// free obligations check

Find out what actually binds you

Not a framework score. A senior read on which obligations genuinely apply to your business — your contracts, the Privacy Act, your customers’ terms, your sector’s rules — and where you’re falling short.

One 30-minute conversation. A one-page read back within 48 hours.
A 20-minute walkthrough to talk it through. That’s the whole thing.

// what you get

Three things, and nothing you didn't ask for

// step one

One 30-minute conversation

What’s driving the question, what you’re contractually and legally on the hook for, and what’s actually in place today.

// step two

A one-page read

Which obligations we think bind you, where the gaps are, and what we’d do in what order. One page, not forty.

// step three

A 20-minute walkthrough

We go through it together. You keep the one-pager either way.

// fit

Who this is for — and who it isn't

This is for you if

  • You’re an Australian business between roughly 20 and 200 people
  • Something specific has raised the question — a tender, a customer questionnaire, insurance, diligence, or defence work
  • Someone owns IT, but nobody senior owns security
  • You need to know which rules actually apply to you before you spend money on any of them

This isn't for you if

  • You’re after a penetration test or vulnerability scan — a different exercise, and we’d point you elsewhere
  • You need a signed certification or formal audit opinion — this reveals gaps; certification is separate paid work
  • You want a free proposal for work you’ve already scoped

And one we’ll tell you for free: if ISO 27001 isn’t actually required in your situation, we’ll say so in writing — even though we sell it.

// the catch

Why it's free — the honest version

Because the fastest way to show you how we work is to do a small piece of it properly.

It’s timeboxed to two hours of our time. If your situation needs more than that, the one-pager will say so plainly and tell you what the paid assessment would cover. No obligation, and you keep it either way.

Most organisations we do this for have gaps that recur — which is why our recommendations usually end with something ongoing rather than a one-off project. We’ll be upfront about that on the call.

// what happens next

Four steps, and you can stop after any of them

// 1

You book

Pick a 30-minute slot. No prep needed.

// 2

We talk

Context, governance, technical posture, evidence.

// 3

You get the read

Within 48 hours. One page.

// 4

We walk it through

Twenty minutes. You decide what, if anything, happens next.

// next step

Book your 30 minutes

Tell us who you are and what’s driving this. We’ll come back within one business day to lock in a time.

// faq

Your questions, answered

Is it really free?

Yes. It’s timeboxed to two hours of our time and there’s no obligation. If your situation needs more than that, the one-pager says so and tells you what the paid assessment would cover.
Thirty minutes and honest answers. No documents to prepare, no portal to fill in. If you have customer contracts with security schedules, having those handy helps — they’re usually where the real obligations are.
This reveals what binds you and roughly where you stand. A paid assessment measures you against it properly, with graded evidence and a costed plan signed by a named practitioner. The free check tells you whether the paid one is worth doing.
Australian obligations: your customer contracts, the Privacy Act and Australian Privacy Principles, the Essential Eight, the ISM and IRAP, ISO 27001, DISP and SMB1001. If something outside that binds you — GDPR, PCI DSS, HIPAA — we’ll say so and name it as out of scope rather than guess.
We’ll tell you what we’d do and what it would cost if you ask. We’ll also tell you when the answer is that you don’t need what we sell — that happens, and we put it in writing.