Powered by Lavawall® — continuous visibility, smarter decisionsBill C-8 / CCSPC readiness for pipelines & utilitiesFree 30-minute consultation — book a time

Independent audits · Senior Tier 3 · Canadian-owned

Independent audits and senior security,
behind your IT.

Whoever runs your IT handles the day-to-day, and they're good at it. We're the senior security team behind them: independent, CISA-led audits that surface 200+ findings where a scan finds a handful, Tier 3 security, cloud, and IT support for the moment something's weird or an auditor shows up, and the Lavawall® platform watching all year. For lean IT departments, MSPs, and Canadian healthcare and accounting firms.

CISSP & CISA certified Canadian-owned, developed & hosted in Canada Builders of Lavawall® Founded 2006 · Headquartered in Canada since 2016
ThreeShield's Calgary-based leadership team — left to right, Angie Wisk, Chris Nowell, Saad Alfakir, and Tyson Jamison
ThreeShield's Calgary-based leadership team. Meet the team →

What we actually sell

You're not alone anymore.

When you leave for vacation, you worry. When you present to management, you worry. When the insurance renewal lands, when an auditor asks for evidence, when Microsoft changes something overnight, when a user says "something weird happened" — you worry, alone. Lavawall® watches while you're away, and ThreeShield picks up when it needs a human. You take real vacations. Weird things get a second set of senior eyes. That's the product.

Start where you are

Three ways to work with us

I run IT

Senior support behind your IT

You run IT day to day, and you're good at it. We're the senior security team behind you: independent audits, penetration tests and vulnerability assessments, PCI DSS and other compliance, and the people you call the moment something's weird or an auditor shows up.

For lean IT departments →

I run an MSP

White-label Tier 3, never a competitor

CISSP/CISA escalation under your brand, with written rules of engagement. We grew out of an MSP — we don't go around partners. Ever.

For MSPs & partners →

I run a clinic or accounting firm

Managed IT for medical & accounting firms

Our only direct managed-IT practice: healthcare and accounting firms in Calgary, Vancouver, and Kingston that want IT, security, and HIA/CPA compliance handled by one accountable team. Outside that niche, we refer you to a partner MSP.

For medical & accounting firms →

Why one partner

Stop paying three vendors to do one job.

Most organizations juggle a compliance platform, a consultant, an auditor, and a support provider — and nobody owns the overall outcome. ThreeShield delivers all four in one relationship, so findings actually get fixed.

Real audits, not checklist scans

CISA-led reviews using government and Fortune 50 methodology — typically 200+ findings where automated scans surface a handful.

Continuous visibility via Lavawall®

Patching, M365/Google breach detection, file monitoring, and GRC evidence — running all year, not just at audit time.

Hands-on remediation

We don't hand you a report and disappear. The team that found the problems fixes the critical ones with you.

Compliance that sticks

SOC 2, HIPAA, Alberta/BC HIA, PCI, NIST, CIS, CMMC, NERC CIP, CPA Canada — operationalized in your daily work, not binders on a shelf.

The platform behind the people

Lavawall®

Powered by Lavawall®

We built Lavawall® because the tools we audited kept missing what mattered. It patches 7,500+ applications, watches Microsoft 365 and Google Workspace for breaches, monitors your files, and automates compliance evidence — with our senior team watching the results. It's developed, hosted, and supported entirely in Canada.

How we work

From first look to year-round security

1. Free 30-minute consultation

A senior person, not a sales call — plus a free Lavawall® domain scan. If you need more, our comprehensive vulnerability assessments (our core service, typically 200+ findings) are scoped and quoted before any work starts.

2. Visibility in minutes

Lavawall® connects to endpoints, Microsoft 365, Google Workspace, and your domains — you see what we see.

3. Fix what matters

Deep audit if you need one; either way we prioritize and remediate the critical items with your team, not around them.

4. Stay strong year-round

Tier 3 escalations, compliance upkeep, and quarterly reviews — the platform watches continuously, and real people respond.

Client voices

Trusted from Main Street to Fortune 50

"They are hands on and proactive. Cyber security insurance providers have confirmed they have protected our business well. It's nice being able to sleep well at night."

Juliane — Calgary accounting firm

"As Chief Compliance Officer of a payments entity, I have relied on ThreeShield to provide risk-based solutions that have satisfied regulators and business partners alike."

Scott, CTO — Tilia Inc. (fintech & payments)

"In a short time, we accomplished what much larger companies still struggle to achieve — with minimal disruption to the engineering organization."

Brian, IT Security Director — Linden Lab

"Chris possesses the rare skill in security professionals of understanding broader business and technical demands... he skillfully avoids the dogmatic, prescriptive approach I've seen all too often and instead builds a security plan that genuinely strengthens the business."

Landon — VP Operations & Platform Engineering

"It is this proactive approach that ensured we had an open line of communication, and made me feel confident that reaching out with a question or concern would net me a direct and actionable response."

Debbi — Director of Customer Support

"ThreeShield went out of their way to get feedback on policies to make sure proposals balanced business needs... they really helped change the culture around security mindfulness in positive ways."

Tara — Sr. Director, Systems & Build Engineering

Experience across accounting, aerospace, fintech, government, healthcare, law, oil & gas, retail, and startups

A sample of the organizations we've served, assessed, or whose teams licensed our founder's tools:

1-Page ACE Project Marketing Affirm Chartered Accountants Alberta 2030 Commonwealth Games Avenge Energy Services Calgary Foothills Primary Care Network Carrier Corporation CAWST Cigar Place Citadel Drilling Collins Barrow Calgary LLP Commodity trading firms (confidential) Computer Sciences Corporation Deloitte Ear Candy Ernst & Young Encompass Medical Experts Escape Ops Financial advisors Fintech companies (confidential) First Gulf Bank Government of Alberta Hamilton Sundstrand Hurricane Computer Solutions IntelliView Technologies International Aero Engines I.T. Connex KPMG Linden Research (Linden Lab) Magtec Marda Loop Braces MTA Urban Design NASA NORESCO Otis Elevator Company Party Enterprises Plateau Systems Pratt & Whitney Precious metals (confidential) Red Link SA (Argentina) Sikorsky Aircraft Strut Creative Tech Fuel Tilia Inc. TOOT'n TOTUM Towers Watson United Technologies Universidade de São Paulo UTC Power Wealth 'N Tax Whitecap Resources YR Plans

As seen on  CBC News  ·  Global News  ·  BBB Accredited  ·  Calgary Chamber of Commerce member

Common questions

Before you call

We already have an MSP. Is this awkward?
Not at all — we work with and through MSPs every day, and much of our work arrives via MSP partners. Our only direct managed-IT practice is Calgary medical clinics and accounting firms; every other managed-IT inquiry is referred to a partner. Lavawall® complements existing RMM and EDR stacks, and our rules of engagement are written down and public.
How is this different from hiring a vCISO?
A vCISO gives you strategy without execution. ThreeShield gives you strategy, the platform, audit execution, compliance delivery, and hands-on support — for less than a single senior hire.
Do you only serve Calgary?
Fully managed IT is offered to healthcare and accounting firms in Calgary, Vancouver, and Kingston, Ontario. Cybersecurity, Tier 3 augmentation, vulnerability assessments, and compliance are delivered throughout Canada and the United States.

Where to find us

Ready to stop guessing about your security?

Free, no-obligation 30-minute consultation: we run a Lavawall® scan of your public-facing infrastructure, review your Microsoft 365 posture, and show you exactly where you stand — before you decide anything.

No credit card. No high-pressure sales. Same or next business day response.