Cyber security

Cyber Security

Security is a maintenance discipline, not a product you buy once. We find the weaknesses, fix the ones that matter first, and keep watching — with plain-language reporting your board can act on.

Security analyst reviewing a threat timeline and endpoint status dashboard on dual monitors
Cyber Security delivered by our own engineers across Brisbane, Sydney, Wellington, the UK and San Francisco.

Assessment and penetration testing

External and internal testing of your websites, applications, cloud configuration and identity setup. Findings are ranked by realistic business impact, each with a specific remediation step and an owner — not a 200-page scanner dump.

Hardening and Essential Eight alignment

Patch discipline, multi-factor authentication, application control, least-privilege administration, backup integrity and logging. We map your current posture against the Essential Eight and work through a prioritised uplift plan.

Monitoring and incident response

Continuous monitoring for suspicious access, malware and configuration drift, backed by a documented response playbook covering containment, recovery, evidence handling and notification obligations.

People and process

Most breaches begin with a person, not a firewall. Awareness training, simulated phishing and clear reporting paths measurably reduce the likelihood of a successful attack.

What you get

  • Prioritised, actionable findings
  • Essential Eight uplift roadmap
  • Documented incident response plan
  • Staff awareness training
Request a cyber security quoteMeet Cipher Synapse

Delivered by our brands

The teams behind cyber security

Security engagements are led by Cipher Synapse and operationalised by our managed IT and network brands, so findings actually get fixed.

  • Cyber security & AI

    Cipher Synapse

    Security testing, hardening and applied AI — threat monitoring, automation and intelligent tooling.

  • Managed IT services

    My Global MSP

    Our flagship managed service provider: helpdesk, endpoint management, patching and proactive monitoring for Australian businesses.

  • Wholesale connectivity

    Australian Wholesale Networks

    Wholesale network services — NBN, fibre, data and voice carriage for channel partners.

  • IT projects & consulting

    NEXIOUS IT

    Project delivery and IT consulting — migrations, network builds, Microsoft 365 and infrastructure modernisation.

  • Core infrastructure

    Root Layer Technologies

    The infrastructure layer beneath the group — compute, networking, DNS and platform engineering.

In detail

Exactly what cyber security looks like when we deliver it

Deliverables

  • Essential Eight maturity assessment with a scored, prioritised remediation plan
  • MFA enforcement across email, remote access and administrative consoles
  • Managed endpoint detection and response with 24/7 alert triage
  • Email authentication hardening: SPF, DKIM and staged DMARC enforcement
  • Immutable offsite backups with tested restore evidence
  • Incident response plan with named contacts and notifiable data breach steps

How the engagement runs

  1. Week 1Assessment across all eight mitigation strategies plus identity review.
  2. Week 2-3Quick wins: MFA, admin privilege restriction, patch baseline, backups.
  3. Week 4-8Application control, hardening, logging and response runbooks.
  4. QuarterlyRe-assessment, tabletop exercise and board-ready reporting.

What we measure

Framework
ACSC Essential Eight
Privacy alignment
Australian Privacy Principles
Alert triage
24/7/365

Platforms we use

  • Microsoft Defender
  • Entra ID Conditional Access
  • Intune
  • Cloudflare Zero Trust
  • SIEM alerting
  • Immutable backup

Not included

  • Penetration testing by an independent assessor, which we coordinate rather than self-assess
  • Cyber insurance underwriting, though we supply the evidence insurers ask for

We list exclusions up front so a proposal never arrives with surprises attached.

Commitments

What every engagement includes as standard

Response targets
P1 within 15 minutes, P2 within 1 business hour, P3 within 1 business day — measured and reported, not aspirational.
Reporting
A monthly service report covering tickets, uptime, patch state, backups and open risks, plus a quarterly strategy review.
Data residency
Australian workloads stay in Australian regions by default; UK, US and NZ clients are hosted in-region on request.
No lock-in
You own your domains, DNS, cloud tenancies and documentation. Exit assistance is written into every agreement.

Cyber security questions, answered

  • Where does a security uplift start?

    With an assessment of identity, endpoints, email, backups and exposed services, scored by risk and effort. You get a prioritised remediation plan rather than a 90-page PDF.

  • Can you help us meet Essential Eight expectations?

    Yes. We map your current state against the Essential Eight maturity levels, agree a realistic target, and implement the controls in stages with evidence captured as we go.

  • What happens if we are breached?

    Managed clients get incident response with containment, forensic preservation, recovery from tested backups, and help with notification obligations under Australian privacy law.

  • Do you provide staff awareness training?

    Yes — phishing simulation and short, practical training, because the majority of incidents still begin with a person, not a firewall.

Ready to talk cyber security?

Tell us what you are trying to fix or grow. You will speak with an engineer, not a salesperson, and leave the call with a clear view of scope, timeline and cost.