Regulated, distributed, or simply out of patience
Eighteen industries, and we are not a single-vertical specialist in any of them. What our clients share is an obligation they cannot delegate — to a regulator, an insurer, a client's risk team, or the people whose records they hold.
Where our clients actually come from
Ordered roughly by how often we are asked. Four of them carry a longer write-up further down the page — the rest we are happy to talk through on a call.
Professional services
Legal, accounting, financial advice and consulting. Client confidentiality is the product, and trust accounts make you a standing target for payment redirection fraud.
In depthHealth & allied health
General practice, dental, specialist clinics, physiotherapy and psychology. Health records are sensitive information under the Privacy Act, and clinical systems cannot be offline mid-session.
In depthAged care & disability
Residential aged care, home care and NDIS providers. A rostered casual workforce on shared devices, holding some of the most sensitive personal records anyone keeps.
Construction & trades
Builders, subcontractors and project managers. Devices get commissioned on sites with no signal, and drawings and variations end up moving through personal accounts.
In depthEngineering & architecture
CAD, BIM and Revit files large enough to punish a thin link and defeat a naive backup schedule. Intellectual property that can walk out with a departing engineer.
Government & councils
Local government and agencies carrying Essential Eight obligations, procurement rules and public-record retention that has to be implemented in the systems, not just written into a policy.
In depthNot-for-profit & community
Charities, peak bodies and member organisations. Volunteer turnover, grant-funded systems that arrive with no operating budget, and non-profit licensing most have never claimed.
In depthEducation & training
Independent schools, RTOs and early learning. Student data, BYO devices, and a network shared with people who are actively trying to get around it.
Financial services
Brokers, planners, funds and insurance. Client money moves on emailed instruction, which makes business email compromise your single largest exposure by a wide margin.
Manufacturing & industrial
The IT and OT boundary. Production systems running operating systems that cannot simply be patched, and downtime measured in lost output per hour.
Transport, logistics & warehousing
Rugged scanners, fleet telematics and warehouse management. Devices spend days out of coverage and still have to come back compliant and enrolled.
Wholesale & distribution
ERP and EDI links running into your trading partners, where an outage stops other people's businesses too, and pricing data is worth stealing.
Retail & hospitality
Multi-site point of sale, high seasonal staff turnover, card data obligations, and at least one venue where the server lives under the counter.
Real estate & property
Agencies, strata and property management. Trust accounts, fast staff turnover, and settlement payment redirection fraud that targets this sector specifically.
Mining, energy & resources
Remote sites on satellite links, contractor identities that have to be granted and revoked quickly, and critical infrastructure obligations where they apply.
Agriculture & agribusiness
Rural connectivity, a seasonal workforce that arrives and leaves in waves, and increasingly connected equipment that nobody has put on an asset register.
Media, marketing & creative
Very large files, freelancers who need access for six weeks and then must lose it, and client assets held under contractual confidentiality.
Sport, clubs & recreation
Licensed and gaming venues with member databases, regulator obligations, and technology decisions made by a volunteer committee.
Not listed? Most of what we do is sector-neutral. Tell us what you are obliged to protect and who asks you to prove it, and we will give you an honest answer about fit.
Professional services
Legal, accounting, financial advice, architecture and consulting. Client confidentiality is the product, and an hour of downtime is an hour nobody can bill.
What we see most
- Practice management and document management systems with no tested restore path.
- Trust account and payment processes exposed to business email compromise.
- Partners with local administrator rights and MFA exemptions dating back years.
- Client due-diligence questionnaires answered differently by different people.
What we do about it
- Payment verification controls and impersonation protection tuned to partner names.
- Restore testing on the practice management database, quarterly, with a measured RTO.
- Privileged access separated, with a managed elevation path that does not slow anyone down.
- A single maintained due-diligence response pack, so a tender takes hours instead of a fortnight.
Health & allied health
General practice, dental, specialist clinics, physiotherapy and psychology. You hold health records, which the Privacy Act treats as sensitive information — and clinical systems that cannot be offline during a session.
What we see most
- Shared clinical logins, because individual accounts were slower at the front desk.
- Practice software on a server that has not been patched since the vendor last visited.
- No documented breach assessment procedure, despite mandatory notification obligations.
- Backups running, restores never attempted.
What we do about it
- Individual identities with fast sign-in, so security and reception speed stop competing.
- Vendor-coordinated patching for clinical systems, with agreed windows outside sessions.
- A written NDB breach assessment procedure, tested in an annual tabletop exercise.
- Restore testing on clinical data with an RTO the practice has actually agreed to.
Construction & field services
Builders, trades, logistics, utilities and field maintenance. Your workforce is distributed by definition, often on shared or rugged devices, connecting from sites with no fixed infrastructure.
What we see most
- Devices that never enrolled because they were commissioned on a site with no signal.
- Shared tablets where sign-out does not clear the previous person's session.
- Project files on personal cloud accounts, because the sanctioned path was too slow.
- An asset register that lost touch with reality three refresh cycles ago.
What we do about it
- Staged provisioning before dispatch and enrolment profiles that tolerate long offline periods.
- Shared device mode, so sign-out genuinely ends the session.
- Mobile access to project data that is faster than the workaround, which is the only way it wins.
- A reconciled asset register, with device location and assignment kept current.
Government & not-for-profit
Local councils, agencies, community services, peak bodies and charities. Procurement rules, public accountability, constrained budgets, and genuine assurance requirements — usually all at once.
What we see most
- Essential Eight obligations without the budget or headcount to reach the target level.
- Grant-funded systems with no ongoing operational funding attached.
- Volunteer and casual access that is granted quickly and revoked slowly.
- Records management obligations met on paper and not in the systems.
What we do about it
- A maturity uplift plan sequenced to fit funding cycles, with the cost of each level stated.
- Non-profit licensing applied where you qualify — many organisations never claim it.
- Automated joiner, mover and leaver processes so revocation is not a manual memory test.
- Retention and disposition policy implemented in Microsoft 365, not just written down.
- Security cleared personnel available where an engagement requires them.
What every one of these sectors has in common
Different regulators, different systems, the same four failures. We look for these first regardless of what industry you are in.
- Identity is the front door, and it is usually the least defended thing in the environment.
- Backups exist; restores are theoretical. The gap between those two is where a bad week becomes a bad year.
- Nobody owns patching for the third-party applications that are not Windows and not Microsoft 365.
- The asset register and reality diverged at some point nobody can identify, and everything downstream inherits the error.
Not in one of these four
Most of what we do is sector-neutral. Tell us what you are obliged to protect and who asks you to prove it, and we will tell you honestly whether we are the right fit.