Canada

SOC onboarding built for Canada.

Client-ready onboarding packs for Canadian MSPs and security teams: Sentinel-first, mapped to PIPEDA, Quebec Law 25 and OSFI B-13, priced in Canadian dollars.

The SIEM platforms we onboard to here

Blueprint generates the full onboarding pack in each platform's own vocabulary - sources, runbooks, detection priorities and validation steps. These are the platforms we see most in this market.

Microsoft Sentinel
Native first-party connectors for the entire Microsoft estate
Splunk Enterprise Security
Roughly 46 percent market share, the largest community and integration ecosystem
CrowdStrike Falcon Next-Gen SIEM
Very strong where Falcon EDR is already deployed
Elastic Security
Node-based pricing decouples cost from data volume
Migrating off QRadar?
Palo Alto Networks acquired IBM's QRadar SaaS business in late 2024, and 2026 is the year most QRadar estates pick their migration path. Blueprint treats QRadar as a migration source: it generates the complete onboarding pack for your target platform, in that platform's own terms.

The security stack we document

Source runbooks are generated per vendor. The global core is always available; vendors with real share in this market are included by default.

Identity
Microsoft Entra ID
Okta
Google Workspace
Active Directory (on-premises)
JumpCloud
Duo
Ping Identity
Endpoint
Microsoft Defender for Endpoint
CrowdStrike
SentinelOne
Sophos
ESET
Trend Micro
Bitdefender
Huntress
Email
Microsoft 365
Google Workspace
Mimecast
Proofpoint
Barracuda
Network Perimeter
Palo Alto
Fortinet
Check Point
Cisco
Juniper
Sophos
WatchGuard
SonicWall
Network Internal
DNS query logs
DHCP logs
Zscaler
Netskope
Cisco Umbrella
Cloud Control Plane
Microsoft Azure
Amazon Web Services
Google Cloud Platform
Vulnerability
Tenable
Qualys
Rapid7
OpenVAS
Microsoft Defender Vulnerability Management
Backup
Veeam
Acronis
Datto
Rubrik
Commvault
Saas Audit
Salesforce
ServiceNow
Atlassian
Slack
Zoom
Telus Health
Ceridian
Data Protection
Microsoft Purview
Forcepoint
Netskope
Ot Ics
OSIsoft PI Historian
Honeywell
Siemens
Rockwell Automation
Schneider Electric
Claroty
Nozomi Networks
Dragos
Change Management
Microsoft Intune
Jamf
Ansible
Puppet

Collectors and gateways

Where logs cannot go straight to the platform, the pack covers the collector layer:

Bindplane
Cribl Stream
NXLog Platform
Vector
Fluent Bit and Fluentd
OpenTelemetry Collector

Frameworks and regulation

Every pack maps onboarding evidence against the frameworks that matter in this market.

PIPEDA
Quebec Law 25
BC PIPA
AB PIPA
CCSPA
OSFI Guideline B-13
PHIPA
CASL
ITSG-33
CCCS Medium Cloud Security Profile
ISO/IEC 27001
ISO/IEC 27017
ISO/IEC 27018
ISO 22301
SOC 2
PCI DSS
CIS Controls
NIST CSF
MITRE ATT&CK
IEC 62443
SWIFT CSP
CSA STAR

Statutory notification deadlines

TriggerDeadlineReport to
Breach of security safeguards with real risk of significant harmAs soon as feasibleOPC and affected individuals
High or critical severity technology or cyber incident72 hoursOSFI
Cyber security incident at a designated operatorPrescribed timelines under CCSPACanadian Centre for Cyber Security
Confidentiality incident presenting risk of serious injuryWith diligenceCAI and affected individuals

Regulators

  • OPC - Federal privacy, PIPEDA enforcement
  • CCCS - National cyber security authority and CCSPA incident reporting point
  • OSFI - Federally regulated financial institutions
  • CAI - Quebec privacy supervision under Law 25
Regulation guide

Partner with us

Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. We are looking for our first delivery partner in Canada.

Apply as a partner