Cyber Security & Compliance
Cyber security
Know your weaknesses before someone else finds them — and be able to show a board, an auditor or an insurer what you did about them.
Security as a program, not a product list
Almost every organisation we take over already owns security products. What is usually missing is the program around them: someone actively watching, someone responding, evidence being collected, and a posture that is measured rather than assumed.
There is no single control that protects against every attack path. What works is layers, maintained — and a documented position you can point at when someone asks.
What the Secure half of NEVO includes
- 24/7 managed threat detection and response — see MDR
- Weekly security checks and an Essential Eight program with a mapped posture and a remediation plan
- Identity security — multi-factor authentication, admin rights review and offboarding that actually closes accounts
- Email and phishing defence — see anti-phishing and spam
- Quarterly staff awareness training — see awareness training
- Independent penetration testing through Vonahi Security, so the assessment is not marked by the same party that built it
- Backups verified by test restore — see business continuity
- Quarterly board reporting in plain language, covering what moved and what did not
Why this sector is different
A club holds member identity and financial data and operates under a gaming licence. A practice or care provider holds health records, which is among the most sensitive category of personal information there is, and carries accreditation obligations on top.
In both cases the organisation is accountable for information it cannot easily de-identify, held in systems it did not build. That is a governance problem before it is a technical one, which is why the reporting matters as much as the controls.
“One of the most important projects you have done for us, now becoming very apparent, is our cyber security — looking at whether we have all the right applications in place so that we aren't at risk. You're on the front foot with those sorts of things.”
— Robyn Mortimer, Chief Financial Officer, St Andrews, Ballina
Common questions
Where do we start if we have no idea of our current position?
With a Technology Review. Cyber posture is one of the six areas it covers, and you get a written position with risks ranked — which is the thing most boards are actually missing.
Do you provide cyber insurance?
No. We are not an insurer or a broker. We do provide the evidence an insurer asks for, which is increasingly what determines whether a policy responds and what it costs.
Can you guarantee we won't be breached?
No, and nobody can. What a program does is reduce the likelihood, limit the damage, and make recovery a tested procedure rather than an improvisation. Any provider offering a guarantee here is selling something they cannot deliver.
Related
Book a Technology Review.
One to two hours onsite, across support, cyber posture, backup and recovery, infrastructure, Microsoft 365 and where the organisation is heading. You receive a written findings report within five days — prioritised risks, quick wins and gaps, in writing.
$1,500 including GST. Credited in full against your engagement if you proceed.
The report is yours to keep regardless of what you decide to do next.
The 90-day guarantee. Give us 90 days. If you're not satisfied with our service in that time, cancel and we'll refund our fees. You keep the audit, the report and every improvement we've made. Third-party hardware, licences and subscriptions purchased on your behalf are excluded. Full terms
