Security and compliance obligations mapped against operating risk

Cybersecurity / Australia

Cybersecurity advice that turns risk into action.

Know what is exposed. Decide what matters first. DivineLab Worx sets the security roadmap. Sharktech Global delivers the approved technical services.

CYB / 06

Direct answer

What does a cybersecurity consultant provide?

DivineLab Worx provides cybersecurity consulting. We assess risk, set priorities and define the right scope. Approved testing, hardening, monitoring and other technical services are delivered through Sharktech Global.

Security posture

Know what is exposed, what matters first and what evidence you can show.

Good security advice turns technical findings into clear business priorities. DivineLab Worx defines the scope you need. Delivery then moves to Sharktech Global.

Evidence, not raw scanner output

Findings are manually verified where applicable, rated by severity and documented with enough detail for an engineer to act.

Authorised scope

Testing boundaries, timing and escalation contacts are agreed in writing before work starts. Nothing is tested without authorisation.

Australian baseline

The security health check uses the Australian Signals Directorate Essential Eight as a core reference for practical cyber hygiene.

Fix and verify

The objective is not simply to produce a report. Remediation is prioritised and fixes are checked where retesting is part of scope.

Cybersecurity services

Eight security services, guided by one consulting roadmap.

DivineLab Worx helps select and prioritise the right scope. Sharktech Global delivers the approved service or programme.

01

Security health check

A practical baseline across systems, accounts, devices and backups, using the Essential Eight as a core Australian reference point.

  • Essential Eight maturity review
  • Administrator and user access
  • MFA, patching and backup checks
  • Recovery and restore verification
Output: Written assessment and prioritised remediation roadmap.
02

Vulnerability assessment and penetration testing

Authorised testing that separates genuinely exploitable findings from scanner noise and gives technical teams evidence they can act on.

  • External and internal network assessment
  • OWASP Top Ten web application testing
  • Manual verification of findings
  • Severity ratings, evidence and retest
Output: Technical report, executive summary and retest confirmation.
03

Website and web application security

Harden public-facing sites and applications across encryption, headers, administrator access, patching, firewall rules and backups.

  • TLS and security headers
  • Platform and plugin patching
  • Web application firewall configuration
  • Backup and restore testing
Output: Hardened site, change record and agreed monitoring.
04

Cloud and Microsoft 365 security

Review the identity, access and logging controls that commonly drift after the original setup.

  • Administrator and dormant accounts
  • Guest access and legacy sign-in methods
  • MFA and access rules
  • Logging and backup checks
Output: Review report, implemented changes and before-and-after evidence.
05

Email security and fraud protection

Reduce domain spoofing and payment-redirection risk by tightening email authentication and the finance workflow attackers target.

  • SPF, DKIM and DMARC
  • Sending-service audit
  • Mailbox rule and forwarding review
  • Payment verification process
Output: Configured authentication, audit summary and finance verification procedure.
06

Security awareness and phishing simulation

Practical staff training backed by controlled phishing simulations and trend reporting focused on improvement rather than blame.

  • Phishing and invoice-fraud training
  • Simulated phishing campaigns
  • Click and report trend measurement
  • Internal reporting process
Output: Training record, campaign results and trend report.
07

Security monitoring

Connect servers, computers and network sources to a monitoring platform, tune alerts and agree how escalation will work.

  • Monitoring platform deployment
  • Alert tuning
  • Monthly reporting
  • Written escalation plan
Output: Working monitoring setup, escalation runbook and monthly report.
08

Policies and compliance support

Build the security documents organisations are asked to produce for insurers, customers, tenders and certification preparation.

  • Information security and acceptable-use policies
  • Password and access policies
  • Incident response plan
  • SMB1001 or ISO 27001 gap analysis support
Output: Policy pack, incident response plan and gap analysis.
Defence layers

Security is a control system across identity, endpoints, applications, email, cloud and people.

The technical scope is designed around the attack paths most relevant to the organisation and the evidence required by management, customers, tenders or insurers.

01Identity & access
02Endpoints & patching
03Web & applications
04Email & domains
05Cloud & logging
06People & response

Controls are scoped to the environment. The current service does not claim 24/7 SOC coverage, independent certification issuance or specialist digital forensics.

Engagement models

Project, retainer or security support on call.

The commercial model should match the risk and operating requirement rather than forcing every client into the same subscription.

01

Fixed-scope project

One service scoped and priced up front, delivered and documented with a clear start and finish.

Output: Common starting point for assessments, testing and hardening work.
02

Ongoing security retainer

A recurring engagement covering agreed monitoring, patching, phishing campaigns and reporting, with periodic re-checks.

Output: Ongoing control maintenance as systems, users and threats change.
03

Security support on call

An agreed allocation of security capability for organisations that need recurring help without building a full internal security function.

Output: Flexible support for questionnaires, tenders, reviews and security change.
How we work

Advise. Authorise. Deliver. Verify.

DivineLab Worx defines the risk, scope and priorities. Sharktech Global completes authorised technical work.

01

Discovery call

Understand what you run, what has changed and what you are being asked to prove. Identify which service is relevant and which is not.

02

Scope and permission

Agree systems, boundaries, timing, escalation contacts and written authorisation before testing or configuration work starts.

03

Technical delivery

Sharktech Global completes the agreed assessment, testing or hardening work. Disruptive activity requires prior approval.

04

Findings

Deliver an executive summary for decision-makers and technical detail for engineers. Critical findings are escalated when confirmed.

05

Fix and retest

Sharktech Global remediates and retests agreed issues. DivineLab Worx reviews priorities and the next decision.

Scope boundaries

Clear limits make security advice more credible.

The available Sharktech Global delivery scope has clear limits. DivineLab Worx will identify when a different specialist is required.

What this service covers

  • Assessment and hardening
  • Authorised vulnerability and penetration testing
  • Microsoft 365, cloud and email security review
  • Security monitoring during the agreed service window
  • Policies, gap analysis and security questionnaire support

What it does not claim

  • 24/7 SOC monitoring
  • Issuing ISO or other independent certifications
  • Specialist digital forensics
  • Full incident-response capability for a live major breach

Where those capabilities are required, the requirement is identified rather than hidden inside an unsuitable scope.

Consulting with connected delivery

Cybersecurity advice with a clear route to delivery.

DivineLab Worx is the cybersecurity consultant. Sharktech Global delivers all approved security, cloud, software and integration services.

Director-readable

Risk, priority, ownership and next decisions are made clear enough for management, tender and insurance conversations.

Engineer-actionable

Technical findings include the detail needed to reproduce, fix and verify issues within the authorised scope.

Frequently asked

Cybersecurity, answered.

Clear answers for decision-makers evaluating the next step.

01 What does a cybersecurity consultant do for a small or medium business?

A cybersecurity consultant assesses business risk and sets a practical security roadmap. DivineLab Worx leads that work. Sharktech Global delivers approved testing, hardening and monitoring services.

02 What is included in an Essential Eight security health check?

The health check reviews the Essential Eight, user and administrator access, MFA, patching, backups and recovery. It produces a written assessment and prioritised remediation roadmap.

03 Do you provide penetration testing?

Yes. DivineLab Worx defines the authorised scope and reporting priorities. Sharktech Global delivers the penetration test, evidence, remediation guidance and agreed retest.

04 Can you review Microsoft 365 and cloud security?

Yes. DivineLab Worx defines the review scope and priorities. Sharktech Global performs the review and implements approved configuration changes.

05 Do you provide 24/7 security monitoring?

No. The current monitoring service is reviewed during Australian business hours with escalation contacts agreed in advance. If round-the-clock coverage is required, that requirement should be identified and sourced separately.

06 Do you issue ISO 27001 or other security certifications?

No. DivineLab Worx can advise on gaps, policies and readiness. Sharktech Global can deliver approved remediation. Certification must come from an independent certifying body.

07 Do you handle live cyber incidents and digital forensics?

The current service is not positioned as a specialist incident response or digital forensics firm. During a live incident, we can help with initial containment coordination and connect the organisation with the appropriate specialist capability.

Start with the decision

Make the next technology move evidence-led.

Tell us which security decision is next. DivineLab Worx will define the right diagnostic and advisory scope before technical work begins.

Schedule a consultation