Cyber security
Controls that are configured, documented and evidenced, so an auditor, an insurer or a client's risk team can verify them for themselves.
Buying the tool is the cheap part
Almost every organisation we assess already owns most of the licences it needs. Microsoft 365 Business Premium alone includes conditional access, Defender, Intune and data loss prevention. In roughly nine assessments out of ten, the gap is a product nobody finished configuring.
Conditional access policies in report-only mode two years after deployment. Legacy authentication still enabled for one application that was decommissioned in 2023. Global administrator accounts without MFA because enabling it once broke a script.
We start with what you already own, finish the configuration, document it, and only then talk about buying anything. It is a less profitable opening move for us and a considerably more honest one.
Seven domains, assessed and hardened in order
Sequenced by how attacks actually start. Identity first, because that is where the overwhelming majority of Australian incidents begin.
- Identity & accessWhere most Australian incidents begin
- Phishing-resistant MFA
- Conditional access enforced
- Legacy authentication blocked
- Privileged accounts separated
- Email & collaborationWhere a compromise most often becomes a fraud loss
- SPF, DKIM and DMARC
- Impersonation protection
- Safe links
- Auto-forwarding restricted
- Endpoint
- EDR
- Application control
- Local admin removed
- Disk encryption
- Network & perimeter
- Firewall review
- Segmentation
- Remote access behind MFA
- External attack surface
- Data
- Sensitivity labels
- Sharing controls
- Data loss prevention
- People
- Simulated phishing
- Role-based training
- One-click reporting
- Governance
- Policies
- Incident response plan
- Continuity plan
- Risk register
- Identity & access
- Entra ID hardening: phishing-resistant MFA, conditional access moved from report-only to enforced, legacy authentication blocked, privileged accounts separated from daily accounts, break-glass accounts documented and monitored, and guest access reviewed on a schedule.
- Email & collaboration
- SPF, DKIM and DMARC published and enforced, anti-phishing and impersonation protection tuned to your executive names, safe links and attachments, external sender marking, and auto-forwarding restricted — the single control that most often turns a compromise into a fraud loss.
- Endpoint
- EDR deployed and tuned, application control where it is workable, local administrator rights removed with a managed elevation path, disk encryption enforced and evidenced, and USB and removable media policy applied.
- Network & perimeter
- Firewall rule review and cleanup, segmentation between corporate, guest and operational networks, remote access consolidated behind MFA, external attack surface enumerated, and firmware kept current on the devices most people forget.
- Data
- Where your sensitive data actually lives, who can reach it, sensitivity labelling where it earns its keep, sharing controls in SharePoint and OneDrive, and data loss prevention rules tested against realistic scenarios.
- People
- Simulated phishing that measures behaviour on a blame-free basis, short role-based training, and a reporting path that takes one click — because a staff member who reports quickly is worth more than one who never clicks.
- Governance
- The written artefacts: information security policy, acceptable use, access control, incident response plan, business continuity plan, and a risk register that names owners and review dates. Each one drafted to fit your organisation.
Security you can hand to somebody else
Sooner or later you will be asked to prove your controls — by a cyber insurer at renewal, a client's procurement team, an auditor, or a board that has read the news. Everything we deploy is built to survive that request.
- A control register mapping each control to the Essential Eight strategy and maturity level it supports.
- Configuration evidence — exported policy states, pulled directly from each platform.
- A monthly posture report showing what changed, what drifted and what was remediated.
- Insurer questionnaire support. We complete the technical sections and stand behind the answers.
- Client due-diligence responses prepared once and reused, so the next tender starts with the answers already written.
- An incident response plan that names people, phone numbers and decision authority — and is tested annually.
Aligned to what Australia actually asks for
We work to the frameworks your regulators, insurers and customers reference — and we will tell you which ones you can safely ignore.
ASD Essential Eight
The baseline. Assessed, uplifted and reported against maturity levels 1 to 3.
Privacy Act & NDB
Australian Privacy Principles and the Notifiable Data Breaches scheme, including breach assessment procedure.
ISO/IEC 27001
Readiness work and control implementation where certification is a commercial requirement.
SMB1001 & sector schemes
Tiered certification for smaller organisations, plus industry schemes where your customers demand them.
What people ask
Does company size make us less of a target?
Size has little to do with it. Most incidents start with a credential that appeared in a breach dump, a mailbox with auto-forwarding enabled, or an internet-facing service that was scanned by something automated at 3am. Almost none of it is personal, which is precisely why organisation size offers so little protection.
Will hardening break things for our staff?
Some of it will, if it is done carelessly. We stage every change: pilot group, report-only mode where the platform supports it, a documented rollback, and a communication to affected users before enforcement. The controls that cause the most friction — removing local admin, blocking legacy authentication — get the longest runway.
Do you do penetration testing?
An independent tester performs it, and we coordinate. A provider that tests its own configuration work is grading its own homework. We scope the engagement, manage the tester, and own the remediation of what comes back.
Can you work alongside our existing IT team?
Frequently, and it is often the better arrangement. An internal team that knows the business paired with a security practice that lives in the tooling daily. We agree a written split of responsibilities so every task has a named owner.
Essential Eight
The measured version of this page — scored, costed and evidenced monthly.
ExploreDetection & response
Prevention fails eventually. This is who is watching when it does.
ExploreEndpoint & mobility
Controls only count on devices you actually manage. This is how they get there.
ExploreFind out where you actually stand
A baseline assessment scores every control, names the gaps and costs the fix. A fixed fee, and the report is yours to keep.