Security work is easy to sell and hard to verify, which is why so much of it is neither. An assessment that produces a long list of findings without severity, evidence or a remediation path is not useful, and a remediation programme that cannot be independently checked afterwards is an act of faith. Everything we do is measured against a stated baseline and evidenced.
For most small and medium Australian organisations that baseline is the Australian Signals Directorate's Essential Eight, assessed by maturity level. It is well documented, it is what regulators and insurers increasingly ask about, and it is specific enough that progress against it can be demonstrated. Where an organisation has a contractual obligation to ISO 27001 or another framework, we work to that instead.
Not every finding will be fixed, and pretending otherwise is dishonest. Some remediations cost more than the risk they remove, and some conflict with how the business needs to operate. Those become documented, accepted risks, signed by someone with the authority to accept them. A decision recorded is defensible; the same decision undocumented is negligence.
What is included
Baseline assessment
Current state measured against the Essential Eight maturity model, or another framework where you are contractually bound to one.
Identity and access review
Privileged accounts, multi-factor authentication coverage, conditional access and joiner-mover-leaver process, which is where most real incidents begin.
Endpoint and patch posture
Device enrolment, disk encryption, endpoint protection and patch currency for operating systems and applications.
Backup verification
Confirmation of what is actually backed up, how long it is retained, and a tested restore. An untested backup is an assumption.
Remediation
Prioritised by risk and effort, executed with your agreement, and re-tested afterwards so the fix is evidenced rather than asserted.
Risk register
Every finding not remediated recorded as an accepted risk, with the reason and the person who accepted it.
How it is delivered
- Findings are rated by realistic business impact rather than by scanner severity. A critical-rated vulnerability on a system with no sensitive data and no network path matters less than a medium on a domain controller.
- Nothing is changed in a production environment without your agreement and a rollback position, because security work that causes an outage has not improved your security.
- Re-testing after remediation is included. A fix that has not been verified is a claim.
What you receive
- Assessment report with findings, evidence and severity
- Essential Eight maturity rating with the evidence supporting each level
- Prioritised remediation plan with effort estimates
- Re-test results after remediation
- Signed risk register of accepted findings
- Executive summary written for a board or owner rather than for engineers
What is not included
Stated plainly, because unstated exclusions are where disputes begin.
- Penetration testing and red teaming, which require a specialist provider and which we will refer rather than pretend to offer
- Security certification audits, which must be performed by an accredited certification body
- Twenty-four-hour incident response, unless a managed IT agreement with those hours is in place
- Licence costs for security tooling, which are billed to your own accounts
Common questions
Do you perform penetration testing?
No. Penetration testing is a specialist discipline and doing it properly requires a dedicated team and current offensive tooling. We will refer you to a specialist and help you scope the engagement and interpret the report, which is often where the value is lost.
What is the Essential Eight?
A set of eight mitigation strategies published by the Australian Signals Directorate, assessed at maturity levels zero to three. It is the de facto baseline for Australian organisations and increasingly what insurers and larger customers ask about during procurement.
What happens if you find something serious?
We tell you immediately rather than saving it for the report. If it is being actively exploited, containment comes before documentation.