Cyber & privacy readiness for Australian small business

Your Essential Eight & Privacy Act gaps, diagnosed in 12 minutes.

Built on the ASD Essential Eight, Privacy Act 1988 and NDB Scheme — the frameworks Australian regulators, insurers and enterprise clients actually ask about.

Cyber & Privacy Readiness Report
0%ready
2Critical gaps
3High risk
8Controls assessed
Essential Eight Snapshot
Multi-factor authenticationGap
Patch applicationsPartial
Application controlGap
Restrict admin privilegesPartial
Regular backupsReady
Remediation Roadmap · Priority-sequenced
First 30 days
Contain exposure

Enforce MFA, remove dormant privileged accounts, run one test restore from backup.

Days 31 to 60
Build defensible evidence

Formalise patch cadence, start an incident register, audit vendor access.

Days 61 to 90
Advance maturity

Tabletop breach exercise, application control, progress view for leadership.

SAMPLE · ILLUSTRATIVE CLIENT View the full sample →
Written for the boardroom

Findings arrive in business language, ranked by severity. Your directors can read it without a translator.

Anchored in law

Every gap cites the specific control or obligation it touches, so you know why it matters and to whom.

Ready to hand over

Includes a 90-day plan and six editable policy templates. Your IT provider can quote against it the same day.

33 structured questions ~12 minutes Report delivered instantly AUD 149 one time, no subscription Data encrypted in transit
How it works~12 minutes

33 questions. One board-ready report.

01
Business profile

Size, sector, operating model — calibrates your benchmark.

LIVE
02
Security controls

MFA, patching, application control, admin privileges and backups.

MAPPED
03
Privacy & breach readiness

Privacy Act APPs, NDB obligations, data handling and incident response.

CHECKED
04
Executive report

Scored findings, regulatory mapping, roadmap and policy templates.

READY
Why this matters

Your business profile calibrates the report so recommendations reflect your actual risk exposure — not a generic checklist produced for every business category.

Output: assessment profile and benchmark context
Report outputSample output

A deliverable your board can read and your team can execute.

0%readiness
Critical exposure ranked by severity — not framework order.

PostureCheck surfaces what actually needs fixing first, so your leadership team gets a prioritised action view rather than an undifferentiated list of controls.

Each finding is ranked by severity, regulatory reference, business impact and the specific evidence required to remediate — so your team knows exactly what to produce.
A prioritised 30 / 60 / 90 day plan. In the full report, every action has an owner, a timeframe and the evidence it should produce.
Editable templates for access, backup, incident response, privacy, retention and vendors — matched to your findings.
Executive summary

Plain-English posture narrative for owners, boards and managers.

Risk evidence

Priority gaps tied to affected controls and expected artefacts.

Legal mapping

References to Essential Eight, Privacy Act and NDB obligations.

Action package

Roadmap and editable templates so the team can move next.

View the full sample report →

What you get

Plenty of tools give you a score. People pay for what comes with it.

A number on its own changes nothing. The report packages your findings in board language, ties each one to the regulation it touches, and includes the templates your team needs to close the gaps without starting from a blank page.

01

Executive risk summary

A plain-language view of where the business stands, written so an owner or director gets it on the first read. Business impact and regulatory exposure come first. Jargon doesn't make the cut.

02

Prioritised findings

Gaps ranked by severity and domain, each with its regulatory reference. Your team knows what to fix first and can point to the reason when someone asks why.

03

Regulatory mapping

Every finding names the Essential Eight control, Privacy Act APP, NDB obligation or Cyber Security Act requirement it implicates. Nothing vague, nothing invented.

04

Implementation toolkit

Six editable policy templates matched to your findings, covering access, backups, incident response, breach handling, retention and vendors. The documentation your gaps are missing.

Your options

Three ways to handle this. Only one costs less than lunch for the team.

Doing nothing Exposure stays invisible

Most businesses find out about a weak control when a client audit, an insurer questionnaire or an actual incident forces the question. By then it's the expensive version of the problem.

  • No baseline to work from
  • No remediation path
  • Nothing to show leadership, insurers or clients
Traditional consulting Thorough, but weeks away

Consultants are worth it for execution. As a first step, though, engagements tend to be expensive, calendar-heavy and scoped for companies far bigger than a team of ten.

  • Thousands of dollars before the first finding
  • Weeks of discovery meetings
  • Often over-scoped for small teams
PostureCheck A baseline today, on your desk

The self-assessment gives you an authoritative starting point this afternoon. If you want human help later, the report doubles as the briefing pack your advisor would spend a week producing.

  • 12 minutes, no IT team needed
  • Board-ready report with regulatory mapping
  • Templates and reassessment included
Pricing

The score is free. Pay once if you want the report.

All prices in AUD. No subscription needed for the report, and nothing renews without you asking.

Ongoing readiness
Essentials
AUD 449 / year
The full bundle, refreshed once a year.
  • The full executive report
  • Policy Pack Pro, 20 templates matched to your gaps
  • Cyber Insurance Readiness Pack
  • Refreshed once a year
  • Email support
Go annual
Ongoing readiness
Assurance
AUD 799 / year
For businesses that must prove compliance all year — not once.
  • Everything in Essentials, refreshed every quarter (4×)
  • Readiness Certificate to hand your insurer or attach to tenders
  • A dated score trend that proves you're improving
  • Priority email support
  • Bought separately, this is over AUD 1,100 of work each year
Go annual
After the reportPolicy Pack Pro, AUD 399. Twenty policies prepared from your assessment data and delivered within 24 hours. No two packs are the same.
For your brokerInsurance Readiness Pack, AUD 149. Your answers reformatted into insurer language. Supports AXA, Chubb and QBE applications.
For your teamHuman Review Session, AUD 399. Thirty minutes with a senior advisor to turn the roadmap into this week's first actions.
Good to knowAdd-ons reuse your existing answers. You never re-do the assessment to unlock them.
Essential Eight Snapshot

Control maturity — without reading a 40-page framework.

PostureCheck converts your answers into a structured control view aligned to the ASD Essential Eight. Each row shows whether your organisation has evidence for baseline controls, partial coverage, or a priority gap that belongs in your remediation roadmap.

Control areaStatusEvidence coverage
Multi-factor authenticationGAP
ML0
Patch applicationsPARTIAL
ML1
Patch operating systemsGAP
ML0
Restrict administrative privilegesREADY
ML2
Application controlGAP
ML0
Restrict Microsoft Office macrosPARTIAL
ML1
User application hardeningGAP
ML0
Regular backupsPARTIAL
ML1
Priority gap Partial evidence Evidence ready ML = Maturity Level (ACSC)
Questions

What people ask before starting.

Do you install anything or scan our systems?

No. Nothing is installed and we never touch your network. You answer structured questions about how the business operates, and the report engine maps those answers to the frameworks. That's the whole footprint.

Who sees our answers?

Your responses are encrypted in transit and used for one purpose: generating your report and any add-ons you buy. We don't sell data, share it with third parties or regulators, or use it to train models. You can ask for deletion at any time and we'll do it.

Is this a compliance certification?

No, and be wary of any AUD 149 product claiming otherwise. PostureCheck is a structured self-assessment. It shows how your practices line up with the Essential Eight and your Privacy Act obligations, and businesses use it to prepare for insurer questionnaires, tenders and formal audits like IRAP. Preparation is where it saves you real money.

We already have an IT provider. Why would we need this?

Your IT provider handles support. Security governance is a different job, and most small providers don't do it. The report gives you an independent view and a concrete list your provider can quote against. Several of our users hand the roadmap straight to their MSP as a work order.

What do I need to answer the questions?

A general sense of how the business handles email, devices, backups and access. If you can answer "who can log into the accounting system?", you're qualified. No technical background needed, and it takes around 12 minutes.

Find out where you stand this afternoon.

The assessment is free and takes about 12 minutes. If the findings are useful, the full report, roadmap and templates unlock for AUD 149. One payment, no subscription.

Start free assessment