reported plainly and issues are raised while there is still time to act.

Practical, measurable outcomes

Work is defined so its result can be demonstrated: a control implemented, a detection proven, a risk closed or an assessment accepted.

Delivery approach

From mission and risk through to measured results

  1. 01

    Understand the mission and risk

    We begin with the service being protected, the information it holds and the risks that matter most to the people accountable for it.

  2. 02

    Design the appropriate security approach

    We select the architecture and controls that fit the environment, its constraints and the security guidance it is expected to follow.

  3. 03

    Implement with accountability

    Work proceeds against agreed milestones and deliverables, with named ownership and a documented trail behind each security decision.

  4. 04

    Measure, improve and communicate

    Results are validated, gaps are fed back into the roadmap, and status is reported in language both engineers and executives can act on.

Partners

A dependable cybersecurity delivery partner.

Frank Dolphins works with government organizations, prime contractors and technology partners to support secure and successful public-sector delivery.

Discuss a Partnership

Engage

Strengthen your next cybersecurity initiative.

Connect with Frank Dolphins regarding cybersecurity requirements, subcontracting, teaming arrangements and professional-services opportunities.