British Columbia, Canada · Est. 2026

Governance.
Risk. Assurance.
Built for Growth.

Proxim Advisory Group brings enterprise-grade cybersecurity GRC and business strategy to startups and SMBs — the organizations that need it most, and deserve it most.

DBADoctoral Credential
4+Frameworks Covered
SMBFocused Practice

ISO 27001 & SOC 2

Readiness assessments and gap analysis aligned to international standards.

HIPAA & PIPEDA

Privacy and healthcare assurance guidance for regulated industries.

Business Advisory

Strategy, operations, and governance for founders navigating growth.

BC-Based. Global Reach.

Founded in British Columbia, Canada — advising clients across Canada and beyond.

Advisory services built
around your scale

We don't retrofit enterprise frameworks onto small teams. We design assurance and advisory programmes that fit where you are — and where you're going.

01

Cybersecurity GRC Consulting

Governance frameworks, risk assessments, AI/automation governance, and assurance roadmaps aligned to SOC 2, ISO 27001, NIST CSF, HIPAA, and PIPEDA.

Learn more →
02

Assurance Readiness & Audit Prep

Gap assessments, policy development, contract reviews, security questionnaire support, and evidence preparation to position your business for audit success.

Learn more →
03

Business Advisory & Strategy

Operational strategy, business model analysis, and governance structures for founders and leadership teams at every stage.

Learn more →
04

Risk Management Programmes

Tailored risk registers, control libraries, and continuous monitoring frameworks that scale with your organization.

Learn more →

Turn assurance into a competitive advantage.

Proximity to your business
is everything.

Proxim Advisory Group was founded on a single conviction: that small and growing businesses deserve the same quality of governance and security advisory traditionally reserved for large enterprises.

Why Proxim?

The word proxim derives from the Latin for closeness — and that's precisely what distinguishes our practice. We don't parachute in with a generic framework and leave. We sit alongside your leadership team, understand your context, and build programmes that actually work for your size, your sector, and your risk appetite.

Founded in British Columbia, Canada, Proxim Advisory Group serves startups and small-to-medium businesses across North America, Europe and Africa. Our practice spans cybersecurity governance, risk and assurance (GRC) consulting, and strategic business advisory — delivered by an advisor with doctoral-level academic credentials and hands-on operational experience.

Whether you're preparing for your first security audit, building investor-ready governance, or navigating a regulated industry, Proxim brings the rigour, clarity, and conviction to guide you through.

Proximity

We engage as a true partner — close to your team, your decisions, and your outcomes.

Precision

Every recommendation is grounded in evidence, frameworks, and academic rigour.

Practicality

Assurance programmes that fit your business — not the other way around.

Trust

We earn it through transparency, consistency, and delivering on every commitment.

PA

Principal Advisor

Founder & Lead Consultant

The principal advisor holds a Doctor of Business Administration (DBA) in Information Systems and Enterprise Resource Management, is a Certified Information Systems Security Professional (CISSP), and brings deep experience in global GRC, cloud security assurance, and strategic risk management across operational and leadership roles.

Doctoral scholarship, hands-on security practice, and business advisory judgment inform every engagement in Proxim's advisory model.

  • DBA — Information Systems & Enterprise Resource Management
  • CISSP — Certified Information Systems Security Professional
  • Global GRC, assurance, and cloud-scale customer security experience
  • SOC 2, ISO 27001, NIST CSF, HIPAA, PIPEDA, GDPR / CCPA-aligned work

Ready to bring your governance and security posture up to standard?

Book a free 30-minute discovery call to discuss where your business stands and what Proxim can do for you.

Assurance & advisory without the
enterprise price tag.

Every Proxim engagement is scoped to your business. We combine frameworks that matter with advice that translates — practical, actionable, and built to last.

01

Cybersecurity GRC Consulting

Core Service

Governance, Risk, and Assurance is no longer optional — it's a business enabler. Customers, investors, and regulators increasingly demand demonstrable security posture. Proxim helps you build it systematically, without the overhead of a full enterprise security team.

We work with you to assess your current state, identify gaps against applicable frameworks, design appropriate controls (including for AI and automation where relevant), and support you through to audit readiness or certification.

  • Current-state security posture assessment
  • Gap analysis against your target framework
  • AI / automation governance (use cases, controls, and oversight)
  • Risk register development and maintenance
  • Security policy and procedure authoring
  • Control implementation guidance and oversight
  • Audit evidence preparation and readiness review
  • Ongoing advisory retainer engagements
SOC 2 Type I & II ISO 27001 NIST CSF HIPAA PIPEDA / Law 25 GDPR (Cross-border) AI / Automation Governance
02

Assurance Readiness & Audit Prep

Assurance

Facing an audit, a customer security questionnaire, or a regulatory review? Proxim's assurance readiness service prepares your organization to perform confidently — not just pass, but demonstrate a mature, sustainable assurance posture that wins customer trust and opens enterprise doors.

We specialize in helping SMBs achieve the certifications and assurance status that expand market access. This includes deep support for the commercial moments that matter most — contract reviews and security questionnaires that directly affect your ability to close deals.

  • Pre-audit gap assessment and remediation roadmap
  • Policy suite development (information security, acceptable use, privacy)
  • Evidence collection and documentation organization
  • Security awareness training programme design
  • Cloud security posture review (AWS, Azure, GCP)
  • Continuous controls monitoring (CCM) programme design
📄 Contract & Security Reviews
  • Review customer and vendor agreements for hidden security obligations
  • Identify privacy and security risks before you sign
  • Strengthen your negotiation position with informed security language
📋 Security Questionnaires & RFPs
  • Complete client security questionnaires accurately and efficiently
  • Respond to enterprise due diligence requests with confidence
  • Improve win rates with enterprise customers through assurance credibility
SOC 2 ISO 27001 HIPAA Cloud-Native Assurance-as-Code Contract Review Security RFPs
03

Business Advisory & Strategy

Advisory

Behind every assurance challenge is a business challenge. Proxim's advisory practice goes beyond security frameworks to address the strategic and operational questions that founders and leadership teams face at every stage of growth.

Drawing on doctoral-level business administration training and extensive executive experience, the principal advisor brings an evidence-based approach to strategy, governance, and operations for growing businesses.

  • Business model review and strategic planning
  • Corporate governance structure and board-readiness
  • Operational risk identification and mitigation
  • Investor-readiness and due diligence preparation
  • Technology strategy and digital transformation advisory
  • Fractional advisor / virtual CISO engagements
DBA-Grounded Startup & SMB Focus BC Business Law Healthcare Sector Technology Industry
04

Risk Management Programmes

Risk

Risk management is the backbone of a resilient organization. Without a structured programme, risk decisions are made ad hoc, inconsistently, and often too late. Proxim designs pragmatic risk management programmes that give your leadership team visibility and control.

We build risk frameworks that are proportionate to your size — rigorous enough to satisfy external scrutiny, practical enough for a lean team to maintain.

  • Enterprise risk register design and population
  • Information security risk assessments (qualitative & quantitative)
  • Third-party / vendor risk programme design
  • Business continuity and disaster recovery planning
  • Incident response plan development
  • Risk reporting dashboards and executive communication
ISO 31000 NIST RMF FAIR Model MITRE ATT&CK

Engagement models

Every business is different. Choose the engagement model that fits your needs and budget — or combine them.

Project

Fixed-Scope Engagements

Defined deliverable, timeline, and fee. Ideal for gap assessments, policy suites, and audit prep projects.

Retainer

Ongoing Advisory

Monthly advisory hours for businesses that need consistent access to a trusted GRC and assurance advisor.

vCISO

Virtual CISO

Fractional Chief Information Security Officer — strategic security leadership without a full-time hire.

Not sure which service you need?

Book a free 30-minute discovery call. We'll listen, ask the right questions, and tell you plainly what will move the needle for your business.

Let's talk about your business.

Every engagement starts with a conversation. Book a free 30-minute discovery call — no obligation, no sales pitch. Just an honest conversation about where you are and where you want to be.

Location

British Columbia, Canada

Service Area

Remote & in-person

Response Time

Within 1 business day

Discovery Call Includes
  • Review of your current assurance & risk posture
  • Identification of your most pressing gaps
  • Recommended next steps — no obligation
  • 1 hour, fully confidential, free of charge
Book a Discovery Call

Submissions are delivered to hello@proximadvisory.ca. Your information is kept strictly confidential; we respond within 1 business day.

✦ Message received — we'll be in touch within 1 business day.