Bringing financial crime compliance into one governed program
How an Australian mutual bank turned seven-plus separate reviews into one prioritised, auditable program of work in eight weeks.
Read the case studyKnow where your cyber security stands and what to fix first.

Avocado's Cyber Security Maturity Assessment is a fixed-scope cyber security assessment of your controls, governance and risk practices. Our consultants assess the gaps across your people, process and technology, map them to frameworks such as the Essential Eight and NIST CSF, and give you a risk-prioritised roadmap your leadership team can act on.
A cyber security maturity assessment measures how well your organisation prevents, detects, responds to and recovers from cyber incidents. It looks at what actually happens in practice, not only what policy says, and shows the gaps between where you are and where you need to be.
It is different from a cyber risk assessment, which analyses specific threats to specific systems. A maturity assessment gives the whole-of-organisation view first, so you know which risks to analyse in depth and which controls to uplift.
Most cyber programs struggle for the same reason: activity without a baseline. Controls get added and frameworks get adopted, but nobody can say with confidence whether risk has actually gone down. An independent maturity assessment fixes that by giving you a defensible starting point. Organisations typically run one when:
An independent gap assessment across people, process and technology, mapped to the frameworks that apply to you, with a risk-prioritised roadmap.
Roles, accountability, skills and awareness, and how security decisions are made from the board down.
Policies, risk management, incident response, business continuity and how you manage suppliers.
How your security controls are designed, configured and operated, including the Essential Eight controls.
We start with your maturity and risk context, then use frameworks to validate and prioritise uplift. Findings are mapped to the frameworks that fit your organisation. We never recommend a framework/control you do not need.
We confirm the questions you need answered, the business units and systems in scope, who we will speak to and the timeframe. If you have completed the online self-assessment, we use your result as the starting point.
We run interviews with IT, security, risk and business stakeholders, review policies and documentation, and look at how controls are configured in practice.
We identify the gaps across people, process and technology, map them to the frameworks that apply to you, and weigh each gap against your sector, size, operating model and risk appetite.
We present findings and a prioritised roadmap to your leadership team in a playback session, in business language your executives and board can act on.
Not ready for a full assessment yet? Our Cyber Maturity Self-Assessment takes under five minutes. You answer 12 multiple-choice questions, one per domain, and get an indicative maturity rating plus a walkthrough of your results with our team.
| Cyber Maturity Self-Assessment | Cyber Security Maturity Assessment | |
|---|---|---|
| Format | 12-question online questionnaire | Consultant-led engagement |
| Time | Under five minutes | Depends on organisation complexity |
| Based on | Your own answers | Interviews, documentation and evidence |
| Output | Indicative overall rating and a results walkthrough | Gap assessment, findings report and prioritised roadmap |
| Cost | No cost | Fixed price |
A few examples of where an Advisory engagement has made a difference.
How an Australian mutual bank turned seven-plus separate reviews into one prioritised, auditable program of work in eight weeks.
Read the case studyHow an asset finance provider got an honest, independent verdict on its new originations platform before committing further investment.
Read the case studyHow a national not-for-profit healthcare association gained an independent, client-side testing function for a nationally significant platform rebuild.
Read the case studyHow a state-owned water utility moved from ad hoc testing to a structured quality assurance capability it owns outright.
Read the case studyHow a global medical technology company replaced manual permission testing with a maintainable automation framework its own team can run.
Read the case study
How a small Avocado team resolved performance issues a large vendor group couldn't — fixing latency, scaling the platform, and rolling out Dynatrace across Hollard.
Read the case study
How HBF Health replaced fragmented monitoring with Dynatrace and Avocado — real-time visibility across 10,000 assets and 30+ hours saved every month.
Read the case study
How Avocado led end-to-end testing and independent governance across eight streams to take a major super fund's new platform live — catching risks the vendor had missed.
Read the case study
We weigh every finding against your sector, size, operating model and risk appetite, and we never recommend controls you do not need.
Your assessment is led by consultants who deliver cyber uplift, governance and architecture work every day.
Findings are written so executives and boards can understand the risk and back the investment.
We work across healthcare, financial services, utilities and government, and assess against the frameworks and obligations that apply to you.
The roadmap is built for your own team to deliver, with support from us only if you want it.
A structured review of how well your organisation prevents, detects, responds to and recovers from cyber incidents. It compares your people, process and technology against good practice and shows which gaps to close first.
The self-assessment is a five-minute questionnaire that gives an indicative rating based on your own answers. The consultant-led assessment is a broader gap assessment across people, process and technology, based on interviews, documentation and evidence, with a findings report and prioritised roadmap.
The Essential Eight is a strong baseline. The assessment confirms whether it is enough for your risk profile and looks at the people and process gaps that technical controls alone do not cover, such as governance, data security and supplier risk.
Not necessarily. We recommend the framework that fits your organisation, which may be Essential Eight uplift, SMB1001, NIST CSF or ISO 27001 where it is justified.
Typically around six weeks, depending on the size and complexity of your organisation. We agree the timeframe with you before any work begins.
A gap assessment across people, process and technology, a findings report, a risk-prioritised roadmap, framework mapping, an executive summary and a playback session with your leadership team.
No. The roadmap is written so your own team can act on it. If you want support, we can help, but there is no obligation.
Most organisations reassess annually, or after a major change such as a cloud migration, new systems, a merger or acquisition, or a significant incident.
Cyber Security
The full cyber security practice, from strategy to delivery.Governance, Risk and Compliance
Map findings into your compliance obligations and governance.Observability Maturity Assessment
See what your monitoring is missing, scored against our model.Find out where your cyber security really stands
Book a Cyber Security Maturity Assessment and get an independent baseline and a roadmap your leadership team can back. Or start with the five-minute self-assessment.