Cyber security
Cyber Security
Security is a maintenance discipline, not a product you buy once. We find the weaknesses, fix the ones that matter first, and keep watching — with plain-language reporting your board can act on.

Assessment and penetration testing
External and internal testing of your websites, applications, cloud configuration and identity setup. Findings are ranked by realistic business impact, each with a specific remediation step and an owner — not a 200-page scanner dump.
Hardening and Essential Eight alignment
Patch discipline, multi-factor authentication, application control, least-privilege administration, backup integrity and logging. We map your current posture against the Essential Eight and work through a prioritised uplift plan.
Monitoring and incident response
Continuous monitoring for suspicious access, malware and configuration drift, backed by a documented response playbook covering containment, recovery, evidence handling and notification obligations.
People and process
Most breaches begin with a person, not a firewall. Awareness training, simulated phishing and clear reporting paths measurably reduce the likelihood of a successful attack.
What you get
- Prioritised, actionable findings
- Essential Eight uplift roadmap
- Documented incident response plan
- Staff awareness training
Delivered by our brands
The teams behind cyber security
Security engagements are led by Cipher Synapse and operationalised by our managed IT and network brands, so findings actually get fixed.
Cyber security & AI
Cipher Synapse
Security testing, hardening and applied AI — threat monitoring, automation and intelligent tooling.
Managed IT services
My Global MSP
Our flagship managed service provider: helpdesk, endpoint management, patching and proactive monitoring for Australian businesses.
Wholesale connectivity
Australian Wholesale Networks
Wholesale network services — NBN, fibre, data and voice carriage for channel partners.
IT projects & consulting
NEXIOUS IT
Project delivery and IT consulting — migrations, network builds, Microsoft 365 and infrastructure modernisation.
Core infrastructure
Root Layer Technologies
The infrastructure layer beneath the group — compute, networking, DNS and platform engineering.
In detail
Exactly what cyber security looks like when we deliver it
Deliverables
- Essential Eight maturity assessment with a scored, prioritised remediation plan
- MFA enforcement across email, remote access and administrative consoles
- Managed endpoint detection and response with 24/7 alert triage
- Email authentication hardening: SPF, DKIM and staged DMARC enforcement
- Immutable offsite backups with tested restore evidence
- Incident response plan with named contacts and notifiable data breach steps
How the engagement runs
- Week 1Assessment across all eight mitigation strategies plus identity review.
- Week 2-3Quick wins: MFA, admin privilege restriction, patch baseline, backups.
- Week 4-8Application control, hardening, logging and response runbooks.
- QuarterlyRe-assessment, tabletop exercise and board-ready reporting.
What we measure
- Framework
- ACSC Essential Eight
- Privacy alignment
- Australian Privacy Principles
- Alert triage
- 24/7/365
Platforms we use
- Microsoft Defender
- Entra ID Conditional Access
- Intune
- Cloudflare Zero Trust
- SIEM alerting
- Immutable backup
Not included
- Penetration testing by an independent assessor, which we coordinate rather than self-assess
- Cyber insurance underwriting, though we supply the evidence insurers ask for
We list exclusions up front so a proposal never arrives with surprises attached.
Cyber security for your industry
- Professional servicesLaw, accounting, consulting and advisory firms that live on confidentiality, availability and billable time.
- Healthcare & allied healthClinics, practices and allied health providers handling sensitive patient data under Australian privacy obligations.
- SaaS & technologySoftware companies that need delivery capacity, secure infrastructure and a marketing engine that scales.
- Education & not-for-profitSchools, training providers and community organisations delivering more with constrained budgets.
Commitments
What every engagement includes as standard
- Response targets
- P1 within 15 minutes, P2 within 1 business hour, P3 within 1 business day — measured and reported, not aspirational.
- Reporting
- A monthly service report covering tickets, uptime, patch state, backups and open risks, plus a quarterly strategy review.
- Data residency
- Australian workloads stay in Australian regions by default; UK, US and NZ clients are hosted in-region on request.
- No lock-in
- You own your domains, DNS, cloud tenancies and documentation. Exit assistance is written into every agreement.
Cyber security questions, answered
Where does a security uplift start?
With an assessment of identity, endpoints, email, backups and exposed services, scored by risk and effort. You get a prioritised remediation plan rather than a 90-page PDF.
Can you help us meet Essential Eight expectations?
Yes. We map your current state against the Essential Eight maturity levels, agree a realistic target, and implement the controls in stages with evidence captured as we go.
What happens if we are breached?
Managed clients get incident response with containment, forensic preservation, recovery from tested backups, and help with notification obligations under Australian privacy law.
Do you provide staff awareness training?
Yes — phishing simulation and short, practical training, because the majority of incidents still begin with a person, not a firewall.
Ready to talk cyber security?
Tell us what you are trying to fix or grow. You will speak with an engineer, not a salesperson, and leave the call with a clear view of scope, timeline and cost.
