Skip to main content

You already own
more security than
you have turned on

Most organisations run at a fraction of what their security licences already cover. This review tells you how much you are paying for and not using, and what you can stop paying for altogether.

Rated 5.0 out of 5. on Google reviews · Sydney HQ · Report portable to any provider

What you get

A report you can act on, and take anywhere

Spend map. Every security product you pay for, what it costs, when it renews, and which controls it is supposed to deliver.

Capability heat map. Every capability across the five in-depth platforms, scored licensed, enabled or tuned, so the gap between what you bought and what you run is visible on one page.

Ranked recommendations. Ordered by risk reduction per dollar, each one marked as switch it on, tune it, stop paying for it, or buy it.

Twelve-month plan. Sequenced, with effort and cost against each item, and aligned to your renewal dates so decisions land when you actually have leverage.

Book a scoping call →
Illustrative, not client data

Twelve-month plan

Switch on identity protection

Retire duplicate email gateway

Tune endpoint exclusions

Enable insider risk policies

Operationalise attack surface tool

Close privileged identity gap

Licence tier decision at renewal

Q1Q2Q3Q4
Sequenced to your renewal dates, with effort and cost against each item.

Capability heat map

Five platforms
LicensedEnabledTunedNot covered
The gap between what you bought and what you run, visible on one page.

Security Platform Review

Findings, ranked recommendations and a twelve-month plan.
Yours to keep. Portable to any provider.

Board-ready summary inside

One honest limit. We rank where your next dollar should go and what it costs, but we do not tell you what comparable organisations spend. A credible spend benchmark needs far more engagements behind it than we have run, and we are not going to invent one.

What we find

Three findings, and every one has a number attached

State 1 · Dormant

Paid for, never switched on

Capability your licence already includes, sitting dark. Two answers, both financial: turn it on at no extra cost, or drop a tier and take the money back.

State 2 · Untuned

Switched on, never tuned

Enabled is not the same as effective. We read your actual configuration against what the product is capable of, and show where the distance leaves you exposed.

Beyond the estate

Covered by nothing you own

The genuine gap. This is the only place new money should go, and we tell you how much it costs to close.

← Capability you already pay forWhere new money belongs →

How it runs

Four stages, and the first one is a gate

Gate: nothing starts until intake is back

Gate: nothing starts until intake is back

01 · The gate

Intake

You return the intake pack and provision read-only access. Nothing starts until it is back, which is what keeps the price fixed.

02

Inventory

Every security product you pay for, mapped to controls, cost and renewal. This is where the five depth platforms are selected.

03

Depth review

A senior security architect scores every capability on those five platforms as licensed, enabled or tuned.

04

Report and readout

Findings, ranked recommendations and a twelve-month plan, walked through live with the people who have to act on it.

Day 0 · Intake pack returnedWeek 1Week 2Live readout

Where our skillset sits

Deep on industry leading platforms Honest about all of them

We partner with nine widely deployed security platforms. That is where our depth sits: certified engineers who work in these consoles every week and know what each product can actually do, not just what the datasheet says. If your estate runs on them, the review benefits from that depth.

It does not stop there. We review products we hold no relationship with at all, and we audit beyond these platforms wherever your estate takes us. Recommendations are control outcomes first, products second.

And where a recommendation does involve a platform we partner with, the report says so on the same page as the recommendation, not in an appendix. The fee buys the assessment, nothing obliges you to build with us, and the report is written to be as useful to another provider as it is to us.

Platforms we partner with

Microsoft, CrowdStrike, Fortinet, KnowBe4, UpGuard, Vanta, Picus, Assetnote, Cybereen.

  • Microsoft
  • KnowBe4
  • CrowdStrike
  • Vanta
  • Fortinet
  • UpGuard
  • Assetnote
  • Picus
  • Cybereen

Practitioners, not presenters

Price

$6,400

ex GST · fixed

One price, agreed before we start, and it does not move because the environment turned out to be messier than you said.

Book a scoping call →

In the price

Licence-level inventory of every security product you pay for

Five platforms reviewed at depth by a senior security architect

Spend map, capability heat map and ranked recommendations

Twelve-month plan aligned to your renewal dates

Board-ready summary

Live readout with your team

What the fixed price assumes

Up to around 200 seats

One primary cloud and identity platform

Read-only access provisioned and the intake pack returned before we start

Not included

Implementation, migration or tuning work. This review recommends, it does not build.

Penetration testing or any form of control testing. This is configuration analysis.

Licence procurement. If you want us to help you buy, that is a separate conversation and a separate agreement.

Larger estates, multiple identity platforms, or more than five platforms at depth are quoted after a scoping call. We will tell you on that call if the fixed price still fits.

Before you ask us on the call.

Our vendor consoles already give us a security score. Why pay for this?
Every one of these platforms ships a posture score, and they share three blind spots. They score you against themselves in isolation, so they recommend capability you are already paying another vendor for. They weight everything the same, because they do not know your risk or your regulatory obligations. And they confirm that a toggle is on without establishing that the control is configured to the depth the product actually allows. A vendor score tells you what that vendor thinks of its own deployment. This tells you what you are getting for everything you spend.
What if you recommend something you sell?
We will, sometimes, because we partner with nine widely deployed platforms and some of them are genuinely the right answer. When it happens the report says so on the same page as the recommendation. The fee covers the assessment only, the report is yours to take to any provider, and we are just as willing to tell you that a product we sell is the wrong fit. That is the whole point of charging for the assessment separately.
Do you need admin access to our tenants?
Read-only, scoped to the platforms in the review, and listed explicitly in the intake pack before you grant anything. We do not need write access and we do not ask for it. If your change control makes even read-only access slow, tell us at scoping and we will work from exports instead, which costs a little granularity but does not change the price.
Can we take the report to another provider?
Yes, and it is written on the assumption that you might. Recommendations are expressed as control outcomes and capability requirements, so they are actionable by whoever you choose. If you take it to your incumbent partner and they close everything in it, that is a good outcome and we will not have earned another dollar from it.
How long does it take?
About two weeks from the point your intake pack comes back to the live readout. The clock does not start until the pack is returned and read-only access is provisioned, because that is the single largest cause of assessments running late.

Find out what you are already paying for

A short call tells us whether the fixed price fits your environment. If it does not, we will say so and quote you properly rather than take the engagement and run out of time.

Book a scoping call →$6,400 ex GST, fixed