Who you are dealing with
IN-SEC PTY LTD is a small, independent cyber security practice working with Australian businesses. Not a reseller, not a managed IT provider, and not a firm that quotes you for fixing what it just found.
Nothing is riding on the findings
We do not sell software, hardware, licences or the remediation work. There is no product to protect and no configuration of our own to defend.
That is not a slogan, it is the reason the assessment is worth anything. A report written by whoever also wants to sell you the fix is a quote with a cover page. When we tell you a control has a gap in it, that finding has nothing attached to it.
Five rules, and they do not bend
-
01
Read-only, always
We look at how systems are configured. We do not change settings, install anything or run live tests. If something needs fixing, you or your IT provider fix it.
-
02
Nothing is touched without written authorisation
A signed scope and authorisation letter comes first, every time, naming the systems in scope and the systems that are not. There is no version of this where somebody said it was fine on the phone.
-
03
Defensive work only
No penetration testing, no red-team activity, no phishing simulations against your staff without separate written authorisation. If that is what you need, we will say so and point you elsewhere.
-
04
Every finding carries its evidence
A finding without evidence attached is an opinion. Each one records what was observed, when, and how it was collected — so you can check it, and so can anyone you forward it to.
-
05
What was not covered is written down
The out-of-scope list is published in the report rather than implied by its absence. Nobody should have to guess what an assessment did not look at.
Measured against ASD Essential Eight
The Essential Eight is the model Australian insurers and tender panels already recognise, so it is the one your evidence is written against. Depth comes from the others.
- ASD Essential Eight
- NIST CSF 2.0
- CIS Controls v8
- MITRE ATT&CK
Work is described as aligned to the ASD Essential Eight (current model). IN‑SEC is not certified or accredited against the Essential Eight and does not claim authority to certify anyone else — no accreditation scheme for Essential Eight assessors exists, so any firm claiming one is describing something that is not there.
We are not lawyers, accountants, insurance brokers or tax agents, and nothing we produce is legal, insurance, tax or regulatory advice. Where a rule has consequences — a reporting obligation, a policy condition, a contractual warranty — we will explain what the rule says, link you to the primary source, and tell you to confirm your own position with your adviser.
This site carries no client names and no testimonials. When it carries them, they will be real, they will be recent, and they will be used with written permission.
Business information
| Entity | IN-SEC PTY LTD |
|---|---|
| Service area | Australia |
| enquiries@in-sec.org |
Twenty minutes is usually enough to tell
Whether this is the right piece of work for you, or whether you should not be spending money on it yet. Both answers happen on that call.