Compromised Assessment
Sydney · NSW · Australia
CyberHarbour · Service Overview
Are You Already
Compromised
Right Now?
Most breaches go undetected for over 200 days. Attackers are already inside thousands of Australian businesses — silently mapping systems, exfiltrating data, and preparing ransomware strikes. A Compromised Assessment identifies threats your current defences have missed — before attackers can act on them.
COMPROMISED ASSESSMENT
⚠️
Australia is under attack every 6 minutes. ASD's ACSC received 84,700+ cybercrime reports in FY2024–25. Average business losses surged 50% year-on-year to $80,850. Small businesses lost an average of $56,600, medium businesses $97,200, and large organisations a staggering $202,700 per incident. Most organisations only discover a breach after the damage is done — if they discover it at all.
Source: ASD's ACSC Annual Cyber Threat Report FY2024–25 — cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025
The Australian Threat Landscape — Latest Data (FY2024–25)
6 min
Attack Frequency
A cybercrime reported in Australia every 6 minutes — 84,700 reports in FY2024–25
ACSC FY2024–25
200+
Mean Dwell Time
Median time attackers remain undetected inside a compromised network
IBM Cost of Data Breach 2024
$4.26M
Avg Breach Cost
Total cost of a data breach in Australia including remediation (2024)
IBM Cost of Data Breach Report 2024
11%
YoY Incident Increase
Year-on-year rise in cyber security incidents responded to by ASD's ACSC (FY2024–25)
ACSC FY2024–25
Why SMEs Are the Primary Target
🎯 High-Value Target
Small Businesses Are Not "Too Small to Hack"
Small businesses represent 91.9% of all Australian businesses and account for the majority of cybercrime reports filed with the ACSC. They hold valuable data yet operate with limited security resources — a gap attackers actively exploit at scale. Phishing, credential theft, and BEC are the primary vectors. For many, a single incident is unrecoverable: studies show a significant proportion of affected small businesses cease operations within six months.
60%
of affected small businesses close within 6 months · NCSA / Verizon DBIR
💸 Severe Financial Risk
Medium Businesses Face the Heaviest Losses
Medium businesses (20–199 employees) consistently record the highest average losses per incident of any business size in Australia — a pattern confirmed across multiple ACSC annual reports. Costs rose 55% year-on-year in FY2024–25. These organisations hold substantial data assets and revenue streams, yet typically lack the mature threat detection and incident response capabilities of enterprise-scale organisations.
55%
year-on-year increase in avg incident cost · medium business · ACSC FY2024–25
Why Act Now — The Cost of Waiting
Sources: IBM Cost of Data Breach 2024 · CrowdStrike Global Threat Report 2024 · Coveware Q4 2024
94%
Malware-Free Attacks
Of intrusions in 2024 used no malware — evading signature-based detection entirely
$4.26M
Avg Breach Cost (AU)
Financial impact per incident including all remediation
<1 hr
Time-to-Ransom
Once inside, threat actors can escalate privileges and deploy ransomware in under 60 minutes
21 days
Avg Ransomware Recovery
Average time to restore operations after a ransomware attack — not including financial losses
Compromised Assessment — Solution Details
Australian Cybercrime Reports & Cost per Incident (FY2020–FY2025)
Bars = total cybercrime reports (left axis) · Line = avg cost per incident, small business (right axis) · Official ACSC data
Total Reports (left)
Avg Cost — Small Biz (right)
100k 75k 50k 25k 0 REPORTS $60k $50k $40k $30k AVG COST 67.5k FY20 67.5k FY21 76k FY22 94k ▲ FY23 87.4k FY24 84.7k FY25 $33k $39k $39k $46k $49.6k $56.6k ▲ Cost per incident (small biz) rose 72% over 5 years — even as total report volumes stabilised
Sources: ASD/ACSC Annual Cyber Threat Reports FY2019–20 to FY2024–25 · cyber.gov.au/about-us/view-all-content/reports-and-statistics · Cost figures from ACSC fact sheets (avg self-reported financial loss, small business). ACSC does not publish segmented incident counts by business size.
What a Compromise Looks Like in Practice
🔴 Common Compromise Scenarios
The most prevalent attack patterns CyberHarbour identifies in Australian SME environments:
Credential harvesting — valid credentials compromised via phishing or password spray, enabling silent persistent access months before any ransom demand.
Active Directory compromise — privilege escalation to domain admin, granting unrestricted lateral movement and the ability to disable security controls.
Living-off-the-land (LotL) — attackers using legitimate system tools (PowerShell, WMI, RDP) that generate no malware signatures and bypass EDR detection.
Data staging prior to encryption — sensitive files exfiltrated to attacker-controlled infrastructure days before ransomware is deployed, enabling double-extortion.
Patterns based on CrowdStrike Global Threat Report 2024 · Verizon DBIR 2024 · ACSC incident data
🟡 Signs Your Environment May Be Compromised
Indicators that warrant an immediate Compromised Assessment:
Unexplained user account lockouts or failed authentication spikes in Active Directory or cloud identity platforms
Unusual outbound network traffic, particularly large data transfers to unfamiliar external destinations
Security tools or logging services that were disabled or reconfigured without a known change request
A third-party supplier, partner, or peer organisation has recently reported a breach — supply chain exposure is high
Your organisation has never undergone a formal threat hunting or compromise assessment exercise
Indicators aligned with ACSC's "Detect" guidance · MITRE ATT&CK Detection framework
Key Benefits of a Compromised Assessment
🤝
Analyst-Led, Not Automated
Every engagement is conducted by senior threat hunters and incident responders — not an automated scanning platform. Human judgement identifies what tools miss. If active threats are confirmed, our incident response capability can be activated immediately.
🔍
Detect Active Compromise
Identify attacker presence, malware implants, backdoors, and persistent footholds that signature-based security controls — AV, perimeter firewalls, and even EDR — are not engineered to detect.
🗺️
Map the Full Attack Chain
Understand exactly how an attacker entered, which systems were touched, what data was accessed or exfiltrated, and how far lateral movement has progressed — not just the point of entry.
🛡️
Contain Before Escalation
Early identification creates the opportunity to contain and eradicate threats before attackers can deploy ransomware, monetise stolen credentials, or cause irreversible operational and reputational harm.
📊
Evidence-Based Findings
Every finding is supported by forensic evidence — not automated scanner output. Confirmed indicators of compromise (IOCs), attacker TTPs mapped to MITRE ATT&CK, and a full affected asset inventory.
📋
Prioritised Remediation Plan
A practical, risk-ranked remediation roadmap tailored to your environment — immediate containment steps alongside strategic hardening recommendations, written for both technical teams and business leadership.
Why CyberHarbour
🏅
Internationally Certified Specialists
Our analysts hold internationally recognised certifications including CISSP, GREM, CHFI, and Security+ — covering digital forensics, malware reverse engineering, and incident response
🌏
Australian Market Expertise
Deep, hands-on experience with the Australian threat landscape, local regulatory obligations, and attack patterns most prevalent across AU industries and sectors
🏥
Cross-Industry Experience
Proven across healthcare, finance, legal, manufacturing, and professional services — understanding sector-specific data risks and compliance requirements
🔒
ISO 27001 Certified
Our own security management practices are ISO 27001 certified — we hold ourselves to the same rigorous standard we expect of our clients
Our Process — How a Compromised Assessment Works
01
🎯
Scoping & Kick-off
Define environment boundaries, critical asset inventory, and detection priorities. Collection methodology is determined by infrastructure scope and complexity. Typical engagements run 2–6 weeks depending on environment size.
02
📡
Evidence Collection
Lightweight, non-invasive telemetry is collected across endpoints, network traffic, Active Directory, and cloud environments. No maintenance windows or system downtime are required.
03
🔬
Threat Hunting & Analysis
Senior threat hunters analyse collected evidence for indicators of compromise (IOCs), attacker TTPs, anomalous authentication activity, lateral movement paths, persistence mechanisms, and signs of data staging or exfiltration.
04
📄
Findings & Reporting
Comprehensive written report covering confirmed indicators of compromise (IOCs), attack chain reconstruction, MITRE ATT&CK framework mapping, and a risk-prioritised remediation plan.
05
🤝
Debrief & Response
A structured debrief session guides stakeholders through all findings, evidence, and recommended actions. Incident response escalation is available if active threats are confirmed.
Assessment Deliverables
Deliverable What You Get Timing
Compromise Report Executive + technical findings: confirmed compromise indicators, attacker tools, affected assets, and lateral movement paths Post-analysis phase — scoped at kick-off
MITRE ATT&CK Mapping All findings mapped to MITRE ATT&CK framework with full IOC list for your environment and threat attribution where possible Included in report
Remediation Roadmap Prioritised action plan — immediate containment steps and strategic hardening recommendations, tailored to your environment Included in report
Executive Briefing Plain-language presentation for board/leadership covering risk exposure, business impact, and recommended next steps Scheduled post-report
🚨
If Active Compromise Is Confirmed — What Happens Next
You will never be left with a finding and no path forward. Our analysts notify you immediately and walk you through containment options before the formal report is issued.
① Immediate notification ② Containment options briefed ③ Incident Response service engagement activated (optional)
24/7 IR Hotline
1300 CYB HAR
Regulatory & Insurance Relevance
ASD Essential Eight — Supports "Assume Compromise" posture
Privacy Act 1988 — Notifiable Data Breaches scheme readiness
Cyber Insurance — Satisfies underwriter assessment requirements
SOCI Act — Supports critical infrastructure security obligations