Services & packages
Fixed packages with the deliverables and price set before we start.
Choose by the deadline in front of you. Every package is assembled from the same scopes below, and the scope is written into the proposal before any work begins.
Packages
Pick the package that matches the deadline in front of you.
Each is a fixed-scope engagement. Where a package leads to certification, an accredited body runs the actual audit.
Package A
Clear a Requirement
One specific obligation to satisfy, fast.
Fixed fee · quoted on scope
- Essential Eight maturity assessment
- SMB1001 Bronze / Silver readiness
- Cyber insurance control audit
- Enterprise vendor & procurement security pack
- Gap report with prioritised actions
Package B · Most common
Get Certified
Full readiness toward an ISO 27001 certificate.
Fixed fee · quoted on scope
- ISMS build to ISO/IEC 27001:2022
- Risk assessment & treatment plan
- Statement of Applicability
- Internal audit + management review
- Stage 1 / Stage 2 pre-audit & support
Package C
Stay Aligned
Keep evidence current after you're certified.
Monthly retainer · fixed remit
- vCISO on retainer, named lead
- Continuous GRC & control monitoring
- Security telemetry (SIEM / Wazuh / Shuffle)
- Surveillance-audit maintenance
- Board & risk reporting
Our Practice Areas
The eleven scopes that make up those packages.
Grouped by the problem each one solves rather than by how it bills. The remit line on each card still names the shape of the engagement.
Certification & readiness
ISO 27001 Readiness
Full ISMS build, gap analysis, Statement of Applicability, and internal pre-audit against ISO/IEC 27001:2022.
Fixed package · leads to Stage 1
WS·SMBSMB1001 Readiness
Tiered readiness (Bronze to Diamond) for smaller businesses that need recognised proof without ISO-scale cost.
Fixed package
WS·E8Essential Eight Uplift
Maturity assessment against the ACSC Essential Eight with a prioritised uplift plan to a defensible target level.
Fixed package
WS·REMFull Remediation Package
End-to-end closure of the gaps a readiness review or audit surfaced, tracked to evidence.
Fixed scope, per finding set
Regulatory & contractual alignment
APRA CPS 234 Alignment
Information-security capability and third-party alignment for APRA-regulated entities and their providers.
Scoped assessment
WS·SOCISOCI Act Alignment
Critical Infrastructure Risk Management Program (CIRMP) alignment for entities captured by the SOCI Act.
Scoped assessment
WS·INSCyber Insurance Audit
Technical review against underwriter requirements so renewals and claims aren't undermined by unmet controls.
Fixed package
WS·TPSASupply Chain & Vendor Assurance
Third-party and supply-chain security assessments, plus questionnaire responses that satisfy prime-contractor, mining, and enterprise vendor portals.
Per-vendor or program
Testing & ongoing governance
VAPT Services
Hands-on vulnerability assessment and penetration testing, with findings scored and mapped, not just listed.
Scoped by target
WS·GRCContinuous GRC & Telemetry
Ongoing control monitoring and security telemetry to keep evidence current between audits.
Monthly retainer
WS·CISOvCISO & Governance
A named security lead on retainer for risk decisions, board reporting, and program ownership.
Monthly retainer
Frameworks & standards
The standards we work against
Every engagement maps to the frameworks your auditors, underwriters, and prime contractors already recognise.
ISO/IEC 27001:2022
Information Security
SMB1001
SME Certification
ASD Essential Eight
ACSC Maturity Model
APRA CPS 234
Financial Services
SOCI Act CIRMP
Critical Infrastructure
Privacy Act APP 11
Data Protection
ISO/IEC 27002:2022
Control Guidance
PSPF Policy 10
Commonwealth
OWASP Top 10
Web Application
OWASP API Top 10
API Security
OSSTMM
Testing Methodology
ISO 31000
Risk Management
Tell us the deadline you're working to.
We'll name the right package, fix the scope, and give you a price before any work starts.