A Canadian management consulting firm engaged LeakTrace to document its client data handling posture as substantiating material for a proposal to a public sector procurement that had introduced cyber posture attestation requirements. The engagement produced the reference material the firm's counsel used to substantiate the attestation.
Engagement origin
The firm operates a mid-market management consulting practice with approximately forty consultants across two Canadian provinces, serving corporate and public sector clients. The firm was preparing a proposal for a public sector procurement that had introduced a cyber posture attestation requirement referencing the Directive on Service and Digital and the current Treasury Board Secretariat cyber posture expectations. The firm's counsel engaged LeakTrace to produce documented substantiating material for the attestation.
Discovery scope
LeakTrace conducted an external attack surface audit covering the firm's registered domain, consultant email patterns, public directory records, and vendor mapping. The audit was formatted specifically to substantiate the attestation categories in the procurement requirement: authentication posture, business email authentication, vendor management, and public disclosure discipline.
Findings summary
- Consultant credential exposure. Multiple consultant email addresses appeared in monitored breach databases. Reuse patterns extended into the firm's project management and document collaboration platforms.
- Business email authentication. The firm's Sender Policy Framework and Domain-based Message Authentication configuration met the current baseline but required minor adjustment to substantiate the attestation.
- Client-adjacent disclosure. The firm's public case-study content referenced client engagements at a level of detail that would allow a targeting actor to construct client-adjacent pretexts. The attestation required documented review of public content against pretext risk.
- Vendor concentration. DNS records disclosed the firm's outsourced information-technology provider and document collaboration platform. Both had documented business relationships in the firm's vendor management records, but the risk registration had not been reviewed against the attestation categories.
Firm actions
The firm executed a remediation program in the three weeks preceding proposal submission. Consultant credentials were rotated and multi-factor authentication was enforced on all client-facing platforms. Sender Policy Framework and Domain-based Message Authentication were revised. Public case-study content was reviewed and adjusted with counsel to reduce pretext-relevant disclosure. Vendor management records were revised to reference the attestation categories.
Outcome
The firm's proposal was accepted for the procurement's next stage. The cyber attestation was substantiated by the LeakTrace baseline as reference material. The firm subsequently retained LeakTrace for annual pre-proposal baseline refreshes tied to major public sector procurement cycles.
All findings were derived from public and monitored sources only. No portion of this engagement required access to the firm's internal systems, any client record, or coordination with any threat actor. Attestation substantiation was executed by the firm's counsel with the LeakTrace baseline as reference material. This case file documents the pattern of pre-proposal cyber attestation engagements LeakTrace conducts with Canadian management consulting firms, and is not attributed to the specific firm, procurement, or clients referenced.