Start with what to verify.
Three illustrative scenarios: the risks to verify, controls to apply, and evidence to collect. Filter by industry to find the closest educational example.
Case file 01 · Legal
Illustrative example — not a verified client result
Seven entry points a legal practice should verify before an attacker finds them
A practical scenario covering exposed remote access, partner MFA, shared administration, guest Wi-Fi, stale accounts, email security, and untested backups.
Risks to check
- Check whether any VPN or remote-access appliance is internet-facing and behind on security updates.
- Verify MFA is enforced on partner, administrator, and finance accounts rather than merely available.
- Review shared administrator credentials, guest-network isolation, departed-user accounts, email filtering, and restore-tested offline backups.
Controls to apply
- Harden and monitor remote access, enforce phishing-resistant MFA, and remove shared administrator access.
- Segment guest Wi-Fi, link offboarding to HR, and monitor email and endpoint events.
- Test restores from isolated backups and record owners, dates, and evidence for each control.
What to verify
- What to verify: the seven control questions have an owner, evidence, and next review date.
- What to verify: insurer and client obligations are mapped to the controls actually operating.
Illustrative example: a 40-person Melbourne family and commercial law practice. Use the assessment to establish a dated remediation plan.
Read the illustrative scenario
The scenario above includes risks to verify, controls to apply, and evidence to collect. We’ll email you a link to this page.
Case file 02 · Financial & Accounting
Illustrative example — not a verified client result
How to verify payment-redirection controls before a supplier mailbox is abused
A business-email-compromise scenario focused on supplier compromise, bank-detail changes, mailbox rules, and independent callbacks.
Risks to check
- Assume a trusted supplier mailbox may be compromised and review how live invoice threads are protected.
- Check whether default filtering can detect sender anomalies and whether mailbox forwarding rules are monitored.
- Verify every bank-detail change requires an independently sourced callback before payment release.
Controls to apply
- Layer sender-anomaly detection over default filtering and monitor mailbox rules in a central log platform.
- Require two-person review and an out-of-band callback using a known contact number for changed payment details.
- Train finance staff on business-email-compromise signals and document the exception path.
What to verify
- What to verify: the callback evidence and approval trail exist before funds move.
- What to verify: supplier compromise can be reported and contained without relying on the suspect mailbox.
Illustrative example: a Melbourne financial advisory and accounting firm. Review payment controls before the next bank-detail change.
Read the illustrative scenario
The scenario above includes risks to verify, controls to apply, and evidence to collect. We’ll email you a link to this page.
Case file 03 · Manufacturing
Illustrative example — not a verified client result
How to test whether ransomware can cross from IT into production
A manufacturing scenario focused on IT/OT segmentation, legacy systems, email controls, and keeping production continuity in the response plan.
Risks to check
- Map whether office IT and operational technology share routes, credentials, or unmanaged trust relationships.
- Identify legacy production systems that cannot receive current updates and record compensating controls.
- Check phishing defenses and whether the incident plan protects production continuity during containment.
Controls to apply
- Separate IT and OT zones, monitor permitted traffic, and restrict administrative paths between them.
- Deploy monitored endpoint controls where feasible and document compensating controls for legacy systems.
- Rehearse an incident plan that contains the office segment without making unsafe production changes.
What to verify
- What to verify: a tabletop exercise demonstrates who can isolate which segment and in what order.
- What to verify: recovery priorities, safety constraints, and restoration evidence are documented.
Illustrative example: a regional Victorian precision-manufacturing business. Exercise the containment path before an incident.
Read the illustrative scenario
The scenario above includes risks to verify, controls to apply, and evidence to collect. We’ll email you a link to this page.
The useful pattern: check risks, apply controls, verify evidence.
Every scenario above is an educational example. Use it to structure a Cyber Readiness Assessment of your own environment and document the evidence behind each control.
Your case file starts with an assessment. Not a guess.
The Cyber Readiness Assessment finds your own vulnerabilities in ten business days and gives you a clear next step.