Everyone will show you the holes. Almost nobody closes them. A security review that ends in a pull request and a patched system, not a sixty-page PDF you file and forget.
Pass 1Every page, every form, every endpoint.
4 holes found. 4 closed. Not a PDF of things for you to do.
The report is the easy half.
Point a scanner at a business and it will find things. That part is nearly free now, and it is why the market is full of people selling you the list. What almost nobody does is the next bit: working out which of those findings actually matter for your business, and then going in and fixing them.
So the list sits in a drive for two years. The login still has no rate limit. The library with the known hole is still the version it was. Nobody was ever going to action a document written for somebody else to action.
We do the second half, because we build things for a living and fixing is the same work. You get told what was wrong in a sentence, and you get it closed.
What gets looked at.
Essential Eight
Where you sit against the ASD's eight controls, honestly, and what it takes to get to the maturity level whoever is asking needs.
Dependencies
Every library you ship, what is behind, and which of the gaps has a published exploit rather than just a version number.
Access
Who can get in, who still can after they left, where multi-factor is missing and which accounts have more power than the job needs.
Configuration
The server, the database, the storage bucket, the admin panel on a default password that has been up since the site launched.
Data
What you hold, where it sits, who it goes to, and whether that matches what your privacy policy says you do.
Backups
Whether they run, and the question nobody asks, whether anyone has ever restored one and watched it come back.
How it's set up.
One call to work out what you've got and what has been asked of you. Then we go through it against a copy of your system, not the live one, and come back with a short list of what is wrong, ranked by what would actually hurt rather than by a severity score.
You pick what gets fixed. We do those as pull requests and configuration changes you can see and approve, the same way any other work lands, and the write-up at the end is one page you can forward to the client, the insurer or the tender that started this.
Most businesses find this comes up alongside everything else that isn't getting done, which is most of what we do. If you want the whole picture scoped before anything is touched, that's the consulting side. We're in Melbourne and work across Australia.
Questions people ask.
Is this a penetration test?
No, and we will not call it one. A pentest is a credentialed discipline with its own accreditation, and anyone selling you scanner output under that name is selling you something else. This is a security review: we read the code, the configuration and the dependencies, find what is wrong, and then fix it.
What is the Essential Eight?
Eight controls the Australian Signals Directorate says stop most of what actually happens to small businesses: patching, application control, macro settings, hardened applications, admin privileges, multi-factor, backups and patching operating systems. There are four maturity levels. Most small businesses sit below level one and have never been told.
Why am I being asked about it?
Because somebody up the chain has to be. Government contracts, enterprise procurement, cyber insurance renewals and tenders all ask now, and the questionnaire lands on a business with nobody to answer it. We work out where you actually sit, then close the gap between there and where the form needs you to be.
What do I get at the end?
A short document that says what was wrong and what we did about it, in language you can forward to whoever asked. Not a sixty-page export with a severity chart. If something is still open, it says so, says why, and says what it would take.
Will you break anything?
We work against a copy, not your live system, and nothing gets deployed without you seeing it first. The point is to find the holes before someone else does, not to prove we can make a mess.
What does a security review cost in Australia?
It depends on how much there is to read, so we scope it first and give you a fixed price in writing before we start. The fixing is usually the bigger half and it is the half most people never get, so it is worth pricing both together.
Photo to come: Cal.
Calum Buchanan.
Melbourne. Ran the systems behind a services business, the phones, the invoices, the marketing, the reporting, and spent the last few years handing them to AI that works. This is that, for yours.