Cyber security
Security is not an add-on to software, it is how it is built and run. We review and test what you already have, harden it, and put the controls in place that Australian law and your insurer expect. When something goes wrong, we are the people who answer.
Every engagement
- Quoted in writing before work starts
- Accounts and code in your name
- Your customers pay you, never us
What we do
The full scope, in plain language.
Pick what you need; the quote lists each item so nothing is vague.
- Security reviews and penetration testing of web and mobile apps
- Hardening of apps, servers, databases and cloud accounts
- Access control, multi-factor sign-in and single sign-on
- Essential Eight assessment and uplift
- Privacy Act and Australian Privacy Principles readiness
- Incident response and recovery when something has gone wrong
- Vulnerability monitoring and patching as a monthly service
- Secrets, keys and credential management
- Staff security training and phishing awareness
- Secure development practices, code review and backups with tested recovery
What you get
What lands in your hands.
- 1A written findings report ranked by risk, with plain-English fixes
- 2Penetration test results and a re-test after the fixes
- 3Hardening applied to apps, servers, databases and cloud accounts
- 4Essential Eight maturity assessment and uplift plan
- 5Privacy Act readiness checklist and data handling documentation
- 6Ongoing vulnerability monitoring and patching on a monthly plan
Who it is for
Any business that holds customer data, takes payments online, or has been asked by a client or insurer to prove its security.
- Scope call at no charge
- Written quote within two business days
- Weekly demos on a preview link
How it runs
From first call to a system you rely on.
- 1
Scope call
Thirty minutes on what the software must do on day one, who uses it and what it connects to. No charge.
- 2
Quote in writing
A written quote within two business days: what is included, what is not, the schedule and the monthly plan after launch.
- 3
Build with weekly demos
You see working software every week on a preview link and give feedback on the real thing. Progress and approvals live in your portal.
- 4
Launch in your accounts
Domain, app stores, email and payments are set up in your name with us as admin. Nothing is held hostage.
- 5
Host and maintain
We host it in Sydney, monitor it, patch it, back it up and answer when something is wrong. One monthly plan, in writing.
Related services
Often paired with this.
Questions
Before you ask for a quote.
Specific answers for this service. Anything else, ask and we reply within one business day.
What does a security review involve?
We look at the code, the hosting, the accounts and how people use them. You get a report ranked by risk with a fix for each item. We can do the fixes or hand the report to your existing developers.
Will testing take my systems down?
No. Penetration testing is scheduled with you, run against a staging copy where possible, and stops short of anything destructive. Production checks are read-only unless you ask otherwise.
What is the Essential Eight and do I need it?
It is the Australian Signals Directorate's set of eight baseline controls. Insurers, government buyers and larger clients increasingly ask for a maturity level. We assess where you sit and plan the uplift in order of impact.
What happens if we are breached?
Call us. We contain the incident, preserve evidence, restore from backups, work out what was accessed and help you meet the Notifiable Data Breaches scheme obligations. Then we fix the cause.
Ready for a quote?
Tell us what you need and we will reply within one business day, Sydney time. The quote follows in writing.