Cybersecurity Readiness Assessment

Know Your Security
Posture. Fix the Gaps.

Our structured cybersecurity assessment evaluates your organisation across five critical areas, aligned to SMB1001 and the Australian Essential Eight, and gives you a clear roadmap to improve.

Three Maturity Levels, Where Do You Stand?

Our assessment maps your security posture to the SMB1001 Bronze, Silver, and Gold certification levels, giving you a clear, benchmarked result.

Bronze

SMB1001 Certified

Foundation security controls for organisations beginning their cyber security journey.

Basic access controls and password policies
Endpoint antivirus protection
Regular operating system updates
Security awareness training basics
Basic data backup procedures

Businesses starting their security journey with limited controls currently in place.

Silver

SMB1001 Certified

Intermediate security with documented policies, MFA, and proactive defences.

Multi-factor authentication (MFA)
Documented incident response plan
Network segmentation and firewall rules
Regular vulnerability scanning
Formalised backup and recovery testing

Organisations that have baseline security but want recognised, verified credentials.

Gold

SMB1001 Certified

Advanced security best practices for mature requirements and high-value targets.

Advanced threat protection (Microsoft Defender)
Security monitoring and SIEM
Vendor and third-party risk management
Business continuity planning and testing
Penetration testing and red team exercises

Businesses handling sensitive data, government contracts, or operating in regulated industries.

Five Core Assessment Areas

Our assessment follows a structured methodology aligned to ISO/IEC 27001 and the Australian Essential Eight, covering every critical dimension of your security posture.

Technology Management

We assess your endpoint protection, patch management cadence, software licensing, and cloud security configuration.

Endpoint detection & response
Patch management process
Software asset inventory
Cloud configuration review

Access Control & Identity

Review of identity management, authentication methods, privileged access, and user offboarding procedures.

MFA deployment status
Privileged account management
User access review process
Offboarding procedures

Backup & Recovery

Assessment of backup coverage, frequency, storage security, and recovery testing, ensuring your backups actually work.

Backup coverage completeness
Offsite and offline copies
Ransomware-resistant storage
Recovery time testing results

Governance & Policies

Review of security policies, risk management processes, compliance obligations, and board/executive oversight.

Information security policy
Risk register maintenance
Supplier security requirements
Compliance obligations mapping

Staff Awareness

Evaluation of security training programs, phishing simulation results, and incident reporting culture.

Security awareness training
Phishing simulation results
Incident reporting process
Social engineering risk
SMB1001
GOLD

Pathway to SMB1001 Certification

Oxana is a licensed Cybercert SMB1001 certification provider. This assessment directly maps to SMB1001 requirements, making certification the natural next step after your assessment.

About SMB1001

Frequently Asked Questions

Common questions about cybersecurity assessments for Australian businesses.

What is the difference between a cybersecurity assessment and penetration testing?

A readiness assessment evaluates your policies, configurations, processes, and controls against a framework like SMB1001 or Essential Eight. Penetration testing actively attempts to exploit vulnerabilities. Our assessment is the right starting point, it identifies gaps so you know where to invest before a pentest.

How long does a cybersecurity readiness assessment take?

Typically 1 to 2 weeks for small to mid businesses. This includes a kick-off session, technical review, stakeholder interviews, and delivery of the final report with remediation roadmap.

What does the assessment cost?

We offer fixed-fee assessments tailored to your business size and target certification level. Contact us for a no-obligation quote, most assessments for businesses under 50 users start from $2,500.

Does passing the assessment automatically certify us for SMB1001?

The assessment directly maps to SMB1001 requirements. Once gaps are remediated, Oxana, as a licensed SMB1001 certification provider, can issue your official certification without needing a separate third-party audit.

What is the Australian Essential Eight?

The Essential Eight is the Australian Signals Directorate's (ASD) set of eight baseline mitigation strategies for cyber threats. Our assessment evaluates your compliance with these controls and maps them to SMB1001 certification levels.

What You'll Receive

A comprehensive assessment package that gives you clear, actionable guidance, not just a score.

Security Maturity Score

Your current Bronze/Silver/Gold maturity rating across all five assessment areas.

Gap Analysis Report

Detailed gaps against SMB1001 and Essential Eight with prioritised remediation actions.

Improvement Roadmap

A practical, prioritised roadmap with quick wins and longer-term security improvements.

SMB1001 Pathway

Clear steps to achieve Bronze, Silver, or Gold SMB1001 certification with Oxana as your provider.

Policy Recommendations

Template policies and procedures tailored to your organisation's size and industry.

Risk Treatment Plan

Documented risk register with treatment options, ownership, and target risk ratings.