Cyber security and compliance · Australia
Practical security and compliance for growing companies
Essential Eight alignment, Privacy Act readiness and the evidence you need when an enterprise customer sends a security questionnaire. Real controls that reduce risk, without a 200-page policy nobody reads.
Why companies call us
Security usually becomes urgent because someone outside the business asks about it.
An enterprise customer's questionnaire
Two hundred questions about access control, encryption and incident response, and a deal that's waiting on the answers.
Cyber insurance renewal
The insurer wants evidence of multi-factor authentication, backups and patching before they'll quote.
Privacy Act changes
Recent amendments raise expectations on how personal information is protected and explained, including new transparency rules for automated decisions from December 2026.
A near miss
A phishing email that almost worked, a lost laptop, or an ex-employee who still had access.
What you get
Controls that make a real difference, and the evidence to prove they're in place.
- An Essential Eight maturity assessment against the Australian Signals Directorate's model
- A prioritised remediation plan, costed and ordered by risk reduced
- Identity done properly: single sign-on, multi-factor authentication and least-privilege access
- Device management, patching and tested backups
- An incident response plan and a tabletop exercise with your leadership team
- A right-sized policy set and a reusable library of security questionnaire answers
- Readiness for SOC 2 or ISO 27001 audits if your customers need them
How it runs
Find the biggest risks quickly, fix them in order, and keep the evidence.
Baseline
We review identity, devices, email, backups, cloud and data handling against the Essential Eight and the Australian Privacy Principles.
One week · $4,900Remediate
We fix the highest-risk gaps first, working with your IT provider or team, and record evidence as we go.
Two to eight weeks · fixed quoteMaintain
Quarterly reviews, questionnaire support and help when a customer or insurer asks for proof.
Optional · from $3,500/moHow we approach it
Security that fits a business of ten to two hundred people.
Risk first, paperwork second
We start with the controls that stop real attacks, like multi-factor authentication, patching and backups, before writing policies.
Work with your IT provider
Most of our clients have a managed service provider. We work alongside them, not around them.
Evidence as you go
Screenshots, configurations and records captured during the work, so the next questionnaire takes hours instead of weeks.
Honest about our role
We prepare you for audits; accredited auditors certify. For penetration testing we scope the work and coordinate a CREST-accredited firm of your choice.
Tools and platforms we use most
Pricing
A fixed price for the baseline, and a written quote for remediation.
| Option | Price |
|---|---|
| Security baseline assessmentOne week. Essential Eight and privacy review with a prioritised, costed plan. | $4,900 |
| Remediation projectFixing the highest-risk gaps, with evidence captured for customers and insurers. | fixed quote |
| SOC 2 or ISO 27001 readinessGap analysis, controls, policies and evidence before your auditor arrives. | fixed quote |
| Ongoing security partnerQuarterly reviews, questionnaire answers and on-call advice. | from $3,500/mo |
Remediation costs depend on the size of your team and systems. Licensing for security tools is billed directly by the vendor; we recommend tools on fit, not commission.
Common questions
Is the Essential Eight mandatory for our business?
It's mandatory for many Australian Government agencies, but voluntary for private businesses. In practice, customers, insurers and government buyers increasingly ask about it, so it's a sensible baseline.
Which Essential Eight maturity level should we aim for?
For most small and mid-sized businesses, Maturity Level One across all eight strategies is a strong first goal, then Level Two for the areas your customers care about most. We'll recommend a target based on your risks and contracts.
Do you do penetration testing?
We scope it, coordinate a CREST-accredited testing firm and help you fix what they find. Keeping testing independent from the people who built the controls is good practice.
Will you replace our IT provider?
No. We work with your managed service provider and give them a clear plan. Many providers welcome the help with security and compliance work.
Can you help us answer a security questionnaire right now?
Yes. We can usually turn around a questionnaire in a few days, and build a reusable answer library so the next one is faster.
Often paired with
Cloud and DevOps
AWS architecture, migration and cost reduction, with infrastructure as code, CI/CD and monitoring set up once and explained properly.
Learn more →LLM agents · RAG · Document AIAI and automation
Assistants, agents and document pipelines built on your own data, measured for accuracy and handed over running in your cloud.
Learn more →Architecture · Hiring · Due diligenceFractional CTO
Senior technical leadership a few days a month: architecture, hiring, vendor management and a roadmap your board can read.
Learn more →Know where you stand before a customer asks
A one-week security baseline for $4,900 gives you an Essential Eight maturity rating, your biggest risks, and a costed plan to fix them.