Cyber security
A programme, not a purchase
Most organisations buy security one tool at a time and end up with overlapping licences, gaps nobody owns, and no straight answer for the board. Ericom runs it as a programme: measure against the Essential Eight, close what matters in priority order, and certify where a contract demands it.
Tools, not a position
Almost every organisation we assess is already paying for security. Antivirus from one vendor, backup from another, multi-factor authentication that covers email but not the VPN, and a firewall somebody configured four years ago.
What none of it produces is a position. Nobody can say which risks are covered, which are accepted, and which are simply unexamined. So the next purchase is made the same way as the last one: in response to whatever went wrong most recently, or whatever a vendor was best at selling that quarter.
That is not a budget problem. Organisations in this state are usually spending enough. It is a sequencing problem, and sequencing is the one thing a product cannot sell you.
Three ways in
Which one you start with depends on how much you already know about your own posture, and on whether somebody external is asking.
-
Assessment and alignment
Essential Eight
The Australian Signals Directorate publishes eight mitigation strategies and three maturity levels. We assess every control against them, tell you where you actually sit, and give you the shortest path to the level you need. Sold on its own, before anything is bought or changed.
-
Modular security
Modular Cyber Security
Eleven security solutions sold on their own, to close a specific gap. Each one deploys into the environment you already have, managed by us, without moving your IT or replacing anything that already works.
-
ISO 27001, with ISO365
Compliance
A full Information Security Management System, built inside your own Microsoft 365 environment and run by real people until you are certified and after. Delivered with ISO365, who specialise in ISO 27001 implementation and auditing, while we handle the technical controls underneath it.
Order beats coverage
A control implemented in the right order stops more than three implemented in the wrong one. The Essential Eight is a ranking as much as a list, and most breaches we are called to involve a control the organisation had already bought and had not appropriately managed.
Common questions
Where should we start?
An Essential Eight assessment, in almost every case. It is the cheapest way to replace opinion with a position, and it tells you which of the other two you need. Starting anywhere else means choosing controls before you know which ones you are missing.
Do we need all three?
No. Most organisations need the assessment and an uplift programme. The modular services exist for organisations that already know their gaps and want specific capabilities run for them. ISO 27001 matters only when a contract, a tender or a regulator is asking for it.
Is this the same as Managed IT?
No, and the distinction is worth holding. Managed IT keeps your environment running and includes a baseline of security controls. This is the security programme itself: measuring posture, closing gaps in priority order, and evidencing it. Organisations buy them together often, but they answer different questions.
Can you achieve Maturity Level Two for us?
Nobody can, in the sense that phrase is usually used. The Essential Eight is a guideline rather than a certifiable framework, so there is no body that awards a level and no certificate to hold up. What we can do is align every control to the letter of the ASD guidance and evidence it, which is what an auditor, an insurer or a board is actually asking for.
Start with where you are
An assessment against the Essential Eight gives you a maturity position, a prioritised gap list, and a costed plan. It is the same first step whichever of the three you end up needing.
Talk to our security team