Skip to the main content.

Assess

Where are we exposed, and how bad is it?

You cannot govern what has never been measured. Assess establishes a position your board can act on.

Why boards are asking now

Three moves in 2026 changed the question directors have to answer. APRA wrote to regulated entities on artificial intelligence on 30 April. ASIC published 26-092MR on 8 May. The Five Eyes agencies issued a joint statement on 22 June. None ask what you bought. All ask what you can evidence.

The standing obligations assume the same thing. APRA CPS 234 and CPS 230, the Privacy Act 1988, the Aged Care Act 2024 and the SOCI Act in Australia. The Privacy Act 2020, NZISM and NCSC New Zealand guidance in New Zealand. Each presumes you already know where you stand.

Start here if this sounds familiar

Most organisations that engage Insicon Cyber at this stage are functioning fine and simply cannot prove it.

  • Your board wants a cyber risk position and nobody can produce one that is not a vendor dashboard.
  • An insurer, customer or regulator has sent a questionnaire and the honest answers are uncomfortable.
  • Artificial intelligence is already in the business and no governance position sits behind it.
  • You are weighing ISO 27001, ISO 42001, Essential Eight or NZISM and need the size of the gap before committing budget.
  • You have spent on tooling for years and cannot demonstrate what improved.
  • Something happened, it was contained, and nobody established whether it can happen again.

What sits under Assess

Four ways in, depending on how much you already know.

Cyber Readiness Assessment

Your position against the framework that actually applies, whether Essential Eight, ISO 27001 or NZISM. You get a score, a prioritised gap list and a costed path.

Start the assessment

AI Readiness Assessment

Built against the 2026 APRA letter, ASIC 26-092MR and the Five Eyes statement. What artificial intelligence is in your environment, who authorised it, and what defensible governance looks like.

Start the AI assessment

Board Cyber Advisory

A diagnostic aimed at directors, not the technical team. What the board is accountable for in Australia and New Zealand, what it is currently told, and the distance between the two.

Board Cyber Advisory

Framework gap assessments

Targeted assessment when you already know the standard. Essential Eight, ISO 27001, ISO 42001, NZISM, APRA CPS 234 and CPS 230.

See Managed Compliance

How an engagement works

No discovery theatre. The people who scope the work do the work.

1

Scope in one conversation

A Fractional CISO establishes what you need to prove, to whom, by when. Around forty five minutes.

2

Evidence, not interviews

Controls tested against artefacts and configuration, not against what people believe is in place.

3

A score and a costed path

Where you sit, what it takes to move, in what order, at what cost. Written so a board can approve it.

4

You decide what follows

Take it in house, take it elsewhere, or move into Comply or Operate. The report is yours either way.

Why the assessment is worth the paper

01

The people who set the standard still do the work

Matt Miller, Co-Founder, CEO and Fractional CISO, and Greg Bunt, Co-Founder, Director and Fractional CISO, are in the engagements.

02

We do not mark our own homework

An assessment that always concludes you need the assessor's platform is a sales document. We are not defending a stack.

03

Australian and New Zealand obligations

Assessed against the regulations you actually carry, in both markets, not a global template.

04

Recognised by the market

ISO 27001 certified. Retail Cyber Security Partner of the Year at the 2025 Benchmark Security Awards. Finalist in two categories at the 2026 Australian Cyber Awards.

Get a position you can put in front of a board.

The Cyber Readiness Assessment is a programme entry point. Start there and we will tell you honestly whether you need us.