Cyber Strength Audit

Find out whether you are actually covered

Most businesses do not discover the gap between having cyber insurance and having a claim paid until the worst possible moment.

A Cyber Strength Audit tells you beforehand. We assess your environment against the compliance frameworks that apply to your industry, document exactly where the gaps are, and show you what it takes to close them. In plain English, not a 90-page report you will never read.

No obligation
Plain-English report
Costed remediation path
Book your audit

Tell us a little about your business and we will come back to arrange a time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

What the audit covers

Your environment is assessed against the compliance frameworks that apply to your industry, including the relevant Essential 8 controls, and against the technical controls a cyber insurer expects to be in place.

Identity and access

Who can reach what, from where, and with what protection.

Patching and currency

Operating systems, applications, firmware, and what has quietly fallen behind.

Backup and recovery

Not whether backups run, but whether they have been tested and whether they would survive the same breach.

Email and endpoint

The two routes almost every incident actually takes.

Configuration drift

The settings that were right on day one and are not right now.

Insurance alignment

If you already hold a policy, we read it against what is technically in place.

What you walk away with

A plain-English risk picture

Where you stand, ranked by what would actually hurt you, not by what scores worst on a spreadsheet.

A documented audit trail

Evidence you can hand to a board, an insurer or a client who asks.

A costed remediation path. Exactly what it takes to close each gap, and what it costs. If you go on to managed support with us, that remediation is included in the fee rather than billed back as a separate project.

Who it is for

Australian businesses of roughly 30 to 300 users. You will recognise yourself if:

Your cyber insurance is up for renewal and someone has finally asked whether you would really be covered.
A competitor in your industry has just been breached and the board wants assurance.
You have been quoted a five-figure sum for an audit, then quoted again to fix what it found.
You are a CFO or owner carrying IT on top of your real job.

What happens next

1
You book. Fill in the form and we will come back to arrange a time.
2
We assess. We document your environment and assess it against your compliance frameworks.
3
You get the picture. A plain-English report, the risks ranked, and the exact path to closing them. What you do next is your call.

What the numbers look like

About 4 hours
Technical onboarding
30 to 90 days
Agreed remediation program complete, by complexity
30-40% to 70-75%
Security posture score, first week
8 frameworks
Essential 8, CIS Controls, Cloud Control Matrix, NIST CSF, SMB1001, IRAP, ISO 27001 / SOC 2-aligned

What this actually costs

$4.22m
The average cost of a data breach in Australia, up 38% since 2019.
IBM / Ponemon
Every 6 min
An Australian business reports a cybercrime. 84,700 reports last year.
ASD
$56,600
The average cost to a small business, up 14% in a single year.
ASD
$50m
Maximum penalty for a serious privacy breach, or 30% of turnover.
Privacy Act 1988

None of these are predictions. They are last year's figures.

The part nobody checks until it is too late

In October 2025 the Federal Court issued Australia's first privacy penalty. $5.8 million against a pathology company after 223,000 people had their information stolen.

$4.2 million of that was for failing to protect the data. The other $1.6 million was for failing to investigate quickly and failing to report in time.

Read that again. A third of the penalty had nothing to do with being hacked. It was for the state they were in when it happened.

The market data says the same thing. An Australian breach found and contained in under 200 days costs an average of $3.26 million. The same breach found slowly costs $5.17 million. Nearly two million dollars, decided by nothing except how fast you knew.

Most businesses could not answer the two questions both of those numbers turn on. What exactly was accessed. And when did you know.

If you have an IT provider, they are almost certainly handling your helpdesk, your patching and your backups. That is not the same thing as being able to prove what happened, to an insurer, to a regulator, or to a client who asks.

Can you afford the downtime?

The average business is down for 24 days after a ransomware attack. Not an afternoon. Fifty people unable to work for that long costs about $638,400 in wages alone, before you have paid to fix anything.

Work out your own number. It takes about fifteen seconds and the maths is on the page.

$638,400
50 people · 24 days · wages only

Common questions

How long does the audit take?

The assessment itself depends on the size and complexity of your environment. Technical onboarding for managed clients runs to about four hours. We will give you a realistic window once we understand your setup.

Am I committing to anything?

No. The audit gives you a picture of your risk and a costed path to closing the gaps. What you do with it is entirely your decision, including taking it to another provider.

Will this guarantee my insurance pays out?

No, and anyone who tells you otherwise is overselling. No provider can guarantee an insurer's decision. What an audit does is show you where your environment does not match what your policy assumes, so you can close those gaps before you ever need to claim. Cover is always subject to the insurer's assessment.

We already have an IT provider. Is this awkward?

It is a second opinion, and a reasonable provider will not object to one. Plenty of businesses run an audit to confirm things are in good shape. That is a valid outcome.

Book your Cyber Strength Audit

Most businesses do not know whether they are genuinely covered until something goes wrong. Find out before that happens.

Book my audit