Think you're being attacked right now? →
Fixed price — fixed scope

Answer the security questionnaire in front of you, with evidence behind every line

An independent review of your security controls, producing evidence you can hand to an insurer, a tender panel or a customer running a vendor assessment.

Book a 20-minute call

$2,950 fixed price. Prices in Australian dollars, excluding GST.

Who books this

Three ways people end up on this page

The renewal

Your insurer sent a questionnaire

Forty questions about controls, and the honest answer to a third of them is that nobody has actually checked. Guessing on an insurance form is its own risk.

The deal

A client is running a vendor assessment

Procurement wants evidence before they sign. The contract is waiting on a document you do not have, and the deadline is theirs, not yours.

The doubt

Someone asked and you were not sure

A director, an accountant, a new IT provider. The question was reasonable and the answer was vague, and it has been sitting there since.

What you receive

Five documents, not a conversation

The work produces artefacts. Everything below is yours to keep, forward and attach to a form — which is the entire point of paying for it rather than guessing.

  1. Executive summary

    One page, written for an owner or a board. The version you forward without having to explain it first.

  2. Readiness report

    Every control assessed against the ASD Essential Eight, with the evidence for each finding attached. A finding without evidence is an opinion.

  3. Prioritised remediation plan

    Phased, with effort estimates, so you can decide what to do this month and what waits until next quarter.

  4. Risk matrix

    Likelihood against impact, in language a non-technical director can act on.

  5. Published scope boundary

    Written down before we start and included in the report, so nobody has to guess what was and was not covered.

How it runs

Four stages, and you are not left guessing during any of them

  1. 01

    Scope, in writing, before anything is touched

    A scope and authorisation letter naming the systems in scope, what will not be touched, the dates, and who signs. Nothing happens until that comes back signed.

  2. 02

    The review

    Read-only. We look at how your systems are actually configured rather than asking you to describe them, and we record the evidence for each finding as we go. No changes are made to anything.

  3. 03

    The write-up

    Every finding gets the same four parts: what the condition is, why it exists, what it means for you, and what to do about it. Findings are ordered by what is worth doing first, not by what scores worst.

  4. 04

    The walkthrough

    We go through the report together so you can use it rather than file it. You leave knowing which three things to do this month and which can wait.

What this is not

This is not a penetration test. It is not a SOC 2 audit. It is not an incident response retainer. It is a fixed-scope assessment of how the business would hold up against ransomware and business email compromise, measured against the ASD Essential Eight, with a prioritised plan to close the gaps.

Out of scope, always: no live testing, no simulated phishing against your staff without separate written authorisation, and no red-team activity of any kind.

Deliverables are worded as aligned to the ASD Essential Eight (current model), and nothing stronger. No accreditation scheme exists for Essential Eight assessors, so IN‑SEC does not claim to be certified, accredited or authorised to certify anyone against it — and neither should anyone else.

Price

$2,950 fixed price

One number, agreed before the work starts. Prices in Australian dollars, excluding GST.

80-150 staff or multi-entity: $3,950. More systems and more people means more to assess, and quoting one price for both would mean over-charging the smaller business.

  • 50% on signature. Work does not start until it clears.
  • 50% on delivery of the report.
  • Retainers are billed monthly in advance, with 30 days notice either way.
  • Invoices are due within 7 days.
Afterwards

We do not quote the remediation

The assessment is independent because nothing is riding on the findings. If the report says your MFA coverage has a hole in it, that finding is not attached to a quote for fixing it.

Most people take the prioritised plan to whoever already runs their IT. If you would rather have someone keeping an eye on it month to month, the Micro-vCISO Retainer exists for that — but it is a separate decision, made later, and the Readiness Check stands on its own.

Questions people actually ask
Will you touch anything, or break anything?

No. The review is read-only throughout. We look at configuration and records; we do not change settings, install anything, or run tests against live systems. That is written into the authorisation letter before we start.

How is this different from the free online questionnaires?

A free tool scores the answers you type into it. That is a self-assessment, and a self-assessment is usually the exact thing your insurer or your client is asking you to go beyond. Here a person looks at how your systems are actually configured and writes down the evidence for each finding.

If you have not done one yet, start with a free tool anyway. Orienting yourself before you spend money is a sensible first move.

Do we need to be on Microsoft 365?

Microsoft 365 or Google Workspace — both are covered. If you run something else, say so on the call and we will tell you honestly whether this is the right piece of work for you.

What do you need from us?

A signed authorisation letter, read-only access to the systems in scope, and one person who can answer questions about how the business actually works. That last one matters more than the access does.

Can you just have a quick free look first?

Not at your systems, no — touching anything without written authorisation is the line this business does not cross, and a rushed look produces a wrong answer with your name on it. The twenty-minute call is free, and it is usually enough to tell you whether you need this at all.

Will this make us compliant?

No, and be careful with anyone who says it will. It tells you where you actually stand and gives you evidence to show for it. Whether that satisfies a particular insurer, contract or regulator is their call, and for anything with legal consequences you should confirm your position with your lawyer.

Bring the questionnaire to the call

Twenty minutes. We will go through what is being asked of you and whether this is the right answer to it. If it is not, you will be told that.

Book a 20-minute call