The controls
Where security money actually goes
Four control areas carry most of the risk for an Australian organisation. Budget spread evenly across a longer list defends less than budget spent in this order.
The decision
Run detection in the team you have, or buy managed detection and response
Once the tooling is in place, this is the question that decides whether any of it does anything at three in the morning.
Detection run in house
Your own team knows the environment, the escalation path is short, and nothing leaves the organisation. It works where there are enough people to cover more than business hours and enough time to tune alerts properly. Below that threshold the tooling generates work nobody has room for, and the alerts quietly stop being read.
Suits larger internal teams, unusual environments, strict data constraints
Managed detection and response
An external team watching your telemetry around the clock, investigating alerts and acting on the ones that matter. It buys coverage outside your hours and pattern recognition across many environments. It needs clear authority to act, a response time written into the contract, and a defined path back if you bring it in house.
Suits lean IT teams, out of hours exposure, board level assurance
The process
How a security decision runs with us
Five stages, from what you have already paid for through to a review cadence that stops the controls decaying. You sign directly with the vendor you choose, and the advisory service costs you nothing.
An audit of what you already own
Microsoft and Google licence bundles include security capability that organisations then buy a second time. We map the entitlements already paid for against what is actually deployed and switched on. This step regularly funds a meaningful part of the rest of the programme.
Gaps ranked by what they would cost you
Findings ordered by plausible impact on your organisation rather than by a generic severity score. A critical rating on a system nobody outside can reach matters less than a moderate one on the finance mailbox.
A shortlist matched to the specific gap
Tools and services compared against the gap in front of you rather than against a product category. Doing nothing, and doing it with what you already own, stay on the list as legitimate options.
A proof of value in your own environment
The shortlisted option run across a slice of your real estate for a defined period against agreed success criteria. Security tooling behaves differently on a live network than in a vendor tenancy, and the true noise level only becomes visible on your own data.
Rollout with a review cadence
Deployment, tuning, and a scheduled review that checks the alerts are still being read and the backups are still being restored from. Security controls decay quietly, and the review is the thing that catches it.
Due diligence
What we check that a security demonstration will not show
Every security product demonstrates well against a scripted attack in a clean tenancy. These are the checks that decide whether it helps you on the night.
What your existing licences already entitle you to
Mapped before anything new is quoted. Buying a capability twice is the most common avoidable line in an Australian security budget.
Who responds outside your hours
Whether a person or a queue, in which country, and what happens between the alert firing and somebody with authority acting on it.
The response time written into the contract
The committed figure rather than the marketing one, the point from which it is measured, and what actually happens when it is missed.
Where the telemetry is stored
Which country your logs and alerts are held in, for how long, and who at the provider is able to read them.
The tuning burden in the first ninety days
How many alerts a week your team will handle before the environment settles, and who does that tuning work.
Authority to act
Whether the provider can isolate a machine at two in the morning, or has to wait for one of your people to answer a phone before anything happens.
How it maps to the Essential Eight
Which maturity level the proposed work actually reaches, and which of the eight strategies it leaves untouched.
Exit and what you keep
Whether the detection rules, tuning and incident history built up over three years leave with you or stay with the provider.
Common questions
Asked on most security projects
The questions that come up in nearly every first conversation about security spend, answered without a qualification call first.
Where should an organisation start?
Start with identity, backup and endpoint. Multi-factor authentication everywhere, backups that have been restored from and not merely taken, and endpoint detection that somebody is actually watching. Most incidents we see discussed would have been stopped or contained by those three.
What is managed detection and response?
Managed detection and response is an external team monitoring your security telemetry around the clock, investigating alerts and acting on the ones that matter. It suits organisations that have bought security tooling but have nobody available at two in the morning to respond to what it finds.
Are we paying for tools we already own?
Frequently, yes. Microsoft and Google licensing bundles include security capability that organisations then buy again from a third party. An audit of what your existing licences already entitle you to is usually the cheapest security work available.
How does compliance fit in?
Compliance obligations set a floor, not a ceiling. Meeting an obligation such as the Essential Eight or an industry standard is worth doing on its own terms, and it is a reasonable way to sequence work, but a passing assessment is not the same as being difficult to attack.
What is the Essential Eight?
The Essential Eight is a set of mitigation strategies published by the Australian Signals Directorate, covering application control, patching applications, configuring macro settings, hardening user applications, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. Organisations assess themselves against maturity levels zero to three. It is a sensible way to sequence work and a common requirement in Australian government and enterprise supply chains.
How much should an Australian organisation spend on security?
Published benchmarks land between five and ten per cent of the technology budget, and that range is wide enough to be of limited use on its own. The more useful test is whether identity, backup and endpoint are covered properly before anything else is bought, because a large budget spread thinly across overlapping tools defends less than a smaller one spent in that order.
We are vendor funded and completely free to your business. Always focused on the right outcome.
Spend on the controls that close a real gap
We audit what you already own, rank the gaps by what they would cost you, shortlist against the specific gap, and prove it in your own environment before you commit. You sign directly with the vendor you choose, and our service costs you nothing.
Book a Call
Independent guidance at no cost to your business.
Read further on this
The pages and articles that answer the next question a buyer usually asks.
- AI agents for contact centres
- AI and automation advisory
- Cloud contact centre advisory
- Cloud phone system and UCaaS advisory
- Connectivity and SD-WAN advisory
- the incident response pack, free download
- the IT continuity pack, free download
- connectivity and SD-WAN
- advice for IT leaders
- advice for finance leaders
- ACMA’s 2026-27 priorities, and the SMS deadline

