Investor briefing — HackFirstAid Group

Cyber first aid for the people technology forgot.

We're building the global Centre of Excellence for personal cyber response — headquartered in Nova Scotia, Canada. B2B cybersecurity subscriptions fund an always-answered first responder for the individual victim — triage is free, recovery is fairly priced, and no one is turned away.

Founder-led from Halifax, Nova Scotia · Capital matched to BDC's full financing menu — senior debt plus a BDC Capital-led equity round, co-invested by Invest Nova Scotia.

Last updated 8 July 2026

12

audience sites live, one shared response backbone

3

paying customers across 2 verticals

CA$240k+

ARR

Detailed traction and pipeline are in the data room.

The problem

There is no 911 for cyber.

When a person gets hacked, there is no one to call. Identity theft, account takeover, romance fraud, sextortion, deepfake grandparent scams, ransomware on a family laptop — these are personal emergencies with no first responder.
$704M+

reported fraud losses in Canada in 2025 (CAFC estimates this is 5–10% of actual).

290%

increase in reported fraud losses in Canada, 2020→2024 (CAFC).

$21,604

average loss per victim aged 60+, who account for ~40% of reported losses (CAFC, 2024).

These are real people, they are alone, and the gap is widening every year.

The gap

Where does a person go?

Police
Take a report, no recovery action.
Their bank
Freezes accounts, won't recover identity.
Their telco
Resets the SIM, damage already done.
Antivirus vendor
Sells a subscription, no human responder.
Family IT person
Means well, out of their depth.
Cyber-insurance
If they have it, for the corporation only.

There is no first responder for the individual cyber victim. Not in Canada. Not anywhere. This is the gap we're closing.

Enterprises have CrowdStrike. Governments have CSE. The wealthy hire boutiques at ~CA$1,200/hour. Everyone else gets a pamphlet and a phone tree.

The same gap has a second face

The cyber industry is priced, built, and sold for large enterprises. Small medical offices, towns, schools, small law firms, and SMBs have no CISO, no SOC, and no security staff — enterprise vendors won't return their call, and horizontal awareness training sells generic modules, not readiness tied to their regulation. Yet insurers and regulators now demand proof anyway. That's why the funding model is ten underserved verticals: the same market failure, the organizational face.

The industry is built for enterprises. HackFirstAid is built for everyone else.

The solution

Mission at the centre, funding model around it.

The mission

Individuals & Families

hackfirstaid.com

  • 24/7 hotline staffed by trained cyber responders
  • Identity-recovery & account-takeover triage
  • Sextortion / romance-fraud crisis support
  • Plain-language recovery playbooks
  • Priced for households, not corporations
  • Free triage, 24/7 — you never pay to be heard.
  • Flat, published recovery pricing. A hardship floor for those who can't pay.
The funding model

Ten B2B verticals fund the mission.

SMBMunicipalitiesK-12MedicalLaw FirmsBoardsLeadershipIT TeamsPension AdministratorsFamily Offices

See the twelve-property family.

flywheel

The HackFirstAid flywheel

  1. 1
    B2B subscriptions
    10 verticals fund the free 911: triage + the hardship floor
  2. 2
    Always-answered free triage
    no one pays to be heard, no one is turned away
  3. 3
    Trust converts
    paid recovery at flat, published prices (~70% margin, self-funding) + optional monitoring subscriptions
  4. 4
    Individuals feed back
    referrals, household upsell, B2B credibility → back to 1

B2B funds the free 911 → trust converts to fairly-priced recovery → both scale the mission.

Why now

Four converging forces.

01

AI now industrializes attacks on individuals.

Voice-cloning scams, deepfake CEOs, romance-fraud chatbots, LLM-written sextortion. The cost to attack one person has collapsed; the cost to defend has not.

02

Personal-fraud losses are exploding.

Reported Canadian losses hit $704M+ in 2025, up 290% in four years. CAFC says reported losses are 5–10% of actual — real exposure likely $7–14B annually.

03

Regulation is creating victims faster than responders.

Breach-notification laws (Canada's PIPEDA, US state laws) surface millions of individual victims a year; anti-fraud and scam-reporting mandates acknowledge the harm — but none of them fund a responder for the person. The infrastructure for personal response still doesn't exist.

04

The funding mandate is wide open.

BDC — Canada's bank for entrepreneurs — finances tech SMEs across a full menu: an ARR-adapted Loan for Tech Companies, Working Capital and Technology Financing for the build, low-dilution Growth & Transition Capital to scale, and BDC Capital venture investment — with cybersecurity also a named priority sector of BDC's $4B Defence Platform. Invest Nova Scotia's venture fund co-invests alongside lead investors in high-growth NS knowledge-economy companies — exactly these jobs. We match each instrument to the phase it's designed for, rather than leaning on any single program.

The business model

A billable individual line, with a B2B-funded safety net.

Triage is always free and B2B-funded. Hands-on recovery is billable at flat, published rates. Monitoring is an optional subscription. And a hardship floor — also B2B-funded — keeps recovery open to people who can't pay.
Essentials
≈ CA$6,600
/ yr

Self-serve training, quarterly briefings, IR templates.

Standard
≈ CA$33,000
/ yr

Cohort coaching, live IR coverage, board reporting.

Strategic
≈ CA$82,000
/ yr

Named vCISO, custom tabletops, regulator-grade documentation.

Anchors apply to Boards, Leadership, IT Teams, and Law Firms — shown in CAD, approximate; exact list pricing on each vertical site (USD list: $4,800 / $24,000 / $60,000). SMB and Medical use volume-priced annual seats; Municipalities and K-12 use sealed multi-year contracts.

80%+ gross marginARR-first~12-month average contract3–6× LTV/CAC target
The cross-subsidy, in one line

Every CA$10,000 of B2B ARR underwrites a modeled ~23 free-triage contacts plus ~3 hardship recoveries — while paid recovery self-funds. B2B funds the free 911 and the safety net, not a meter.

Paid recovery (~70% margin) self-funds; the earmark stretches across free triage + a capped hardship floor. Full unit economics in the data room.

How a human service keeps software-grade margins.

A 24/7 human responder sounds like a services business. It isn't run like one. Three things hold the margin:

01
Subscription, not hourly

Customers pay an annual ARR fee for readiness plus a defined response entitlement — recurring and predictable, not billed by the hour.

02
AI-assisted, human-escalated triage

Most contacts resolve through guided playbooks and automated triage; a trained responder is escalated to only when the case needs one. Headcount scales sub-linearly with volume.

03
A reusable playbook library

Every incident type is already documented, so response is execution against owned IP — not bespoke consulting each time.

The result: a human-trust product on a software cost curve — 80%+ gross margin at the B2B layer, with the individual line now carrying its own ~70% gross margin — and a B2B-funded floor that keeps it open to everyone. The human-vs-automated mix and full unit economics are in the data room.

How we price help

Free triage, always answered · Flat, published pricing · No surge, no hourly · No cold outreach to victims · A hardship floor — no one turned away.

Live traction metrics, financial model, and pipeline are available in the data room. Request access →
Market

Market sizing is directional; full model in the data room.

TAM
~$28B CAD

Personal + SMB cyber, blended (2027).

SAM
~$7B CAD

Canada + US underserved core.

Year-5 revenue target
~$28M CAD

Year-5 revenue target from the NS-based national capability + select US footprint — the beachhead, not the ceiling. Full bottom-up model in the data room.

A personal-cyber market this large does not yet have a category leader.

Competitive landscape
Capability
Enterprise tools
(CrowdStrike)
Consumer AV / ID
(Norton, LifeLock)
Consultants
(Big 4 / IR boutiques)
HackFirstAid
The category
Human responder for the victimPartial
Built for individualsPartial
Crisis response (not just prevention)
Funding model serves the mission
Canadian / NS presencePartial

The only category-defining response capability built for the individual victim.

The moat

Why this compounds — advantages a competitor can't buy quickly.

A response-playbook library, already built.

Hundreds of incident playbooks across consumer and ten B2B verticals — the institutional knowledge of how to recover a victim, productized. Every case sharpens it; a new entrant starts from zero.

The Household retention engine.

Free with any paid plan, the Household layer puts the whole family — spouse, kids — inside the product: the stickiest possible relationship and a built-in referral surface. Retention is the moat in subscription businesses; this is ours.

AtlSecCon — a channel a startup can't build.

A founder-owned security conference — one of Canada's longest-running: a standing, trusted channel into the exact buyers (IT, boards, government, MSPs) the verticals sell to.

Each turn of the flywheel deepens all three. The IP inventory and channel metrics are in the data room.

The vision

Make Nova Scotia the global Centre of Excellence for combating personal cyber compromise.

Public-safety DNA

JRCC Halifax, RCMP H-Division — Atlantic Canada has run national response for decades.

Right-sized to execute

Dalhousie, NSCC, Saint Mary's talent pipeline — deep, accessible, and loyal.

Provincial appetite

Cyber is a stated NS priority; Invest NS aligned with knowledge-economy growth.

Bridge to US + Europe

Atlantic time zone, bilingual, Five-Eyes jurisdiction.

Five-year outcome: Nova Scotia = where personal cyber gets solved.

Nova Scotia hiring plan

40 net-new NS jobs in 12 months.

3
Today
12
Q1
22
Q2
32
Q3
40
Q4

Where the 40 go

  • Personal-response specialists12
  • B2B sales & success12
  • Delivery / vCISO pod6
  • Content & vertical leads5
  • Engineering & product5

Use of funds (12 mo)

  • Talent / NS payroll65%
  • Go-to-market15%
  • Product & content12%
  • Working capital & reserves8%
Capital → milestones → value inflection
  1. Close
  2. 40 NS jobs
  3. CA$1.0–1.5M ARR run-rate
  4. Operating-basis profitability
  5. Series A-ready
Government-track impact
40
net-new NS jobs
~10,000
individual victims served / yr
~$25M
estimated NS GDP contribution over 5 yrs

Victim and GDP figures are directional pending NS-Invest validation.

12 of the 40 are personal-response specialists — the front line of the mission. Exactly the high-value job creation Invest Nova Scotia's venture mandate backs.

Sales and the response line are co-largest — the ARR engine and the mission front line.

Team

Founded in Nova Scotia by a cyber operator embedded in the community.

A short message from Travis.

Travis Barlow

Founder & CEO
LinkedIn →

25+ years in incident response, 580+ engagements, founder of AtlSecCon — the Atlantic Security Conference, one of Canada's longest-running independent cyber conferences. Halifax, Nova Scotia.

Why now, why me: 25 years inside Atlantic Canada's incident-response and security community, and the convening network (AtlSecCon) to staff and scale a Nova Scotia response capability others can't.

Dalhousie / NSCC / Saint Mary's talent pipelineAtlSecCon networkGovernment alignmentAtlantic time zone + bilingual bridge

Full founder background and the early-team plan are in the data room.

An advisory bench across IR, insurance, and public-sector procurement is detailed in the data room.

Investor FAQ

The questions investors ask, answered.

Isn't a 24/7 human hotline a low-margin services business?

No. Subscription not hourly + AI-assisted, human-escalated triage + a reusable playbook library = software-grade margins. 80%+ gross margin at the B2B layer; the individual line now carries its own ~70% gross margin, with a B2B-funded triage and hardship floor on top. Full mix in the data room.

Is there enough senior security talent in Nova Scotia?

Yes. Dalhousie / NSCC / Saint Mary's pipeline + the AtlSecCon network + a 30–40% cost advantage versus Toronto / Waterloo make a 40-person NS build realistic.

Doesn't the subsidized consumer arm drag overall margin?

No — it's now a billable line at ~70% gross margin, not a cost centre. B2B funds only the free triage and a capped hardship floor. The consumer line contributes margin and reaches more people.

Aren't you charging victims in crisis? Isn't that ambulance-chasing?

No. Triage is free and always answered — you never pay to be heard. Recovery is billed only after you're stabilized, at flat, published, capped prices — never surge pricing, never hourly. We don't cold-solicit victims or buy breach lists; demand is inbound and referral. And a hardship floor means no one who can't pay is turned away. See How we price help.

What if regulation stalls?

Demand is fraud-volume- and contract-driven, not statute-dependent. Breach-notification laws surface victims, but the thesis holds even if new regulation slips.

Why now, why you?

AI-scaled fraud is the convergence — and a founder with the IR record (25+ years, 580+ engagements) and the channel (AtlSecCon) to execute is the rare combination needed to staff and scale a national-grade NS capability.

What happens if it's only you?

It isn't designed to be. The playbook library productizes the response knowledge so delivery doesn't route through the founder; 12 of the first 40 hires are responders and 6 are the delivery/vCISO pod; and the advisory bench and early-team plan are in the data room.

For investors

Two tracks, one mission.

We're assembling a blended round — BDC senior debt, a priced equity round led by BDC Capital, and Invest Nova Scotia's venture capital fund co-investing alongside the lead — sized to the 40-job, 12-month Nova Scotia build-out. Exact amounts and terms are in the data room.
Track 1

Strategic & government capital

BDC + Invest Nova Scotia

We map each BDC instrument to the phase it's built for — not a single program.

  1. Build (now)

    Loan for Tech Companies (financing structured around recurring revenue, not hard assets) + Working Capital Loan + Technology Financing → funds the 12-month, 40-job Nova Scotia build-out and platform.

  2. Equity lead (now)

    BDC Capital venture investment leads the priced equity round — with cybersecurity also a named priority sector of BDC's $4B Defence Platform as later dual-use upside.

  3. Provincial equity (now)

    Invest Nova Scotia's venture capital fund co-invests alongside the BDC Capital lead — plus provincial flagship co-marketing.

  4. Scale

    BDC Capital · Growth & Transition Capital (quasi-equity / subordinated debt; growth capital with minimal dilution) → layered on a proven ARR base.

Request the data room
Track 2

Private & strategic investors — future rounds

Angels / VC / strategic

  1. Stage

    The current round is BDC debt plus a BDC Capital-led equity round with Invest Nova Scotia co-investing. Private and strategic investors: register interest now for the Series A via the data-room form.

  2. Instrument

    Equity in the group holdco at the Series A — alongside institutional holders already on the cap table.

  3. The opportunity

    Category creation in personal cyber response; ARR-first B2B engine at 80%+ gross margin; NS cost structure 30–40% below Toronto / Waterloo.

  4. Return logic

    Series A optionality at Year 2 on operating-basis profitability.

  5. Exit logic

    A natural tuck-in for telcos, insurers, banks, and identity / security incumbents extending into the household — a strategic-acquirer set that doesn't exist for an hourly consultancy. Strategic optionality beyond Series A.

Request the data room
What has to be true

And how we're de-risking it.

Risk
Consumer acquisition cost.
Mitigation

Personal-cyber CAC can be high. The B2B verticals, the Household add-on, and the AtlSecCon channel acquire individuals at near-zero marginal cost (employees, board members, families) — we don't buy consumer demand cold.

Risk
Staffing a 24/7 responder pool in Nova Scotia.
Mitigation

AI-assisted triage caps headcount growth; the Dalhousie / NSCC / Saint Mary's pipeline and the AtlSecCon network feed hiring; Invest Nova Scotia's venture mandate backs the high-value job creation.

Risk
Cross-subsidy durability.
Mitigation

The individual mission is sized to a defined share of B2B ARR — not an open-ended cost — so it flexes with the funded base.

Risk
Regulatory dependence.
Mitigation

Demand is driven by fraud volume and client / contract requirements, not any single statute; the thesis holds even if regulation stalls.

We'd rather name these than paper over them. The full risk register and mitigations are in the data room.

The gate

Request the investor data room.

The data room contains live ARR and traction, the full financial model and pipeline, the capital ask, cap table, and founder background. Access is granted to qualified investors and funding partners.

Used only to evaluate and respond to your request. Never shared, never added to a marketing list.

Travis reviews every request personally.

What you'll receive

  • • Live ARR and customer traction
  • • Full financial model and pipeline
  • • Capital ask, cap table, and use-of-funds detail
  • • Founder background and early-team plan
  • • LOIs and signed engagements
The HackFirstAid family

One cyber-readiness stack. Twelve audiences.

One mission, twelve front doors. The investor briefing covers the whole stack — personal, SMB, medical, municipal, K-12, boards, executive leadership, IT practitioners, law firms, pension administrators, family offices, and households.
Individuals & Families

Plain-language cyber first aid for your household — phones, accounts, identity, and family devices.

Visit
Small & Mid-sized Business

Incident triage and readiness for SMBs without a security team — ransomware, BEC, vendor breaches.

Visit
Municipalities

First-hour playbooks for towns, cities, and utilities — built around public-service continuity.

Visit
K-12 Districts

Calm K-12 incident response — SIS outages, family communication, FERPA, and trustee hand-off.

Visit
Small Medical Practices

HIPAA, OCR, and cyber-insurer response for 1–25 provider clinics — at small-business staffing levels.

Visit
Boards & Trustees

Governance oversight: the questions to ask management before, during, and after an incident.

Visit
Executive Leadership

Cyber readiness for the officers who sign for it — accountability, disclosure, and crisis posture.

Visit
IT Teams & MSPs

Defender and Multiplier tracks for internal IT practitioners and managed-service providers.

Visit
Law Firms

First-hour incident response for small and mid-sized firms: trust-account wire fraud, client-confidentiality breaches, and OCG security questionnaires.

Visit
Pension Administrators

Cyber readiness for pension and benefit plan administrators — member-data protection, fiduciary oversight, and third-party administrator risk.

Visit
Family Offices

Discreet cyber readiness for single- and multi-family offices — principal protection, wire-fraud interception, and household staff hygiene.

Visit
Households

The whole family inside the product — spouse, kids, and staff. Free with any paid plan, with upgrade tiers for higher-exposure households.

Visit

Partner with us to build the global Centre of Excellence for personal cyber response.