Independent IT Posture Review

A structured, independent review of your organisation's actual IT security posture. Not a compliance checklist. Not a vendor assessment. An honest account of where your environment stands across the areas that cause the most damage when they are wrong, written by someone with no interest in selling you the remediation.

The review covers five areas:

  1. Identity and access

    Who has access to what, and whether enforcement matches policy. MFA coverage, admin account hygiene, stale accounts, privileged access patterns.

  2. Endpoint and patch posture

    Whether devices are actually managed, patched, and visible to the organisation. The difference between enrolled and compliant.

  3. Email and data protection

    Whether your domain can be used to impersonate you, and whether the records meant to stop that are enforcing or only present. This is the one area I can verify from outside before we start, from the same public DNS an attacker checks to decide whether your domain is worth forging.

  4. Backup and recovery

    Whether backups exist, whether they have been tested, and whether recovery is a documented process or an assumption.

  5. Operational ownership

    Whether someone is formally accountable for each system, credential, and configuration. The gap between "our IT provider handles that" and what is actually in scope for them.

Email deliverability above is one of these five areas, looked at on its own. It is the part I can verify from outside before any engagement begins, which is why it stands alone. The posture review is the whole picture: that same area alongside identity, endpoints, backup and ownership. Deliverability is the right starting point when the specific concern is whether your domain can be forged. The posture review is the broader engagement that contains it.

Deliverables are a written report (8 to 12 pages), a 60-minute walkthrough call, and a prioritised next actions list. The report is written to be read by a business owner, not a technical audience. It states what was found, what the risk is, and what to do about it.

Fixed price: AUD 1,200 + GST. Turnaround: two weeks from scoping call. Work is conducted independently.

If the deliverability fix preceded this within sixty days, its $650 fee comes off this price. You do not pay twice for me to look at the same environment.

Common questions

What do you need from us to run the review?
Read-only access to the environment, agreed at the scoping call, and a short conversation with whoever runs your IT day to day. I change nothing during the review, and you keep control of your systems throughout.
Is this a penetration test?
No. A penetration test tries to break in. This review reads how the environment is actually configured, across identity, endpoints, email, backups and ownership, and reports where practice has drifted from intent. For most small businesses it is the review to do first.
How is this different from the reports our IT provider already gives us?
Your provider reports on the work they are engaged to do. This review is independent of whoever runs your IT, covers the gaps between providers and systems that nobody formally owns, and is written for the business owner rather than for a technical audience.
What happens after the report?
The report ends with a prioritised list of next actions, and we walk through it together on a call. Your own IT provider or team carries out the changes. I take no commission and do not sell the remediation, so the recommendations have nothing behind them except the findings.

Let's talk.

If you want to work together, book a call below. If you would rather write first, email me and I will get back to you.