What types of organizations do you work with?
We primarily work with small and medium-sized businesses, SaaS providers, technology companies, professional services firms, healthcare organizations, and growing businesses that need practical cybersecurity guidance without maintaining a large internal security team.
Do I need a dedicated security team to work with you?
No.
Many of our clients do not have a full-time security engineer or dedicated security department. Our assessments are designed to provide clear findings and actionable recommendations that can be implemented by existing IT teams, managed service providers, or internal technical staff.
Do you only work with Australian companies?
No.
While AussieCyberGuard is based in Australia, we can support organizations in other regions depending on the engagement requirements.
Security Assessment Questions
What is a Web Security Assessment?
A Web Security Assessment evaluates websites, web applications, customer portals, APIs, and other internet-facing systems for security weaknesses that could expose data, disrupt operations, or increase business risk.
The assessment combines automated testing, manual verification, and risk analysis to identify meaningful security issues.
What types of vulnerabilities do you look for?
Assessments may include identification of:
- Authentication weaknesses
- Authorization flaws
- Security misconfigurations
- API security issues
- Sensitive data exposure
- Session management weaknesses
- Input validation issues
Common web application vulnerabilities
The exact scope depends on the systems being assessed.
Will testing affect our production environment?
Assessment activities are planned to minimise disruption wherever possible.
We work with clients to define testing windows, scope boundaries, and operational requirements before testing begins.
How long does a security assessment take?
The duration depends on the size and complexity of the environment.
Smaller engagements may be completed within several days, while larger assessments may require several weeks.
A timeline is provided during the scoping process.
Will I receive a report?
Yes.
All engagements include a report containing findings, risk observations, supporting evidence, and recommendations for remediation.
Reports are designed to be useful for both technical and non-technical stakeholders.
Do you provide remediation guidance?
Yes.
Our reports include practical recommendations and prioritised remediation guidance to help address identified risks.
Where appropriate, we can also discuss findings with your internal team after the assessment.
Compliance Questions
Can you help us prepare for a compliance audit?
Yes.
Our Compliance Review Services are designed to identify gaps and improvement opportunities before formal audits or certification activities begin.
Which standards and frameworks do you support?
We currently provide reviews aligned with:
SOC 2 Type II
ISO 27001
GDPR
NIST Cybersecurity Framework (CSF)
PCI DSS
Essential Eight
Are your compliance reviews certification audits?
No.
We provide readiness reviews, gap assessments, and security-focused evaluations.
Formal certification or attestation activities must be performed by appropriately accredited certification bodies or auditors.
What is a gap assessment?
A gap assessment compares your current controls, processes, and security practices against a specific framework or standard.
The goal is to identify areas requiring improvement before a formal audit or compliance review.
How often should compliance reviews be performed?
Most organizations benefit from annual reviews, or whenever significant changes occur to infrastructure, business processes, or regulatory obligations.
Business and Engagement Questions
How does the engagement process work?
A typical engagement includes:
- Initial discussion
- Scoping
- Assessment activities
- Reporting
- Remediation guidance
- This process helps ensure that objectives, scope, and expectations are clearly defined before work begins.
What information do you need to get started?
Typically, we require:
A high-level understanding of your environment
Systems or applications to be assessed
Business objectives
Relevant compliance requirements
Preferred assessment timelines
Additional information may be requested depending on the engagement.
How much involvement is required from our team?
Most engagements require limited involvement after the initial scoping phase.
However, availability of key technical contacts can help answer questions and support efficient assessment activities.
Why not just use automated security scanning tools?
Automated tools can identify certain issues, but they cannot fully understand business context, validate exploitability, assess risk, or identify many complex security weaknesses.
A meaningful assessment combines automated tooling with manual analysis and professional judgement.
Can you work alongside our existing IT provider or MSP?
Yes.
Many clients engage us alongside internal IT teams, managed service providers, software development teams, or cloud consultants.
Our role is to provide an independent security perspective and actionable recommendations.
Do you sign Non-Disclosure Agreements (NDAs)?
Yes.
We understand that security engagements often involve confidential information and are happy to review reasonable NDA requirements before commencing work.
What happens after the assessment?
After receiving the final report, your organization can use the findings to prioritise remediation efforts, improve security controls, support compliance initiatives, and strengthen overall security posture.
Where appropriate, follow-up discussions can be arranged to clarify findings and recommendations.
How do I request an assessment?
Simply contact us through our website or email us directly.
We'll discuss your objectives, answer any questions, and provide guidance on the most appropriate assessment for your environment.