Website and hosting review
CMS, plugins, TLS, admin exposure, and common misconfigurations that turn a brochure site into an entry point.
Cyber security audit
A plain-English security audit of your websites, email, cloud accounts, and devices. Ranked findings, fixed quotes for remediation, and citations to ASD guidance. Built for Australian SMBs, not enterprise theatre.
Audit scope
We look at the surfaces attackers hit first on small Australian businesses. Every finding is ranked by likelihood and impact, with a clear fix and a price before remediation starts.
CMS, plugins, TLS, admin exposure, and common misconfigurations that turn a brochure site into an entry point.
Mailbox MFA, forwarding rules, password hygiene signals, and SPF, DKIM, and DMARC alignment for domains attackers spoof.
Microsoft 365 or Google Workspace permissions, shared drives, and dormant admin accounts that still hold the keys.
Endpoints, remote access, and privilege patterns that decide whether one phished laptop becomes a business-wide incident.
Whether backups exist, whether they are tested, and whether ransomware would leave you negotiating instead of restoring.
Fixed-price hardening items from the report, Essential Eight uplift when maturity is the goal, and optional monitoring after the cleanup.
Fit
You run on email, cloud apps, and a website, but nobody owns security day to day. You need an honest baseline and a ranked fix list, not a 200-page binder.
Renewals and supplier questionnaires ask what you have reviewed. An audit report with dated findings is evidence you can hand over.
If you only want a red-team logo for the board and no remediation budget, we are the wrong partner. Our audits exist to drive fixes.
Industries
Law, accounting, consulting, and agencies holding client files in email and cloud drives that attackers assume are soft targets.
Job apps, invoicing, and customer records on phones and laptops. MFA, backups, and device hygiene without slowing crews.
Stores, payment flows, and customer databases where a breach costs trust as well as money. Website and DNS/email hardening included.
Outcomes
Every issue explained without jargon walls, ordered by real business risk, with a recommended fix you can approve item by item.
Findings map to practical Essential Eight themes (MFA, patching, backups, admin hygiene) without pretending you have an enterprise SOC.
Typical SMB audits surface missing MFA on admin mailboxes, untested backups, open WordPress plugins, and SPF/DKIM/DMARC gaps. We fix what we find when you ask us to.
How it works
A free Discovery Session to map systems, owners, and what “done” looks like for insurers or clients.
Structured review of sites, email, cloud, and devices with evidence captured as we go.
Plain-English findings ranked by risk, with recommended fixes and fixed quotes for remediation.
Optional follow-on work: MFA, patching, backups, website hardening, and staff awareness.
Book a free Discovery Session. We will scope your environment and send a fixed quote before any work starts.
Book a free Discovery SessionTransparent pricing
No gated brochures, no “request a quote” games. These are the real starting prices.
Most popular
From $1,500 + GST
One-off assessment
From $3,500 + GST
Audit plus top fixes
Scoped monthly
After the cleanup
Questions
A one-off small-business security audit typically starts from $1,500 + GST. Hardening work is quoted as fixed items from the report. Ongoing monitoring is scoped monthly to your systems.
A structured review of websites, email, cloud accounts, and devices: what an attacker would try first, ranked by real risk, reported in plain English with remediation options.
It is a practical SMB security audit focused on exposure and controls you can fix. Full red-team penetration testing is a different engagement and only useful once basics are in place.
Audit findings often map to Essential Eight themes such as MFA, patching, backups, and admin privileges. For a full maturity assessment and adoption roadmap, see our Essential Eight Adoption Melbourne service.
Yes. We align recommendations with ACSC / ASD published guidance, including the Essential Eight, and we link official sources on this page so you can verify the baseline yourself.
No. Reports are confidential to your organisation. Public case studies on this site use anonymised industry outcomes only where NDAs apply.
Yes. Most clients ask us to implement the priority items as fixed-price follow-on work. You approve each item before we start.
Most SMB audits complete within one to two weeks after Discovery, depending on access to systems and stakeholders.
Official guidance
Next step
Book a free Discovery Session. We will scope your environment and send a fixed quote before any work starts.