Cybersecurity Services

Essential Eight Compliance & Cybersecurity Consulting for Australian SMBs

Protect what matters. Meet compliance. Stay insurable.
All without a Big 4 price tag.

VAPT Starter
From $7,500 AUD
Full VAPT
From $12,000 AUD
Essential Eight
From $8,500 AUD
Free
Cyber Health Check
βœ… Essential Eight AlignedπŸ”’ OWASP & NIST🏦 APRA CPS 234
πŸ›‘οΈ Book Your Free Cyber Health Check β†’
Why Act Now

Cyber Incidents Are No Longer β€œIf” β€” They’re β€œWhen”.

  • 94% of organisations undergoing red-team testing face successful penetration β€” most had no idea their defences were inadequate.
  • Australian SMBs are the #1 target β€” small enough to lack enterprise defences, large enough to hold valuable client data and financial records.
  • Cyber insurers now require documented Essential Eight compliance or deny coverage β€” leaving unprotected businesses fully exposed to breach costs.
Start with a Free Cyber Health Check β†’
rabbiico VAPT Scanner | Live Assessment
[*] Initiating external vulnerability scan...[*] Scanning ports, services & web endpoints...CRITICAL SQL Injection β€” /admin/login Β· POST param 'user'CRITICAL .env exposed β€” DB_PASSWORD readable via direct URLHIGH     Port 3306 open β€” MySQL accessible from public internetCRITICAL Default creds accepted β€” admin:admin123 on /wp-adminHIGH     No MFA β€” admin portal reachable with password onlyCRITICAL File upload bypass β€” Remote Code Execution confirmedHIGH     Session tokens persist after logout β€” fixation riskRESULT   4 CRITICAL Β· 3 HIGH Β· full compromise in < 4 hrs[*] Awaiting remediation...
Cybersecurity Services & Pricing

Transparent Pricing. Fixed Quotes. No Surprises.

Protect what matters. Meet compliance. Stay insurable. All without a Big 4 price tag.

Free

Free Cyber Health Check

$0
External risk review delivered in 48 hours. Zero obligation.
  • External attack surface scan
  • SSL/TLS & security headers review
  • Basic vulnerability indicators
  • Plain-English report in 48 hours
  • Zero obligation
Book Free Health Check β†’
Compliance

Essential Eight Gap Assessment

From $8,500
Full ASD Essential Eight maturity assessment for compliance and insurance.
  • Full ASD Essential Eight maturity assessment
  • Gap analysis across all 8 strategies
  • Maturity rating per strategy
  • Prioritised remediation roadmap
  • Compliance-ready documentation
Get Assessment Quote β†’
Penetration Testing

VAPT Starter

From $7,500
Automated vulnerability assessment with OWASP Top 10 coverage.
  • Automated vulnerability scanning (Nessus/OpenVAS)
  • OWASP Top 10 automated coverage
  • SSL/TLS, headers & port scanning
  • CVE detection & CMS checks
  • Automated report with CVSS ratings
Get Started β†’
Most Comprehensive β˜…
Enterprise

Full VAPT + Essential Eight

From $18,500
Complete Full VAPT plus Essential Eight in one engagement.
  • Complete Full VAPT + Essential Eight
  • Combined unified report
  • Compliance mapping & gap analysis
  • Ideal for cyber insurance & audits
  • Timeline: 3–5 weeks
Request Scope Quote β†’
Add-On
Code Security

Secure Code Review

From $2,500
White-box source code analysis. Add to any tier.
  • SAST tooling (Semgrep, ESLint security)
  • Manual code review by security engineers
  • OWASP secure coding verification
  • Remediation guidance per finding
  • Available for JS/TS, Python, PHP
Add Code Review β†’
FeatureE8StarterFull VAPTFull + E8
Automated vulnerability scanningβ€”βœ“βœ“βœ“
OWASP Top 10 coverageβ€”AutomatedManual verifiedManual verified
SSL/TLS & security headersβœ“βœ“βœ“βœ“
Port scanning & service enumerationβ€”βœ“βœ“βœ“
DNS & subdomain reconβ€”βœ“βœ“βœ“
Web app scanning (OWASP ZAP)β€”βœ“βœ“ + Burp Suiteβœ“ + Burp Suite
Authentication testingβ€”BasicDeep-diveDeep-dive
Known CVE detectionβ€”βœ“βœ“βœ“
CMS vulnerability checksβ€”βœ“βœ“βœ“
API endpoint discoveryβ€”BasicFull REST/GraphQLFull REST/GraphQL
Manual penetration testingβ€”β€”βœ“βœ“
Business logic testingβ€”β€”βœ“βœ“
IDOR / privilege escalationβ€”β€”βœ“βœ“
OWASP ASVS verificationβ€”β€”βœ“βœ“
Essential Eight assessmentβœ“β€”β€”βœ“
Compliance documentationβœ“β€”β€”βœ“
Re-test periodβ€”14 days30 days30 days
Timeline2–3 weeks1–2 weeks2–3 weeks3–5 weeks

What is a re-test? A re-test is a focused verification scan performed after you’ve remediated the vulnerabilities found in the initial assessment. It confirms your fixes are effective and provides updated evidence for insurers and auditors. Re-tests cover only the original findings β€” they are not a new full assessment. VAPT Starter includes a 14-day re-test window; Full VAPT and Full VAPT + E8 include 30 days.

πŸ›‘οΈ Cyber Shield Plans β€” Ongoing Protection

Annual plans with bi-annual assessments, continuous monitoring, and priority support. Save up to 20% vs. standalone.

View Cyber Shield plans

Cyber Shield

From $12,500/year
  • 2 VAPT Starter assessments per year
  • Vulnerability alerts between tests
  • Priority booking & support
  • Monthly security digest email
  • Save $2,500 vs. 2 standalone tests

Cyber Shield Pro

From $19,500/year
  • 2 Full VAPT assessments per year
  • Continuous vulnerability monitoring
  • Dedicated security consultant
  • Quarterly security posture report
  • Save $4,500 vs. 2 standalone tests

Cyber Shield Complete

From $29,500/year
  • 2 Full VAPT + E8 assessments per year
  • Essential Eight compliance tracking
  • Annual security strategy session
  • Board-ready reporting
  • Save $7,500 vs. 2 standalone tests
Enquire About Cyber Shield β†’
Who We Work With

Built for Australian Businesses

We understand the compliance obligations and risk profile of the sectors we serve β€” not just the technology.

🏒

Small & Medium Businesses

Essential Eight compliance and VAPT without the Big 4 price tag.

πŸ›’

E-commerce & Retail

Customer data protection, breach prevention and PCI DSS awareness.

🏦

Financial Services

APRA CPS 234 compliance, cyber insurance documentation and incident planning.

πŸ₯

Healthcare

Privacy Act obligations, patient data security and ransomware resilience.

πŸ’Ό

Professional Services

Client data protection and cyber insurance eligibility for law firms and consultants.

πŸ›οΈ

Government Suppliers

PSPF and Essential Eight evidence package for panel managers.

Our Process

How It Works

From first contact to findings β€” five clear steps, no surprises.

01

Free Health Check

External attack surface review delivered in 48 hours β€” at no cost.

02

Scoping Call

30 minutes to align on environment, obligations, and a fixed-price quote.

03

Assessment

ASD, OWASP, and NIST-aligned gap analysis or penetration test.

04

Findings & Roadmap

Plain-English report with risk-prioritised actions and board summary.

05

Cyber Shield

Optional annual plan for ongoing monitoring, bi-annual assessments, and dedicated support.

Common Questions

Frequently Asked Questions

Straightforward answers to the questions we hear most often.

What is an Essential Eight Gap Assessment?

The Australian Signals Directorate’s (ASD) Essential Eight is the baseline cybersecurity framework for Australian organisations. It covers eight strategies: application control, patch management, macro configuration, user application hardening, administrative privilege restriction, OS patching, multi-factor authentication, and backups.

A Gap Assessment benchmarks your current controls against all eight strategies and produces a maturity level score (0–3) for each. The deliverable is a plain-English report with findings and a risk-prioritised remediation roadmap β€” the documentation your cyber insurer and government panel manager require. Our assessment starts at $8,500 AUD with a 2–3 week timeline.

Do I need Essential Eight compliance for cyber insurance?

Increasingly, yes. Australian cyber insurers are tightening underwriting requirements. Many now require evidence of Essential Eight Maturity Level 1 or higher as a baseline condition for coverage. Without documented controls, premiums rise significantly or coverage is declined entirely.

A rabbiico Gap Assessment produces the compliance documentation your broker and insurer need.

What is the difference between VAPT Starter and Full VAPT?

VAPT Starter ($7,500) is an automated + guided vulnerability assessment ideal for a first security test. It covers automated scanning, OWASP Top 10 (automated checks), port scanning, DNS recon, CVE detection, and includes a 14-day re-test.

Full VAPT ($12,000) is the gold standard. It includes everything in VAPT Starter plus manual penetration testing by senior consultants β€” advanced injection testing, business logic analysis, API security, OWASP ASVS verification, proof-of-concept exploitation, and a 30-day re-test. It’s how red teams operate and what we recommend for any business with a web application, API, or complex environment.

What are the Cyber Shield annual plans?

Cyber Shield plans give you ongoing protection at a significant saving compared to booking standalone assessments. Each plan includes two assessments per year plus continuous support between tests:

  • Cyber Shield ($12,500/year) β€” 2 VAPT Starter assessments, vulnerability alerts, priority booking, monthly security digest. Save $2,500.
  • Cyber Shield Pro ($19,500/year) β€” 2 Full VAPT assessments, continuous monitoring, dedicated consultant, quarterly posture report. Save $4,500.
  • Cyber Shield Complete ($29,500/year) β€” 2 Full VAPT + E8 assessments, compliance tracking, annual strategy session, board-ready reporting. Save $7,500.

All Cyber Shield plans are annual with no hidden fees.

What is VAPT (Vulnerability Assessment and Penetration Testing)?

VAPT combines two complementary activities. A vulnerability assessment systematically identifies weaknesses across your systems. Penetration testing goes further β€” a security expert actively attempts to exploit those weaknesses the way an attacker would, demonstrating real-world risk.

rabbiico offers VAPT Starter from $7,500 AUD (automated + guided) and Full VAPT from $12,000 AUD (including manual penetration testing by senior consultants). For complete coverage including Essential Eight compliance, the Full VAPT + Essential Eight package starts at $18,500 AUD. All findings are reported with CVSS severity scores and actionable remediation recommendations.

How long does an assessment take?

Timelines depend on the engagement:

  • Essential Eight Gap Assessment: 2–3 weeks
  • VAPT Starter: 1–2 weeks
  • Full VAPT: 2–4 weeks
  • Full VAPT + Essential Eight: 3–5 weeks
  • Secure Code Review: 1–3 weeks

A scoping call (30 minutes) establishes timelines before we begin. We do not start billable work until a fixed scope and price are agreed.

Do you provide remediation support after the assessment?

Yes. After your assessment we can scope a fixed-price remediation project to address findings systematically. Ongoing Cyber Shield annual plans are also available for VAPT tiers β€” contact us to discuss the right arrangement for your business.