What we do

Services

DingoSec focuses on a small set of services we can deliver deeply and repeatably: Microsoft 365 security, firewall uplift, Windows hardening, incident response, and governance for Australian SMBs.

Microsoft 365 Hardening & Email Security

Secure identity, Conditional Access, Defender for Office configuration, and mail protection.

  • Tenant baseline review
  • Conditional Access design
  • Defender / Exchange Online Protection uplift
  • Privileged access & admin roles review

Firewall Review & Uplift

Fortigate, pfSense, Palo Alto, or vendor-agnostic firewall review and clean-up.

  • Ruleset simplification & documentation
  • VPN and remote access patterns
  • Segmentation across environments

Windows Baselines & Hardening

Practical hardening aligned with Essential Eight and modern ransomware threats.

  • GPO and baseline review
  • Application control options
  • Admin privilege reduction

Incident Response

Hands-on support for account compromise, malware outbreaks, or suspected breach.

  • Investigation & triage
  • Containment and eradication guidance
  • Recovery and lessons learned

GRC & Policy Work

Light-weight governance aligned with Essential Eight, ISO 27001, and NIST CSF.

  • Policy and standard creation
  • Risk register and treatment approaches
  • Board and executive reporting

Business Continuity & IR Planning

Plans, runbooks, and testing for when things go wrong.

  • IR and escalation runbooks
  • Backup validation
  • Tabletop exercises

IT Architecture & Deployment Support

Assistance with infrastructure projects where security needs to be built in, not bolted on.

  • Network & security design input
  • Secure rollout patterns
  • Logging & monitoring setup, runbooks and handover

How we measure success

We report back with a prioritised backlog, before/after diagrams where relevant, and specific changes your IT team or MSP can action. Where possible we also leave you with monitoring and logging that makes future reviews easier, including clear records for auditors, insurers, or customer due diligence.

Download the Essential Eight checklist we use as a starting point for many engagements, or get in touch to talk about how we can tailor this to your environment. It gives us a shared baseline for the discovery call.

Common questions

Do you replace our MSP?
No. We work alongside your existing IT provider. We produce the changesets and the reasoning; they implement, or we implement with their access. Most engagements make the MSP relationship easier because expectations become explicit.
How quickly can you start on an incident?
Active incidents are triaged same-day where capacity allows. Email info@dingosec.com.au with “INCIDENT” in the subject line and a phone number.
Are you a reseller for any security vendor?
No. We are vendor-neutral. Where a product genuinely solves a problem we will say so, but we take no commission and have no quota to fill.
Can you work with our compliance or insurance requirements?
Yes. Essential Eight, ISO 27001, and NIST CSF alignment is core work, and we routinely produce evidence packs for cyber insurers and customer due diligence questionnaires.
Do you do penetration testing?
We do vulnerability assessment and targeted testing. For formal, scope-heavy penetration tests requiring independence from remediation work, we will refer you to a specialist — testing your own remediation is a conflict we would rather avoid.

Let's find your weakest link before someone else does

A 30-minute scoping call is usually enough to tell you where the real risk sits and what a sensible first engagement looks like. No obligation, no sales theatre.

Book a consult