ProtectSEC

And we keep it standing

Audits, penetration testing, monitoring and compliance support that keep breaches, downtime and awkward disclosure calls out of your quarter.

Cyber Security

Overview

Security failures rarely arrive as sophisticated attacks. They arrive as an unpatched plugin, a shared password, an exposed storage bucket or a staff member clicking a convincing invoice — and they cost far more than the work that would have prevented them.

We provide practical cyber security for businesses that hold customer data but do not have a security team. That means finding the real exposure, fixing what matters first, and giving you monitoring so you learn about a problem before your customers do.

Because we also build software, our findings come with remediation, not just a severity score in a PDF.

What's included

8 inclusions

Security audit and risk assessment

Infrastructure, applications, access control, backups and vendor exposure reviewed and ranked by real business risk.

Penetration testing

Web application, API, network and cloud testing with a report your developers can act on, plus a retest after fixes.

Vulnerability management

Continuous scanning, patch policy and dependency monitoring so known holes do not stay open for months.

Monitoring and incident response

Alerting, log review and a documented response plan for the day something does happen.

Email and identity security

SPF, DKIM, DMARC, multi factor authentication and least privilege access to shut down the most common intrusion routes.

Compliance support

Practical help toward ISO 27001, Essential Eight, SOC 2 readiness, GDPR and Australian Privacy Principles obligations.

Staff awareness training

Phishing simulation and short, practical training for the people attackers actually target.

Secure development

Code review, secrets management and secure by default patterns applied to everything we build.

Our security partners

6 technology stacks

Since 2017 we have delivered assessments, audits and managed defence alongside the vendors below as an authorised partner, distributor or certified implementation team. That means licensing, deployment, tuning and support come from one place instead of three.

SEC

Cyber security

  • AT&T Cybersecurity
  • Barracuda
  • Bitdefender
  • Broadcom
  • Cisco
  • Cofense
  • CrowdStrike
  • Forcepoint
  • GFI
  • IBM
  • Kaspersky
  • Mandiant
  • Nexthink
  • Nuix
  • Okta
  • OpenText
  • Progress
  • Rubrik
  • SonicWall
  • Sophos
  • Skyhigh
  • Tenable
  • Trellix
  • Trend Micro
  • VMware
TOOL

Assessment, forensics and PAM

  • Exterro FTK Forensic Toolkit
  • OpenText EnCase
  • Nessus Professional
  • CYRISMA
  • Bacon Unlimited
  • StrikeReady
  • Positive Technologies MaxPatrol 8
  • PT Industrial Scanner
  • PT MultiScanner
  • BeyondTrust PAM
  • One Identity PAM
  • EaseUS
CLD

Cloud and continuity

  • Acronis
  • AvePoint
  • Cloudamize
  • Dropbox for Business
  • DocuSign
  • IBM
  • Microsoft
  • N-able
  • NetApp
  • Quest
  • Red Hat
  • Sophos
  • Veeam
  • Veritas
  • VMware
  • Zoho
INF

Infrastructure and networking

  • Cisco
  • Dell Technologies
  • Hewlett Packard Enterprise
  • IBM
  • NetApp
  • Oracle
  • ExaGrid
  • CommScope
  • Corning
  • Cradlepoint
  • Extreme Networks
  • NETGEAR
  • Nexans
  • Schneider Electric
  • Vertiv
  • Ekahau
PHY

Physical security and IoT

  • Avigilon
  • Axis Communications
  • AxxonSoft
  • Milestone
  • Motorola Solutions
  • Pelco
  • Optex
  • Fiber SenSys
  • Suprema
  • 2N
  • BCD
  • Veracity
  • IPVideo
  • Supermicro
  • INSYS icom
TRN

Training and professional services

  • A10 Networks
  • Avaya
  • Check Point
  • Cisco
  • Fortinet
  • Forcepoint
  • Broadcom
  • Brocade
  • HPE
  • IBM
  • Kaspersky
  • Red Hat
  • SUSE
  • Skyhigh Security
  • Trellix
  • Veeam
  • Veritas

How we work

Four stages
01

Assess

Establish the attack surface, the crown jewel data and the current controls.

02

Test

Penetration testing and configuration review to find what is genuinely exploitable.

03

Remediate

Fixes prioritised by risk and delivered — by your team or ours — then retested.

04

Monitor

Ongoing scanning, alerting and periodic review as your systems change.

What you get

Outcomes

Questions

FAQ
We are small are we really a target?

Most attacks are automated and indiscriminate. Small businesses are targeted precisely because their controls are weaker and their backups often untested.

Will a penetration test break our systems?

Testing is scoped and scheduled with you, and destructive techniques are excluded unless you explicitly authorise them in a non production environment.

Do you help after an incident?

Yes containment, forensic review, remediation and the documentation you need for insurers and regulators.

How often should we test?

Annually as a baseline, plus after any significant release or infrastructure change. Continuous scanning covers the gaps in between.

Works well with

Related services

Tell us what's broken. We'll tell you honestly if we can fix it.