Methodology
Auditors publish their method. Here's ours.
The 4-Week Commercial IT Health Check is not a vibe check. It maps to the frameworks Australian regulators, insurers and boards actually reference, and every finding carries its evidence basis so you can test the arithmetic.
Framework mapping
ACSC Essential Eight
Security controls are assessed against the Australian Cyber Security Centre's Essential Eight maturity model: application control, patching (applications and operating systems), macro settings, application hardening, admin privilege restriction, multi-factor authentication and regular backups. You receive a maturity position per strategy and a pragmatic, costed uplift path, not a demand to be Maturity Level 3 everywhere.
AICD / ACSC Cyber Governance Principles
Board-facing findings are structured against the AICD and Cyber Security Cooperative Research Centre's governance principles: clear roles, risk oversight, incident readiness and, pointedly, independent testing of controls. The deliverable is written so directors can discharge their duties with evidence, which is precisely what the guidance expects them to hold.
COBIT-Aligned Governance Assessment
IT governance is assessed against COBIT-derived practices: value delivery, risk management, resource optimisation, vendor oversight and performance measurement. We use the framework as a measuring stick, not a religion: findings are expressed commercially, ranked by value and exposure rather than by framework chapter.
Privacy Act & APP Alignment
Data handling is reviewed against the Australian Privacy Principles: what personal information is held, where, who can reach it, how long it is kept, and whether stated practice matches actual practice. Where the notifiable data breach scheme or sector obligations apply, gaps are flagged with remediation priorities.
AI Governance (Emerging Practice)
Shadow AI discovery and AI governance are assessed against emerging Australian regulatory guidance and our principals' engagement pattern: tool discovery, data classification rules, human accountability, disclosure norms and review cadence. New enough that no static standard exists; the method is discovery-first, policy-second.
The four weeks
Week 1
Evidence Collection
Contracts, invoices, licence reports, system and security data collected via a structured request list. Non-disruptive by design: we work from documents and telemetry, not your team's calendars.
Week 2
Analysis & Benchmarking
Spend benchmarked line-by-line against market comparators. Controls verified against Essential Eight. Governance assessed against COBIT-aligned practices. Early critical findings escalated immediately, not held for the report.
Week 3
Validation & Quantification
Findings tested with your stakeholders for factual accuracy. Every opportunity and risk quantified with its evidence basis: contract clause, benchmark delta, licence count or exposure estimate. You can check our arithmetic.
Week 4
Board-Ready Delivery
The Risk Register, Cost-Out Ledger, Vendor Hit List and 15+ ranked recommendations, presented to your executive or board. The 2x value guarantee is assessed against this document, in writing.
The independence rules
- We sell no hardware, software, licensing, managed services or implementation. Ever.
- We accept no referral fees, commissions or consideration from any vendor or provider.
- If any conflict could exist on a specific engagement, it is disclosed in writing before we start.
- Findings are ranked by your value and exposure, not by anyone's product catalogue.
- When the finding is that your current arrangements are good value, the report says so.
2x value identified, or you don't pay.
The 4-Week Commercial IT Health Check is fixed fee, non-disruptive, and guaranteed in writing: if we don't identify value worth at least twice our fee, we refund it.
