Most IT providers sell you security in pieces. The audit is one bill. The remediation is another, usually triple the first. The ongoing support is a third. And the cyber insurance is left for you to sort out with a broker.
You end up with a folder full of compliance paperwork and no real idea whether you are actually covered.

We built the 6 Step Cyber Strength System to do it differently.
The 6 Step Cyber Strength System is inSUPPORT's method for taking an Australian business from its first audit through an agreed remediation programme, usually completed within 30 to 90 days depending on how the environment looks when we start. One team runs your managed IT, your compliance-framework-aligned security and remediation, and a cyber insurance pathway, so the pieces actually fit together. Remediation is included in your support fee, not billed back to you as a surprise project. Cyber insurance, backup and security-awareness training are available as clearly-quoted add-ons, arranged and coordinated by the same team, so nothing falls through the gap between your IT provider and your broker.
The difference is what we optimise for. We do not align your environment to a framework just to tick a box. We maintain it against the controls your insurer actually expects, so that if you are ever breached, your policy has the best chance of responding.
Each step builds on the one before it. We call them Strengths, because each one is a layer of protection your business keeps for good.
We start by understanding your business: your goals, your industry obligations, your risk profile, and where you want to be in twelve months. We listen before we recommend anything. This is the foundation everything else is built on.
We run a full technical audit of your environment against the compliance frameworks that apply to your industry, and document it as a plain-English report. You get a complete picture of where you stand, with an audit trail you can rely on.
The gaps the audit finds get fixed, included in your support fee, with most environments through the agreed remediation in about 30 days depending on complexity. No project invoice. No separate quote. In the first week we lock down what is actually exposing you: administrator access nobody needed, unmanaged devices, and the accounts nobody closed when people left.
We align your environment to the compliance frameworks appropriate for your business and to your obligations under Australian privacy law, and we give you documented evidence of it, not just verbal assurance. If you ever want formal ISO 27001 certification, the groundwork is already done.
Cyber insurance that matches your industry and coverage requirements is arranged through our licensed insurance partners and underwritten by some of the world's most reputable insurers. Cover is subject to the insurer's assessment. If you already hold a policy, we review it against the technical controls it assumes, because a policy you cannot claim on is not protection.
Once your environment is clean and aligned, we keep it that way. Ongoing support on the service level you choose, covering your users and devices, with a named contact and an escalation path that does not end in a ticket queue.
The Australian Signals Directorate publishes eight mitigation strategies, and they are genuinely good. They are also the minimum, they were written for government, and they were written before cyber insurance underwriting looked the way it does today. inSUPPORT works to all eight, and then to the controls the Essential 8 does not reach.
Eight is what the government asks for. It is not what an insurer looks at, and it is not what we think it takes. The remediation this turns up sits inside your support fee. Backup, insurance and the security-awareness platform are quoted separately, so you can see exactly what each one costs.
Here is the insight most providers miss: an environment can pass a framework checklist on paper and still fail the conditions your insurer needs to actually pay a claim.
Cyber insurance claims do not usually get denied because the breach did not happen. They get denied because the controls the insurer assumed were in place were not: a setting that lapsed, a gap that was never closed, an incident that was not reported in time. The framework said aligned. The policy still said no.
This is not theoretical any more. In October 2025 the Federal Court fined Australian Clinical Labs $5.8 million. $4.2 million was for failing to protect the information of more than 223,000 people. The other $1.6 million was for failing to investigate the incident promptly and failing to report it in time.
A third of that penalty was for what happened after the attack. The controls you can evidence, the speed you can investigate, the records you can produce: that is the difference between an incident and a catastrophe.
So we manage to a different test. When a policy's wording changes, we adjust your environment so there is no avoidable reason a claim would not be paid.
The six Strengths are about the 364 days when nothing happens. This is the other one.
It is no longer a matter of if. So the response process is designed for your organisation during onboarding, while everyone is calm, rather than written on the day while everyone is not. When something happens we engage immediately and work to that plan: preserve the evidence so you can answer what was accessed and when you knew, restore the critical services in the order your business actually needs them, and handle reporting to the authorities inside the timeframes the law sets.
Those first and third points are worth sitting with. In the Australian Clinical Labs judgment, $1.6 million of the $5.8 million penalty had nothing to do with being hacked. It was for failing to investigate quickly and failing to report in time.
Built for Australian businesses, roughly 30 to 300 users, that have outgrown break-fix IT and cannot carry the risk of getting cyber wrong. You will recognise yourself if:
We work with businesses that are ready to lock it down. We standardise environments to a known-good state, and we do not negotiate on the controls that keep you covered.
What the system delivers.
One of inSUPPORT's longest-standing clients, with an environment managed to SMB1001, Essential 8 and the ISO 27001 standard, and frontline workers across the network brought up to standard with managed devices and accounts.
inSUPPORT standardised IT and telco across the network, taking per-store cost down sharply and freeing budget the franchises redirected into a new ERP system.
Kane Nawrocki, Founder & CEO, inSUPPORT. More than 25 years in IT, from building servers as a teenager to running enterprise security and compliance for Australian businesses.
It is inSUPPORT's method for taking a business from first audit through an agreed remediation programme, usually completed within 30 to 90 days. The six steps are Consult, Audit, Remediate, Comply, Insure and Support, run by one team so your IT, compliance and insurance pathway actually join up.
Because charging for the audit and then quoting more to fix what it found is how most of the industry works, and it leaves businesses half-protected. We include the remediation in your support fee so the work actually gets done, within about 30 days depending on complexity.
We cannot guarantee any insurer's decision. What we can do is maintain your environment against the controls your policy assumes, and review the policy against what is technically in place, so when something goes wrong your claim has the best chance of responding. Cover is always subject to the insurer's assessment.
Most businesses do not know whether they are genuinely covered until something goes wrong. A Cyber Strength Audit tells you before that happens, where the gaps are and exactly what it takes to close them.
Book your Cyber Strength Audit