Getting Started

What's brought you here? Pick the situation that fits β€” we'll point you to the right starting point.

Each Getting Started assessment is fixed-fee, fixed-scope, and completed within one to two weeks. You leave with a clear answer and a concrete next step β€” not an open-ended engagement.

πŸ”

Cyber Risk Snapshot

Something happened β€” find out what it means for your business

A staff member nearly clicked a phishing link. You couldn't answer a security question from a client. You realised you have no real idea what would happen if something went wrong tonight. Any of those is reason enough to get a clear picture β€” fast.

The Cyber Risk Snapshot gives you exactly that: a plain-language view of what is actually exposed in your business, ranked by priority. Not a 200-page compliance report. A practical answer to the question your leadership team is already asking β€” where do we actually stand, and what do we fix first?

This assessment draws on ISO 27001, the Essential Eight, and the Privacy Act β€” not to lock you into a framework, but to make sure nothing significant gets missed. The output is yours to act on immediately, or use as the starting point for your next step.

Deliverables

  • Written risk summary with plain-language executive brief
  • Prioritised gap findings β€” what to fix first, not a wall of findings
  • Recommended starting-point roadmap

Business benefits

  • A clear answer for your leadership team on where you actually stand
  • Know which compliance path (if any) makes sense for your business
  • Evidence base for your next insurer or client conversation
  • Delivered in days, not months
Get your snapshot
βœ…

Essential Eight Maturity Assessment

Your enterprise clients are starting to ask β€” here is where you stand

Westpac, CBA, BHP β€” and most government procurement panels β€” are now asking their suppliers about Essential Eight maturity. If you've received one of those questionnaires, or a tender asked the question and you weren't ready, you need an independent scorecard before someone asks again.

This assessment scores your business against each of the eight controls at your target maturity level. Not a checklist β€” a verified review of whether the controls are actually in place and operating as intended. The output is an independent scorecard you can hand directly to a client, insurer, or government agency.

If gaps need closing to reach your target level, we'll give you a prioritised roadmap your MSP can act on directly.

Deliverables

  • E8 maturity scorecard β€” ML1 to ML3 per control
  • Gap analysis against your target maturity level
  • Prioritised remediation roadmap
  • Evidence pack suitable for client and government requirements

Business benefits

  • Know your maturity level before someone forces the question
  • Independent scorecard that stands up to client and government scrutiny
  • Clear path from where you are to where you need to be
  • Actionable recommendations your MSP can implement directly
Get your E8 scorecard
πŸ”’

Privacy Health Check

1 July 2026: your Privacy Act exemption ends β€” are you ready?

If your business turns over less than $3 million, you've been exempt from the Privacy Act. That exemption ends on 1 July 2026. More than 100,000 Australian businesses will move into compliance scope β€” whether they're ready or not.

The Privacy Health Check tells you exactly where you stand. We map what personal data your business collects, where it goes, who can access it, and whether your current practices hold up against the Australian Privacy Principles. You get a plain-language gap report and a prioritised action list β€” not legal jargon and not an open-ended project.

This review is also relevant for NZ businesses under the Privacy Act 2020, and for any AU business whose accountant, lawyer, or insurer has already started asking questions about data handling practices.

Deliverables

  • Privacy gap report β€” compliance status against the Australian Privacy Principles
  • Personal data flow map (what's collected, where it's stored, who can access it)
  • Recommended actions in priority order
  • Summary of obligations specific to your sector

Business benefits

  • Know your compliance status before a complaint forces the issue
  • Understand what needs to change β€” in plain language, without a lawyer
  • Reduce the risk of a notifiable data breach through better data handling
  • Foundation for a full privacy programme if you decide to go further
Check your privacy readiness
βš™οΈ

M365 Security Review

Know who has access to your Microsoft 365 β€” and what they can do with it

A staff member nearly fell for a phishing email in your M365 inbox. Someone left the company and you're not certain what access they still have. Your insurer asked about M365 configuration and you weren't sure what to say. Any of those is worth acting on.

55% of M365 compromises involve misconfiguration β€” not sophisticated attacks. Email forwarding rules sending data outside the business. Admin accounts without MFA. SharePoint sharing settings that expose more than intended. This review finds them before someone else does.

We audit your M365 environment against Microsoft's own security benchmarks and hand your MSP a clear, prioritised list of what to lock down β€” with specific configuration changes, ready to action.

Planning to work with defence? M365 security configuration is one of the first things assessed in DISP accreditation. This review is a strong starting point for businesses entering the Australian defence supply chain. Learn about our DISP pathway β†’

Deliverables

  • Configuration audit across Entra ID, Exchange, SharePoint, Teams, and Defender
  • Risk-rated findings against Microsoft security benchmarks
  • MSP-ready remediation checklist with specific configuration changes
  • DISP pathway note (where applicable)

Business benefits

  • Independent check on your M365 security β€” not from the people who set it up
  • Reduce the risk of business email compromise and data leakage
  • MSP-ready output means your provider can act on it immediately
  • Starting-point evidence for DISP accreditation or cyber insurance requirements
πŸ›‘οΈ

Cyber Insurance Readiness

Your insurer is asking questions β€” here's how to answer them before renewal

Your insurer sent a security questionnaire you weren't sure how to answer. Your premium went up at renewal. Or you're applying for cyber cover for the first time and realise you don't know what they'll ask. These conversations are getting more specific every year.

Most insurers now require evidence of MFA, tested backups, an incident response plan, and staff security awareness training as a minimum baseline. If you can't evidence those controls, you're at risk of coverage exclusions β€” or a premium that doesn't reflect the security you actually have in place.

This assessment maps your current security controls to what your insurer is asking for. We identify what you can evidence today, where the gaps are, and which gaps are most likely to affect your premiums or coverage. The output includes an evidence pack your broker can use at renewal.

Deliverables

  • Cyber insurance readiness report
  • Gap analysis against common insurer requirements (MFA, backups, patching, IR plan)
  • Insurer evidence pack mapped to standard questionnaire requirements
  • Broker-ready summary document
  • Remediation plan targeting insurer-critical controls

Business benefits

  • Come to renewal prepared β€” not scrambling
  • Reduce the risk of coverage exclusions from undisclosed gaps
  • Potential premium reduction by evidencing strong controls
  • Clear picture of insurer expectations before the conversation starts
Prepare for your renewal
πŸ“‹

ISO 27001 Readiness Assessment

A client asked if you're certified β€” here's what it actually involves for a business your size

An enterprise client asked "are you ISO 27001 certified?" A government tender required it. A potential partner wants to see a certificate before they'll proceed. You said "not yet" β€” and now you need to understand what's actually involved before committing.

ISO 27001 certification typically takes 12–18 months and requires a significant investment in time and resource. Before committing, you need an honest picture of where you stand and what the gap looks like for a business your size. This assessment gives you that β€” without the sales pitch to proceed.

We map your current state against ISO 27001:2022 β€” the ISMS management clauses and all 93 Annex A controls. We factor in what your MSP already handles on your behalf, and give you a realistic estimate of cost, effort, and timeline to certification.

Deliverables

  • ISO 27001 gap assessment β€” control-by-control against Annex A
  • Readiness score and ISMS clause assessment
  • MSP coverage mapping β€” what your provider already handles
  • Realistic certification cost, timeline, and effort estimate
  • Phased implementation roadmap

Business benefits

  • Informed decision on whether to pursue certification β€” before spending on implementation
  • Respond to client and tender requirements with a concrete plan and timeline
  • Avoid paying twice for controls your MSP already covers
  • Realistic budget to put in front of leadership or a board
Understand what's involved
πŸ…

SMB1001 Readiness Assessment

Achievable certification, designed for businesses with 3–50 staff

What is SMB1001? SMB1001 is a cybersecurity standard developed by CyberCert specifically for small and medium businesses. Unlike ISO 27001, it's built for businesses with 3–50 staff β€” with four certification levels (Bronze, Silver, Gold, Platinum) and a certificate you can show clients and insurers. Recognition is growing fast among AU and NZ insurers and enterprise procurement teams.

You want a certifiable security standard that doesn't require 18 months and $50,000. SMB1001 was built for exactly that. If you've heard about it from your insurer, a peer, or a cyber broker β€” or if ISO 27001 feels out of reach right now β€” this assessment tells you where you currently stand and what certification would actually involve.

We assess your business against the SMB1001 controls across all four levels and tell you which level you're ready for today, what it takes to reach Bronze or Silver, and which controls your MSP already covers. The output is a readiness report and a clear certification pathway β€” not a project proposal.

Most businesses targeting Bronze certification can get there within 8–12 weeks of this assessment.

Deliverables

  • SMB1001 readiness report
  • Controls gap analysis across all four certification levels
  • Recommended certification pathway (direct to target or Bronze first)
  • MSP coverage mapping

Business benefits

  • Know whether you're already close to certification β€” or what it would take
  • A certificate you can show to clients and insurers
  • Faster and more achievable than ISO 27001 for most businesses with under 50 staff
  • Clear roadmap from current state to your target certification level
See where you stand

Not sure which assessment is right for you?

Tell us what's brought you here β€” an incident, an insurer question, a client requirement β€” and we'll point you to the right starting point. No obligation, no sales pitch.

Talk to us

Kaurna Acknowledgement

We acknowledge and pay our respects to the Kaurna people, the traditional custodians of the ancestral lands on which we work. We acknowledge the deep feelings of attachment and relationship of the Kaurna people to country and we respect and value their past, present and ongoing connection to the land and cultural beliefs.