Reviews and assessments
Security posture review
An independent assessment of how well your organisation is protected across identity, email, endpoints, network and cloud, measured against the ACSC Essential Eight. You receive a risk-ranked list of fixes and not a generic scorecard.
Who it is for
This is for small and mid-sized Australian businesses, boards and executives who need to answer a customer security questionnaire, a cyber insurance renewal or a director's question about exposure.
What gets reviewed
- Essential Eight maturity across all eight mitigation strategies.
- Identity, including Microsoft Entra ID, multi-factor authentication, conditional access and privileged accounts.
- Email security, including SPF, DKIM and DMARC enforcement.
- Microsoft 365, Intune and Defender configuration.
- AWS and Azure configuration, including public exposure, logging and encryption.
- Network perimeter, remote access and VPN.
- Certificates, TLS configuration and cryptographic hygiene.
- Backup and recovery readiness.
What you get
- A report with findings ranked by risk.
- An Essential Eight maturity assessment for each strategy, with a realistic target level.
- A fix list with effort estimates, ordered so that the largest risk reductions come first.
- An executive summary suitable for a board or an insurer.
- Optional remediation of the findings.
How it runs
The review uses read-only access to your tenancy and cloud accounts and usually takes one to two weeks.
This is a configuration and architecture review. It is not a penetration test, and where a penetration test is warranted the report will say so.
Common questions
What is a security posture review?
It is an assessment of the security controls an organisation has in place across identity, email, devices, network and cloud, compared with a recognised baseline. The result shows where the gaps are and which fixes reduce the most risk.
Is this a penetration test?
No. A posture review examines configuration and architecture with read-only access. It finds the weaknesses that most attacks rely on, such as missing multi-factor authentication or unenforced DMARC, and it costs less and takes less time than a penetration test.
What is the Essential Eight?
The Essential Eight is a set of eight mitigation strategies published by the Australian Cyber Security Centre. It has defined maturity levels, and it is widely used by Australian government agencies, insurers and enterprise customers as a baseline for their suppliers.