Cyber security and compliance · Australia

Practical security and compliance for growing companies

Essential Eight alignment, Privacy Act readiness and the evidence you need when an enterprise customer sends a security questionnaire. Real controls that reduce risk, without a 200-page policy nobody reads.

Why companies call us

Security usually becomes urgent because someone outside the business asks about it.

An enterprise customer's questionnaire

Two hundred questions about access control, encryption and incident response, and a deal that's waiting on the answers.

Cyber insurance renewal

The insurer wants evidence of multi-factor authentication, backups and patching before they'll quote.

Privacy Act changes

Recent amendments raise expectations on how personal information is protected and explained, including new transparency rules for automated decisions from December 2026.

A near miss

A phishing email that almost worked, a lost laptop, or an ex-employee who still had access.

What you get

Controls that make a real difference, and the evidence to prove they're in place.

  • An Essential Eight maturity assessment against the Australian Signals Directorate's model
  • A prioritised remediation plan, costed and ordered by risk reduced
  • Identity done properly: single sign-on, multi-factor authentication and least-privilege access
  • Device management, patching and tested backups
  • An incident response plan and a tabletop exercise with your leadership team
  • A right-sized policy set and a reusable library of security questionnaire answers
  • Readiness for SOC 2 or ISO 27001 audits if your customers need them

How it runs

Find the biggest risks quickly, fix them in order, and keep the evidence.

Baseline

We review identity, devices, email, backups, cloud and data handling against the Essential Eight and the Australian Privacy Principles.

One week · $4,900

Remediate

We fix the highest-risk gaps first, working with your IT provider or team, and record evidence as we go.

Two to eight weeks · fixed quote

Maintain

Quarterly reviews, questionnaire support and help when a customer or insurer asks for proof.

Optional · from $3,500/mo

How we approach it

Security that fits a business of ten to two hundred people.

Risk first, paperwork second

We start with the controls that stop real attacks, like multi-factor authentication, patching and backups, before writing policies.

Work with your IT provider

Most of our clients have a managed service provider. We work alongside them, not around them.

Evidence as you go

Screenshots, configurations and records captured during the work, so the next questionnaire takes hours instead of weeks.

Honest about our role

We prepare you for audits; accredited auditors certify. For penetration testing we scope the work and coordinate a CREST-accredited firm of your choice.

Tools and platforms we use most

Microsoft 365 and Entra IDIntuneGoogle WorkspaceAWS IAM Identity Center1PasswordVantaDrataCrowdStrikeMicrosoft Defender

Pricing

A fixed price for the baseline, and a written quote for remediation.

OptionPrice
Security baseline assessmentOne week. Essential Eight and privacy review with a prioritised, costed plan.$4,900
Remediation projectFixing the highest-risk gaps, with evidence captured for customers and insurers.fixed quote
SOC 2 or ISO 27001 readinessGap analysis, controls, policies and evidence before your auditor arrives.fixed quote
Ongoing security partnerQuarterly reviews, questionnaire answers and on-call advice.from $3,500/mo

Remediation costs depend on the size of your team and systems. Licensing for security tools is billed directly by the vendor; we recommend tools on fit, not commission.

Common questions

Is the Essential Eight mandatory for our business?

It's mandatory for many Australian Government agencies, but voluntary for private businesses. In practice, customers, insurers and government buyers increasingly ask about it, so it's a sensible baseline.

Which Essential Eight maturity level should we aim for?

For most small and mid-sized businesses, Maturity Level One across all eight strategies is a strong first goal, then Level Two for the areas your customers care about most. We'll recommend a target based on your risks and contracts.

Do you do penetration testing?

We scope it, coordinate a CREST-accredited testing firm and help you fix what they find. Keeping testing independent from the people who built the controls is good practice.

Will you replace our IT provider?

No. We work with your managed service provider and give them a clear plan. Many providers welcome the help with security and compliance work.

Can you help us answer a security questionnaire right now?

Yes. We can usually turn around a questionnaire in a few days, and build a reusable answer library so the next one is faster.

Know where you stand before a customer asks

A one-week security baseline for $4,900 gives you an Essential Eight maturity rating, your biggest risks, and a costed plan to fix them.