Consulting Services.
Independent cybersecurity, GRC, and security-assessment consulting for Government of Canada delivery teams, integrators, and enterprise clients — delivered by a working practitioner, not a slide deck.
Six ways Skymeba plugs in.
Every engagement is scoped from a concrete outcome backwards — an ATO letter, an ISO certificate, a hardened architecture, a resilient security culture, a strong academic program, a coached career — and delivered on a fixed statement of work.
Security assessment & authorization / ISO 27001
Authorship or independent review of the full ITSP.10.033 package for medium-impact systems — SoS, TRA, SSP, SRTM — with assessor-ready traceability from injury statement to control evidence. On the certification side, Skymeba runs ISO/IEC 27001 lead-implementer engagements end to end: scope, statement of applicability, risk treatment plan, and internal-audit dry run.
- Typical duration — 6 to 14 weeks per SA&A package; 3 to 6 months for a full ISO 27001 implementation.
- Primary deliverables — SoS, TRA, SSP, SRTM, POA&M, continuous-monitoring plan; or ISMS documentation, SoA, and risk treatment plan.
- Best fit — Protected B systems moving to authorization, and SMB or mid-market organizations pursuing ISO 27001 certification.
- Adjacent — concept & scope memos, tailoring statements, control-inheritance letters, cross-framework mapping.
Security architecture
Reference architectures, control-informed design reviews, and hardening plans for cloud, hybrid, and on-premises estates. Skymeba writes architecture that maps cleanly to ITSP.10.033, ISO 27002, and CIS Controls — so what you build lines up with what you'll be assessed against.
- Typical duration — 4 to 12 weeks.
- Primary deliverables — target-state architecture, security patterns, hardening baselines, control-mapping matrix.
- Best fit — cloud migrations, zero-trust programs, and platform teams building shared services with an inheritable control posture.
Cybersecurity awareness & culture programs
Enterprise-wide awareness programs that go beyond annual click-through training — role-based curricula, phishing-simulation cadences, human-risk metrics, and culture-change interventions designed to move the needle on measurable behaviours, not just completion rates.
- Typical duration — 3 to 9 months to design, launch, and hand over.
- Primary deliverables — program charter, role-based learning paths, campaign calendar, human-risk metrics dashboard, and executive reporting pack.
- Best fit — security teams that own the human-risk mandate but need a coherent program instead of ad-hoc campaigns.
Fractional / virtual CISO advisory
Interim CISO or senior security leadership capacity for organizations that need senior direction without a full-time hire — typical engagements run one to three days per week over a defined arc. Deliverables travel with the role: strategy, board reporting, control-program cadence, vendor-security oversight, and incident readiness.
- Typical duration — 3 to 12 months.
- Primary deliverables — security strategy, board-report cadence, control-program plan, incident-response playbook, hiring criteria for the permanent role.
- Best fit — growth-stage organizations, or mature teams between permanent leaders.
Academic program development & instruction
Curriculum design, course authorship, and instruction for post-secondary cybersecurity programs, corporate academies, and professional-certification pathways. Every module is designed for independent self-study so learners are not held hostage to live-workshop schedules, and every statistic in the material is sourced.
- Typical duration — single courses through multi-term programs.
- Primary deliverables — program outlines, course outlines, participant workbooks in the Print Edition style, facilitator notes, and evaluation instruments.
- Best fit — colleges, universities, and corporate academies building or refreshing a cybersecurity pathway.
Career coaching & workforce development
One-on-one career coaching for cybersecurity practitioners and cohort-based workforce development for teams and employers. Skymeba helps individuals plan certification pathways, sharpen résumés and interview presence, and target senior GRC, SA&A, and leadership roles — and helps employers build hiring rubrics and onboarding tracks that convert junior talent into productive practitioners.
- Typical duration — single-session reviews through multi-month coaching arcs.
- Primary deliverables — career plan with a sequenced certification pathway, résumé and LinkedIn review, interview coaching, or an employer-side hiring rubric and onboarding track.
- Best fit — practitioners planning a senior move, and employers investing in a durable cybersecurity workforce.
Small, senior, evidence-first.
Fixed statements of work
Every engagement starts with a written scope, a written deliverable list, and a written price. Time-and-materials only when the discovery genuinely requires it.
Senior on the tools
The person you meet in the first conversation is the person who writes the deliverable. No pyramid, no offshored ghost-writing.
Evidence over opinion
Recommendations trace back to a control, a standard, or a documented risk. Deliverables are usable inside your evidence store, not decorative.
Book a 30-minute intro call.
Describe the outcome you're after — ATO, certificate, uplift, training — and Skymeba will come back with a proposed shape for the engagement.