Risk-based assessments tailored to your organisation
Our team helps you baseline your cyber security control and capability effectiveness and performance by conducting in-depth assessments.
Assessment procedures can be tailored to our in-house cyber security control and capability assessment model that is mapped against multiple frameworks and industry standards or performed against specific industry best practice frameworks like NIST CSF, ISO 27001/2, Essential 8 and many more.
How it works
Our approach combines top-down and bottom-up assessment techniques to ensure that you get an accurate picture of your cyber security posture and identify the people, process and technology gaps that purely top-down or bottom-up assessments can’t always find.
01
Business Analysis
We start off with understanding your business and IT environment. We learn about your critical assets and your control environment to inform our assessment approach to target our testing approach.
02
Best Practice Framework
Using our in-house proprietary Cyber Security Capabilities and Controls Framework or a specified industry best practice standard or framework, we use both top-down techniques, such as documentation reviews and interviews, as well as bottom-up techniques, like configuration reviews and other technical discovery methods to test capability maturity and control effectiveness.
03
Gap Identification and Remediation
We identify and document capability and control gaps from the expected state and work with organisations to close these gaps.
Key Assessments
Assessing how your organisation’s control environment is performing is crucial to proactively maintaining and improving your security controls.
Key assessments include:
- NIST CSF v1.1 and v2
- ISO 27001/2
- Essential 8
Our Security Maturity Assessments Experts
Our expert team have diverse and in-depth experience across various maturity assessments.
Jennifer Vu
Jennifer is the Head of Advisory Services and leads the cyber strategy and GRC capability at Skylight Cyber.
As an experienced cyber security consultant, she specialises in delivering pragmatic and risk-driven cyber security strategies, assessments and cyber risk management services to her clients. Jennifer has engaged with CISOs and cyber security teams to build their security organisations and successfully gain funding for their programs. She also has experience in getting into the weeds of cyber risk management to design, implement and run client's GRC processes and capabilities.
Additionally, in her most recent previous role at NSW Government, she has helped create the 2021 NSW Cyber Security Strategy and led the development and delivery of the first NSW government-wide training sessions for executives and senior management across all departments of NSW government.
Jennifer holds a Bachelor of Information Systems (Co-op) (Honours) from the University of New South Wales (UNSW).
Jimmy Hong
Jimmy is a senior cyber security and strategy consultant, specialising in cyber risk management and governance, and cyber security strategy. He excels in customising critical industry standards such as the ISM, ACSC Essential Eight, ISO 27001, and NIST to align with the unique needs of client organisations, as well as a deep understanding of regulatory compliance requirements such as GDPR and PDPA. This ensures their cybersecurity strategies are effective and well-integrated with business objectives.
Additionally, Jimmy is skilled in information security contractual negotiations and third-party risk management, providing comprehensive safeguards and compliance strategies for organisations.
Jimmy’s consultancy work covers a broad spectrum of sectors, including government agencies, private entities, and global financial institutions. His impact is noted with significant contributions for clients across Australia, Europe, and Asia.
He holds a Bachelor and Master of Electrical Engineering with a focus in Telecommunications from the University of New South Wales.
Mischa Tanne
Mischa is senior cyber security consultant with comprehensive experience delivering governance, risk, and compliance engagements. He has worked with clients to assist them in complying with industry standards and frameworks as well as regulations and laws, including ISO 27001, NIST CSF, ACSC Essential Eight, and GDPR. Mischa has also served as a vCISO, acting as the client’s on-call cyber security expert while also coordinating efforts to increase security practically. Mischa always makes an emphasis to provide business-led cyber security advice in order to provide practical advice to uplift maturity that has the most benefit.
Mischa’s consulting experience has included engagements with national, state, and local governments, public, and private sector clients, across both the APAC and EMEA regions.
He holds a Bachelor of Economics and a Bachelor of Art from the University of Sydney with majors in Econometrics, Financial Economics, and Political Economy. In his focus on continual development, he has also attained industry certifications including CompTIA Security+, and ISC2 Certified in Cybersecurity.