Security controls engineering · Australia

Get the security you're already paying for.

Boutique security engineering for the Australian small to mid-market. We harden the stack you already own, across cloud, endpoint, SIEM and AI, then hand it back. Every engagement is project-based, with no lock-in.

Challenges we help solve

Sound familiar?

Most mid-market organisations don't have a security problem so much as an activation problem. The capability is bought, half-deployed, and never tuned.

You're paying for security you're not using

You already pay for serious capability across M365, EDR and firewalls, and use a fraction of it. We turn the tools you own into controls that work.

See what you own

No clear picture of where you stand

Controls half-deployed, policies stuck in audit-only, no consolidated view of exposure. We benchmark your posture and prioritise the gaps that matter.

Get a posture read

Security tools bought, never tuned

A SIEM ingesting noise, an EDR stuck in audit mode, a scanner nobody acts on. We make the platforms you pay for earn their keep, then hand them back documented.

Get them working

01 · Approach

Implement, tune, hand over.

We're engineers, not a managed service. We deploy, tune and document your controls, then train your team to run them. You keep the keys.

01

Assess

An honest look at what you own, what's configured, and where the exposure sits, graded to the frameworks that matter to you.

02

Engineer

Design and deploy the controls, Microsoft-first and multi-vendor where it's the right fit. Migrations, build-outs, policy uplift.

03

Hand over

Documentation, runbooks and knowledge transfer so your team runs it confidently. Time-boxed advisory later if you want it.

02 · Services

Fixed scope. Defined finish.

Productised projects with a defined start, end and deliverable. Then your team runs it.

Best starting point

Security Posture Assessment

Your posture across M365, Azure, AWS and GCP, assessed against the Essential Eight, ISO 27001 and 40+ more frameworks.

Free check → full report → monitoring · typical 2–3 weeks Run your free check →
In Demand

AI Security Review

We don't implement AI. We prove yours is safe: M365 Copilot readiness plus AWS and GCP AI posture, reviewed from real configuration.

Typical 1–2 weeks See what's reviewed →

Cloud Security Engineering

Turn findings into action, with identity, data and workload hardening across M365, Azure, AWS and GCP.

Typical 4–8 weeks

Endpoint Security

Endpoint controls configured to your framework baseline: EDR/XDR implementation, migration and uplift; application control; device hardening and baselines; secure web gateway; endpoint DLP and device control; and disk encryption.

Typical 3–8 weeks

Vulnerability Management System Engineering

From scan noise to a program that closes risk, on Qualys, Tenable or Rapid7, with the operating model to keep the backlog down.

Typical 6–10 weeks

SIEM & Detection Engineering

See the right signals and cut the rest, on Sentinel and beyond, with tuned detections your team can actually read. How we cut a Sentinel bill 30–50%.

Typical 3–6 weeks

Need a hand after hand-over? Time-boxed advisory at $2,000/day ex-GST, minimum two days, and never a retainer. Ask about advisory

Essential Eight

Essential Eight maturity you can prove.

Australia's baseline, assessed against your actual Microsoft estate rather than a workshop and a spreadsheet. Identity controls are measured directly from configuration; the endpoint strategies are assessed by an engineer against your device policy and patch evidence. Every verdict carries its evidence.

Maturity Level 0–3, per strategy

Each of the eight strategies graded to the ACSC maturity model, with the evidence behind every verdict — automated where your configuration proves it, engineer-assessed where it doesn't. The numbers stand up to your auditor.

Measured + assessed

Identity controls — MFA and administrative privilege — are measured directly from your Entra configuration. The strategies that live on endpoints are assessed by an engineer against your device policy and patch evidence, each with an evidence note. Nothing is silently assumed.

Honest scope

The Essential Eight is an endpoint and Microsoft framework, so that is where we score it. AWS and GCP are graded to CIS and NIST instead.

Going deeper? Read our practical guide: Essential Eight Maturity Level 2 with Microsoft 365 — control by control, what your E3/E5 licensing covers and where it can't.

03 · Why RG Labs

Built for delivery, not for billing hours.

Boutique by design: one senior engineer with deep enterprise experience, working directly with your team. No account-manager layer, no offshore handoffs, no lock-in.

Platforms the security tooling and vendors we engineer across
Microsoft
CrowdStrike
Qualys
Tenable
Zscaler
SentinelOne
Palo Alto Networks
ThreatLocker
Rapid7
Selected outcomes real engagements, anonymised

90% backlog reduction

National enterprise vulnerability program. Backlog cut 90% by rebuilding the operating model, not just the scanner.

600+ endpoints migrated

CrowdStrike Falcon to Microsoft Defender across 600+ endpoints and servers, staged in waves with no coverage gap at cut-over.

04 · Where we focus

The Australian small to mid-market.

Big enough that security matters. Lean enough that nobody owns it full-time. That's where we do our best work.

  • 50–2,000 staff, with established operations and a lean security headcount
  • Microsoft E3 or E5 already on the books, rarely fully deployed
  • No full-time security architect, and no appetite to hire one yet

05 · Contact

Let's talk.

If you're paying for security tooling and aren't sure you're getting your money's worth, that's the conversation to start.

Replies come from an engineer, not a sales team.