Assess
Where are we exposed, and how bad is it?
You cannot govern what has never been measured. Assess establishes a position your board can act on.
Why boards are asking now
Three moves in 2026 changed the question directors have to answer. APRA wrote to regulated entities on artificial intelligence on 30 April. ASIC published 26-092MR on 8 May. The Five Eyes agencies issued a joint statement on 22 June. None ask what you bought. All ask what you can evidence.
The standing obligations assume the same thing. APRA CPS 234 and CPS 230, the Privacy Act 1988, the Aged Care Act 2024 and the SOCI Act in Australia. The Privacy Act 2020, NZISM and NCSC New Zealand guidance in New Zealand. Each presumes you already know where you stand.
Start here if this sounds familiar
Most organisations that engage Insicon Cyber at this stage are functioning fine and simply cannot prove it.
- Your board wants a cyber risk position and nobody can produce one that is not a vendor dashboard.
- An insurer, customer or regulator has sent a questionnaire and the honest answers are uncomfortable.
- Artificial intelligence is already in the business and no governance position sits behind it.
- You are weighing ISO 27001, ISO 42001, Essential Eight or NZISM and need the size of the gap before committing budget.
- You have spent on tooling for years and cannot demonstrate what improved.
- Something happened, it was contained, and nobody established whether it can happen again.
What sits under Assess
Four ways in, depending on how much you already know.
Cyber Readiness Assessment
Your position against the framework that actually applies, whether Essential Eight, ISO 27001 or NZISM. You get a score, a prioritised gap list and a costed path.
Start the assessmentAI Readiness Assessment
Built against the 2026 APRA letter, ASIC 26-092MR and the Five Eyes statement. What artificial intelligence is in your environment, who authorised it, and what defensible governance looks like.
Start the AI assessmentBoard Cyber Advisory
A diagnostic aimed at directors, not the technical team. What the board is accountable for in Australia and New Zealand, what it is currently told, and the distance between the two.
Board Cyber AdvisoryFramework gap assessments
Targeted assessment when you already know the standard. Essential Eight, ISO 27001, ISO 42001, NZISM, APRA CPS 234 and CPS 230.
See Managed ComplianceHow an engagement works
No discovery theatre. The people who scope the work do the work.
Scope in one conversation
A Fractional CISO establishes what you need to prove, to whom, by when. Around forty five minutes.
Evidence, not interviews
Controls tested against artefacts and configuration, not against what people believe is in place.
A score and a costed path
Where you sit, what it takes to move, in what order, at what cost. Written so a board can approve it.
You decide what follows
Take it in house, take it elsewhere, or move into Comply or Operate. The report is yours either way.
Why the assessment is worth the paper
01
The people who set the standard still do the work
Matt Miller, Co-Founder, CEO and Fractional CISO, and Greg Bunt, Co-Founder, Director and Fractional CISO, are in the engagements.
02
We do not mark our own homework
An assessment that always concludes you need the assessor's platform is a sales document. We are not defending a stack.
03
Australian and New Zealand obligations
Assessed against the regulations you actually carry, in both markets, not a global template.
04
Recognised by the market
ISO 27001 certified. Retail Cyber Security Partner of the Year at the 2025 Benchmark Security Awards. Finalist in two categories at the 2026 Australian Cyber Awards.
Where this goes next
Assess, Comply and Operate group our work. They are not a sequence you have to walk. Start where the pressure is.
Get a position you can put in front of a board.
The Cyber Readiness Assessment is a programme entry point. Start there and we will tell you honestly whether you need us.