Cyber security
Controls that are configured, documented and evidenced — not a licence someone bought and a dashboard nobody opens. Built so an auditor, an insurer or a client's risk team can verify it.
Buying the tool is the cheap part
Almost every organisation we assess already owns most of the licences it needs. Microsoft 365 Business Premium alone includes conditional access, Defender, Intune and data loss prevention. In roughly nine assessments out of ten, the gap is not a missing product — it is a product nobody finished configuring.
Conditional access policies in report-only mode two years after deployment. Legacy authentication still enabled for one application that was decommissioned in 2023. Global administrator accounts without MFA because enabling it once broke a script.
We start with what you already own, finish the configuration, document it, and only then talk about buying anything. It is a less profitable opening move for us and a considerably more honest one.
Seven domains, assessed and hardened in order
Sequenced by how attacks actually start. Identity first, because that is where the overwhelming majority of Australian incidents begin.
- Identity & access
- Entra ID hardening: phishing-resistant MFA, conditional access enforced rather than reported, legacy authentication blocked, privileged accounts separated from daily accounts, break-glass accounts documented and monitored, and guest access reviewed on a schedule.
- Email & collaboration
- SPF, DKIM and DMARC published and enforced, anti-phishing and impersonation protection tuned to your executive names, safe links and attachments, external sender marking, and auto-forwarding restricted — the single control that most often turns a compromise into a fraud loss.
- Endpoint
- EDR deployed and tuned, application control where it is workable, local administrator rights removed with a managed elevation path, disk encryption enforced and evidenced, and USB and removable media policy applied.
- Network & perimeter
- Firewall rule review and cleanup, segmentation between corporate, guest and operational networks, remote access consolidated behind MFA, external attack surface enumerated, and firmware kept current on the devices most people forget.
- Data
- Where your sensitive data actually lives, who can reach it, sensitivity labelling where it earns its keep, sharing controls in SharePoint and OneDrive, and data loss prevention rules tested against realistic scenarios rather than defaults.
- People
- Simulated phishing that measures behaviour rather than punishing it, short role-based training, and a reporting path that takes one click — because a staff member who reports quickly is worth more than one who never clicks.
- Governance
- The written artefacts: information security policy, acceptable use, access control, incident response plan, business continuity plan, and a risk register that names owners and review dates. Drafted to fit your organisation, not downloaded.
Security you can hand to somebody else
Sooner or later you will be asked to prove your controls — by a cyber insurer at renewal, a client's procurement team, an auditor, or a board that has read the news. Everything we deploy is built to survive that request.
- A control register mapping each control to the Essential Eight strategy and maturity level it supports.
- Configuration evidence — exported policy states, not screenshots taken on a good day.
- A monthly posture report showing what changed, what drifted and what was remediated.
- Insurer questionnaire support. We complete the technical sections and stand behind the answers.
- Client due-diligence responses prepared once and reused, so a tender does not consume a fortnight.
- An incident response plan that names people, phone numbers and decision authority — and is tested annually.
Aligned to what Australia actually asks for
We work to the frameworks your regulators, insurers and customers reference — and we will tell you which ones you can safely ignore.
ASD Essential Eight
The baseline. Assessed, uplifted and reported against maturity levels 1 to 3.
Privacy Act & NDB
Australian Privacy Principles and the Notifiable Data Breaches scheme, including breach assessment procedure.
ISO/IEC 27001
Readiness work and control implementation where certification is a commercial requirement.
SMB1001 & sector schemes
Tiered certification for smaller organisations, plus industry schemes where your customers demand them.
What people ask
We are small. Are we actually a target?
You are not usually a target. You are usually a result — of a credential that appeared in a breach dump, a mailbox with auto-forwarding enabled, or an internet-facing service that was scanned by something automated at 3am. Almost none of it is personal, which is precisely why organisation size offers so little protection.
Will hardening break things for our staff?
Some of it will, if it is done carelessly. We stage every change: pilot group, report-only mode where the platform supports it, a documented rollback, and a communication to affected users before enforcement. The controls that cause the most friction — removing local admin, blocking legacy authentication — get the longest runway.
Do you do penetration testing?
We coordinate it with an independent tester rather than performing it ourselves. A provider that tests its own configuration work is grading its own homework. We scope the engagement, manage the tester, and own the remediation of what comes back.
Can you work alongside our existing IT team?
Frequently, and it is often the better arrangement. An internal team that knows the business paired with a security practice that lives in the tooling daily. We agree a written split of responsibilities so nothing sits in the gap between us.
Essential Eight
The measured version of this page — scored, costed and evidenced monthly.
ExploreDetection & response
Prevention fails eventually. This is who is watching when it does.
ExploreEndpoint & mobility
Controls only count on devices you actually manage. This is how they get there.
ExploreFind out where you actually stand
A baseline assessment scores every control, names the gaps and costs the fix. Two weeks, fixed fee, no obligation to continue.