Skip to main content

Business-wide assessment

Find the paths that could become your next breach.

We examine how weaknesses across your identity, cloud, endpoints, networks, backups and suppliers could combine into a serious incident, then give your team a practical plan to close the most important paths first.

What's included

The short answer

A Breach Prevention Assessment is an independent, business-wide review of how an attacker could gain access, expand control, steal data or stop your operations. It goes beyond a vulnerability scan by connecting technical gaps to the outcomes that matter to your business.

01Business context and critical services
02Identity and privileged access
03Microsoft 365 and cloud controls
04Endpoints and internal networks
05Backups and recovery readiness
06Vendor and third-party access
07Attack paths ranked by business impact
08Prioritised 90-day improvement roadmap

What you walk away with

The deliverables

You receive evidence your leadership team can understand and your IT provider can act on. The package also gives your board, insurer or clients a clear view of the risks identified and the plan underway.

Executive Report

Plain-English summary your leadership team can read and act on. Not a list of CVEs. Written so a non-technical owner can understand what was found and what to do next.

Attack-Path Register

Connected weaknesses mapped into credible breach scenarios, then ranked by exploitability and business impact. This shows what needs fixing now and what can wait.

90-Day Roadmap

A prioritised improvement plan with owners, dependencies and practical next steps. Your IT provider can use it directly, with Cubit Cyber available to guide and verify critical fixes.

Findings Walkthrough

We walk management and your IT provider through the evidence, priorities and recommended actions so everyone leaves clear on what happens next.

How it works

From business impact to action

We start with what matters to the business, test the controls around it and finish with a plan your team can execute.

  1. Scope and Business Context

    We identify your critical services, sensitive data, important suppliers and likely business impacts. Then we agree the systems, access and testing boundaries before work begins.

  2. Evidence Collection and Discovery

    We map your external footprint and collect evidence from identity, cloud, endpoints, networks, backups and security tooling. Automated checks support the work, but do not replace practitioner judgement.

  3. Security Controls Assessment

    We test the controls that prevent, contain and recover from a breach. That includes privileged access, MFA, patching, endpoint protection, segmentation, logging, backups and vendor access.

  4. Attack-Path Analysis

    We connect individual gaps into realistic paths an attacker could use to gain access, expand control, steal data or disrupt operations. This turns a long findings list into a clear breach story.

  5. Risk Prioritisation

    We rank each attack path by exploitability, likely impact and the effort required to reduce it. Current ASD guidance and other relevant standards provide evidence, not a one-size-fits-all score.

  6. Reporting and Action Plan

    You receive an executive report, technical evidence and a prioritised 90-day roadmap. We then walk management and your IT provider through the findings and agree the next actions.

Pricing and timeline

What to expect

From $5,000

For a typical Australian SME (10–200 employees)

2–4 weeks

Typical end-to-end delivery

The final cost depends on your environment, locations, cloud platforms, critical suppliers and the depth of evidence required. We agree the scope and fixed price before work begins.

A senior practitioner owns the engagement from scope through delivery, so the technical evidence stays connected to your business priorities.

The assessment stands on its own. If the findings justify further work, your IT provider can implement the roadmap or Cubit Cyber can guide and verify the critical improvements.

FAQ

Common questions

How long does a Breach Prevention Assessment take?

Most assessments take two to four weeks from kick-off to final report. The exact timeline depends on the size and complexity of your environment. We agree the scope and schedule before work begins.

Do you need access to our systems during the assessment?

Yes, for parts of the assessment. We use read-only access wherever possible and agree every access requirement with you before work begins. External discovery requires little or no access from your team.

Will the assessment disrupt our day-to-day operations?

The work is non-destructive and designed around normal operations. Where a check could affect a production system, we agree the method and timing with you first.

Which Cyber Security standards do you assess against?

We use current Australian Signals Directorate guidance and the standards relevant to your risks, contracts and industry. Frameworks support the evidence, but your priorities are based on credible attack paths and business impact rather than a generic compliance score.

What's the difference between this assessment and a penetration test?

A penetration test actively exploits a defined technical target. A Breach Prevention Assessment examines how weaknesses across your wider environment could combine into a serious business incident. We may recommend targeted penetration testing when the evidence justifies it.

Can we use the assessment report for cyber insurance applications?

The report provides documented evidence of your current controls, material gaps and improvement plan. Insurer requirements vary, so we can also help map the findings to the questions your broker or underwriter asks.

What happens after the assessment? Do you help us fix things?

Your IT provider can implement the roadmap directly. Where useful, Cubit Cyber can guide the work and independently verify critical fixes. Clients that need ongoing security leadership can then move into Security Stewardship.

Ready to see the whole attack path?

Tell us what your business relies on. We will confirm whether this is the right assessment and scope it around your environment.

No obligation · We respond within one business day