Home  /  Services  /  Cyber & Compliance

In the plan

Security built for a regulated industry.

Enforced MFA, conditional access, tested backups and scheduled access reviews. Built into how we run every client from the first day rather than sold as an upgrade later,  and recorded as we go, so you can show it rather than say it.

The problem

Being secure and being able to show it are different jobs.

01

“MFA is on.” Is it? For everyone?

You can say it. Can you show who it is enforced for, which accounts are exempt and why, and when it was turned on? That is the question that actually gets asked.

02

The evidence gets built by hand, the week before

Someone exports lists, cross-checks them against a staff spreadsheet and hopes nothing was missed. It takes days, and it is out of date the moment it is sent.

03

The person who left in March still had access in June

Not because anyone was careless. Because offboarding lives in somebody’s memory rather than in a process that runs whether they remember or not.

Who is asking

Four people will ask you for this.

And they want different things. A provider who only knows one of these columns will get you through one conversation and leave you exposed in the other three.
Who asksWhat they wantWhat we produce
Your AFSL licenseeEvidence that the controls they mandate are actually in place, not just written into a policy document.Access reviews and offboarding records on their schedule, in a form you can forward without editing.
APRA CPS 234Information security capability, and assurance over the service providers you rely on — which includes us.Documented controls for your environment, plus our own security posture as your provider.
Essential EightMaturity measured against a named baseline, rather than a general claim of being secure.A baseline assessment against the standard, and the gaps written down rather than glossed over.
Your cyber insurerStraight answers at renewal. MFA coverage, backup testing, offboarding, incident history.The questionnaire answered from records rather than from memory.

Swipe the table sideways to see all three columns →

Four askers, four formats, one set of underlying records. That is the whole reason this sits inside the plan rather than being quoted as a project every time somebody asks a question.

What's included

What we actually run.

  • MFA enforced and validated. Not just switched on. Checked, with every exception visible and accounted for.
  • Conditional access policies. Who can sign in, from where, on what device.
  • Security baseline checks against a known standard. Repeated on a schedule, not done once at onboarding and filed.
  • Backup and disaster recovery, tested. With the date and result of the last successful restore, because an untested backup is a hope.
  • Scheduled access reviews. Producing the audit evidence as a by-product rather than as a separate exercise.
  • Offboarding records that stand up to scrutiny. Written at the time, not reconstructed afterwards.
In practice

Your cyber insurance renewal lands.

  • THE EMAIL ARRIVES

    Twenty-odd questions, and a deadline.

    MFA coverage. Backup testing. Offboarding process. Incident history. Historically this is the point where three people start guessing, and somebody puts “yes” next to a question nobody has actually checked.

  • WHAT ALREADY EXISTS

    None of it was assembled for the occasion.

    MFA coverage by user, including every exception and the reason for it. The date and result of the last restore test. Every offboarding in the period, with timestamps. It is already there because it is produced as the work happens.

  • YOU ANSWER IT

    In an hour, from records rather than recollection.

    And every answer is one you could defend if the insurer came back and asked how you know.

  • IF THERE IS A GAP

    You hear it from us in March, not from them at renewal.

    A baseline check that never finds anything is not a good result. It is an unused one. The point of running them on a schedule is that problems surface while there is still time to fix them quietly.

How it is charged

In the plan.

Not a project, and not an upsell
How it usually works

Access reviews and baseline assessments are quoted as consulting work, then billed again the next time somebody asks a question.

How we run it

Part of how every BrokerReady client is run, at no separate charge. It happens on a schedule whether or not anybody asks.

In a regulated industry this is not optional, and pretending otherwise just moves the cost around.
Common questions

What people ask about compliance.

Our licensee has not asked for any of this. Why does it matter?
Because the request usually arrives with a deadline attached, and the work takes weeks if none of it has been running. The firms that find this painful are the ones starting from nothing the week they are asked. It is also increasingly the cyber insurer who asks first, not the licensee.
Are you doing an audit, or just the IT?
Just the IT, and the evidence that comes out of running it properly. We are not auditors and we do not sign anything off. What we do is make sure that when an auditor, a licensee or an insurer asks a question, the answer already exists and is defensible.
What happens if the baseline check finds problems?
It will, on the first run. Nearly every environment we pick up has something — a shared login, an exempt account nobody remembers creating, a backup that has never been restore-tested. You get the list, in priority order, with what it would take to fix each one. Nothing is hidden to make the report look better.
Does this cover our broking platform, or only Microsoft 365?
Both. Access to the broking system is part of the same access review and the same offboarding process, which is the bit that usually falls through the gap when the broking platform is somebody else’s problem.
We already have cyber insurance. Is that not enough?
Insurance pays out after something happens, and only if you answered the questionnaire accurately. Most of what is on this page is what the questionnaire asks about, so the two are not alternatives — one is the evidence the other relies on.
The rest of it

The other four services.

Could you answer it today? Let’s talk.

Thirty minutes to work out what you could evidence right now, and what would take a fortnight of somebody’s life.