Services

We tell your firm exactly where its security stands, then we fix it

Security, continuity and compliance for Australian accounting firms, law firms and professional practices. Fixed price. Written down. Your data stays in Sydney.

5 to 50People in a typical client firm
Essential EightEvery finding mapped to it
SydneyWhere your data stays
Who we serve

Firms that hold sensitive information and have nobody to ask

Accounting and law firms, SMSF auditors, financial advisers, insolvency practitioners and finance brokers. Five to fifty people, Microsoft 365, maybe one server, no internal IT. You carry the same Privacy Act obligations as a firm of five hundred, and increasingly your clients and insurers want that proven in writing.

Led by a former accountant Six years compliance advisory Not a helpdesk, not an IT reseller
How it works

Three steps, and most firms take all three

1. Assess

Two weeks, fixed price, a written report telling you where you actually stand.

2. Fix

Staged remediation against a ceiling you set. Nothing open ended.

3. Protect

A monthly service that keeps it fixed, and gives you something to show an auditor.

What we do

Open any line for the detail

Assess

Find out where you stand. Fixed price, two weeks, a written report.

Web exposure scan, free

Run it yourself against your own domain. Security headers, TLS, DNS and email authentication including SPF, DKIM and DMARC, and exposed library versions, all mapped to the Essential Eight. It exists so you can see we can do the technical work before you have paid us anything. Run it now.

Essential Eight Baseline Assessment, fixed price, two weeks

We review your external attack surface, your Microsoft 365 tenant configuration, and Entra ID access: who holds administrator rights, who has left and still has access, where multi-factor authentication is missing. We check what is backed up, whether a restore has ever been tested, and how long a recovery would genuinely take. We assess patch currency and application control.

You receive a report rating you against each Essential Eight strategy at Maturity Level One, Two or Three, a list of what is wrong ranked by what would actually hurt your firm, a costed remediation plan, and a one page summary for a partners' meeting. If little is wrong, we say so, and you keep the report.

Microsoft 365 and Backup Baseline, fixed price, one week

A narrower version for firms that are entirely cloud based with no server. A sensible way to test us before committing to anything larger.

Fix

You had a penetration test and nothing was fixed. This is the most common thing we find.

Penetration test remediation programme

  • Triage and plan, two weeks. We validate every finding against your actual environment. Most reports contain findings that are not exploitable in context, and findings far more serious than their rating suggests. You get a sequenced plan, a fixed price for delivery, and an honest statement of what can safely wait.
  • Remediation, in agreed blocks. Delivery against the plan, agreed in writing before work starts, against a ceiling you set.
  • Retest and closure, one to two weeks. We verify each finding is closed and produce an evidence pack: what it was, what changed, what proves it. Written to hand to an insurer, a board, or a client running a supplier review.
  • Keep it fixed. A firm that fixes everything and changes nothing about how it operates is back where it started inside a year. That is the managed service below.

Identity and access remediation

Multi-factor authentication enforced, conditional access configured, administrator accounts separated from daily-use accounts, departed staff removed, and access documented as a register you can maintain yourself. The highest value fix for most firms, and it produces an artefact an auditor can read.

Protect

Monthly managed backup, email security and AI data protection. All held in Sydney.

Business hours support, thirty days notice to cancel, no exit fee. Three packages.

  • Protected Mailbox. Microsoft 365 backup across mail, OneDrive, SharePoint, Teams and OneNote, plus Entra ID backup. Backups rescanned against current malware signatures, with a monthly restore test and a written result.
  • Protected Practice. Everything above, plus inbound email security, collaboration security across Teams, SharePoint and OneDrive, security posture management, AI data protection, and a quarterly report mapped to the Essential Eight and the Privacy Act.
  • Server Continuity. Full machine backup, physical or virtual, agentless for VMware, Proxmox, Nutanix and vSphere, with Sydney hosted storage. Backups are malware scanned, so a restore point can be proven clean before you use it. Quarterly recovery verification, written result.

Why AI data protection matters this year

It stops client information and matter detail being pasted into ChatGPT, Copilot, Claude and similar tools, and blocks prompt injection arriving inside documents and emails. Detect-only if you want visibility first, or block mode if you want it enforced. For a firm that has just realised its junior staff are drafting with AI, this is usually the whole conversation.

Security awareness training with phishing simulation and quarterly click-rate reporting is available alongside any package. Every engagement starts with a fixed onboarding: tenant connection, policy configuration, first full backup verified, baseline report.

Comply

SMB1001, Essential Eight, Privacy Act, ISO 27001 and APRA CPS 234 readiness.
  • SMB1001 readiness, Bronze, Silver or Gold. The Australian five tier standard for small and medium business. Recognised by insurers, government bodies and supply chain partners, and a far more realistic target for a fifteen person firm than ISO 27001.
  • Essential Eight uplift, built directly from your baseline assessment so the scope is known before it is priced.
  • Privacy Act and Australian Privacy Principles review, including your position under the Notifiable Data Breaches scheme.
  • ISO 27001 gap assessment and preparation of the evidence you will be asked for.
  • APRA CPS 234 readiness, scoped per engagement.

We prepare. We do not certify. We are never the auditor. Where a firm needs certification, we say so and tell them who does that. On SMB1001, Bronze, Silver and Gold are self-attested, which is the work we deliver. Platinum and Diamond require independent audit and sit outside what we offer.

Advise

Artificial intelligence applied to audit and compliance workflows.

A system that reads documents before a professional does. It extracts the figures, reconciles them against the accounts, matches every assertion to the evidence supporting it, applies the compliance tests, and hands the reviewer a queue already ranked by risk.

  • Discovery, three weeks. We map how the work actually runs, look at real files, and state honestly what can and cannot be automated. The pilot price is set at the end of this stage, not before it.
  • Pilot, three months. Built for a narrow slice and run against historical files whose outcomes are already known, so accuracy is measured against your own conclusions rather than against a claim we make.
  • Build, four to six months. Integrated, security tested, documented, your people trained, against a ceiling you set.
  • Managed service. We run it, patch it, keep it current with regulation, and report monthly against agreed service levels.

The line we do not cross. The machine prepares. The professional decides. Every finding cites the document it came from. Nothing is asserted without a source. The registered professional forms and signs the opinion exactly as they do today. We are not building something that audits. We are building something that does the reading.

Technically: Claude via Amazon Bedrock in the AWS Sydney region, inside an account you own, encrypted with keys you control. Nothing retained, nothing used to train any model, and every document processed logged in a form your own auditors can read.

Specialist work

Penetration testing, digital forensics, OSINT. Scoped and quoted individually.

These are not productised and we will not price them in a first meeting. They are scoped against your specific environment and objectives.

  • Penetration testing. Specialist led, and only ever run with written authorisation.
  • Digital forensics. Specialist led, with evidence handling documented throughout.
  • OSINT and people locating. Subject to licensing, and only after the licensing position for that jurisdiction has been confirmed.
How we work

The parts most providers leave you to find out later

Your data stays here

Managed services in a Sydney datacentre. Advisory and AI work in the AWS Sydney region, in an account you own. Reports, evidence packs and working papers on Australian infrastructure. Where you need a second copy, we hold it on Australian infrastructure or on storage you own, never offshore.

On request we provide the platform provider's SOC 2 Type 2 report and ISO 27001 certificate, a data processing agreement and sub-processor list, and our position on termination.

What we do not do

No twenty four hour monitoring or on-call security operations centre. No helpdesk or general IT support. No hardware. No endpoint detection and response with a response time commitment, until there is a team to carry that service level agreement. Where something falls outside what we do, we say so, and we say who should do it instead.

How we engage

Fixed price wherever scope can genuinely be fixed. Otherwise an agreed day rate in blocks against a ceiling you set. Nothing open ended. Your reports and configuration belong to you from day one. Findings always go in writing. You get the principal on the engagement, not a graduate.

Start with the assessment

Two weeks, a fixed price, and a written report that tells you where your firm actually stands. If little is wrong, we will say so.