Agility Next
Services
Why Us
Proof
Resources
Pricing
Contact Us
Independent Cyber Risk Review

The only party saying you're secure is the party you pay to secure you.

Independent verification of your actual cyber position, written for your board: quantified, prioritised, and aligned with what regulators and insurers now expect.

The Australian Cyber Security Centre and the AICD tell boards plainly: security controls should be tested by independent experts with a mandate to challenge, not by the provider who built them. Cyber resilience sits inside directors' duties, and 'the MSP said we were covered' is not a defence anyone wants to test. We verify what is actually in place: the controls, the backups that have never been restore-tested, the questionnaire answers your insurer is relying on.

Book Your Cyber Risk Review

Self-Assessed Security

Your provider assesses the controls your provider built. The conflict is structural, and your board carries the residual risk.

Director Exposure

ASIC treats cyber as a directors' duty issue. Boards are expected to hold independent evidence, not vendor assurances.

The Untested Backup

A backup that has never been restore-tested is a hope, not a control. It is the most common critical gap our principals find.

The Optimistic Insurance Form

Cyber insurance questionnaires answered generously are a claim denial waiting for its trigger event.

What We Test

  • Security controls against the ACSC Essential Eight, independently verified
  • Backup and recovery: tested restore capability, not claimed capability
  • Access control and privilege hygiene across your environment
  • Incident response readiness: what actually happens on day zero
  • Cyber insurance questionnaire answers against reality
  • Vendor and MSP security claims, evidence-checked

The Deliverable

The Board Risk Register

A quantified, prioritised cyber risk register written for directors, not system administrators.

  • Risks ranked by likelihood, business impact and remediation cost
  • Essential Eight maturity position with a pragmatic uplift path
  • Backup and recovery verification results
  • Insurance-readiness assessment
  • Board briefing pack aligned with ACSC/AICD governance principles
15+
Board-ready recommendations per audit
$0
Earned from security vendors or remediation
4 wks
To a defensible, minuted risk position

Essential Eight maturity, in plain English

The ACSC's Essential Eight maturity model scores each of eight mitigation strategies from Level 0 to Level 3. For a 50-250 seat business the point is not chasing Level 3 everywhere; it is knowing where you sit, choosing target levels that match your risk, and being able to show your board and insurer the evidence.

Maturity levelWhat it meansWhat it means for you
Level 0Weaknesses in overall security posture; strategy not meaningfully implementedExposed to commodity attacks. Most unaudited mid-market environments have at least two strategies here
Level 1Partly mitigates commodity tradecraft using broadly available toolsThe pragmatic floor for most mid-market businesses; insurers increasingly assume it
Level 2Mitigates adversaries with modestly more capability and targetingThe sensible target where client data, regulated data or deep pockets raise your profile
Level 3Mitigates adaptive, targeted tradecraftWarranted for genuinely high-value targets; rarely cost-effective wall-to-wall in the mid-market

What we test against each of the eight strategies

01

Application control

Whether unapproved executables actually run on your endpoints and servers, not whether a policy says they shouldn't.

02

Patch applications

Real patch latency on internet-facing and productivity applications against the ACSC's 48-hour-to-one-month expectations by severity.

03

Configure Microsoft Office macro settings

Whether macros from the internet are blocked, who has exemptions, and why. Still one of the cheapest breach vectors going.

04

User application hardening

Browser and application configurations against ACSC hardening guidance, including the legacy features attackers love.

05

Restrict administrative privileges

Who actually holds privileged access, whether it is separated from daily-driver accounts, and when it was last reviewed. Orphaned admin accounts from departed staff are the most common critical finding.

06

Patch operating systems

OS patch latency across servers and endpoints, including the forgotten estate: the old file server, the hypervisor, the NAS in the comms room.

07

Multi-factor authentication

Coverage across email, remote access, admin accounts and critical SaaS, and the exemption list nobody talks about.

08

Regular backups

Not whether backups run: whether a full restore has been tested, how long it took, and whether backup credentials are isolated from the environment they protect.

Our assessment methodology

Evidence-based, four weeks, aligned to the same structure as every Agility Next audit: structured evidence collection (configurations, telemetry, policies, provider reports), independent verification against the Essential Eight and AICD/ACSC governance principles, quantification of every gap by likelihood, business impact and remediation cost, then board-ready delivery with 15+ ranked recommendations. Critical findings are escalated the day they are confirmed, not saved for week four. Our principals have assessed environments across health, education, financial services, professional services, government and not-for-profit over two decades of independent reviews.

Proof

The board wanted assurance, not another vendor report.

A Queensland independent school board required objective assessment of ICT operations. Internal teams were too close; vendors were conflicted. The independent review delivered 17 board-ready recommendations and a baseline for every decision since.

Read the case study

Straight Answers

The Guarantee

2x value identified, or you don't pay.

The 4-Week Commercial IT Health Check is fixed fee, non-disruptive, and guaranteed in writing: if we don't identify value worth at least twice our fee, we refund it.

Book Your Cyber Risk ReviewRead the guarantee terms
Agility Next

Sydney HQ

119 Willoughby Road

Crows Nest NSW 2065

hello@agilitynext.com.au

Services

  • The Full IT Audit
  • MSP Audit
  • AI Audit
  • Cyber Risk Review
  • IT Cost Reduction
  • IT Due Diligence
  • IT Strategy Review

Company

  • Pricing
  • Methodology
  • Sample Report
  • IT Spend Benchmark Tool
  • Case Studies
  • Industries
  • Insights
  • About
  • Contact

Subscribe to The Audit

Monthly insights on IT governance and vendor management.

© 2026 Agility Next Pty Ltd · Proudly supported by 3P Digital

Privacy PolicyTerms & Guarantee