Answer the security questionnaire in front of you, with evidence behind every line
An independent review of your security controls, producing evidence you can hand to an insurer, a tender panel or a customer running a vendor assessment.
$2,950 fixed price. Prices in Australian dollars, excluding GST.
Three ways people end up on this page
Your insurer sent a questionnaire
Forty questions about controls, and the honest answer to a third of them is that nobody has actually checked. Guessing on an insurance form is its own risk.
A client is running a vendor assessment
Procurement wants evidence before they sign. The contract is waiting on a document you do not have, and the deadline is theirs, not yours.
Someone asked and you were not sure
A director, an accountant, a new IT provider. The question was reasonable and the answer was vague, and it has been sitting there since.
Five documents, not a conversation
The work produces artefacts. Everything below is yours to keep, forward and attach to a form — which is the entire point of paying for it rather than guessing.
-
Executive summary
One page, written for an owner or a board. The version you forward without having to explain it first.
-
Readiness report
Every control assessed against the ASD Essential Eight, with the evidence for each finding attached. A finding without evidence is an opinion.
-
Prioritised remediation plan
Phased, with effort estimates, so you can decide what to do this month and what waits until next quarter.
-
Risk matrix
Likelihood against impact, in language a non-technical director can act on.
-
Published scope boundary
Written down before we start and included in the report, so nobody has to guess what was and was not covered.
Four stages, and you are not left guessing during any of them
-
01
Scope, in writing, before anything is touched
A scope and authorisation letter naming the systems in scope, what will not be touched, the dates, and who signs. Nothing happens until that comes back signed.
-
02
The review
Read-only. We look at how your systems are actually configured rather than asking you to describe them, and we record the evidence for each finding as we go. No changes are made to anything.
-
03
The write-up
Every finding gets the same four parts: what the condition is, why it exists, what it means for you, and what to do about it. Findings are ordered by what is worth doing first, not by what scores worst.
-
04
The walkthrough
We go through the report together so you can use it rather than file it. You leave knowing which three things to do this month and which can wait.
This is not a penetration test. It is not a SOC 2 audit. It is not an incident response retainer. It is a fixed-scope assessment of how the business would hold up against ransomware and business email compromise, measured against the ASD Essential Eight, with a prioritised plan to close the gaps.
Out of scope, always: no live testing, no simulated phishing against your staff without separate written authorisation, and no red-team activity of any kind.
Deliverables are worded as aligned to the ASD Essential Eight (current model), and nothing stronger. No accreditation scheme exists for Essential Eight assessors, so IN‑SEC does not claim to be certified, accredited or authorised to certify anyone against it — and neither should anyone else.
$2,950 fixed price
One number, agreed before the work starts. Prices in Australian dollars, excluding GST.
80-150 staff or multi-entity: $3,950. More systems and more people means more to assess, and quoting one price for both would mean over-charging the smaller business.
- 50% on signature. Work does not start until it clears.
- 50% on delivery of the report.
- Retainers are billed monthly in advance, with 30 days notice either way.
- Invoices are due within 7 days.
We do not quote the remediation
The assessment is independent because nothing is riding on the findings. If the report says your MFA coverage has a hole in it, that finding is not attached to a quote for fixing it.
Most people take the prioritised plan to whoever already runs their IT. If you would rather have someone keeping an eye on it month to month, the Micro-vCISO Retainer exists for that — but it is a separate decision, made later, and the Readiness Check stands on its own.
Will you touch anything, or break anything?
No. The review is read-only throughout. We look at configuration and records; we do not change settings, install anything, or run tests against live systems. That is written into the authorisation letter before we start.
How is this different from the free online questionnaires?
A free tool scores the answers you type into it. That is a self-assessment, and a self-assessment is usually the exact thing your insurer or your client is asking you to go beyond. Here a person looks at how your systems are actually configured and writes down the evidence for each finding.
If you have not done one yet, start with a free tool anyway. Orienting yourself before you spend money is a sensible first move.
Do we need to be on Microsoft 365?
Microsoft 365 or Google Workspace — both are covered. If you run something else, say so on the call and we will tell you honestly whether this is the right piece of work for you.
What do you need from us?
A signed authorisation letter, read-only access to the systems in scope, and one person who can answer questions about how the business actually works. That last one matters more than the access does.
Can you just have a quick free look first?
Not at your systems, no — touching anything without written authorisation is the line this business does not cross, and a rushed look produces a wrong answer with your name on it. The twenty-minute call is free, and it is usually enough to tell you whether you need this at all.
Will this make us compliant?
No, and be careful with anyone who says it will. It tells you where you actually stand and gives you evidence to show for it. Whether that satisfies a particular insurer, contract or regulator is their call, and for anything with legal consequences you should confirm your position with your lawyer.
Bring the questionnaire to the call
Twenty minutes. We will go through what is being asked of you and whether this is the right answer to it. If it is not, you will be told that.