Know Where You Stand. Feel Confident About What Comes Next.
When a client asks how you protect their data, or an insurer sends another security questionnaire, you should be able to answer with confidence. Our Cyber Business Review is an independent cyber security audit that shows you what is working, where you are exposed and what to do first. Get clear answers without changing IT providers.
Replace the nagging uncertainty with a clear plan
You are responsible for client information, your team's ability to work and the reputation you have built. It is hard to feel in control when the answer to every security question is simply ‘IT handles that’. We examine the agreed systems and controls, explain the findings in plain English and put the priorities in order. You leave knowing what deserves attention, what is already working and where to focus your budget.
For the questions you need to answer with confidence
Perhaps your insurance renewal is approaching, a prospective client wants evidence of your controls, or a recent phishing scare has left you wondering what else you have missed. This review gives owners and managers of professional services firms an informed second opinion. You can take the findings to your leadership team or existing IT provider and have a specific conversation about what needs to happen next.
What you get
Choose Basic for a clear starting point, or In-Depth for deeper testing, practical remediation and evidence you can use in security discussions.
Basic
$1,500 ex GST
Understand your exposure and set your priorities. A focused review with approximately 6–7 hours of assessment work.
- External attack-surface scan, what's visible and exposed from outside your network, checked without needing any access to your systems
- M365 security audit, Secure Score, Conditional Access, data-loss prevention rules, and mailbox rule checks
- Dark web credential check, with findings explained in the context of your wider security controls
- Essential 8 self-assessment scorecard, a remote, mostly-automated first read (not a certified assessment)
You get: a risk heatmap, a one-page cyber maturity score, and a 60-minute walkthrough call.
In-Depth
$4,995 ex GST
Turn uncertainty into documented evidence and practical action. Everything in Basic, with deeper investigation and approximately 20–27 hours of work.
- A scoped, light-touch external penetration test, led by our OSCP-certified tester
- Backup and disaster recovery audit, not just "is it backing up," but whether a restore has actually been tested
- ICT policy and incident response review
- Remediation of your top 3 critical findings included, with changes agreed with you before implementation
- A 90-minute executive walkthrough
You keep: a certificate documenting the scoped penetration test, a cyber insurance evidence pack, your documented ICT/cyber security policies, a 12-month security roadmap, and one 30-minute follow-up call available over the next 12 months. The test certificate records the engagement; it is not certification that your business is secure.
Put evidence behind the compliance tick boxes
“Do you enforce MFA?” “Have you tested your backups?” “Do you have an incident response plan?” A confident answer starts with knowing what is actually in place. We help you distinguish a documented control from an assumption, with the depth of evidence depending on your review tier.
- Understand your Essential Eight starting point. Both tiers include a self-assessment scorecard to identify areas needing attention.
- Prepare for insurer questions. In-Depth includes an evidence pack to support accurate answers about the controls reviewed.
- Make policies useful. In-Depth reviews ICT policies and incident response, so you can see where documented procedures need work.
- Give management a way forward. Clear priorities help you assign responsibility and budget; In-Depth adds a 12-month roadmap.
The review supports preparation for client, insurer and compliance discussions. It does not confer Essential Eight or SMB1001 certification or guarantee insurance acceptance. Bring the questionnaire or requirement you need to address so we can agree the relevant scope before starting.
100% money-back guarantee
You should finish your review feeling better informed and clear about your next steps. If you're not satisfied with its depth or value, tell us and we'll refund 100% of your review fee.
Both tiers are covered. No requirement to change providers or buy another service.
What happens after
We walk you through the findings, answer your questions and explain the priorities. You keep the review outputs for your chosen tier and can act on them with your existing provider, your internal team or us. You decide the next step with a clearer understanding of the risks and the work involved. If you want ongoing help, explore our managed cyber security services for ongoing security support, or our managed IT services for day-to-day IT support, maintenance and security together.
Start with a free domain check
Get your free business domain security report for an automated check of email authentication, web security, breach exposure, domain hygiene, and lookalike domains. For a deeper look at internal controls, priorities, and remediation, choose the Cyber Business Review scope that fits your organisation.
Frequently asked questions
Will this make us certified or guarantee cyber insurance approval?
No. The review identifies gaps and helps you understand the evidence behind your security answers. Basic includes an Essential Eight self-assessment scorecard; In-Depth adds an insurance evidence pack and further documentation. Formal certification and insurer acceptance have their own requirements. We distinguish what has been checked, what is self-reported and what still needs work.
Does my current IT provider need to know about this?
You do not need to change providers. We agree the scope and access needed before starting. External checks need no internal access; Microsoft 365 configuration checks and deeper testing require authorised access or evidence supplied by your team. We can coordinate with your existing provider where needed.
Is this the same as a penetration test?
Only In-Depth includes a (scoped, light-touch) pentest. Basic is a configuration and exposure review, not a pentest.
What if you find something urgent?
We flag anything critical immediately, not held back for the final report.
What does the 100% money-back guarantee cover?
If you are not satisfied with the depth or value of your Cyber Business Review, tell us and we will refund 100% of your review fee. This applies to both tiers, with no requirement to buy another service or change providers.