The inSUPPORT Method

The 6 Step Cyber Strength System

Most IT providers sell you security in pieces. The audit is one bill. The remediation is another, usually triple the first. The ongoing support is a third. And the cyber insurance is left for you to sort out with a broker.

You end up with a folder full of compliance paperwork and no real idea whether you are actually covered.

The 6 Step Cyber Strength System: Consult, Audit, Remediate, Comply, Insure, Support

We built the 6 Step Cyber Strength System to do it differently.

The 6 Step Cyber Strength System is inSUPPORT's method for taking an Australian business from its first audit through an agreed remediation programme, usually completed within 30 to 90 days depending on how the environment looks when we start. One team runs your managed IT, your compliance-framework-aligned security and remediation, and a cyber insurance pathway, so the pieces actually fit together. Remediation is included in your support fee, not billed back to you as a surprise project. Cyber insurance, backup and security-awareness training are available as clearly-quoted add-ons, arranged and coordinated by the same team, so nothing falls through the gap between your IT provider and your broker.

The difference is what we optimise for. We do not align your environment to a framework just to tick a box. We maintain it against the controls your insurer actually expects, so that if you are ever breached, your policy has the best chance of responding.

How it works: the six Strengths

Each step builds on the one before it. We call them Strengths, because each one is a layer of protection your business keeps for good.

1
Consult

Consult: Know Your Risk

We start by understanding your business: your goals, your industry obligations, your risk profile, and where you want to be in twelve months. We listen before we recommend anything. This is the foundation everything else is built on.

2
Audit

Audit: See the Gaps

We run a full technical audit of your environment against the compliance frameworks that apply to your industry, and document it as a plain-English report. You get a complete picture of where you stand, with an audit trail you can rely on.

3
Remediate

Remediate: Close the Gaps

The gaps the audit finds get fixed, included in your support fee, with most environments through the agreed remediation in about 30 days depending on complexity. No project invoice. No separate quote. In the first week we lock down what is actually exposing you: administrator access nobody needed, unmanaged devices, and the accounts nobody closed when people left.

4
Comply

Comply: Prove It

We align your environment to the compliance frameworks appropriate for your business and to your obligations under Australian privacy law, and we give you documented evidence of it, not just verbal assurance. If you ever want formal ISO 27001 certification, the groundwork is already done.

5
Insure

Insure: Stay Covered

Cyber insurance that matches your industry and coverage requirements is arranged through our licensed insurance partners and underwritten by some of the world's most reputable insurers. Cover is subject to the insurer's assessment. If you already hold a policy, we review it against the technical controls it assumes, because a policy you cannot claim on is not protection.

6
Support

Support: Always On

Once your environment is clean and aligned, we keep it that way. Ongoing support on the service level you choose, covering your users and devices, with a named contact and an escalation path that does not end in a ticket queue.

Beyond the Essential 8

The Essential 8 is the floor, not the ceiling

The Australian Signals Directorate publishes eight mitigation strategies, and they are genuinely good. They are also the minimum, they were written for government, and they were written before cyber insurance underwriting looked the way it does today. inSUPPORT works to all eight, and then to the controls the Essential 8 does not reach.

The Essential 8, as published by the ASD
01Application control
02Patch applications
03Configure Microsoft Office macro settings
04User application hardening
05Restrict administrative privileges
06Patch operating systems
07Multi-factor authentication
08Regular backups
The four we add
PLUS
Verified recovery
The Essential 8 asks whether you take backups. We test whether they actually restore, and confirm they are free from at-rest breaches, so you are not quietly restoring the ransomware along with the data.
PLUS
The human layer
Simulated phishing tailored to each individual person, based on how they went in that fortnight's class. Most incidents arrive through a person, and there is no technical control that catches that.
PLUS
Continuous drift control
The settings that were right on day one and are not right now. Monitored continuously, rather than discovered at the next audit and billed back to you as a project.
PLUS
Insurance alignment
Your controls maintained against your insurer's actual policy wording, and adjusted when that wording changes. This is the control that decides whether a claim responds, and it is the reason the other eleven are worth doing.

Eight is what the government asks for. It is not what an insurer looks at, and it is not what we think it takes. The remediation this turns up sits inside your support fee. Backup, insurance and the security-awareness platform are quoted separately, so you can see exactly what each one costs.

Why we built it around the insurance, not the framework

Here is the insight most providers miss: an environment can pass a framework checklist on paper and still fail the conditions your insurer needs to actually pay a claim.

Cyber insurance claims do not usually get denied because the breach did not happen. They get denied because the controls the insurer assumed were in place were not: a setting that lapsed, a gap that was never closed, an incident that was not reported in time. The framework said aligned. The policy still said no.

This is not theoretical any more. In October 2025 the Federal Court fined Australian Clinical Labs $5.8 million. $4.2 million was for failing to protect the information of more than 223,000 people. The other $1.6 million was for failing to investigate the incident promptly and failing to report it in time.

A third of that penalty was for what happened after the attack. The controls you can evidence, the speed you can investigate, the records you can produce: that is the difference between an incident and a catastrophe.

We are not building you a compliant environment that just looks good on paper. We are building you an insurable one, and maintaining it that way.

So we manage to a different test. When a policy's wording changes, we adjust your environment so there is no avoidable reason a claim would not be paid.

And on the worst day

The six Strengths are about the 364 days when nothing happens. This is the other one.

It is no longer a matter of if. So the response process is designed for your organisation during onboarding, while everyone is calm, rather than written on the day while everyone is not. When something happens we engage immediately and work to that plan: preserve the evidence so you can answer what was accessed and when you knew, restore the critical services in the order your business actually needs them, and handle reporting to the authorities inside the timeframes the law sets.

Those first and third points are worth sitting with. In the Australian Clinical Labs judgment, $1.6 million of the $5.8 million penalty had nothing to do with being hacked. It was for failing to investigate quickly and failing to report in time.

Who this is for

Built for Australian businesses, roughly 30 to 300 users, that have outgrown break-fix IT and cannot carry the risk of getting cyber wrong. You will recognise yourself if:

You have been quoted a five-figure sum for a security audit, then quoted again, more, to fix what it found.
Your cyber insurance is up for renewal and someone has finally asked whether you would actually be covered.
A competitor or someone in your industry just got breached, and the board wants to know you are protected.
You are a CFO or owner carrying IT on top of your real job, with no one in-house who can answer the compliance questions.

We work with businesses that are ready to lock it down. We standardise environments to a known-good state, and we do not negotiate on the controls that keep you covered.

Evidence

What the system delivers.

About 4 hours
Technical onboarding
30 to 90 days
Agreed remediation program complete, by complexity
30-40% to 70-75%
Security posture score, first week
8 frameworks
Essential 8, CIS Controls, Cloud Control Matrix, NIST CSF, SMB1001, IRAP, ISO 27001 / SOC 2-aligned

Instant Windscreens & Tinting

One of inSUPPORT's longest-standing clients, with an environment managed to SMB1001, Essential 8 and the ISO 27001 standard, and frontline workers across the network brought up to standard with managed devices and accounts.

A national franchise network

inSUPPORT standardised IT and telco across the network, taking per-store cost down sharply and freeing budget the franchises redirected into a new ERP system.

About Kane Nawrocki

Kane Nawrocki, Founder & CEO, inSUPPORT. More than 25 years in IT, from building servers as a teenager to running enterprise security and compliance for Australian businesses.

Common questions about the 6 Step Cyber Strength System

What is the 6 Step Cyber Strength System?

It is inSUPPORT's method for taking a business from first audit through an agreed remediation programme, usually completed within 30 to 90 days. The six steps are Consult, Audit, Remediate, Comply, Insure and Support, run by one team so your IT, compliance and insurance pathway actually join up.

Why is the remediation included instead of quoted separately?

Because charging for the audit and then quoting more to fix what it found is how most of the industry works, and it leaves businesses half-protected. We include the remediation in your support fee so the work actually gets done, within about 30 days depending on complexity.

Will this make sure my cyber insurance pays out?

We cannot guarantee any insurer's decision. What we can do is maintain your environment against the controls your policy assumes, and review the policy against what is technically in place, so when something goes wrong your claim has the best chance of responding. Cover is always subject to the insurer's assessment.

Ready to see where you stand?

Most businesses do not know whether they are genuinely covered until something goes wrong. A Cyber Strength Audit tells you before that happens, where the gaps are and exactly what it takes to close them.

Book your Cyber Strength Audit