monthly run cost for the full monitored estate
Security monitoring and evidence retentionMelbourne, Australia
Security, AI and cloud expertise for licensed firms.
I look after Microsoft, Azure and CRM estates for small Australian licensed firms. The controls, the evidence your clients and auditors ask for, and the ongoing administration that keeps both true. Alongside an in-house team or in place of one, as a standing arrangement or a defined piece of work.
Email meor read on
Two suppliers, and the gap between them
Most firms pay for both halves of this, which causes confusion when communication falls through.
The compliance adviser
Produces the manual, the register and the policy set. Describes what the controls should be. Is not asked to implement any of it, and does not.
The IT provider
Keeps the systems running, patched and backed up, and generally does that job properly. Is not asked to produce evidence an auditor will accept, so does not.
Neither is asked to check that what the manual describes is what your estate actually does, or to keep the record that proves it. That is the gap, and it is the part I do. Where you have both already, I work alongside them rather than in place of either.
Security monitoring and alerting, as delivered
The architecture of a platform running today at a licensed firm. Where events go, how long each retention tier is kept, and which path stays up when the reporting layer does not.
The pipeline runs in one line: Defender XDR sends endpoint and identity events to an Event Hub, which passes them to a Function for processing, then to Log Analytics as the queryable store, and finally to Managed Grafana. Two paths branch off that line rather than continuing it. Urgent alerts leave the Function directly for Teams, and the evidence archive is written from Log Analytics to write-once locked storage.
Defender XDR
endpoint and identity
Event Hub
ingest
Function
event processing
Log Analytics
queryable store
32-day detail, 24-month rollup
Managed Grafana
two audiences
Urgent alerts
to Teams
seconds, independent of dashboards
Evidence archive
write-once, locked
7 years, 25 containers
Runs at roughly A$160 a month for the full monitored estate.
Where this has been done
1 of 6
stored deployment secrets after the change
Deployment without stored credentialsmonthly Azure run-rate, a reduction of about 81 per cent
Cloud cost reduction that funded the security workprivileged directory role assignments on the primary administrative account
Privileged access and endpoint hardeningartefacts delivered: guidelines, usage register, enforced policy
AI usage policy, register and enforcementpolicies added across the IT, cyber and privacy layer
Compliance manual and coverage mapOne engagement, an AFSL and ACL holder. Scroll for more.
How we would work
Three shapes
Ongoing
Month to month
I hold the estate. The things that drift get checked before they matter, and when a client or an auditor asks you something you have an answer the same day instead of a fortnight later.
What a month actually contains
Every month
A written pass over the things that drift. Administrative access against what people need now rather than what they needed a year ago. Alerts triaged instead of accumulating. Configuration checked against the documented standard. Posture and cloud spend reported. You get it in writing, which means it is also the evidence.
As things arrive
Client security questionnaires answered from what is actually configured rather than from the manual. Changes made properly rather than quickly. Somebody to ask before you do something, which is consistently cheaper than somebody to call afterwards.
Terms
Month to month. Every change documented with a reverse command and a reason, so you can hand the estate to anyone, including in the month you decide to stop. Cost depends on the size of the estate and is a conversation before either of us commits to anything.
Not included: general helpdesk. Where you already have an IT provider I work with them rather than around them, and where you do not, that is a separate conversation.
A defined piece of work
Scoped up front
An identity clean-up, monitoring stood up, a policy set written and enforced, a migration. Fixed scope agreed before it starts, and documented so your next provider can pick it up.
How a scoped engagement runs
Before it starts
A short look at what is actually configured, so the scope is written against your estate rather than against assumptions about it. You get the scope in writing, with what is in it and what is not.
While it runs
Documented as it goes rather than written up at the end. A reverse command and a reason against every change, so you can see what happened rather than being told about it afterwards.
Terms
The scope is fixed at the point it is agreed. If something turns up that changes the shape of the work, that is a conversation before it becomes work, not a surprise on an invoice. Handover documentation is part of the job rather than an extra.
Worth knowing: the review below is usually the cheapest way to find out whether a piece of work is the right size, and it is not wasted if you decide to go ahead.
A review
Short
Where you stand, as opposed to where the paperwork says you stand. You get the findings and what I would do about each, in order, with no obligation to have me do any of it. Most ongoing arrangements start here.
What a review involves
What I look at
What is actually configured rather than what the manual says. Administrative access, logging and its retention, device compliance, multi-factor coverage, backup. Where a questionnaire or an audit prompted this, I work from that document instead, since it has already told us what matters.
What you get
The findings, what I would do about each, in what order, and roughly what each involves. Written so you could hand it to somebody else and they could act on it.
Terms
No obligation to have me do any of it. If the answer is that you are in reasonable shape and the questionnaire is the only real problem, I will tell you that, because it is true more often than the industry admits.
Most ongoing arrangements start here, because it is the cheapest way for both of us to find out whether the fit is right.
Reasons people get in touch
Urgent and otherwise
Nobody owns this
The estate works, more or less, and no one is responsible for it. Perhaps a provider changed, or the person who knew it left. Nothing is obviously wrong, which is the state in which things quietly stop being true.
A client has asked you to prove something
A security questionnaire arrived, there is a contract behind it, and the answers are not to hand.
An audit or attestation is coming
The manual describes the controls. Producing evidence anyone implemented them is a separate job that has never been done.
Your staff are using AI tools
Client data is going somewhere. There is no register of what is in use and nothing technically stopping any of it.
Get in touch
A sentence or two about where you are is enough to start. If there is a deadline it helps to know it, and if there is not, wanting this in hand is reason enough to write.
If I am not the right fit for what you need, I will say so and point you towards someone who is.
Where somebody already handles your IT, I would rather work with them than pitch against them. On most engagements they end up implementing part of the answer, and that goes better when they are brought in early than when they are handed a finding. Where nobody does, I can pick that up as well.Recent work if you want the detail first.