DyCom Group Queensland
← All posts

You can have great cyber security and still lose the tender

You can have great cyber security and still lose the tender

Here's a scenario we see a lot. A business does the right things. Multi-factor authentication is on. There's a 24/7 security operations centre watching for trouble, proper endpoint protection on every device, mail filtering catching the phishing, and backups that are actually tested. By any sensible measure, they're in good shape.

Then a government tender lands, or the cyber insurance renewal turns up, or an auditor asks a few pointed questions — and suddenly none of that matters, because they can't prove any of it on paper.

That's the gap we spend a fair bit of time closing. Having good security and being able to demonstrate good security are two different jobs, and the second one is the one that wins contracts.

Why “we do that, we just haven't written it down” stops working

A while back we picked up this exact problem for a not-for-profit we look after — a Group Training Organisation that places apprentices and trainees, and therefore holds a lot of personal information about young people. Good controls already in place. Not much documentation to show for them.

The trigger was a government tender. Along with it came a security questionnaire — the kind Victorian and other departments now send to any third party that will touch their data. Dozens of questions. Do you have an Information Security Policy? An Access Management Policy? A patch management process? Show us.

The honest answer at the time was “yes, we do the thing, but the document doesn't exist yet.” On a scored tender assessment, “we'll have that written by next month” reads as a gap. Cyber insurers are heading the same way — the questions on renewal forms have quietly shifted from do you have MFA? to show me the policy that says everyone has MFA and the process that keeps it that way.

The controls were never the problem. The paperwork was.

What we actually built

We put together a complete information security framework — the sort of thing a big enterprise has a compliance team maintaining, sized and priced for an organisation that very much does not have a compliance team.

That meant a full set of security policies (risk management, access, asset management, data protection, incident response, backup and recovery, supplier security, and the rest), each one matched to a plain-English procedure. Underneath it sits a live risk register and a mapping against the Australian Cyber Security Centre's Essential Eight.

The part worth stealing, even if you never call us, is how we split policy from procedure.

A policy says what and why. It's short, it's approved by the board, and it deliberately names no products. “All information is encrypted in transit and at rest.” “Only managed devices access company data.” That kind of thing.

A procedure says how, and names the actual tools. This is where the specific products live — the backup platform, the endpoint agent, the identity provider.

Why bother separating them? Because tools change. Swap your security operations centre or your backup vendor, and if the product name is baked into a board-approved policy, you're technically meant to re-approve the policy. Do that a few times and nobody bothers, and the policies quietly drift out of date until they're fiction. Keep the products in the procedures and a vendor change is a five-minute edit, not a governance event. The policy stays true for years.

Essential Eight, the honest version

The Essential Eight is the ACSC's baseline of eight mitigation strategies, measured across three maturity levels. It comes up in nearly every government tender and a growing number of insurance forms.

Here's the bit people get wrong: you do not wake up one morning at Maturity Level 3. It's a climb, and some of the higher-level controls are genuinely hard work. So we didn't tick every box and hope. We assessed the environment honestly, wrote down where it actually sat, and built a roadmap to move it up level by level — with a couple of the trickier items flagged as work in progress rather than quietly marked “done.”

Assessors and insurers have seen the everything-is-perfect questionnaire before, and they don't believe it. An honest current position with a credible plan carries far more weight than a wall of green ticks that falls apart the moment someone asks for evidence.

The payoff

The same tender questionnaire that used to be full of “we'll get to it” is now mostly “yes — and here's the document.” The organisation can hand a department, an insurer or an auditor a tidy, cross-referenced set of policies and procedures and move on with the actual work.

There's a quieter win too. When the process for granting access, patching a server or responding to an incident is written down, the answer no longer lives in one person's head. New staff can read it. The managed IT provider and the client are working from the same book. And when something does go wrong at 2am, nobody's improvising.

A few things worth taking away

  • Documentation is a control, not admin. If you can't show it, for tender and insurance purposes you don't have it. That's harsh, but it's how the assessment works.
  • Keep products out of your policies. Put them in procedures instead, so swapping a vendor doesn't quietly break your governance.
  • Be honest about the Essential Eight. A real current state plus a roadmap beats a fantasy scorecard every time.
  • Do it before you need it. Tender deadlines are unforgiving, and you cannot write a credible security framework in the fortnight before one closes.

If any of this sounds familiar

If you're a Queensland business or not-for-profit chasing government work, renewing cyber insurance, or just tired of not knowing where you actually stand, we can help — and we'll give you the honest version, not a sales pitch dressed up as an audit.

Start with a free on-site technology review. We'll take a proper look and tell you straight what's solid, what's exposed, and what's worth doing first.

DyCom Group Queensland — enterprise-grade IT, run from up the road.
07 3558 1076 · bruce@dycom.com.au · dycomqld.com.au

Cyber securityComplianceEssential Eight