Why do I need a Policy Review if we already have security policies?+
Even mature organisations often have policies that are outdated or inconsistently applied. Our review identifies where intent and practice diverge, surfacing the gaps auditors and insurers tend to find first.
How often should security policies be reviewed?+
We recommend a formal review every 12 to 18 months, or after significant regulatory, operational or technology changes.
What frameworks do you benchmark against?+
We benchmark against best practice including ISO 27001 by default, with the NIST Cybersecurity Framework, CIS18 or the Essential 8 available if you’d prefer one of those instead.
What’s included in the Policy Review?+
We focus on your three most critical information security policies: Security Incident Management, Vulnerability Management and Disaster Recovery.
How long does the Policy Review take?+
The engagement runs over 7 days*, fixed regardless of scope.
What size organisation is this best suited for?+
The Policy Review is designed for mid-market Australian organisations looking to uplift GRC maturity, prepare for an audit, or get an independent read on their security governance.
What happens after the review?+
You’ll have the option of a follow-up consultation to walk through findings. Many organisations use that conversation to scope a broader GRC uplift or ongoing vCISO support.
How is this different from a security audit?+
An audit checks compliance against a pass or fail line. Our review looks beyond that to find practical, risk-aligned opportunities to strengthen governance and control application.