Skip to content

Defend · Service 02

Cyber security

Controls that are configured, documented and evidenced, and a blue team that keeps them working. Built so an auditor, an insurer or a client's risk team can verify them for themselves.

The position

Buying the tool is the cheap part

Almost every organisation we assess already owns most of the licences it needs. Microsoft 365 Business Premium alone includes conditional access, Defender, Intune and data loss prevention. In roughly nine assessments out of ten, the gap is a product nobody finished configuring.

Conditional access policies in report-only mode two years after deployment. Legacy authentication still enabled for one application that was decommissioned in 2023. Global administrator accounts without MFA because enabling it once broke a script.

We start with what you already own, finish the configuration, document it, and only then talk about buying anything. It is a less profitable opening move for us and a considerably more honest one.

Coverage

Seven domains, assessed and hardened in order

Sequenced by how attacks actually start. Identity first, because that is where the overwhelming majority of Australian incidents begin.

Identity & access

Entra ID hardening: phishing-resistant MFA, conditional access moved from report-only to enforced, legacy authentication blocked, privileged accounts separated from daily accounts, break-glass accounts documented and monitored, and guest access reviewed on a schedule.

Email & collaboration

SPF, DKIM and DMARC published and enforced, anti-phishing and impersonation protection tuned to your executive names, safe links and attachments, external sender marking, and auto-forwarding restricted — the single control that most often turns a compromise into a fraud loss.

Endpoint

EDR deployed and tuned, application control where it is workable, local administrator rights removed with a managed elevation path, disk encryption enforced and evidenced, and USB and removable media policy applied.

Network & perimeter

Firewall rule review and cleanup, segmentation between corporate, guest and operational networks, remote access consolidated behind MFA, external attack surface enumerated, and firmware kept current on the devices most people forget.

Data

Where your sensitive data actually lives, who can reach it, sensitivity labelling where it earns its keep, sharing controls in SharePoint and OneDrive, and data loss prevention rules tested against realistic scenarios.

People

Simulated phishing that measures behaviour on a blame-free basis, short role-based training, and a reporting path that takes one click — because a staff member who reports quickly is worth more than one who never clicks.

Governance

The written artefacts: information security policy, acceptable use, access control, incident response plan, business continuity plan, and a risk register that names owners and review dates. Each one drafted to fit your organisation.

Cyber defence

A blue team that keeps the controls working

Hardening is a point in time. Cyber defence is the ongoing work of keeping it true: catching drift, closing new exposure as it appears, and making sure the attacks that matter would be seen.

Our blue team works from the attacker's playbook backwards. Every control we deploy is tied to the techniques it prevents or detects, and the work carries on after the hardening project ends.

  • Detection engineering. Detection rules in Microsoft Defender, Sentinel or your SIEM, mapped to MITRE ATT&CK, tuned to your environment and tested against the techniques they are meant to catch.

  • Threat hunting. Hypothesis-led hunts through identity, endpoint and cloud telemetry for activity that slipped past the alerts, driven by current threat intelligence and ASD advisories.

  • Attack surface management. Continuous discovery of internet-facing hosts, domains, certificates and exposed services, so a forgotten server is found by us first.

  • Vulnerability management. Authenticated scanning across servers, workstations and cloud, prioritised by exploitability and exposure, with patch timeframes measured against the Essential Eight.

  • Configuration drift. Baselines for Entra ID, Intune, Defender and firewalls, with every change detected, reviewed and either approved or reverted.

  • Incident readiness. Playbooks for the incidents most likely to reach you, logging that answers the questions an investigation will ask, and tabletop exercises that test the plan with the people who will run it.

When the blue team needs a sparring partner, our penetration testing and red team practice provides one. Purple team exercises run real attack techniques against your defences and close the gaps they reveal the same day.

The difference

Security you can hand to somebody else

Sooner or later you will be asked to prove your controls — by a cyber insurer at renewal, a client's procurement team, an auditor, or a board that has read the news. Everything we deploy is built to survive that request.

  • A control register mapping each control to the Essential Eight strategy and maturity level it supports.

  • Configuration evidence — exported policy states, pulled directly from each platform.

  • A monthly posture report showing what changed, what drifted and what was remediated.

  • Insurer questionnaire support. We complete the technical sections and stand behind the answers.

  • Client due-diligence responses prepared once and reused, so the next tender starts with the answers already written.

  • An incident response plan that names people, phone numbers and decision authority — and is tested annually.

Standards

Aligned to what Australia actually asks for

We work to the frameworks your regulators, insurers and customers reference — and we will tell you which ones you can safely ignore.

ASD Essential Eight

The baseline. Assessed, uplifted and reported against maturity levels 1 to 3.

Privacy Act & NDB

Australian Privacy Principles and the Notifiable Data Breaches scheme, including breach assessment procedure.

ISO/IEC 27001

Assessments against ISO/IEC 27001:2022, plus readiness and control implementation where certification is a commercial requirement.

AESCSF

Australian Energy Sector Cyber Security Framework assessments for electricity, gas and liquid fuels operators, scored by Maturity Indicator Level and Security Profile.

SMB1001 & sector schemes

Tiered certification for smaller organisations, plus industry schemes where your customers demand them.

Questions

What people ask

Does company size make us less of a target?

Size has little to do with it. Most incidents start with a credential that appeared in a breach dump, a mailbox with auto-forwarding enabled, or an internet-facing service that was scanned by something automated at 3am. Almost none of it is personal, which is precisely why organisation size offers so little protection.

Will hardening break things for our staff?

Some of it will, if it is done carelessly. We stage every change: pilot group, report-only mode where the platform supports it, a documented rollback, and a communication to affected users before enforcement. The controls that cause the most friction — removing local admin, blocking legacy authentication — get the longest runway.

What does a blue team actually do day to day?

Keeps the defences working: building and tuning detections, hunting for activity the alerts missed, tracking new exposure and vulnerabilities, catching configuration drift and rehearsing incident response. It is the ongoing half of cyber security, after the hardening project ends.

Do you do penetration testing?

Yes. Network, application, cloud and social engineering testing, plus red and purple team engagements, are a service in their own right. Findings feed straight into the hardening and blue team work on this page, so the fix follows the test.

Can you work alongside our existing IT team?

Frequently, and it is often the better arrangement. An internal team that knows the business paired with a security practice that lives in the tooling daily. We agree a written split of responsibilities so every task has a named owner.

Pairs with

Essential Eight

The measured version of this page — scored, costed and evidenced monthly.

Explore →

Detection & response

Prevention fails eventually. This is who is watching when it does.

Explore →

Penetration testing & red teaming

The proof. We attack the controls on this page to show they hold.

Explore →

Find out where you actually stand

A baseline assessment scores every control, names the gaps and costs the fix. A fixed fee, and the report is yours to keep.