Specialist Capability · Cyber & Risk
A clear, benchmarked answer to "how exposed are we."
Boards, insurers, and customer contracts are asking cyber questions that "we think we're fine" can no longer answer. This is a cyber risk and controls review benchmarked against the ACSC Essential Eight, ISO 27001 and the Australian Privacy Act (plus PCI-DSS and GDPR where they apply to your business), a defensible position, not a vague reassurance.
What this covers
Controls review
A structured assessment of your current security controls against the ACSC Essential Eight and ISO 27001, informed by direct experience deploying a global Zero Trust architecture (CrowdStrike, Netskope, Cisco Meraki, KnowBe4) protecting 5,000+ staff across four countries.
Benchmarked gap analysis
Exactly where you sit against the Essential Eight, ISO 27001 and the Australian Privacy Act, plus PCI-DSS and GDPR where they apply to your business: direct compliance ownership across four different sectors (retail, automotive, hospitality and children's services), not theoretical familiarity with the standards.
Risk-ranked findings
Issues ordered by actual business risk, not by how easy they are to fix: the same discipline behind a Data Breach Playbook and live executive simulation exercises I built to pressure-test response readiness before it's needed.
Board-ready reporting
A report written for a board or insurer to read directly, not just a technical team.
Outcomes
What you can expect
Cyber and governance questions used to be background noise. Now they show up in board packs and insurance renewals. This assessment turns that uncertainty into a clear, board-ready position.
- A defensible, benchmarked answer the next time a board, insurer or contract asks
- A risk-ranked list of what to fix first, and why
- A report you can hand directly to your board or cyber insurer
- A credible baseline for ongoing governance, if that's the next step
Frequently asked questions
What does a Security Posture Assessment actually check?
A structured review of your current security controls, benchmarked against the ACSC Essential Eight, ISO 27001 and the Australian Privacy Act, plus PCI-DSS and GDPR where they apply to your business.
How much does a Security Posture Assessment cost?
A fixed-scope assessment. Get in touch for pricing.
Who is the Security Posture Assessment report written for?
A board or insurer to read directly, not just a technical team. Findings are risk-ranked by actual business impact rather than by how easy they are to fix.
What happens after the assessment?
You get a defensible, benchmarked position and a risk-ranked list of what to fix first. It also provides a credible baseline for ongoing governance, such as Cyber Risk Advisory, if that's the next step.
Benchmarked against the ACSC Essential Eight, ISO 27001 and the Australian Privacy Act (plus PCI-DSS and GDPR where applicable), with findings ranked by actual business risk.
Book a discovery call →Ready for a clear answer?
Book a 30-minute discovery call. No pitch, no obligation: a direct conversation about the cyber question you can't yet answer.
Book a discovery call →