Assessments

One Methodology.Seven Obligations.

Every engagement uses the same passive methodology. What changes is the framework the findings map to, and the audience the report is written for.

7Obligations, one methodology
9Frameworks mapped
5 daysTypical delivery
$1,500Board-ready assessment, from — ex GST

Passive only — no systems, networks or accounts are accessed at any point.

Which Assessment
Do You Need?

Assessments are organised by the obligation you carry rather than by technology. If more than one applies, they combine into a single engagement and a single report.

What Does Not Change

  • Passive only — no systems, networks or accounts are accessed, probed or tested at any point. No authorisation to test is required and no operational risk is introduced.
  • Evidence attached to every finding — nothing is asserted that cannot be reproduced from publicly available sources.
  • Triaged, not counted — findings are prioritised against confirmed exploitation status, exploitation probability and asset exposure, so you receive decisions rather than a severity histogram.
  • Dual-audience reporting — a Board section stating the position plainly, and a technical section your security function or auditors can verify independently.
  • A recorded rationale for every finding not remediated immediately, which is the artefact that matters if the question is asked after an incident rather than before one.

Packages and pricing are set out on the assessment packages page. To scope an engagement against your specific obligations, book a short call.

Assessed Against the Obligation
You Actually Carry

Every engagement is the same passive methodology. What changes is the framework the findings are mapped to, and the audience the report is written for.

AI Governance
AI Governance Assessment

Find the AI you are running, not the AI you declared — exposed model endpoints, MCP servers and shadow deployments, mapped to ISO/IEC 42001.

View Assessment →
APRA CPS 234
CPS 234 Assessment

Independent external exposure evidence mapped clause by clause to the APRA prudential standard — for your Board and internal audit function.

View Assessment →
ASD Essential Eight
Essential Eight Assessment

Externally verified evidence against the mitigation strategies that can honestly be assessed from outside — and an explicit statement of those that cannot.

View Assessment →
Privacy Act & APPs
Privacy Act & APP 11 Assessment

What your organisation exposes, mapped to the Australian Privacy Principles — including tracking, consent sequencing and overseas disclosure.

View Assessment →
Supply Chain
Third-Party Risk Assessment

What your suppliers actually expose, observed from outside without their cooperation. Evidence rather than questionnaires.

View Assessment →
AML/CTF Tranche 2
Tranche 2 Cyber Assessment

For law firms, accountants, conveyancers and agencies now holding seven years of client identity documents under obligations that commenced 1 July 2026.

View Assessment →

Start With What
You Actually Expose.

Every assessment begins from the same place: an independent, evidenced view of what your organisation presents to the outside world. Passive only. Nothing accessed.

Request an Assessment →
Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber Which one do I need? →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report