WHO AUDITS
YOUR IT PROVIDER?
Independent verification of IT risk, for boards that refuse to take the vendor's word for it.
Your MSP reports on its own performance. The Australian Cyber Security Centre and the AICD now tell boards plainly: security controls should be tested by independent experts, not the people who built them. Cyber risk sits inside directors' duties. We give you the independent evidence your board minutes need.
THE BLIND SPOT: THE QUESTIONS YOUR BOARD WILL ASK NEXT.
Cyber and technology risk now sit squarely inside directors' duties. Here is what keeps showing up when we look independently:
The Homework Problem
The only party telling you your IT is fine is the party you pay to run it. ACSC and AICD guidance is blunt: control testing should be independent. Right now, yours is not.
The Director Exposure
ASIC has made clear that cyber resilience is a directors' duty issue. 'The MSP said we were covered' is not a defence your board wants to test in public.
Shadow AI
In one recent independent audit by our principals, 30% of staff were already using unapproved AI tools with company data. Ungoverned. Nobody had told the board.
The Unpriced Risk
Backups that have never been restore-tested. Single-vendor dependency with no exit plan. Insurance questionnaires answered on hope. Risks that cost nothing, until they cost everything.
YOUR OPTIONS: THE THREE PATHS TO INDEPENDENT ASSURANCE
Three ways to answer the board's questions about IT risk. Only one is actually independent and actually affordable.
The Big Four
World-class advice, at a price point built for the ASX100.
Out of reach
The Managed Service Provider
Convenient for day-to-day support, but their strategic advice is shaped by the products they sell.
Can you trust the fox to guard the henhouse?
Conflicted
The Third Way
Agility Next
Independent verification, board-ready output, four weeks.
We audit your IT environment with no stake in the findings: risk register, governance gaps, vendor exposure, quantified and written for a board pack. The kind of independent testing regulators and the AICD now expect directors to have.
The Clear Choice for Boards
Not sure which path is right for you?
Schedule a free discovery callOUR GUARANTEE: BOARD-READY INSIGHT IN 4 WEEKS, OR WE REFUND.
Independent testing your board can rely on, with our fee at risk, not yours:
2x
Minimum value identified, or your fee back
15+
Board-ready recommendations per audit
Quantified
Risks ranked by impact, exposure and remediation cost
$0
Earned from the vendors we assess
If our 4-Week Commercial IT Health Check does not identify and demonstrate value improvement opportunities worth at least twice our engagement fee, we will refund our fee. No questions asked. Terms published, in writing.
The deliverable is written for your board, not your server room: a quantified risk register, governance gaps ranked by exposure, and the independent evidence directors are now expected to hold. If it does not demonstrate value worth twice the fee, you get the fee back.
What "Value Improvement" Means
Value improvement is not just cost savings. It includes:
RISK REDUCTION
Governance gaps and risks quantified before they become breaches, outages or headlines.
GOVERNANCE IMPROVEMENT
A framework your board can stand behind; director exposure reduced.
COMPLIANCE VERIFICATION
Documented evidence against Privacy Act, regulator expectations and industry standards.
AI GOVERNANCE
Shadow AI found and governed before it becomes a data-loss story.
STRATEGIC ALIGNMENT
Verification that IT supports the strategy the board has actually approved.
This guarantee applies to all new 4-Week Commercial IT Health Check engagements. Read the terms.
THE AGILITY NEXT DIFFERENCE: ASSURANCE YOUR BOARD CAN MINUTE.
Independent testing of the people who run your IT, delivered in the language of risk, not the language of servers.
What We Deliver
Independent Risk Verification
We test what your providers tell you against what is actually in place: security controls, backups, recovery, vendor dependency.
Board-Ready Governance
A quantified risk register and governance framework written for directors, aligned with ACSC and AICD expectations of independent assurance.
AI Exposure Assessment
Where AI is already inside your business ungoverned, and how to capture the upside without the data-loss story.
What We Don't Do
We don't sell technology.
No products, no resale, no referral fees. Our only deliverable is the truth, in writing.
We don't do fear theatre.
Risks are quantified by likelihood, impact and remediation cost, so the board can prioritise instead of panic.
We don't always find a villain.
Sometimes the independent answer is that your provider is good value. When it is, we say so, and you plan with confidence.
The Result
Board Confidence
Directors hold independent evidence, not vendor assurances, when the questions come.
Governed Risk
A live risk register with owners, priorities and costs, not a shelf document.
Defensible Position
Independent testing on record: the standard regulators and insurers increasingly expect.
Sleep
You stop wondering what the provider is not telling you, because someone independent has looked.
THE PEOPLE YOUR BOARD WOULD PICK.
Former CIO, CTO and COO leadership on one side; a $330M scale operator on the other. Nobody in the room selling anything.

Greg Spencer
Founder & Principal Consultant
Greg has spent more than twenty years running independent technology reviews for Australian organisations, after senior executive careers as CIO, CTO and COO. He founded one of Australia's longest-running independent technology advisory practices and has delivered board-level reviews across health, education, financial services, professional services and the public sector.
"One client told us: 'Reading your report, produced without conflict of interest, I finally understood how biased the advice we'd been getting really was.' That sentence is the whole firm."
Alex Frew
Partner & Enterprise Growth Lead
Alex has scaled technology businesses from $5M to $330M, led the integration of 12 acquisitions and managed IT teams of up to 1,100 people. He has sat on the buying side of the exact vendor contracts our audits test.
"I partnered with Agility Next to bring enterprise rigour to the mid-market. I have lived the journey from $5M to $330M. I know what breaks at scale, and where IT costs get away from you."
The Record
Two decades of independent reviews. Zero dollars earned from technology vendors.
The Track Record
Where our principals have done this before.
Independent technology reviews and advisory delivered by our principals across two decades of prior practice, from airports and regulators to universities, councils and national charities.
Engagements listed were delivered by Agility Next principals in prior advisory practice. Listing does not imply endorsement of Agility Next Pty Ltd by the organisations named.
READY FOR AN INDEPENDENT ANSWER?
Download the Board IT Risk Questions guide: the ten questions ACSC and the AICD expect boards to be asking, with what a good answer looks like.
Take it to your next board meeting. If your providers can answer all ten with evidence, you may not need us. If they cannot, you know where the gaps are.

BOARD IT RISK QUESTIONS
Ten questions every Australian board should ask about IT risk, and what good answers look like.
No spam. Unsubscribe anytime.
Or, if you're ready to talk...
Or go straight to the independent answer: thirty minutes on your current assurance arrangements and whether they would satisfy your board, your insurer and a regulator.
- 30-minute discovery call
- No obligation, no pitch deck
- An honest answer on whether you need us
