Built on the ASD Essential Eight, Privacy Act 1988 and NDB Scheme — the frameworks Australian regulators, insurers and enterprise clients actually ask about.
Enforce MFA, remove dormant privileged accounts, run one test restore from backup.
Formalise patch cadence, start an incident register, audit vendor access.
Tabletop breach exercise, application control, progress view for leadership.
Findings arrive in business language, ranked by severity. Your directors can read it without a translator.
Every gap cites the specific control or obligation it touches, so you know why it matters and to whom.
Includes a 90-day plan and six editable policy templates. Your IT provider can quote against it the same day.
Size, sector, operating model — calibrates your benchmark.
MFA, patching, application control, admin privileges and backups.
Privacy Act APPs, NDB obligations, data handling and incident response.
Scored findings, regulatory mapping, roadmap and policy templates.
Your business profile calibrates the report so recommendations reflect your actual risk exposure — not a generic checklist produced for every business category.
Output: assessment profile and benchmark contextPostureCheck surfaces what actually needs fixing first, so your leadership team gets a prioritised action view rather than an undifferentiated list of controls.
Plain-English posture narrative for owners, boards and managers.
Priority gaps tied to affected controls and expected artefacts.
References to Essential Eight, Privacy Act and NDB obligations.
Roadmap and editable templates so the team can move next.
A number on its own changes nothing. The report packages your findings in board language, ties each one to the regulation it touches, and includes the templates your team needs to close the gaps without starting from a blank page.
A plain-language view of where the business stands, written so an owner or director gets it on the first read. Business impact and regulatory exposure come first. Jargon doesn't make the cut.
Gaps ranked by severity and domain, each with its regulatory reference. Your team knows what to fix first and can point to the reason when someone asks why.
Every finding names the Essential Eight control, Privacy Act APP, NDB obligation or Cyber Security Act requirement it implicates. Nothing vague, nothing invented.
Six editable policy templates matched to your findings, covering access, backups, incident response, breach handling, retention and vendors. The documentation your gaps are missing.
Most businesses find out about a weak control when a client audit, an insurer questionnaire or an actual incident forces the question. By then it's the expensive version of the problem.
Consultants are worth it for execution. As a first step, though, engagements tend to be expensive, calendar-heavy and scoped for companies far bigger than a team of ten.
The self-assessment gives you an authoritative starting point this afternoon. If you want human help later, the report doubles as the briefing pack your advisor would spend a week producing.
All prices in AUD. No subscription needed for the report, and nothing renews without you asking.
PostureCheck converts your answers into a structured control view aligned to the ASD Essential Eight. Each row shows whether your organisation has evidence for baseline controls, partial coverage, or a priority gap that belongs in your remediation roadmap.
| Control area | Status | Evidence coverage |
|---|---|---|
| Multi-factor authentication | GAP | ML0 |
| Patch applications | PARTIAL | ML1 |
| Patch operating systems | GAP | ML0 |
| Restrict administrative privileges | READY | ML2 |
| Application control | GAP | ML0 |
| Restrict Microsoft Office macros | PARTIAL | ML1 |
| User application hardening | GAP | ML0 |
| Regular backups | PARTIAL | ML1 |
No. Nothing is installed and we never touch your network. You answer structured questions about how the business operates, and the report engine maps those answers to the frameworks. That's the whole footprint.
Your responses are encrypted in transit and used for one purpose: generating your report and any add-ons you buy. We don't sell data, share it with third parties or regulators, or use it to train models. You can ask for deletion at any time and we'll do it.
No, and be wary of any AUD 149 product claiming otherwise. PostureCheck is a structured self-assessment. It shows how your practices line up with the Essential Eight and your Privacy Act obligations, and businesses use it to prepare for insurer questionnaires, tenders and formal audits like IRAP. Preparation is where it saves you real money.
Your IT provider handles support. Security governance is a different job, and most small providers don't do it. The report gives you an independent view and a concrete list your provider can quote against. Several of our users hand the roadmap straight to their MSP as a work order.
A general sense of how the business handles email, devices, backups and access. If you can answer "who can log into the accounting system?", you're qualified. No technical background needed, and it takes around 12 minutes.
The assessment is free and takes about 12 minutes. If the findings are useful, the full report, roadmap and templates unlock for AUD 149. One payment, no subscription.
Start free assessmentAnswer 33 guided questions and receive an instant preview of your security and privacy posture. The full report, roadmap and templates unlock only if the findings are useful.