Skip to content

Security Audits

Independent review of your security posture against frameworks like the Essential Eight, ISO 27001, and CIS, delivered with a practical roadmap.

A clear-eyed assessment of where you stand: policies, configurations, access, and backups measured against recognised frameworks, delivered as a scorecard and a prioritised plan you can actually action.

What gets reviewed

An audit covers the areas where problems actually originate, rather than everything that could theoretically be examined.

  • Identity and access. Who can log in to what, how they prove it, what happens when they leave, and how much damage one compromised account does.
  • Devices and patching. What is managed, what is current, and what is quietly running an operating system that stopped getting fixes.
  • Data and backups. Where your important data lives, who can reach it, whether backups exist, and whether anybody has ever restored one.
  • Email and collaboration. Microsoft 365 or Google Workspace configuration, email authentication, and the sharing settings nobody revisits after setup.
  • Cloud and network. What is exposed, how it is segmented, and whether the defaults from three years ago are still in place.
  • Process and policy. What happens when something goes wrong, and whether anybody other than the person who wrote it down knows.

What you get back

Two documents and a conversation.

The scorecard rates each control area against the framework, with the evidence behind each rating. It is deliberately specific: “MFA is enforced for administrators but not for the 34 standard accounts” is useful, “identity management: amber” is not.

The roadmap turns the gaps into a sequence. Each item carries an estimate of effort, an indication of cost, and what it actually reduces. Items are ordered so that the cheap, high-impact work comes first, which in most engagements means the first three items cost very little and close most of the real exposure.

The walkthrough is where the value usually lands. You get to ask why something is rated the way it is, push back where you have context we do not, and leave knowing which two things you are doing this quarter.

What an audit is honest about

Most audits of businesses that have never had one find the same handful of things: incomplete MFA, backups nobody has tested, more administrators than anyone expected, old accounts still active, and one system everybody has quietly been afraid to touch since the person who set it up left.

If that is you, the audit will not be a surprise so much as a confirmation with a price tag attached, and that is its value. The hard part of security spending is rarely knowing that something is wrong. It is being able to say what, specifically, in an order somebody can fund.

We also report what you are doing well. A report with nothing but failures in it is easy to write and easy to dismiss, and it makes the genuinely urgent items harder to see rather than easier.

Typical timeframe
Typically 2 to 4 weeks, depending on size
Best for
Anyone who suspects they have gaps but cannot say where, or needs a baseline
One finding, and the only thing that changes its statusThe finding shown is a worked example rather than anything taken from a client. The retest is within the scope of a testing engagement rather than a separate job, which is the only reason there is ever a second row.

The engagement

How it runs

Every engagement follows the same shape, so you always know which part you are in and what is coming next.

  1. 1

    Discovery

    We review what you have: systems, identity, backups, policies, and the way things actually work day to day rather than the way a document says they do.

  2. 2

    Assess

    We measure that against the framework that fits you, most often the Essential Eight for Australian businesses, and record evidence for each control.

  3. 3

    Score

    You get a maturity rating per control, so you can see the specific gap rather than a single number that tells you nothing actionable.

  4. 4

    Roadmap

    We sequence the gaps by what they cost to close against what they reduce, and tell you plainly which ones we would do first with your money.

Common questions

What is the Essential Eight, and does it apply to me?

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate. It is mandatory for federal government entities and increasingly expected of anyone who supplies them, but it is worth using regardless because it is a genuinely good prioritisation of what stops real attacks. It is the framework we default to for Australian businesses, because it is specific, locally relevant, and free to read.

Is this the same as a penetration test?

No, and they answer different questions. An audit asks whether the right controls exist and are working. A penetration test asks what somebody could actually do to you. An audit is broader and usually the better first engagement: it finds the missing MFA and the untested backups that a test would find more slowly and more expensively.

Will you just hand me a document and leave?

No. The report includes a walkthrough session, and the roadmap is written so you can act on it with your existing IT provider if you would rather not use us for the remediation. If a report needs us in order to be useful, it is a sales document rather than an audit.

We already have an IT provider. Is this awkward?

It comes up often and it is usually fine. An independent audit is not an attack on your provider, and good providers welcome it because it turns a vague conversation about budget into a specific list. We audit the environment, not the people, and the report is written accordingly.

Do you audit against ISO 27001?

We assess against ISO 27001 and the CIS Controls where that is what you need, typically because a client or a certification path has asked for it. Note that we are not a certification body, so this is a readiness assessment and a gap analysis rather than a certification audit.

Need help with Security Audits?

Tell us where you are and what is worrying you. We will tell you honestly what we would do first.

Get in touch