Security controls engineering · Australia

Get the security you're already paying for.

Boutique security engineering for the Australian small to mid-market. We harden the stack you already own, across cloud, endpoint, SIEM and AI, then hand it back. Every engagement is project-based, with no lock-in.

Challenges we help solve

Sound familiar?

Most mid-market organisations don't have a security problem so much as an activation problem. The capability is bought, half-deployed, and never tuned.

You're paying for security you're not using

You already pay for serious capability across M365, EDR and firewalls, and use a fraction of it. We turn the tools you own into controls that work.

See what you own

No clear picture of where you stand

Controls half-deployed, policies stuck in audit-only, no consolidated view of exposure. We benchmark your posture and prioritise the gaps that matter.

Get a posture read

Security tools bought, never tuned

A SIEM ingesting noise, an EDR stuck in audit mode, a scanner nobody acts on. We make the platforms you pay for earn their keep, then hand them back documented.

Get them working

01 · Approach

Implement, tune, hand over.

We're engineers, not a managed service. We deploy, tune and document your controls, then train your team to run them. You keep the keys.

01

Assess

An honest look at what you own, what's configured, and where the exposure sits, graded to the frameworks that matter to you.

02

Engineer

Design and deploy the controls, Microsoft-first and multi-vendor where it's the right fit. Migrations, build-outs, policy uplift.

03

Hand over

Documentation, runbooks and knowledge transfer so your team runs it confidently. Time-boxed advisory later if you want it.

03 · Product

See your own findings first.

The platform is not the business — it is the cheapest honest way to put real findings about your estate in front of you before you commit to anything.

How these fit together. Free check, then a Snapshot of the clouds that matter, then a Security Controls Assessment when you need a rating your auditor, insurer or board will accept. Every Snapshot credits in full against an assessment paid for within 90 days of it.

Essential Eight

Essential Eight maturity you can prove.

Australia's baseline, graded from your live configuration — not a workshop and a spreadsheet. Every verdict carries its evidence.

Maturity Level 0–3, per strategy

All eight strategies, graded to the ACSC model. Measured where configuration proves it. Engineer-attested where it can't.

Measured + assessed

Measured: MFA, privileged access, Conditional Access. Attested from your evidence: patching, backups, macro governance, application control on unmanaged endpoints.

Honest scope

Maturity is the lowest level reached across all eight strategies — so we report the one that holds you back, not a flattering average. Any strategy we can't evidence stays unassessed until an engineer attests it, and a level is never awarded from a scan alone. We assess and engineer the controls; we don't run your compliance programme or issue certification.

Going deeper? Read our practical guide: Essential Eight Maturity Level 2 with Microsoft 365 — control by control, what your E3/E5 licensing covers and where it can't.

04 · Why RG Labs

Six things we’ll put in writing. Ask anyone else to.

01

Nothing to sell you.

No licences, no reseller margin, no managed service waiting at the end. The report says what to fix, not what to buy.

02

We round down.

Essential Eight graded at your weakest strategy, never the average. What we couldn’t evidence never counts as a pass.

03

Measured or signed. Labelled.

Every level says whether a machine read it or an engineer attested it — and when. Ask your current assessor to show you that split.

04

Your credentials never touch our platform.

Read-only, revocable by you, run off-platform. Even a breach of our platform can’t reach your environment.

05

We don’t keep your weaknesses.

Findings deleted on a published schedule. Ask sooner and they’re out of our live systems in five business days.

06

We practise it on ourselves.

DNSSEC, DMARC, MTA-STS, security.txt, a public disclosure policy. Check our domain before you trust us with yours.

05 · Where we focus

Small and mid-sized Australian business. On purpose.

Same attackers as the enterprise. A fraction of the team.

Sold to

Vendor-funded security reviews are pre-sales — built to sell you more platform, not to fix what you already have.

Paid up

You already pay Microsoft, AWS or Google. The controls ship with the platform. The gap isn’t budget — it’s someone who knows how to switch them on.

Asked anyway

Insurers, tenders and customers want your Essential Eight level regardless of size. The question arrives long before a security team does.

06 · Contact

Let's talk.

If you're paying for security tooling and aren't sure you're getting your money's worth, that's the conversation to start.

Replies come from an engineer, not a sales team.