Evidence-based findings
Recommendations are grounded in configuration, documentation and operational evidence rather than assumptions.
Cybersecurity maturity assessment
An evidence-based commercial assessment of identities, devices, email, networks, cloud services, backups and business processes—with practical priorities your organisation can act on.
How we help
ITSPLUS examines how your technology is configured and how your people actually work. We identify material risks, recognise controls that are already effective and translate technical findings into a staged improvement plan suited to your business, budget and responsibilities.
Recommendations are grounded in configuration, documentation and operational evidence rather than assumptions.
Risks are ranked by likelihood, impact and practical urgency so management knows where to begin.
A realistic maturity pathway separates immediate protections from longer-term improvements.
A useful cybersecurity assessment starts by understanding what the organisation depends on. ITSPLUS discusses critical applications, sensitive information, payment processes, remote work, regulatory expectations, recent incidents and the amount of disruption the business could tolerate. This context prevents low-value technical observations from distracting attention from risks that could stop operations or harm clients.
The scope is agreed before review. It may cover Microsoft 365 or Google Workspace, computers, servers, cloud workloads, firewalls, wireless networks, backups, third-party access and the processes used when people join, change roles or leave. Where an area requires a specialist test outside the agreed assessment, we identify that clearly instead of implying every possible security test has been performed.
Business email and cloud identities are common entry points for attackers. We review administrator roles, multi-factor authentication, Conditional Access where licensed, legacy authentication exposure, account recovery, user lifecycle processes and the separation of everyday and privileged access. The assessment also considers external sharing, mailbox rules, forwarding, suspicious sign-in visibility and the protection available through Microsoft Defender, MailGuard or other configured services.
Configuration is considered alongside behaviour. A technically enabled control can still fail when exceptions are widespread, shared accounts remain in use or payment changes are approved through email alone. Recommendations therefore connect identity security with clear verification and escalation processes.
Supported and consistently managed devices make many other controls more reliable. ITSPLUS reviews operating-system and application patching, endpoint protection, encryption, local administrator rights, device inventory and management through tools such as Microsoft Intune. We also look for unmanaged computers or mobile devices that can reach sensitive business information without an appropriate security baseline.
The goal is not to demand identical controls for every device regardless of use. Higher-risk roles, privileged users, mobile teams and computers holding sensitive data may require stronger controls. The report distinguishes immediate exposure from lifecycle improvements that can be scheduled with normal hardware and software planning.
The network review considers internet-facing services, FortiGate or other firewall configuration, secure administration, VPN access, wireless security, guest networks, segmentation and the separation of servers, users and operational devices. Multi-site connectivity and remote access are assessed as part of one access model rather than isolated technical features.
Cloud and hosted infrastructure are reviewed for exposed management paths, privileged access, logging, support status and recovery dependencies. Automated vulnerability scanning may support the assessment where appropriate, but results are validated and placed in business context before becoming recommendations. A scan result alone is not treated as a complete security assessment.
Backups are assessed by what the business can recover, not simply whether a job reports success. We review coverage of servers, Microsoft 365 data and important applications, together with retention, protected credentials, offsite or immutable copies, monitoring and evidence of restore testing. Recovery priorities should reflect which services the organisation needs first and how long an outage can be tolerated.
We also examine practical incident readiness: who makes decisions, how the organisation communicates if normal systems are unavailable, where technical and supplier information is stored, and when legal, insurance or specialist response assistance may be required. These measures can reduce confusion and downtime even when prevention controls have worked well for years.
The Essential Eight provides a valuable baseline across application control, patching, Microsoft Office macro settings, user application hardening, administrative privileges, operating-system patching, multi-factor authentication and regular backups. ITSPLUS reviews relevant evidence against the maturity model and explains where existing technology, licensing or operating practices support—or prevent—the desired maturity level.
An assessment does not automatically mean every business should pursue the highest maturity level immediately. The roadmap considers risk, client requirements, cyber-insurance expectations, available resources and dependencies between controls. This produces a defensible sequence of work rather than a collection of disconnected products.
The assessment follows a clear process so management and technical contacts know what is happening, what access is required and when results will be available. Scope and timing are adjusted to the size and complexity of the organisation.
A nominated business contact helps coordinate the assessment and confirm how systems are used. ITSPLUS may request relevant policies, diagrams, supplier information and read-only or supervised administrative access where appropriate. Brief access to key staff can clarify payment processes, remote work, onboarding, offboarding, recovery expectations and other controls that cannot be understood from configuration alone.
The standard cybersecurity assessment is designed to be non-disruptive. ITSPLUS does not attempt exploitation, make configuration changes or perform intrusive penetration testing without separate written authorisation. Any active testing, service interruption risk or proposed change is scoped and approved before it occurs.
ITSPLUS provides a commercial cybersecurity and Essential Eight maturity assessment based on evidence available within the agreed scope. The service is not an IRAP assessment, accredited certification audit, penetration test, legal opinion or legally binding determination of compliance. ITSPLUS does not claim endorsement by ASD, ACSC or another government authority.
Findings reflect the environment and samples examined during the assessment period. They help management understand observed risks and prioritise improvements, but they do not guarantee that every vulnerability or future incident will be identified or prevented. Customers requiring IRAP, ISO certification, PCI DSS validation, regulatory assurance or legal advice should engage an appropriately authorised specialist for that purpose.
Findings are grouped by severity, business impact and recommended timing. Each material issue explains what was observed, why it matters and the practical next step. Quick improvements are separated from projects that require planning, licensing, user communication or equipment replacement. Effective existing controls are also recorded so management has a balanced view of the environment.
ITSPLUS presents the results in plain language and discusses priorities with decision-makers. Your business can use the roadmap internally, ask ITSPLUS to implement agreed improvements or coordinate responsibilities with other providers. The objective is informed action and measurable risk reduction—not a report that disappears into a drawer.
What’s included
Frequently asked questions
The agreed scope can include identities, Microsoft 365, email, devices, patching, endpoint protection, firewalls, networks, remote access, backups and important business security processes.
No. An Essential Eight assessment reviews evidence against the maturity model, while a penetration test attempts to identify and exploit particular technical weaknesses within an agreed scope. We explain when a specialist penetration test may be appropriate.
Yes. Material findings explain what was observed, why it matters, the recommended response and an appropriate priority. The report is supported by a management discussion and practical improvement roadmap.
No. The roadmap can guide your internal team or existing providers. ITSPLUS can also scope and implement agreed improvements when you want one accountable Melbourne team to carry the work forward.
Yes. We can review administrator access, MFA, Conditional Access where available, account lifecycle, sharing, email protection, device access and other relevant Microsoft 365 security settings.
No. ITSPLUS provides a commercial cybersecurity and Essential Eight maturity assessment based on evidence available within the agreed scope. It is not an IRAP assessment, accredited certification audit, penetration test, legal opinion or legally binding compliance determination.
Start a conversation
Speak with an experienced ITSPLUS engineer about support, security and your next technology project.