Cyber security Brisbane

Cyber security services in Brisbane

We advise Brisbane organisations on what to spend security money on, in what order, and what a managed service is genuinely taking off your plate. We are paid by the provider that is selected rather than by you, and in Queensland we pay particular attention to response coverage, because “eastern time” means two different things for five months of the year.

Where the money goes

What actually reduces risk in a Brisbane business

Four areas carry most of the risk. The order matters more than the brand on any of them.

01

Identity, first and by a distance

Multi-factor authentication on every account that can reach data, and a real process for removing access when somebody leaves. It prevents more incidents than everything else on this page combined, it is usually already licensed, and it is the one control that works the same at three in the morning whatever timezone your provider is in.

02

Backups you have actually restored from

A backup that has never been restored is a report, not a backup. Test a restore, time it against how long the business can genuinely be down, and check where the copies physically sit, because Queensland organisations frequently find their offsite copy is only offsite as far as Sydney.

03

Who responds outside your hours, in which eastern time

Whether a person or a queue, in which country, and what happens between the alert firing and somebody acting on it. In Queensland there is a second question: a contract promising cover until six in the evening eastern time is promising you an hour less than you think for five months a year. Get the timezone written down, not assumed.

04

The Queensland policy you will be measured against

Queensland departments work to Information Security Policy IS18, which requires a risk-based approach to information security across every department and flows through to suppliers holding departmental data. It is risk-based rather than prescriptive, which means the evidence you produce matters more than the product you bought.

The decision

Build detection in house, or buy managed detection and response

This decision sets your security operating cost for the next three years. It turns on staffing, and in Queensland it also turns on whose clock the roster is written in.

In house

You keep the context, the tuning and the institutional knowledge. You also need people awake at three in the morning, which is where this option usually fails. It suits organisations with an existing team and a genuine reason to hold the capability.

Suits an existing team you can roster around the clock

Managed detection and response

Somebody is watching at three in the morning and that is most of the value. The question is authority: whether they can isolate a machine without you, or only tell you about it. Ask what leaves with you if you change provider in three years.

Suits most organisations, provided the cover hours are stated in Queensland time

Due diligence

What we check that a demonstration will not show you

A demonstration shows the product working in ideal conditions. These decide what it is like to own.

Capability you are buying twice

Buying a control you already own inside another licence is the most common avoidable line in a security budget, and it is found by inventory rather than by argument.

Where the telemetry is stored

Which country your logs and alerts are held in, for how long, and who at the provider is able to read them.

Authority to act

Whether the provider can isolate a machine at two in the morning, or has to wait for one of your people to answer a phone.

Exit, and what you keep

Whether the detection rules, tuning and incident history built up over three years leave with you or stay with the provider.

Which eastern time the contract means

A response window written as eastern time is an hour out for five months a year in Queensland. Get it stated explicitly and test the escalation path at both changeovers.

Evidence against IS18, not just a product list

Queensland IS18 is risk-based rather than prescriptive, so what you are asked for is the assessment and the evidence rather than the brand of the tool.

Common questions

Asked by Brisbane organisations

The questions that come up in nearly every first conversation about security spend here.

Where should a Brisbane organisation start?

Identity, backup and endpoint, in that order. Multi-factor authentication on every account that can reach data, backups that have been restored from rather than merely reported as successful, and endpoint protection that somebody actually watches.

We work with Queensland government. What do we need to show?

Evidence against Information Security Policy IS18, which requires a risk-based approach across every Queensland department and flows through to suppliers holding departmental data. Because it is risk-based rather than prescriptive, the assessment and the evidence matter more than which product you bought.

Does daylight saving affect our security cover?

It affects the contract more than the technology. Queensland does not observe daylight saving, so for roughly five months a year a provider working to Sydney hours is an hour out from yours. A response window written as “eastern time” needs to say which one, and after hours escalation paths should be tested at both changeovers.

What does the Essential Eight actually require?

Eight mitigation strategies with four maturity levels, and the honest answer is that most organisations sit between level one and two on some strategies and nowhere on others. The useful exercise is establishing which level each of the eight currently reaches, because that is what turns a security budget into a plan rather than a shopping list.

Should we run detection in house or buy managed response?

It depends on whether you can staff it around the clock, which most organisations cannot. The question worth asking a managed provider is what they are permitted to do without you: isolating a machine at two in the morning is response, sending you an email is monitoring, and the price difference between them is smaller than the outcome difference.

What does your advice cost us?

Nothing. We are vendor funded, so the service costs your business nothing.

We are vendor funded and completely free to your business. Always focused on the right outcome.

Spend the security budget in the right order

Tell us what you already own and what worries you. We come back with what closes a real gap, what overlaps with something you are already paying for, and what a managed service would genuinely take off your plate.

Book a Call

Independent guidance at no cost to your business.

Read further on this

The pages and articles that answer the next question a buyer usually asks.