Already dealing with a fraud incident? Get help now →

Know exactly where you stand.

Every engagement has a clear point of accountability, with specialist technical support added when the scope requires it. You receive a plain-language report, a prioritized action list, and a follow-up call to walk through the findings. Three ways to work with us, below — a one-time assessment, ongoing protection, or a coordinated managed service.

Fraud & Cyber Risk Assessment
A practical review of payment workflows, supplier verification practices, and the Microsoft 365 settings most often linked to fraud losses.
$750
CAD · starting at, one-time
5-business-day target after intake
What we assess
  • Email & payment fraud (BEC) exposure
  • Microsoft 365, MFA & identity controls
  • Vendor payment process & vendor verification
  • Banking-change verification practices
  • Invoice authorization & payment approval controls
  • Phishing & supplier/executive impersonation exposure
  • AI-enabled impersonation (voice & deepfake scams)
  • Employee fraud awareness
  • Incident preparedness
What you get
  • Prioritized findings report, in plain language
  • 30-minute findings review and follow-up call
Request an Assessment
Managed Protection
Coordinated ongoing protection for businesses that want hands-on technical layers after the initial assessment.
Custom
pricing — based on business size, technology environment, and risk profile
Scoped after a short conversation
What's included
  • Endpoint threat detection & response (MDR/EDR), delivered via specialist partners
  • Microsoft 365 identity & account-takeover monitoring
  • Security posture monitoring and backup protection
  • Security awareness training and email security
  • 24/7 monitoring, delivered through specialist partners

Delivered via specialist partners under the applicable client service agreement. PrivaCore does not require businesses to replace their existing IT provider — we can work alongside your current IT team, MSP, or technology provider.

Discuss Managed Protection
Scope note: Each price above covers the listed deliverables. Any specialist technical work, remediation, or additional service is optional, separately scoped, and approved in writing before work begins.

Need help with a suspected incident instead?

Get Incident Response Help →
Quick checks

A narrow, focused diagnostic — not a smaller assessment.

Quick Checks look closely at one system, on a fixed short timeline. They're not a lighter-weight version of the services above — if you want the full picture of your business, see the services above.

Microsoft 365 Fraud & Security Check

A focused review of your Microsoft 365 setup — the specific settings most often behind a fraud loss.

$349
CAD · one-time
Most reports back within 3 business days
What's included
  • MFA and admin-account review
  • Mailbox forwarding and inbox-rule check
  • SPF, DKIM and DMARC check
  • Anti-phishing and impersonation policy review
  • Payment-change process review
  • One-page Red / Amber / Green report

Is this a routine check, or are you concerned about something specific?

Has money already been sent to an account you now believe is fraudulent?

Ongoing protection

Continuous M365 Fraud & Identity Monitoring

The Microsoft 365 Fraud & Security Check above is a snapshot — accurate the day we run it, but silent about anything that changes afterward. Most Microsoft 365 fraud doesn't happen on day one. It happens weeks later, through one quiet change most businesses never see: a new forwarding rule, a sign-in from somewhere unfamiliar, an app someone approved without reading what it asked for. Continuous monitoring watches for exactly those changes, for as long as you need it.

New mail-forwarding rules
A hidden forwarding rule is one of the most common signs of a compromised inbox. It lets someone read invoices, payment confirmations, and client emails silently — without ever needing your password again. We flag every new rule the moment it's created.
Unusual sign-in activity
An unfamiliar location, device, or time of day is often the very first sign something is wrong — usually days before any fraud attempt becomes visible. Catching it here means catching it before money moves.
Suspicious OAuth app consent grants
Increasingly, attackers skip passwords altogether and trick someone into approving a malicious app instead — a technique most businesses have never heard of and don't check for. We watch for consent grants that request unusual or excessive access.
Mailbox rule changes
Rules that quietly delete or hide messages — like replies from your bank or accountant — are used to keep fraud invisible while it's happening. We flag rule changes that don't match normal use.

Think of the one-time Check as a health exam, and this as the ongoing check-up — most fraud happens in the gap between exams. You're alerted as soon as a suspicious change is detected, with plain-language guidance on what it means and what to do next, not just a dashboard you have to interpret yourself.

How it's delivered: this level of monitoring is included starting with PrivaCore Business Protection ($299/month and up), alongside continuous email threat monitoring and ongoing verification procedures. Monitoring is provided directly or coordinated through specialist security partners — consistent, no surprise vendor.
Ask About Business Protection →
Managed Protection

Turn findings into finished, maintained work.

PrivaCore can help businesses implement and maintain appropriate cybersecurity protection following an assessment. Depending on the environment and risk profile, this may include Microsoft 365 security improvements, email protection, identity monitoring, endpoint protection, employee awareness and managed detection and response.

Microsoft 365 security configuration and hardening
Email phishing and impersonation protection
Identity and account-compromise monitoring
Endpoint security coordination
Security awareness and phishing education
Vendor and payment-change fraud controls
Security alerts and incident escalation
Managed detection and response through specialist security partners where required
We work with your existing technology wherever practical and recommend additional services only where they address an identified risk.
After the assessment: the Fraud & Cyber Risk Assessment tells you where you stand — remediation and managed protection are what close the gaps. Both are scoped and quoted separately, and can include Microsoft 365 hardening, email protection, awareness-training refreshers, and regular check-ins. PrivaCore Business Protection already includes a quarterly risk review; Managed Protection is the same relationship taken further, with PrivaCore handling day-to-day protection directly.
Working with your existing IT provider: PrivaCore does not require businesses to replace their existing IT provider. We can work alongside your current IT team, MSP, or technology provider, coordinating any technical work with the providers you already use — you don't need to switch anything to work with us.
Scope and transparency: PrivaCore does not operate its own security operations centre and does not claim 24/7 monitoring unless a service is specifically contracted. Where SOC or managed detection and response capability is referenced, it is delivered through specialist security partners under the applicable client service agreement.
Discuss Managed Protection →

Need vendor-payment verification on its own? Get the Vendor Payment Verification Toolkit — $349 CAD →

Business email compromise

The email can be real. The payment request can still be fraud.

Business email compromise can involve criminals impersonating a supplier, executive or employee — or gaining access to a legitimate email account and entering an existing conversation. PrivaCore helps businesses strengthen both sides of the problem: the technology protecting email and identities, and the business controls used before money moves.

Technology
  • Microsoft 365 security
  • Multi-factor authentication
  • Email threat protection
  • Identity monitoring
  • Suspicious-email reporting
  • Account-compromise detection
Business controls
  • Vendor verification
  • Banking-change verification
  • Independent callback procedures
  • Dual payment approval
  • Employee fraud awareness
  • Incident-response procedures
Protect Your Payment Process →

Want a written policy first? Generate a free Payment Verification Policy →

Not sure which fits?

Tell us how your business works.

A short set of qualifying questions — industry, team size, and what has your attention — is all we need to point you at the right package. The first call is free.

Talk to PrivaCore →