Security controls engineering · Australia
Get the security you're already paying for.
Boutique security engineering for the Australian small to mid-market. We harden the stack you already own, across cloud, endpoint, SIEM and AI, then hand it back. Every engagement is project-based, with no lock-in.
Challenges we help solve
Sound familiar?
Most mid-market organisations don't have a security problem so much as an activation problem. The capability is bought, half-deployed, and never tuned.
You're paying for security you're not using
You already pay for serious capability across M365, EDR and firewalls, and use a fraction of it. We turn the tools you own into controls that work.
See what you ownNo clear picture of where you stand
Controls half-deployed, policies stuck in audit-only, no consolidated view of exposure. We benchmark your posture and prioritise the gaps that matter.
Get a posture readSecurity tools bought, never tuned
A SIEM ingesting noise, an EDR stuck in audit mode, a scanner nobody acts on. We make the platforms you pay for earn their keep, then hand them back documented.
Get them working01 · Approach
Implement, tune, hand over.
We're engineers, not a managed service. We deploy, tune and document your controls, then train your team to run them. You keep the keys.
Assess
An honest look at what you own, what's configured, and where the exposure sits, graded to the frameworks that matter to you.
Engineer
Design and deploy the controls, Microsoft-first and multi-vendor where it's the right fit. Migrations, build-outs, policy uplift.
Hand over
Documentation, runbooks and knowledge transfer so your team runs it confidently. Time-boxed advisory later if you want it.
02 · Services
Four things. Done properly.
Productised projects with a defined start, end and deliverable. Then your team runs it.
Security Controls Assessment
Every control on every cloud, graded against the framework you answer to. Essential Eight included.
See what’s switched off → M365 COPILOT · AWS AIAI Security Review
Copilot and cloud AI, secured before your data finds its way into a prompt.
Check before rollout → CLOUD · ENDPOINT · VULN · DETECTIONEngineering
Built, tuned, documented, handed back. The work that follows the findings.
Fix it → BY THE DAY · BY THE MONTHAdvisory
A senior security voice, without the full-time hire.
Talk it through →03 · Product
See your own findings first.
The platform is not the business — it is the cheapest honest way to put real findings about your estate in front of you before you commit to anything.
What the whole internet can already see: email authentication, DNS, HTTPS and security headers, exposed services. Public data only, no credentials, no obligation.
Run the free check → Snapshot $1,000 ex GST, per cloud platformA credentialed, read-only scan of one cloud platform, delivered by an engineer, with the evidence and the vendor's fix for every finding. No maturity rating, no attestation.
How a Snapshot works →How these fit together. Free check, then a Snapshot of the clouds that matter, then a Security Controls Assessment when you need a rating your auditor, insurer or board will accept. Every Snapshot credits in full against an assessment paid for within 90 days of it.
Essential Eight
Essential Eight maturity you can prove.
Australia's baseline, graded from your live configuration — not a workshop and a spreadsheet. Every verdict carries its evidence.
Maturity Level 0–3, per strategy
All eight strategies, graded to the ACSC model. Measured where configuration proves it. Engineer-attested where it can't.
Measured + assessed
Measured: MFA, privileged access, Conditional Access. Attested from your evidence: patching, backups, macro governance, application control on unmanaged endpoints.
Honest scope
Maturity is the lowest level reached across all eight strategies — so we report the one that holds you back, not a flattering average. Any strategy we can't evidence stays unassessed until an engineer attests it, and a level is never awarded from a scan alone. We assess and engineer the controls; we don't run your compliance programme or issue certification.
Going deeper? Read our practical guide: Essential Eight Maturity Level 2 with Microsoft 365 — control by control, what your E3/E5 licensing covers and where it can't.
04 · Why RG Labs
Six things we’ll put in writing. Ask anyone else to.
Nothing to sell you.
No licences, no reseller margin, no managed service waiting at the end. The report says what to fix, not what to buy.
We round down.
Essential Eight graded at your weakest strategy, never the average. What we couldn’t evidence never counts as a pass.
Measured or signed. Labelled.
Every level says whether a machine read it or an engineer attested it — and when. Ask your current assessor to show you that split.
Your credentials never touch our platform.
Read-only, revocable by you, run off-platform. Even a breach of our platform can’t reach your environment.
We don’t keep your weaknesses.
Findings deleted on a published schedule. Ask sooner and they’re out of our live systems in five business days.
We practise it on ourselves.
DNSSEC, DMARC, MTA-STS, security.txt, a public disclosure policy. Check our domain before you trust us with yours.
05 · Where we focus
Small and mid-sized Australian business. On purpose.
Same attackers as the enterprise. A fraction of the team.
Vendor-funded security reviews are pre-sales — built to sell you more platform, not to fix what you already have.
You already pay Microsoft, AWS or Google. The controls ship with the platform. The gap isn’t budget — it’s someone who knows how to switch them on.
Insurers, tenders and customers want your Essential Eight level regardless of size. The question arrives long before a security team does.
06 · Contact
Let's talk.
If you're paying for security tooling and aren't sure you're getting your money's worth, that's the conversation to start.
Replies come from an engineer, not a sales team.