AI is changing how Australian business works. The ones who do it properly will compound the advantage.
Inside Managed IT · Nine years operating depth · 50 five-star reviews
This is what makes our AI claim credible. Nine years of quietly running Australian business security. The baseline underneath everything else.
Essential Eight ML1 as the delivered baseline; ML2+ where regulators require it. Full Microsoft Security stack, deeply deployed. ISO 27001 audit in progress. Normally part of Managed IT — available standalone for businesses that want enterprise-grade security at SMB-friendly economics.
EVISENT // POSTURELIVE
Essential Eight readout
CLIENT SAMPLE · MAY 2026
- ✓Application control ML2
- ✓Patch applications ML2
- ✓Office macros configured ML2
- ↑Restrict admin privileges ML1→ML2
- ✓Multi-factor authentication ML2
- ✓Regular backups ML2
8 OF 8 CONTROLS IN SCOPE · ISO 27001 IN PROGRESS
"AI Governance is the next layer on the same operating standard — not a new business in a different building."
The Microsoft Security stack we run
Four core platforms. Deeply deployed across the client base.
We don't run a "security toolkit" — we run a Microsoft-aligned security stack with nine years of operating depth. The same controls that protect your business today extend naturally to govern your AI environment tomorrow.
Microsoft Defender
ENDPOINT + 365 SECURITY
Endpoint detection & response, M365 phishing & malware protection, attack surface reduction across all client environments.
Microsoft Sentinel Add-on
SIEM + SECURITY MONITORING
Cloud-native SIEM correlating signals across identity, endpoint, M365 and Azure. Available where the use case justifies it — typically regulated clients with material supervisory exposure. We run it for ourselves and for selected clients; not included in the standard $185/user/month bundle.
Microsoft Purview
DLP + DATA GOVERNANCE
Sensitivity labels, DLP rules, vendor-level AI guardrails (Claude, Copilot, others), Acceptable Use Policy enforcement. The bridge between security and AI Governance.
Microsoft Intune
DEVICE MANAGEMENT
Conditional access, device compliance, endpoint hardening, mobile device management. Windows and MacOS endpoints both fully supported.
Essential Eight · ML1 baseline · ML2+ where regulators require it
The ACSC's eight strategies. Operated to a defensible standard.
The Australian Cyber Security Centre's Essential Eight is the de facto baseline for any regulated or regulated-adjacent Australian business. Maturity Level 1 is our delivered baseline across the client base; clients with APRA, ASIC, or government-tender obligations sit at ML2+ on a defensible, evidenced roadmap.
✓
01
Application control
Approved-application whitelisting via Defender + Intune.
✓
02
Patch applications
Critical patches within 48h; rest within 2 weeks.
✓
03
Configure Office macros
Macros blocked from the internet; signed-only where needed.
✓
04
Application hardening
Browser, M365, PDF reader hardened to ASD baselines.
✓
05
Restrict administrative privileges
Just-in-time admin via Entra PIM; privileged access workstations.
✓
06
Patch operating systems
Critical patches within 48h; all systems within 2 weeks.
✓
07
Multi-factor authentication
MFA mandatory for all users; phishing-resistant where licence permits.
✓
08
Regular backups
Immutable backups; tested recovery quarterly; 30-day retention minimum.
ESSENTIAL EIGHT MATURITY LEVEL 3 ATTESTATION IS PART OF THE 2026 CERTIFICATIONS ROADMAP · SEE OUR ROADMAP DOCUMENT FOR DETAIL
What managed security includes
Eight services. One operating standard.
The list below is the standard managed-security envelope we run for every client. It's inclusive — not a "starter tier" with optional add-ons. Some clients add specialist services (penetration testing, third-party SOC integration, advanced threat hunting) but the base envelope is fixed.
1
24/7 monitoring & alerting
Microsoft Defender XDR running continuously, with same-day triage for high-severity alerts and same-business-hour response for critical events. Sentinel SIEM available as an add-on for clients with deeper monitoring needs.
2
Endpoint protection
Microsoft Defender for Endpoint deployed and tuned. EDR signals correlated with M365 + identity data for higher-fidelity detection.
3
Identity protection
Entra ID Conditional Access policies, MFA enforcement, risky sign-in detection, privileged access management via PIM.
4
Vulnerability management
Continuous vulnerability scanning of endpoints and cloud assets; patch deployment within Essential Eight tolerances; quarterly executive report.
5
Security awareness training
Quarterly phishing simulations and education modules. Reported per-user and per-department. Builds the "human firewall" most security platforms can't.
6
Email security
Microsoft Defender for Office 365 with advanced threat protection. Phishing, BEC, malware filtering; safe links and safe attachments.
7
Backup & disaster recovery
Immutable backups for M365, Azure workloads, and endpoint data. Tested recovery quarterly. RPO and RTO documented per workload.
8
Incident response
Documented IR plan, runbooks per scenario, executive briefings during incidents, post-incident review and learning capture.
Compliance content other MSPs treat as marketing fluff
We wrote the compliance pages other MSPs don't.
Australian SMBs in regulated industries deal with overlapping obligations from multiple regulators. We've published deep content on every one of them — not because it's good for SEO, but because we operate against each in delivery.
ESSENTIAL EIGHT
ACSC alignment
PRIVACY ACT
OAIC + ADM rules
APRA CPS 230
Operational risk
ASIC RG 234
Cyber resilience
TPB
Tax practitioner duties
ATO DIGITAL
Digital service standards
LAW SOCIETY
Legal professional
OT SECURITY
Industrial systems
The bridge from security to AI
The reason you can trust us with AI Governance is what's underneath it.
Every claim we make about AI Governance is credible because the security work underneath it is already running. Identity, M365 hardening, DLP, Essential Eight, Quarterly Business Reviews. AI Governance is the next layer on the same operating standard — using the same Microsoft Purview controls, the same Defender stack, the same audit discipline. One team. One contract. One standard.
How security extends to AI Governance
✓ Purview DLP rules become AI data-leakage controls
✓ Defender for Cloud Apps detects shadow AI from any vendor
✓ Entra Conditional Access applies to AI service access
✓ Sentinel SIEM ingests AI service signals (Claude, Copilot, others)
✓ Essential Eight discipline becomes ISO 42001 alignment
Two ways to engage
Bundled with Managed IT, or standalone.
Most clients take cybersecurity as part of our Managed IT service — same team running both, one contract, one monthly fee. For clients who want to keep their existing IT provider but upgrade their security, we run a standalone managed-security engagement with the same operating standard.
BUNDLED · WITH MANAGED IT
From $185/user/mo
+ GST · 10-user minimum · security included
- All Managed IT services included
- Microsoft Defender + Purview + Intune (Sentinel SIEM as add-on)
- 24/7 monitoring + same-day triage
- Quarterly phishing simulations
- Essential Eight ML1 baseline; ML2+ where required
- Backup & DR for M365 + endpoints
- Quarterly Business Reviews + quarterly security review
STANDALONE · SECURITY ONLY
Custom
+ GST · quoted to your environment · scope-dependent
- For clients with existing IT provider
- Microsoft Security stack deployment + management
- Essential Eight uplift program
- 24/7 monitoring + incident response
- Vulnerability management
- Security awareness training program
- Quarterly security review + reporting
Framework alignment & certifications
What we're aligned to today. What we're certifying for next.
We don't claim certifications we don't hold. "Aligned to" means we map our delivery against the framework. "Certified to" only appears when an external audit has confirmed it. Two ISO certifications are in active progress through 2026.
- ESSENTIAL EIGHTML1 baseline across the client base; ML2+ where regulators require it; ML3 attestation on the 2026 roadmap
- ISO 27001Information Security Management certification audit in progress · expected H2 2026
- ISO 42001AI Management System certification to follow ISO 27001 · expected late 2026 / early 2027
- PRIVACY ACTADM transparency obligations covered ahead of 10 Dec 2026
- APRA CPS 230Material supplier checks for regulated client supply chains
- MICROSOFT PARTNERMicrosoft Solutions Partner designations in progress (Security, Modern Work, Infrastructure)
"Evisent's security work just runs. We don't think about it day-to-day — which is the best compliment you can pay a managed-security provider. The monthly reports are clean, the patches happen, the alerts are triaged before we know about them."
— IT Manager, Mid-market accounting firm (sample testimonial)
The 2-week first step
Security that compounds — measurable from day one.
Whether you're swapping providers or starting from scratch, the AI Readiness Sprint is the cleanest way to see what's actually in your environment — security posture, AI exposure, and the gaps before they cost you.