Cyber security for Australian SMBs

Practical security engineering for

Microsoft 365 hardening, firewall uplift, and Essential Eight governance — delivered by engineers with real experience across large-scale manufacturing, enterprise, M&A, and ISO 27001 programs.

Microsoft 365 identity · Conditional Access · email security Firewalls Fortigate · pfSense · Palo Alto Essential 8 assessments · roadmaps · automation
0Years in security
0Essential 8 controls
0Typical response
0Remote-first, AU
NIST CSFISO 27001ACSC Essential 8ManufacturingLocal GovernmentLogisticsFood & BeverageProfessional Services NIST CSFISO 27001ACSC Essential 8ManufacturingLocal GovernmentLogisticsFood & BeverageProfessional Services
What we do

Six things, done properly

We deliberately keep the service list short. Everything below is something we deliver repeatably, with artefacts your IT team, MSP, auditor, or insurer can actually use.

Microsoft 365 & Azure Hardening

Conditional Access, secure baselines, identity hygiene, mail hygiene, logging, and privileged access reviews — the controls that actually stop business email compromise.

  • Tenant baseline review and remediation plan
  • Conditional Access design and rollout
  • Defender / Exchange Online Protection uplift

Firewall Review & Uplift

Fortigate, pfSense, Palo Alto, or vendor-agnostic review. We rationalise rulesets that have grown for a decade and document what's left.

  • Ruleset simplification and documentation
  • VPN and remote access patterns
  • Segmentation across sites and environments

Windows / GPO Baselines

Essential Eight-aligned hardening: OS baselines, application control options, USB and device lockdown, secure config.

Vulnerability Assessments

Targeted scanning, triage, and remediation plans your IT team or MSP can actually execute — ranked by real exploitability.

Incident Response

Compromise assessment, containment, and cleanup across accounts, endpoints, and email. Focused on rapid, practical recovery.

GRC & Policy

Policy development aligned to Essential Eight, ISO 27001, and NIST CSF — including board-level summaries that a non-technical director can act on.

Business Continuity & IR Planning

Runbooks, escalation paths, backup validation, and tabletop exercises so the plan works on the day it's needed rather than the day it was written.

How an engagement runs

From first call to verified uplift

No 90-day discovery phase. We aim to have you measurably safer inside the first engagement, with evidence you can hand to an auditor.

Scoping call

30 minutes to understand your environment, obligations, and what's actually keeping you up at night.

Assessment

We review the real configuration — tenant, edge, endpoints — not a questionnaire, and rank findings by exploitability.

Remediation

Changesets your team or MSP can implement, or hands-on delivery by us. Documented as we go.

Verify & hand over

Re-test, evidence pack, and a prioritised backlog for what comes next. Optional ongoing monitoring.

dingosec@audit — zsh

Illustrative output. Real findings are delivered as a written report with evidence.

In their words

What clients say

DingoSec completely overhauled our firewall and M365 security in a matter of weeks. Highly pragmatic and no fluff. They operate exactly as advertised.

— CIO, National Logistics Firm

Their Essential 8 roadmap finally gave our board the clarity we needed. We now have a verifiable security baseline and can prove it to our insurers.

— IT Director, Manufacturing Sector

Who we help

DingoSec focuses on Australian small and mid-sized organisations that need to make meaningful security progress without hiring a full-time internal security team.

Typical clients include manufacturing, food and beverage, logistics, regional councils, and services businesses built around Microsoft 365, Windows endpoints, and a firewall that “works” but hasn't been revisited in years.

Engagements are remote-first across Australia, with on-site work by arrangement where factories, warehouses, or data centres are involved.

Approach & outcomes

Work is prioritised around threats that matter: ransomware, business email compromise, account takeover, and destructive insider activity.

Deliverables are pragmatic: secure baselines, changesets that your IT team or MSP can implement, and clear documentation. We can also deploy automated solutions to continuously track control status for Essential Eight programs.

The goal is to leave you measurably safer with artefacts that stand up to auditors, insurers, and customers — not a slide deck that gathers dust.

Let's find your weakest link before someone else does

A 30-minute scoping call is usually enough to tell you where the real risk sits and what a sensible first engagement looks like. No obligation, no sales theatre.

Book a consult