Defend · Service 02

Cyber security

Controls that are configured, documented and evidenced, so an auditor, an insurer or a client's risk team can verify them for themselves.

Analysts reviewing security alerts on screen in a darkened operations room
The position

Buying the tool is the cheap part

Almost every organisation we assess already owns most of the licences it needs. Microsoft 365 Business Premium alone includes conditional access, Defender, Intune and data loss prevention. In roughly nine assessments out of ten, the gap is a product nobody finished configuring.

Conditional access policies in report-only mode two years after deployment. Legacy authentication still enabled for one application that was decommissioned in 2023. Global administrator accounts without MFA because enabling it once broke a script.

We start with what you already own, finish the configuration, document it, and only then talk about buying anything. It is a less profitable opening move for us and a considerably more honest one.

Coverage

Seven domains, assessed and hardened in order

Sequenced by how attacks actually start. Identity first, because that is where the overwhelming majority of Australian incidents begin.

The seven domains, in the order we harden them The order follows how attacks start. The main controls in each domain are shown here; each one is set out in full below.
  1. Identity & accessWhere most Australian incidents begin
    • Phishing-resistant MFA
    • Conditional access enforced
    • Legacy authentication blocked
    • Privileged accounts separated
  2. Email & collaborationWhere a compromise most often becomes a fraud loss
    • SPF, DKIM and DMARC
    • Impersonation protection
    • Safe links
    • Auto-forwarding restricted
  3. Endpoint
    • EDR
    • Application control
    • Local admin removed
    • Disk encryption
  4. Network & perimeter
    • Firewall review
    • Segmentation
    • Remote access behind MFA
    • External attack surface
  5. Data
    • Sensitivity labels
    • Sharing controls
    • Data loss prevention
  6. People
    • Simulated phishing
    • Role-based training
    • One-click reporting
  7. Governance
    • Policies
    • Incident response plan
    • Continuity plan
    • Risk register
Identity & access
Entra ID hardening: phishing-resistant MFA, conditional access moved from report-only to enforced, legacy authentication blocked, privileged accounts separated from daily accounts, break-glass accounts documented and monitored, and guest access reviewed on a schedule.
Email & collaboration
SPF, DKIM and DMARC published and enforced, anti-phishing and impersonation protection tuned to your executive names, safe links and attachments, external sender marking, and auto-forwarding restricted — the single control that most often turns a compromise into a fraud loss.
Endpoint
EDR deployed and tuned, application control where it is workable, local administrator rights removed with a managed elevation path, disk encryption enforced and evidenced, and USB and removable media policy applied.
Network & perimeter
Firewall rule review and cleanup, segmentation between corporate, guest and operational networks, remote access consolidated behind MFA, external attack surface enumerated, and firmware kept current on the devices most people forget.
Data
Where your sensitive data actually lives, who can reach it, sensitivity labelling where it earns its keep, sharing controls in SharePoint and OneDrive, and data loss prevention rules tested against realistic scenarios.
People
Simulated phishing that measures behaviour on a blame-free basis, short role-based training, and a reporting path that takes one click — because a staff member who reports quickly is worth more than one who never clicks.
Governance
The written artefacts: information security policy, acceptable use, access control, incident response plan, business continuity plan, and a risk register that names owners and review dates. Each one drafted to fit your organisation.
The difference

Security you can hand to somebody else

Sooner or later you will be asked to prove your controls — by a cyber insurer at renewal, a client's procurement team, an auditor, or a board that has read the news. Everything we deploy is built to survive that request.

  • A control register mapping each control to the Essential Eight strategy and maturity level it supports.
  • Configuration evidence — exported policy states, pulled directly from each platform.
  • A monthly posture report showing what changed, what drifted and what was remediated.
  • Insurer questionnaire support. We complete the technical sections and stand behind the answers.
  • Client due-diligence responses prepared once and reused, so the next tender starts with the answers already written.
  • An incident response plan that names people, phone numbers and decision authority — and is tested annually.
Standards

Aligned to what Australia actually asks for

We work to the frameworks your regulators, insurers and customers reference — and we will tell you which ones you can safely ignore.

ASD Essential Eight

The baseline. Assessed, uplifted and reported against maturity levels 1 to 3.

Privacy Act & NDB

Australian Privacy Principles and the Notifiable Data Breaches scheme, including breach assessment procedure.

ISO/IEC 27001

Readiness work and control implementation where certification is a commercial requirement.

SMB1001 & sector schemes

Tiered certification for smaller organisations, plus industry schemes where your customers demand them.

Questions

What people ask

Does company size make us less of a target?

Size has little to do with it. Most incidents start with a credential that appeared in a breach dump, a mailbox with auto-forwarding enabled, or an internet-facing service that was scanned by something automated at 3am. Almost none of it is personal, which is precisely why organisation size offers so little protection.

Will hardening break things for our staff?

Some of it will, if it is done carelessly. We stage every change: pilot group, report-only mode where the platform supports it, a documented rollback, and a communication to affected users before enforcement. The controls that cause the most friction — removing local admin, blocking legacy authentication — get the longest runway.

Do you do penetration testing?

An independent tester performs it, and we coordinate. A provider that tests its own configuration work is grading its own homework. We scope the engagement, manage the tester, and own the remediation of what comes back.

Can you work alongside our existing IT team?

Frequently, and it is often the better arrangement. An internal team that knows the business paired with a security practice that lives in the tooling daily. We agree a written split of responsibilities so every task has a named owner.

Find out where you actually stand

A baseline assessment scores every control, names the gaps and costs the fix. A fixed fee, and the report is yours to keep.