Assessment

A cyber security audit that gives you facts, not opinions

A useful cyber security audit answers three questions: what is exposed right now, how hard would it be to exploit, and what should be fixed first. We check your live configuration rather than relying on a questionnaire.

What we look at

Identity and multi-factor coverage, conditional access, administrator accounts, device compliance, patch levels, email authentication, external sharing, and whether your backups have ever been restored successfully.

For Microsoft 365 environments we pull the actual tenant configuration, so findings are evidence rather than assumption.

What you get back

A written report in plain English with findings ranked by real risk, not by scanner severity. Each item has the business impact, the fix, and a rough effort estimate.

You own the report. You are free to have someone else do the remediation, and we will say so if that is the sensible option.

Free checks before you spend anything

If you just want a starting point, run our free external domain scan. It checks email authentication and public exposure in under a minute and needs nothing installed.

Questions we get asked

What is the difference between an IT audit and a cybersecurity audit?

An IT audit reviews whether your technology is fit for purpose: device age, licensing, performance and cost. A cybersecurity audit reviews exposure: what an attacker could reach, how quickly, and which controls would stop them. We can do either, but they answer different questions.

How long does a cyber security audit take?

For a typical Australian small or medium business on Microsoft 365, the review takes about a week from access being granted to the report landing. Larger or multi-site environments take longer, mostly because of network and operational technology discovery.

What do you need access to?

Read-only access to your Microsoft 365 tenant, visibility of your device management and backup platforms, and a short conversation with whoever administers your network. We do not need to install agents to complete the review.

Who needs Essential Eight alignment?

Businesses supplying into Australian government are asked for it most often, but the eight strategies are a sensible internal benchmark for any organisation. We rate your alignment as part of the audit with the evidence behind each rating.

Do we have to use you for the remediation?

No. You own the report and the remediation plan, and you are free to have your internal team or another provider do the work. If that is the sensible option we will say so.

What you get

  • Live configuration review, not a questionnaire
  • Identity, device, email and backup coverage
  • Essential Eight alignment rating with evidence
  • Findings ranked by business risk
  • Costed remediation plan you can act on
  • Report written for leadership as well as IT

Tell us how many staff you have and which platform you run, and we will quote the audit as a fixed price.

Book a conversation