CYBERSECURITY HEALTH CHECK

Know where you stand.
Know what to fix.

A practical, independent review of your business’s cybersecurity posture — with clear, prioritised recommendations you can actually act on.

From $1,250 + GST

Book a Cybersecurity Health Check
WHAT IS A HEALTH CHECK?

A clear picture of your current cybersecurity posture.

Most businesses know cybersecurity is important, but don’t always know where their biggest weaknesses are — or what they should fix first. The Cybersecurity Health Check gives you an independent, practical assessment of where you are today, where the key risks are, and what you should do next.

WHAT YOU GET

A practical assessment. Not a 200-page report.

01

Independent Assessment

An objective review of your current cybersecurity controls, practices and overall security posture.

02

Risk-Rated Findings

Clear identification of weaknesses and areas requiring attention, prioritised according to risk and business impact.

03

Practical Recommendations

Straightforward recommendations focused on what you should do, without unnecessary technical jargon.

04

90-Day Improvement Roadmap

A prioritised plan showing what should be addressed first, what can follow, and where to focus longer term.

WHAT WE REVIEW

10 areas of your cybersecurity.

The assessment looks beyond individual technical controls to consider the broader cybersecurity practices that protect your business.

01   Governance & Cybersecurity Management Policies, responsibilities, risk management and security governance.
02   Asset, Data & Risk Management Understanding what you have, what matters and where the risks are.
03   Identity & Access Management Accounts, MFA, privileged access and access controls.
04   Endpoint & Device Security Workstations, laptops, servers and security controls.
05   Cloud & Email Security Microsoft 365, cloud services, email protection and configuration.
06   Network & Remote Access Security Networks, firewalls, remote access and connectivity.
07   Vulnerability & Patch Management Software updates, vulnerabilities and exposure management.
08   Backup & Recovery Backups, recovery capability and resilience against disruption.
09   Incident Response Preparedness, response processes and recovery from security incidents.
10   People & Third-Party Risk Security awareness, suppliers, contractors and external dependencies.
YOUR DELIVERABLES

Everything you need to understand what happens next.

Executive Summary

A clear overview of your current cybersecurity posture, key strengths and major areas of concern.

Key Findings

The most important weaknesses and risks identified during the assessment.

Risk-Rated Recommendations

Practical actions prioritised according to risk and business importance.

90-Day Roadmap

A realistic improvement plan covering immediate, near-term and longer-term actions.

Results Walkthrough

A discussion of the findings and recommendations so you understand exactly what they mean.

Professional Opinion

Independent cybersecurity advice based on the information and evidence made available during the assessment.

HOW IT WORKS

Simple from start to finish.

01
Initial Discussion Understand your business and scope.
02
Information Gathering Questionnaire and relevant evidence.
03
Assessment Review across the ten assessment areas.
04
Report & Roadmap Findings, recommendations and priorities.
05
Results Walkthrough Talk through the results and next steps.
OUR METHODOLOGY

Based on recognised cybersecurity principles.

The Health Check is informed by recognised cybersecurity frameworks and Australian cybersecurity guidance. We use these as practical reference points rather than treating them as a rigid checklist.

NIST CSF 2.0
ACSC Guidance
Essential Eight
ISO/IEC 27001 Principles
READY TO GET STARTED?

Find out where your business really stands.

Start with a short discussion about your business and what you want to achieve. We’ll confirm the scope and provide a clear price before the assessment begins.

From $1,250 + GST
Enquire About a Health Check

The Cybersecurity Health Check is a practical advisory assessment based on information and evidence made available by the client. It is not a penetration test, vulnerability scan, forensic investigation, formal compliance audit, ISO 27001 certification assessment or formal Essential Eight maturity assessment. The assessment does not guarantee that all cybersecurity risks or vulnerabilities will be identified.