← All services

Managed Cyber Security Brisbane

Dedicated security expertise alongside your IT team.

Protect your endpoints, identities and people with managed threat detection and response. Add ongoing governance and monthly control assurance to check that your agreed security requirements remain in place.

This is a security-only service for organisations with internal IT or an existing IT provider. We work with your team to coordinate improvements, clarify responsibilities and verify agreed changes. Your team continues to run day-to-day IT.

Discuss your security requirements →

Start with a conversation about your current IT arrangements, security priorities and the level of support you need.

OSCP OSEP

Verified certifications held by our lead security operator, Michael Jordison.

Keep your IT team. Add dedicated security capacity.

Your IT team understands your business and keeps it running. Security adds another workload: investigating threats, reviewing access controls, tracking exceptions and answering management questions about risk.

For a Brisbane firm with more than 20 staff, we introduced passwordless primary sign-in and central control of shared credentials. See the passwordless sign-in and shared account case study for the rollout and staff-adoption work.

Novaguard works alongside internal IT teams and existing managed service providers across Brisbane and Southeast Queensland. We bring specialist security expertise with clear ownership of the work we take on.

For IT leaders, that means additional security capacity and practical support. For business leaders, the assurance tier provides an outside view of agreed controls, documented findings and visibility of what still needs attention.

Managed protection across devices, identities and people

Endpoint protection

Detect and investigate suspicious activity on covered devices, with response and containment within the agreed scope.

Identity security

Monitor for account compromise and identity threats, supported by an agreed baseline for secure access.

Security monitoring

Bring agreed security logs together so specialist analysts can investigate threats with context, around the clock.

Staff awareness

Security awareness training and phishing simulations help staff recognise threats and know how to report them.

Choose protection, or protection with ongoing assurance

Both service levels include the core security capabilities and a defined incident escalation process. Bastion adds the recurring checks, evidence and coordination needed to keep your agreed security baseline under review.

Sentry

Managed Protection

Estimated pricing

$60 /user/month

AUD, excluding GST. Minimum 10 users.

$600/month minimum, excluding GST.

Month-to-month. Cancel anytime.

For organisations that want managed security protection while their IT team retains ownership of governance and ongoing control assurance.

  • Endpoint and identity threat detection and response
  • Centralised security logging and 24/7 threat monitoring
  • Security awareness training and phishing simulations
  • Initial security configuration and an agreed best-practice baseline
  • Defined incident escalation and initial containment within agreed authority
Discuss your security requirements →

Bastion

Managed Protection & Assurance

Estimated pricing

$99 /user/month

AUD, excluding GST. Minimum 10 users.

$990/month minimum, excluding GST.

Month-to-month. Cancel anytime.

For organisations that also want specialist oversight, evidence of control performance and help keeping security improvements on track.

  • Everything in Managed Protection
  • Monthly automated checks of agreed, testable security controls
  • Configuration change and control exception reporting
  • Remediation coordination with IT and verification of agreed fixes
  • An evidence register and monthly security assurance report
  • Scheduled governance reviews with your IT and business stakeholders
Discuss your security requirements →

Estimates are based on a minimum of 10 users for either plan. We confirm the final price against your environment and agreed scope, including coverage, prerequisites, onboarding costs and any additional work, before you commit.

What monthly security assurance looks like

With Bastion, we agree the security framework and control baseline you want to maintain. Monthly automated checks cover the controls that can be tested reliably; requirements needing manual review are identified in the scope.

The value of checking actual coverage is illustrated by our onboarding audit of a 20-person accounting firm. It identified MFA exemptions and a former employee’s active application account, which we remediated. That engagement shows the gaps an access review can uncover.

  1. Define the baseline

    Document the requirements, systems and accounts in scope, along with approved exceptions and who owns each control.

  2. Check controls and changes

    Run the agreed monthly checks, identify gaps and review configuration changes against the baseline.

  3. Coordinate improvements

    Explain the findings, prioritise recommended changes with your IT team and agree who will implement them.

  4. Verify and report

    Check the agreed fixes and record the result, including outstanding exceptions and work still requiring attention.

Example: keeping your authentication policy in place

If your baseline requires device-bound passkeys, we agree checks for user coverage and the access policies enforcing that requirement. We review relevant policy changes and investigate exceptions with IT, then verify the agreed corrective action.

The checks distinguish between registering a credential and enforcing its use. A user having a passkey registered is only one part of the evidence.

Threat monitoring runs 24/7. Control assurance checks run monthly. Each has a separate purpose and an agreed scope.

Evidence your team can use

Bastion's monthly security assurance report gives IT and management a shared record of what was checked and what happens next.

  • Controls checked, results and supporting evidence.
  • Relevant configuration changes since the previous review.
  • Exceptions, affected systems or accounts, and their priority.
  • Agreed remediation owners, progress and verification results.
  • Requirements needing manual review or outside the agreed coverage.

The Australian Cyber Security Centre (ACSC) recommends the Essential Eight as a baseline for reducing cyber risk. Bastion's checks can support your work towards an agreed framework, such as Essential Eight or SMB1001. They provide evidence about the controls in scope; they do not automatically certify compliance or establish an organisation-wide maturity level. For a formal assessment or uplift project, explore our cyber compliance services.

SMB1001 is published by Dynamic Standards International (DSI), with certification available through CyberCert. DSI’s SMB1001 Unlocked initiative, starting 1 January 2027, aims to make the standard freely accessible to small businesses. Our service covers the implementation, evidence, and ongoing work agreed in your plan.

Clear responsibilities alongside your IT team

Your IT team

Continues to own general IT support, infrastructure operations and routine patching. They bring the operational context needed to plan changes safely.

Novaguard

Provides the agreed managed security service and incident escalation. With Bastion, we also check controls, document findings, coordinate recommended improvements and verify agreed fixes.

Working together

Security changes can be implemented by your IT team, Novaguard or both. We agree access, approvals and responsibilities before making changes, so there is a clear owner for each action.

When an incident happens

Specialist security analysts handle first-line investigation and response within agreed authority. Novaguard provides the next level of investigation and coordinates with your IT team. Containment permissions, escalation contacts, Novaguard response availability and incident support scope are documented before the service starts.

Start with your environment and priorities

  1. Discuss the gaps you want to cover. Tell us about your IT arrangements, existing security capabilities and any framework or reporting requirements.
  2. Agree the scope with IT. We establish coverage, access, prerequisites, response arrangements and ownership. For Bastion, we also define the control checks and governance schedule.
  3. Put the service into operation. We coordinate onboarding with your team, establish the agreed baseline and confirm how findings and incidents will be handled.

Still weighing up the need? Read Do you need managed cyber security? for practical questions to work through with your IT team.

Need a clearer view of your current position first? Start with a Cyber Business Review.

For an initial look at external exposure, try our free domain security scan. The automated report covers email authentication, web security, breach exposure, domain hygiene, and lookalike domains. A Cyber Business Review goes further into the agreed environment and control scope.

Looking for day-to-day IT support as well? Explore our managed IT services.

Frequently asked questions

Is managed cyber security the same as managed IT?

No. This is a security-only service. Your internal IT team or existing managed service provider continues to run day-to-day IT, including user support, infrastructure and patching. Novaguard provides managed security protection and, with the assurance tier, ongoing control checks and security governance.

Can Novaguard work with our internal IT team or existing MSP?

Yes. We agree security responsibilities, access and escalation paths with you and your IT team. Changes can be implemented by your IT team, Novaguard or both, depending on the agreed scope and authorisation. You do not need to replace your IT provider.

What is the difference between Sentry and Bastion?

Sentry provides managed endpoint and identity protection, security logging, threat monitoring, staff awareness and an initial security baseline. Bastion adds monthly control checks, evidence reporting, remediation coordination and scheduled governance reviews.

How often are security controls checked?

Threat monitoring runs 24/7 across the agreed coverage. In Bastion, automated assurance checks run monthly against an agreed control baseline and selected security framework. Checks that need manual review are identified in the scope. Monthly assurance checks are separate from real-time threat monitoring.

Who responds to a security incident?

Specialist security analysts provide first-line investigation and response within agreed authority. Novaguard provides the next level of security investigation and coordination with your IT team. Before service starts, we document escalation contacts, containment permissions, Novaguard response availability and the scope of incident support.

Does Novaguard apply patches and fix security gaps?

Routine patching remains with your IT team. Under Bastion, we identify gaps in the controls being checked, agree recommended changes with IT and verify the agreed fixes. Security configuration changes may be carried out by your team, Novaguard or both, with responsibilities agreed in advance.

Do monthly checks certify compliance with a security framework?

No. Monthly checks provide evidence about the controls in scope and highlight exceptions. Some requirements need manual assessment or evidence from other parts of your organisation. We agree the framework, checks and assessment boundaries before making any claims about coverage.

Can we cancel the service?

Yes. Both plans are month-to-month and you can cancel anytime, with no long-term contract lock-in. We set out the cancellation process and final billing arrangements in your proposal before you sign.

How much does managed cyber security cost?

Estimated pricing is AUD $60 per user per month for Sentry and AUD $99 for Bastion, excluding GST. Both have a 10-user minimum, giving estimated monthly minimums of $600 and $990 respectively, excluding GST. We confirm coverage, onboarding and any separately scoped work in your proposal.

Stay because it works for your team.

Both plans are month-to-month. Cancel anytime, with no long-term contract lock-in. Start with a conversation about the security support you need.

Discuss your security requirements

We agree the scope, costs, cancellation process and final billing arrangements before you sign.