Your IT provider says everything is fine. I check whether it is.

Independent, fixed-price reviews and project work for Australian organisations that already have an IT provider. Enterprise architecture and infrastructure background, twenty-five years of it, now applied to small and growing businesses.

No managed services, no licences, no remediation to sell. The answer is the only thing on offer.

Three reasons people call

Your cyber insurance renewal is due. The proposal form asks whether MFA covers everyone, whether backups sit apart from the systems they protect, whether patches land inside thirty days. Someone signs a declaration on those answers. I check them against the environment before anyone does. Cyber insurance

You are not sure what your provider is actually covering. The monthly report is green and you have no way of knowing what was checked. An independent review reads the tenant, the identities, the devices and the backups and tells you, in plain language, what is in place and what is not. Your provider stays your provider. Independent IT review

Nobody has ever restored a backup. A backup that completes is not a backup that works. A witnessed restore with timestamped evidence is the difference. Backup verification

Point of view

Most of the environments I look at have similar issues. Controls that exist on paper and are not enforced in practice, ownership that nobody has formally claimed, and configuration problems that were predictable years before they happened.

Once a year that gap gets written down. A cyber insurance proposal form asks whether multi-factor authentication covers everyone with remote access, whether backups sit apart from the systems they protect, whether patches land within thirty days. Someone answers, the owner signs, and the declaration binds them to answers they did not usually supply. Those are matters of fact about an environment, not matters of opinion, and they are checkable before anyone signs anything.

Most IT environments have Multi-Factor Authentication enabled. Fewer have it enforced. The gap between those two states is where the breach happens. A policy set to report-only, a conditional access rule with an exception that became permanent, a shared account that predates the rollout and never got cleaned up.

Email authentication is the rare control that fails silently. A domain can be sending mail that lands in spam, or be open to anyone forging mail in its name, with nothing bouncing and no one told. It is also the one area I can verify from outside before any engagement, from the same public records an attacker reads to decide whether a domain is worth forging. You can read your own domain's records here, free.

It runs across whole sectors. Across 4,320 Australian business domains read to August 2026, 60 percent publish nothing that would stop someone forging mail in their name, from 59 percent of 252 law firms open to a forged settlement email to two in three of 124 wineries open to a forged message reaching their wine club.

The control looks right in the dashboard but it is not doing what the dashboard implies.

Small business IT tends to run on reactive support. Something breaks, someone fixes it, the ticket closes. What that model quietly skips is posture. Nobody owns the question of whether the environment is getting more or less secure over time, because that question does not generate a ticket. The people responsible for keeping the lights on are rarely the same people thinking about what happens when the lights go out, and in small organisations they are usually the same person with not enough hours to do both.

Compliance reports and security posture are not the same thing. A report can show green across every control and still describe an environment that an attacker would find straightforward. The report reflects what was true on the day the data was collected, under the assumptions built into the framework. It does not reflect what your IT provider actually checked last Tuesday, whether your backup has been tested since the server was replaced, or whether the admin account your previous MSP used still exists. Those gaps do not appear in reports. They appear in incidents.

Let's talk.

If you want to work together, book a call below. If you would rather write first, email me and I will get back to you.