Most businesses get cyber security wrong in one of two ways: doing nothing because it’s overwhelming, or overspending on controls they don’t need. Both come from the same place — no clear way to match security investment to actual risk. We fixed that with three defined security tiers, so you always know where you stand, what’s next, and why.
Source: Australian Signals Directorate, Annual Cyber Threat Report
Frameworks are confusing by design — Essential Eight, NIST, ISO 27001, CIS, CPS 234 all overlap and none tells you where to start. Our tiers translate them into a practical path. You start where your risk actually sits, and step up only when your business needs it.
The essential protections every business needs. If you’re a 3rdmill managed services client, this is where you start — not an optional extra.
For businesses handling sensitive data — financial services, legal, health — or anyone who wants real visibility and control. A structured cycle: assess, remediate, monitor.
For organisations with formal compliance obligations — CPS 234, ISO 27001 — or boards that want cyber risk managed like every other business risk.
Insurance-driven? Cyber insurers increasingly demand evidence of specific controls before they’ll write or renew a policy. Our gap assessment maps exactly what your insurer expects against what you have, and the roadmap closes the difference — documented, so renewal time is paperwork rather than panic.
Compliance-driven? Whether it’s Essential Eight for government work, CPS 234 for financial services, or a client security questionnaire holding up a deal, we’ve run the process: assess, remediate, evidence. Start with our plain-English guide to the Essential Eight.
Just want to be safe? Then Baseline plus a conversation is the right start. Security is a shared responsibility — we bring the technical controls, monitoring and guidance; you bring the internal policies and processes. We’ll tell you honestly which side needs work.
The Essential Eight is the Australian Cyber Security Centre’s recommended set of baseline mitigation strategies. It’s government-recommended rather than mandatory for most private businesses, but it’s increasingly used by insurers and enterprise clients as the yardstick for whether you take security seriously. Our Baseline and Fortify tiers are designed to move you up its maturity levels pragmatically.
A 3rdmill gap assessment typically costs $3,000 to $5,000 depending on the size of your environment and target framework. You get a clear baseline of where you stand and a prioritised, costed roadmap – so every dollar you spend afterwards is justified by risk, not fear.
Yes. We map your insurer’s control requirements against your current environment, close the gaps, and document the evidence. For many clients this is the difference between being insurable and not, or a meaningful premium reduction.
Not every business does. Baseline includes endpoint detection with alerts actioned by our team. 24/7 managed detection and response with a security operations centre becomes worthwhile when you hold sensitive data, face compliance requirements, or can’t tolerate the response gap outside business hours. We’ll tell you which one you actually need.
Start with Baseline: patching, endpoint protection, email security, backups and user training. It covers the attack vectors behind most SMB incidents and doesn’t require a big program to stand up. From there, a gap assessment tells you whether you need more.
A 30-minute call, or a gap assessment if you want it in writing. Either way you’ll know where you stand and what it should cost — before you spend a dollar.
Enquire today