Cyber security

A programme, not a purchase

Security bought one tool at a time ends up as overlapping licences, gaps with no owner, and no straight answer for the board. Ericom runs it as a programme: measure the position against the Essential Eight, close what matters in priority order, and where a tender or a contract names ISO 27001, build and run the management system an accredited body can certify.

Tools, not a position

Almost every organisation we assess is already paying for security. Antivirus from one vendor, backup from another, multi-factor authentication that covers email but not the VPN, and a firewall somebody configured four years ago.

What none of it produces is a position. Each product can report its own state and none of them can report the others', so the organisation cannot say which risks are covered, which have been accepted on the record, and which are simply unexamined. The next purchase is then made the same way as the last one: in response to whatever went wrong most recently, or whatever a vendor was best at selling that quarter.

That is not a budget problem. Organisations in this state are usually spending enough. It is a sequencing problem, and sequencing is the one thing a product cannot sell you.

Order beats coverage

A control implemented in the right order stops more than three implemented in the wrong one. The maturity model sets an organisation's level at its weakest strategy, so the order in which gaps are closed determines whether the level moves at all. A recurring pattern in breaches we are called to is a control the organisation had already bought but had not finished implementing or operating properly.

“Ericom’s comprehensive cybersecurity training has significantly improved our team’s ability to identify and respond to threats, giving us confidence in our security measures.”

Graeme Warren
Head of Finance, Australian Steel Mill Services
Read the case studies

Common questions

Short answers first.

Where should we start?

An Essential Eight assessment, in almost every case. It is the cheapest way to replace opinion with a position, and it tells you which of the other two you need. Starting anywhere else means choosing controls before you know which ones you are missing.

Do we need all three?

No. Most organisations need the assessment and an uplift programme. The modular controls are managed security services for organisations that already know their gaps and want specific controls run for them. ISO 27001 is usually driven by a contract, a tender or a regulator asking for it by name.

Is this the same as Managed IT?

No, and the distinction is worth holding. Managed IT keeps the environment running and includes a security baseline, with operated controls at its higher tiers. Cyber Security is the assessment and uplift programme for the whole environment: measure the position, close the gaps in priority order, and keep the evidence. Many organisations run both. They answer different questions.

Can you achieve Maturity Level 2 for us?

No cyber security company can, in the sense that phrase is usually used. The Essential Eight is guidance published by the Australian Signals Directorate. There is no body that awards a level and no certificate to hold up. Alignment to the guidance at the level you need, with the evidence behind it, is what we deliver and what a board or an insurer can use.

Where you are, before what to buy

Bring the licences that overlap, the gaps with no owner, the board question that was answered with a list of products, and the last purchase made because of the last incident. We will establish where the position actually sits, put the gaps in the order that moves it, and say which of the three ways in is yours, and whether it is more than one. Ericom's head office is in Wollongong.

Talk to our security team