Explained
Cyber Health Check
A structured check-up for your business's security — find the gaps, see them ranked by risk, and get a plain-English plan to fix them. About 60 minutes, no IT expertise required.
What a cyber health check is — and isn't
A cyber health check is exactly what it sounds like: a structured check-up of your business's security basics, the same way a medical check-up reviews your vitals. You answer guided, plain-English questions about how your business actually operates — passwords and access, backups, software updates, email security, staff awareness, incident readiness — and you get back a score, a list of gaps ranked by risk, and specific actions to close each one.
It is not a penetration test (no one attacks your systems), not a software scan (nothing is installed or probed), and not a consulting engagement (no one needs to visit, and there is no report-writing fee). It's the fastest honest answer to the question most business owners can't currently answer: "Are we actually protected, or are we just hoping?"
What you get at the end
A score — your overall security posture, the moment you finish.
A gap list ranked by risk — what's missing, ordered by what matters most.
A plain-English action plan — fix the gaps yourself, or hand the list to your IT provider.
Word and Excel reports — ready for insurers, supplier questionnaires, or your own records.
Everything runs in your own browser, on your own device. Your answers are never transmitted anywhere — which matters if you operate in a regulated industry. And because the check is repeatable, you can run it again next quarter and show the improvement, which is the kind of evidence insurers and regulators increasingly expect. (If you want the deeper picture of why evidence matters, see cyber security assurance explained.)
Why Australian businesses run one
Because the Privacy Act requires "reasonable steps." If you hold customer data and suffer a breach, the OAIC will ask what protections you had. A completed health check with a remediation trail is documented evidence; "we thought IT had it covered" is not.
Because insurers and customers are asking. Cyber insurance applications now probe your controls in detail — and claims get denied when answers don't match reality. Supplier questionnaires and tenders ask the same questions. A current health check report answers them in one attachment.
Because professional regulators have raised the bar. The TPB for accountants and bookkeepers, ASIC for advice licensees, AHPRA for health practitioners, the NDIS Commission, Law Societies — expectations around protecting client data are now explicit across professional Australia.
Choose your health check
Every check follows the same approach — guided questions, scored results, risk-ranked actions, exportable reports — but the industry versions speak your language: your software, your regulator, your specific risks.
General — any industry
The Small Business Cyber Security Health Check covers the fundamentals every business needs: passwords, backups, updates, email security, staff awareness, and incident readiness.
Industry-specific versions
Accounting · Bookkeeping · Law Firms · Financial Planning · Mortgage Broking · Real Estate · GP Clinics · Allied Health · NDIS Providers · Childcare
Larger organisation?
If you need framework-aligned maturity assessment — NIST CSF, ISO 27001, APRA CPS 234, AESCSF, Essential Eight and more — the enterprise assessments are built for security teams, GRC leaders and boards.
Find out where you stand — today
Pick your health check, run it in about 60 minutes, and have your score, your gaps, and your action plan before the end of the day. No sales call, no waiting, no data shared.
