Think you're being attacked right now? →
About

Who you are dealing with

IN-SEC PTY LTD is a small, independent cyber security practice working with Australian businesses. Not a reseller, not a managed IT provider, and not a firm that quotes you for fixing what it just found.

Independence

Nothing is riding on the findings

We do not sell software, hardware, licences or the remediation work. There is no product to protect and no configuration of our own to defend.

That is not a slogan, it is the reason the assessment is worth anything. A report written by whoever also wants to sell you the fix is a quote with a cover page. When we tell you a control has a gap in it, that finding has nothing attached to it.

How we work

Five rules, and they do not bend

  1. 01

    Read-only, always

    We look at how systems are configured. We do not change settings, install anything or run live tests. If something needs fixing, you or your IT provider fix it.

  2. 02

    Nothing is touched without written authorisation

    A signed scope and authorisation letter comes first, every time, naming the systems in scope and the systems that are not. There is no version of this where somebody said it was fine on the phone.

  3. 03

    Defensive work only

    No penetration testing, no red-team activity, no phishing simulations against your staff without separate written authorisation. If that is what you need, we will say so and point you elsewhere.

  4. 04

    Every finding carries its evidence

    A finding without evidence attached is an opinion. Each one records what was observed, when, and how it was collected — so you can check it, and so can anyone you forward it to.

  5. 05

    What was not covered is written down

    The out-of-scope list is published in the report rather than implied by its absence. Nobody should have to guess what an assessment did not look at.

Frameworks

Measured against ASD Essential Eight

The Essential Eight is the model Australian insurers and tender panels already recognise, so it is the one your evidence is written against. Depth comes from the others.

  • ASD Essential Eight
  • NIST CSF 2.0
  • CIS Controls v8
  • MITRE ATT&CK

Work is described as aligned to the ASD Essential Eight (current model). IN‑SEC is not certified or accredited against the Essential Eight and does not claim authority to certify anyone else — no accreditation scheme for Essential Eight assessors exists, so any firm claiming one is describing something that is not there.

What we will never tell you

We are not lawyers, accountants, insurance brokers or tax agents, and nothing we produce is legal, insurance, tax or regulatory advice. Where a rule has consequences — a reporting obligation, a policy condition, a contractual warranty — we will explain what the rule says, link you to the primary source, and tell you to confirm your own position with your adviser.

This site carries no client names and no testimonials. When it carries them, they will be real, they will be recent, and they will be used with written permission.

The details

Business information

Entity IN-SEC PTY LTD
Service area Australia
Email enquiries@in-sec.org

Twenty minutes is usually enough to tell

Whether this is the right piece of work for you, or whether you should not be spending money on it yet. Both answers happen on that call.

Book a 20-minute call