Skip to content
CYBER ASSURANCE

Know whether the controls you rely on are actually in place.

Many businesses have bought cybersecurity products.

That does not automatically mean the underlying controls are complete, configured correctly or operating consistently.

Baselayer helps management understand what protections exist today, where important gaps remain and what should be improved next.

EVIDENCE, NOT ASSUMPTION
Cyber assurance turns those assumptions into a clearer operating picture.

Security needs evidence, not assumption.

Cyber assurance turns those assumptions into a clearer operating picture.

Common statements such as:

“We have MFA.”
“The MSP handles backups.”
“Everyone has antivirus.”
“Microsoft looks after the cloud.”

do not answer the important questions.

Which users?
Which systems?
What exceptions exist?
Who checks it?
What happens when it fails?
How quickly would the business know?

AREAS WE CAN REVIEW

Identity and access

MFA, privileged access, administrator accounts, access lifecycle and authentication controls.

Microsoft 365

Important security, administration and configuration controls across the Microsoft environment.

Endpoint protection

Device management, patching, endpoint security and management visibility.

Backup and recovery

Whether important systems and information are covered and whether recovery expectations are realistic.

Email and user risk

Protection against common account compromise and email-based threats.

Security ownership

Who is responsible for each important control and how exceptions are handled.

Incident readiness

Basic preparation for account compromise, ransomware, outage or other significant technology events.

Essential Eight readiness

Practical review and uplift planning against relevant Essential Eight controls where appropriate.

Supplier assurance

Understand which cybersecurity responsibilities sit with technology providers and where gaps exist between them.

From findings to uplift.

The objective is not to produce a list of technical deficiencies.

Baselayer can then help coordinate or deliver practical remediation.

THE OUTPUT SHOULD DISTINGUISH
urgent risk
important improvement
accepted risk
low-value technical observations
areas requiring specialist assessment

Specialist security still has a place.

Baselayer focuses on practical cyber control assurance, governance and improvement.

Where the business requires services such as:

penetration testingformal certificationspecialist digital forensicsincident responsedeep application security testing

we can help define the requirement and coordinate appropriate specialist providers.

Replace security assumptions with a clearer view.