Cenvra is a Brisbane based cyber advisory practice. We work with organisations of any size, and we care particularly about Queensland small and mid size businesses, because that is where the risk is highest and the help is hardest to find.
Owned, operated and focused here. Queensland money stays in Queensland.
Australia wide
Brisbane is home, and we deliver nationally when clients need us to.
Fixed price by default
Cost, output and date agreed before we start. Time and materials or a secondment where that suits you better.
Who we work with
Our people have run cyber for global organisations and delivered into some of the largest enterprises and agencies in the country. We still do that work, and we are equipped for it.
What we set out to change is the middle. Queensland small and mid size organisations deliver the health services, move the freight and hold the data, and most carry serious risk with nobody whose job it is to own it. They do not need a six figure programme. They need a senior person for fifteen days who leaves behind a plan the team can run.
That includes non profits, charities, community and aged care organisations. They hold some of the most sensitive personal data in the state, usually with the smallest budgets, and they are rarely anyone’s priority. They are ours.
Small and mid size business
Non profit and charity
Community and aged care
Member associations
Government and statutory bodies
Large enterprise
Sized to the organisation
Scoped to what you can absorb and afford, whether that is a fifteen day engagement or a multi year programme. The method is the same, the depth is not.
The right people on it
Whatever the work needs, we put the right resource on it. Our own team where that is us, and qualified or certified partners where it is not. We will not sell you something we are not the best people to deliver.
Your team, ready to carry it
We train the people who will own it, so when we hand over they can maintain the maturity we reached and keep the risk down. The point is not to be needed again next quarter.
Reinvesting in Queensland
Queensland owned and Queensland employed, with larger work scaled through Queensland small and medium businesses. What you spend here stays here.
What we solve
Most organisations are not careless about security. They are working with an incomplete picture, and there is no way to know that from the inside. You cannot audit for a gap you have never heard of, so the risk that stays hidden is the risk nobody had the vocabulary to raise.
Our job is to bring that view in, tell you plainly what we find, and leave your people better equipped than we found them.
Security leadership is stretched or missing
You have a CISO, a head of security, a CIO carrying it alongside everything else, or nobody at all. Wherever you sit on that, the seat needs support.
Security Leadership
Interim CISO, ongoing advice, strategy.
You need a defensible answer on exposure
Never assessed, assessed once and out of date, or assessed against a framework you are no longer measured on. A client, an insurer or a regulator will ask, and the answer has to hold.
Security Assurance
An assessment, a rating, and a costed plan.
AI is moving faster than the guardrails
Whether you have banned it, allowed it, or have no idea what is in use, the exposure is the same. The work is knowing what is running and being able to say yes safely.
Data and AI
AI readiness, governance, and knowing what data you hold.
Access has outgrown how it is managed
Whether you run identity on a platform, on spreadsheets, or somewhere in between, accounts outlive people and privilege creeps. The same audit finding comes back every year.
Identity
Access reviews, and a plan for managing identity as you grow.
Services we offer
Every service is available as a fixed price engagement, a monthly retainer, or embedded capability inside your team.
01
Security Leadership
Interim Chief Information Security Officer, cover or support
Standing up a security function from scratch
A security strategy, and how it will actually run
Ongoing advice, and reporting your board can follow
A starter programme for smaller organisations
Board and executive reporting we prepare for you
02
Security Assurance
A short health check to see where you stand
An assessment with a rating you can track over time
A review with a costed plan attached
Yearly reassessment, so you can show progress
Moving from the Essential Eight to the new ASD Essentials
Risk carried by your suppliers and partners
Practising what you would actually do in an incident
03
Data and AI
Finding out what AI is already in use
A review of how AI decisions get made and approved
Knowing what data you hold and how sensitive it is
A regular review as your AI use changes
Getting ready for ISO 42001, the AI management standard
Briefing your board and executive on AI risk
04
Identity
Who has access to what, and who should not
How well identity is managed today, and what to fix
A plan for managing identity properly as you grow
Regular reviews so access does not drift
Access that keeps up when people join, move or leave
Control over administrator and privileged accounts
Assessment packages
A known scope and a known price. The same package for everyone, with the effort, timeline and cost scaling to the size of the organisation.
What an assessment covers
Eighteen areas, the same in every engagement. The depth of evidence is what scales with the organisation.
Governance, roles and accountability
Risk management and risk appetite
Policies, standards and how they are followed
Identity, authentication and access control
Administrator and privileged accounts
Endpoint and device management
Network and infrastructure configuration
Cloud and Microsoft 365 configuration
Email and collaboration security
Data classification, handling and loss prevention
Backup, recovery and business continuity
Logging, monitoring and alerting
Patching and vulnerability management
Incident readiness and response planning
Third party, supplier and supply chain risk
People, training and security awareness
AI usage, approval and data boundaries
Physical and environmental controls
Three packages
Each one builds on the last. Start where it makes sense for you, and move up when you are ready. Price scales with the size of the organisation, not with the package you choose.
01
Assess
Know where you stand
Assessment and report
Assessment across all eighteen areas
Rated against the framework you are measured on
AI usage discovery, so you know what is running
Prioritised findings with owners and effort
Executive debrief and a board level summary
02
Assess and uplift
Fix the things that matter
Assessment, then we configure
Everything in Assess
Single sign on and multi factor authentication
Endpoint protection deployed and configured
Conditional access set to how your people work
Data loss prevention configured and tuned
Joiner, mover and leaver process built
Administrator accounts brought under control
AI governance: approval path and data rules
03
Assess, uplift and sustain
Keep it there
Assessment, uplift, then ongoing
Everything in Assess and uplift
Target state agreed with your executive
Costed, sequenced multi year roadmap
Identity governance design and recertification
Recurring AI risk review as adoption grows
Annual reassessment showing movement year on year
Your team trained to carry it after we leave
On the timeline and the price
Assess runs four to six weeks, uplift adds four to eight. We could compress that. We do not, deliberately, because interviews need the right people and enabling controls means change your staff absorb alongside their actual jobs. If you need it sooner, say so and we will scope it that way.
What you end up with
01
Risks and exposures, named
Rated so you can tell a serious problem from an irritation, in terms your board will follow.
02
The maturity level you want
Not the highest score. The level that matches what you are willing to accept.
03
A plan to close the gap
Every finding an action, with an owner, an effort estimate and a cost.
04
A roadmap and a resourcing view
What needs a project, what needs a person, what your team can carry with training.
We fix it, fixed price
Pick the findings that matter most and we quote them fixed price, with the assessment updated to show the movement.
Or we train your team to fix it
Working sessions with the people who will own it. We set the approach, they do the work, we review it. Cheaper, and it lasts.
Add to any package, or take on its own
Each of these can be added to a package or bought as a standalone piece of work.
AI risk assessment
Where AI is in use, what data reaches it, and the exposure that creates. Includes tools staff adopted without telling anyone.
AI governance uplift
An approval path for new AI use, acceptable use rules people can follow, and a way to review it as adoption grows.
Penetration testing
Application and infrastructure testing against the outsider threat, with specialist partners.
Red team exercise
What an attacker could actually achieve, including the insider path. For organisations with the basics already in place.
Framework assessment
Rated against Essential Eight, Queensland IS18 and the ISM, NIST CSF 2.0 or ISO 27001. Assessed once, reported against whichever applies.
How we engage
The same five steps whether we are running an assessment, holding the CISO seat, or embedded in your team.
01
Scoping call
Thirty minutes. What is driving this, what you have already, and what good looks like.
02
Written proposal
Fixed scope, fixed price, defined output and a delivery date. Within three working days.
03
We start
Signed statement of work, dates locked, and the first session booked.
04
Delivery
Whether that is an assessment, an interim CISO seat or an implementation, the principal stays on it.
05
Hand over
A debrief with your team, and something your own people can carry on running.
You are assessed once. If the standard changes, the report changes and the work does not. Fixed price against a written scope, with time and materials or a secondment where that suits better. Microsoft 365 implementation is delivered with our technology partner.
Partners
Small firm, wide reach. We stay independent on advice and bring partners in where they add something we should not pretend to have in house.
Principal technology partner
Applecart Digital
Microsoft 365 digital transformation specialists · Brisbane
SharePoint, Teams, Power Apps, Power Automate and Power BI. Where our identity, data governance and AI work needs to be built rather than just recommended, Applecart build it. Brisbane based, so the whole engagement stays local.
Principal testing partner
Umbra Team
Penetration testing and red teaming · Brisbane
Application and infrastructure testing, and red team exercises run against both the outsider and the insider path. Where an assessment needs proving rather than reviewing, Umbra do the testing and the findings come back into the same plan as everything else.
Operational security testing
Penetration testing, red teaming, and application and infrastructure testing, run against both the insider and the outsider threat. Delivered with Umbra Team, with the findings mapped back into the same plan as everything else.
Auditors and accredited assessors
Formal audits go to accredited auditors and assessors, whether that is ISO certification, IRAP for government work, or PCI DSS for card payments. We get you ready and we fix what is found. We never audit our own advice.
Technology partners
Tooling led services are delivered with technology partners, so you get the platform and the people who know how to run it under one relationship rather than three.
Queensland SMEs
Larger engagements scale through a network of Queensland small and medium businesses, so delivery and spend stay in the state.
Industry experience
Where we work, and what that work looks like. Delivered by our people in prior roles and at Cenvra. Named references available on request.
Government and statutory bodies
Current state assessment, security strategy and a multi year roadmap, then remediation delivered at a pace the agency could absorb. Assessed against IS18 and the ISM.
Health and aged care
Identity and access rebuilt so joiners, movers and leavers are handled properly, and operational security tested rather than taken on assurance. Clinical and corporate systems, privacy and patient data.
Financial services and insurance
Assessment against NIST CSF 2.0, target state agreed with the executive, and a costed roadmap sequenced to regulatory obligations and board reporting. AI governance for a business already using it.
Organisations holding sensitive personal data on the smallest budgets and the thinnest IT support. Scoped to what they can genuinely afford, and costed so it can go into a grant application.
Queensland small and mid size business
The bulk of our work. Local businesses from twenty to two hundred and fifty people across trades, professional services, technology and member associations, most with no security team and real exposure.
The team
Deliberately small. The person who scopes your work is the person who does it.
Tim Speelman
Founder and Managing Director
Twenty years across IT, cyber and AI. Has led a national cyber practice, held the CISO seat across Asia Pacific for a global organisation, and consulted into large enterprise and government.
Works with executive teams and boards on the decisions that move risk: what to invest in, what to accept, and what to fix first. Equally at home in the technical detail and in a board paper.
CISSP
CCSP
ITIL
PRINCE2 Agile
Brisbane · Queensland
We are down the road, not down the wire.
Queensland owned, Queensland employed, and larger work scaled through Queensland small and medium businesses. Delivery and spend stay in the state, and we can be in your office the same week.
Australian owned
Queensland based SME
100% local employment
Registered on QTenders
Start with a conversation
Most engagements begin with a short call. No charge, no obligation, and you will get a straight answer on whether we are the right fit.