Skip to the main content.

Cyber Advisory Services

Know where you stand against the obligation that binds you.

An independent, expert led Cyber Readiness Assessment for organisations across Australia and New Zealand. We measure your current position against the standard, regulation, or contractual obligation you actually have to answer to, then give you a prioritised roadmap and a board ready briefing. Two to four weeks from scoping.

Essential Eight ISO/IEC 27001:2022 ISO/IEC 42001 APRA CPS 234 and CPS 230 NZISM SMB1001
Request Your Assessment Choose your framework

Why it matters now

$80,850

Average self reported cost of cybercrime per report for Australian businesses, up 50 per cent year on year.

84,700

Cybercrime reports received by the ASD in FY2024-25, an average of one every six minutes.

39%

Of ransomware incidents the ASD responded to were only identified because the ASD contacted the organisation first.

Source: ASD Annual Cyber Threat Report 2024-25, https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025

The problem

Frameworks describe the destination. They do not tell you where you are.

The Essential Eight, ISO 27001, ISO 42001, CPS 230, and NZISM all set out what good looks like. None of them tell you how far you currently are from it, which of your gaps carry the most risk, or what to do first with the budget you actually have. That is the work a readiness assessment does.

01

You cannot protect what you have not measured

Without a structured assessment, organisations over invest in areas of low risk and leave critical exposure unaddressed. The assessment tells you where the risk actually sits before an attacker or an auditor finds it first.

02

Assurance has to be evidenced, not asserted

Regulators, insurers, and enterprise customers increasingly ask for the basis of your assurance, not a statement of it. A documented assessment is the artefact that answers that question.

03

Boards need visibility, not jargon

Directors across Australia and New Zealand are increasingly accountable for cyber outcomes. Our output is written to be tabled at a board meeting, not translated by someone else first.

Choose your framework

One assessment. Scoped to the obligation you answer to.

Same process, same deliverables, same team. What changes is the framework we measure you against. Most organisations have more than one in play, and we scope across them where that is the case.

AUSTRALIA AND NEW ZEALAND

AI Readiness Assessment

Assessed against the APRA letter to industry on AI of 30 April 2026, ASIC 26-092MR of 8 May 2026, the Five Eyes joint statement of 22 June 2026, and ISO/IEC 42001. For organisations that have adopted AI faster than they have governed it.

See the AI Readiness Assessment

AUSTRALIA

Essential Eight Readiness Assessment

Assessed against the ASD Essential Eight Maturity Model, maturity levels zero to three. The most common requirement in Australian government tenders, insurance applications, and enterprise supplier onboarding.

Essential Eight services

AUSTRALIA AND NEW ZEALAND

ISO 27001 Readiness Assessment

Assessed against ISO/IEC 27001:2022, with a projected pathway and indicative timeframe to certification readiness. For organisations where a customer contract or procurement process has made certification a requirement.

ISO 27001 compliance services

AUSTRALIA

Operational Resilience Readiness Assessment

Assessed against APRA CPS 234 and CPS 230. For regulated entities, and for the material service providers whose own controls now sit inside a regulated entity's accountability.

APRA prudential standards

NEW ZEALAND

NZISM Readiness Assessment

Assessed against the New Zealand Information Security Manual and the Privacy Act 2020, with reference to current NCSC New Zealand guidance. For New Zealand public sector organisations and their suppliers.

NCSC New Zealand

AUSTRALIA

SMB1001 Readiness Assessment

Assessed against the SMB1001 cyber resilience standard, a five tier certification pathway. A proportionate starting point for smaller Australian organisations that need a credible baseline quickly.

SMB1001 standard

Is this you

The right starting point if any of these sound familiar.

You have never had a formal cyber review and you are not sure where to start.

Your board is asking cyber questions and you need credible, evidenced answers.

A tender, insurer, or enterprise customer has asked you to demonstrate alignment to a standard.

You are considering certification and want to know the distance before committing to the programme.

You have grown quickly and security has not kept pace. Something feels exposed.

You had an incident or a near miss and want to understand your real exposure.

You want an independent second opinion on what your IT team or current provider has told you.

You operate across the Tasman and need one view of your position in both jurisdictions.

What you receive

Six deliverables. Decision ready.

Not a two hundred page report that sits in a drawer. A set of artefacts your leadership team, your auditor, and your remediation team can each use directly.

01

Current state assessment

A structured review of your existing controls, policies and practices across the domains of your chosen framework, scored against maturity levels with supporting evidence.

02

Findings register

A complete, prioritised register of every finding, categorised by risk level and mapped to the specific control or requirement it relates to. Traceable, auditable, and ready to hand to whoever does the work.

03

Framework alignment summary

A clear view of your current alignment to your chosen framework, with a projected pathway to your target state and indicative timeframes for certification readiness where that is the destination.

04

Prioritised remediation roadmap

A sequenced action plan telling you what to fix first, why, and the level of effort involved. Scoped to your budget and risk appetite, and implementable with or without further Insicon Cyber support.

05

Executive briefing pack

A board and leadership ready summary covering risk posture, key findings, and recommended actions in plain language. Designed to inform decisions, not describe technology.

06

Advisory debrief session

A facilitated session with your Insicon Cyber fractional CISO to walk through findings, answer challenge from your team, and agree the right next steps for your organisation.

How it works

Four steps. Two to four weeks.

Designed to be low friction on your side. Most of the effort sits with us.

01

Scoping and obligation mapping

We confirm which obligations actually bind you, agree the target framework or frameworks, and gather context on your organisation, systems, and risk environment.

02

Assessment and evidence gathering

Our fractional CISO team reviews your current controls against framework requirements through stakeholder interviews, policy review, and technical checks where applicable.

03

Analysis and reporting

Findings are scored and prioritised by risk, likelihood and effort, then compiled into the full deliverable set. The executive briefing pack is prepared in parallel.

04

Debrief and next steps

We present findings to your leadership team, work through the remediation roadmap, and set out your options for progressing toward certification or ongoing uplift.

Lower commitment option

Want a fast technical picture first?

In partnership with TrendAI, we offer a rapid, non invasive scan of your environment. A useful starting point if you want evidence before committing to a full readiness assessment, or if you need something concrete to put in front of your board or leadership team first.

Cloud infrastructure misconfiguration and compliance gaps

Internet facing asset vulnerabilities and insecure connections

Microsoft 365 and Gmail email threats and endpoint exposure

Common vulnerabilities and exposures across your estate

Staff phishing vulnerability identification

Downloadable report with recommended response actions

Request a TrendAI Scan

Includes a 30 day full access trial of TrendAI Vision One.

Your assessment team

Founder reviewed. Every time.

Matt Miller and Greg Bunt are Co-Founders and Fractional CISOs at Insicon Cyber, and both remain in client-facing roles. Whoever runs your assessment, a founder reviews the output before it reaches you.

"The question is not which framework to target. The more important question is: what are we actually doing today to reduce the likelihood of a breach, and is it enough?"

Matt Miller, Co-Founder, CEO, and Fractional CISO, Insicon Cyber

CO-FOUNDER, CEO, AND FRACTIONAL CISO

Matt Miller

Matt works directly with boards and executive teams across Australia and New Zealand, translating cyber risk into decisions leadership can actually make. His experience spans board briefings through to operational programme delivery, with depth across the Essential Eight, ISO/IEC 27001:2022, and APRA requirements. He is a 2026 Australian Cyber Awards finalist for CISO of the Year.

CO-FOUNDER, DIRECTOR, AND FRACTIONAL CISO

Greg Bunt

Greg brings technical and governance depth to Insicon Cyber's assessment and advisory work. His experience across the Essential Eight and ISO/IEC 27001:2022 ensures assessments translate into practical, implementable outcomes. His hands on approach means findings are grounded in operational reality, not theory.

Why Insicon Cyber

We can act on our own findings.

Independent by construction

Our fractional CISOs carry no product quota. We do not onsell platforms. The assessment tells you what we found, not what we need you to buy.

The team that finds it can fix it

Most firms assess and exit. We can carry the findings through to implementation, certification readiness, and ongoing operation. Nothing is lost re briefing a second supplier.

Australia and New Zealand depth

The Essential Eight, APRA CPS 234 and CPS 230, the Privacy Act, NZISM, the NZ Privacy Act 2020, and NCSC New Zealand guidance. One team, both jurisdictions.

ISO 27001 certified ourselves

We hold ISO 27001 certification. When we assess your readiness, we are speaking from having been through the process, not from theory.

Scoped to you, not templated

Every assessment is built around your sector, your size, your systems, and the specific obligations you carry. There are no off the shelf templates.

Written for the board table

Deliverables are designed to be presented to directors and executives, informed by what boards across Australia and New Zealand are actually being asked to answer for.

After the assessment

Close the gap. Then hold it closed.

The assessment gives you a documented position and a plan. Where you want support closing the priority items, the same team can carry it through. There is no obligation to continue, and the roadmap is written so that you can act on it independently if you choose to.

Strategic advice

Fractional CISO leadership and board advisory, carrying the findings upstairs and keeping them on the agenda.

CISO as a Service

Compliance programme

Programme delivery and certification readiness. Insicon Cyber prepares your organisation. An accredited certification body issues the certificate.

Managed Compliance

AI security and governance

Test it. Govern it. Maintain it. AI assurance, ISO/IEC 42001 implementation, and ongoing governance.

AI Security and Governance

Keeping risk in tolerance

The Adaptive SOC, backed by Insicon Cyber analysts, keeping detection and response continuous once the programme lands.

Security Operations Centre

Get started

Find out where you actually stand.

Tell us about your organisation and a member of our team will be in touch within one business day to discuss scope and pricing.

Founder reviewed before it reaches you. Every time, no exceptions.

Two to four weeks from scoping. Fast enough to be timely, thorough enough to be trusted.

Outputs are board ready and actionable. You leave with a document you can act on, not a report that sits on a shelf.

Australia and New Zealand. We deliver across both markets, against both regulatory contexts.

Request your assessment

Or email info@insiconcyber.com

Sources and references

ASD Annual Cyber Threat Report 2024-25 https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025
ASD Essential Eight Maturity Model https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight
ASD and AICD Cyber Security Priorities for Boards of Directors 2025-26 https://www.cyber.gov.au/resources-business-and-government/governance-and-user-education/governance/cyber-security-priorities-boards-directors
APRA prudential standards, including CPS 234 and CPS 230 https://www.apra.gov.au
National Cyber Security Centre New Zealand https://www.ncsc.govt.nz
ISO/IEC 27001:2022 Information Security Management Systems https://www.iso.org/standard/27001
ISO/IEC 42001 Artificial Intelligence Management System https://www.iso.org/standard/42001
SMB1001 Cyber Resilience Framework https://www.smb1001.com.au