Cyber security, compliance and the build in between.
Five services covering consultancy, framework audits, incident response and web work for businesses on the Sunshine Coast and remotely across Australia. Most engagements start with an assessment, because it is the cheapest way to find out what actually needs doing.
A freelance cyber security specialist.
JamesKDesigns is a freelance cyber security consultancy based on the Sunshine Coast, Queensland. I have worked with clients in the digital space since 2019, and have been pulling systems apart to understand them since well before that.
Self-taught first, then studying cyber security at TAFE and university. I keep active subscriptions to the TryHackMe labs, and meet other IT enthusiasts.
Cyber security moves quickly enough that continual learning is the job, not an extra. Where an engagement needs a specialism outside my own, I collaborate with other cyber professionals rather than stretch to cover it. You get the right person on it either way.
The work runs from initial consultancy and assessment through to implementing the controls that come out of it, aligned to the frameworks below. That means assessing where your organisation actually sits, strengthening your security posture, and defining the roles, responsibilities, processes and controls that make it hold together as the business grows.
Standards the work aligns to.
Working to a recognised framework means the outcome is measurable and defensible rather than a matter of opinion. The approach follows Australian Cyber Security Centre guidance.
NIST CSF
ISO 31000 & NIST RMF
Risk management frameworks used to build a control library, find the risks specific to your organisation, and prioritise what to do about them.
Jump to a service.
01 · Cyber Security Consultancy
Cyber security consultancy.
Cyber security consultancy is ongoing, independent advice on protecting a business’s systems and data including strategy, assessment, and the implementation that follows. I deliver it on the Sunshine Coast and remotely Australia-wide, aligned to the NIST Cybersecurity Framework.
What’s included
- General IT questions on improving security
- Consultation on securing IT infrastructure
- Website security audits
- DNS checks and configuration, including SPF, DKIM and DMARC
- Staff cyber awareness training
- Microsoft 365 security and compliance reviews
- Risk assessments and vulnerability management
- Cyber security policy development
Who it’s for
Small and medium businesses whose systems matter to revenue, with no in-house security expertise and no appetite for a retainer they will not use. Also anyone being asked to demonstrate a security position to a client, an insurer or a tender.
How it works
An initial conversation to work out what is actually being asked, then a scoped piece of work quoted in writing before anything starts. No lock-in, and I will say so if a full engagement is not worth your money.
02 · Microsoft 365 Security Audit
Microsoft 365 is not secure out of the box.
A Microsoft 365 security audit reviews an entire tenancy including accounts, permissions, authentication and data control, all checked against Microsoft’s own recommendations. Buying licences is not the same as configuring them. A default tenancy leaves multi-factor authentication optional, administrator rights broadly assigned and data loss prevention switched off. The audit finds where that exposes you, tightens it, and lifts your Secure Score and Compliance Manager position with changes that hold.
What’s included
- Tenancy health check and environment audit
- Review of accounts, roles and access permissions
- Multi-factor authentication coverage
- Data loss prevention and access controls
- Audit log and user activity review
- Secure Score and Compliance Manager uplift
- Implementation of the tightened controls
Who it’s for
Any business running Microsoft 365 that has never had the tenancy reviewed, particularly where administrator rights were handed out early and never revisited, or where the default out-of-the-box configuration is still in place.
What you get
A detailed report drawn from user activity, audit logs and configuration review, with recommendations prioritised so you know what to fix first. Alignment with ISO 27001 expectations, reducing non-compliance exposure. Implementation is included, not quoted separately.
03 · NIST CSF Controls Audit
NIST CSF controls audit, then the remediation.
The NIST Cybersecurity Framework organises security around five functions.
Identify, Protect, Detect, Respond and Recover.
A controls audit measures your existing systems against all five, produces a gap analysis against each, and is followed by the implementation work to close what it finds.
What’s included
- Controls audit against all five core functions
- Compliance gaps and areas for improvement identified
- Gap analysis with actionable remediation steps
- Tailored control implementation
- Prioritised reporting for technical and executive readers
Who it’s for
Organisations that need a defensible structure around security rather than a collection of individual fixes, particularly where several systems have grown up separately and nobody has assessed them as one estate.
What you get
A comprehensive report with prioritised recommendations, and controls deployed with the policies, tools and procedures to keep them in place. A sample report is available on request before you commit.
04 · Incident Response & Risk Management
Incident response and risk management, before you need them.
An incident response plan sets out who does what in the first hours of a cyber incident including roles, escalation, communication and recovery. Risk management is the other half of the same problem, identifying what could go wrong before it does. Plans are built to align with Australian Cyber Security Centre guidance, and risk work follows ISO 31000 and the NIST Risk Management Framework.
Incident response
- Tailored incident response plan aligned to ACSC guidance
- Clear roles, escalation paths and communication protocols
- Recovery actions for ransomware, malware, phishing and DoS
- Monitoring to identify and respond to threats quickly
- Support during an incident, including stakeholder communication
- Post-incident review capturing lessons learned
Risk management
- Detailed analysis of systems, processes and environment
- Risks specific to your organisation identified, not generic ones
- A control library built to address them
- Mitigation strategies prioritised by likely impact
- Regulatory compliance alignment
- Ongoing monitoring as the risk picture changes
What you get
Reduced downtime, because a prepared response is faster than an improvised one. Evidence for audits and assessments that the plan exists and has been tested. Tabletop exercises where useful, and a team that recognises a problem early enough to act on it. Sample plans can be provided.
How findings are ranked
Severity reflects what an attacker could actually do with it, not how alarming the scanner output looks.
05 · Web, Media, SEO & GEO
Web development, SEO, and everything pointing at the site.
Web development and SEO cover the two halves of being found. The site itself, and the search visibility that decides whether anyone reaches it. GEO, generative engine optimisation, is the newer third: a growing share of questions that used to be searches are now put to AI assistants, and the answer depends on what they can read about you. Structured data, an llms.txt file and plain, specific copy are what make that answer accurate. Covers building new sites, auditing existing ones, print-ready material, and the analytics that make performance measurable. Recent builds are on the portfolio page, and the website security basics post covers what hardening a build actually involves.
What’s included
- Website design and development
- SEO review covering structure, metadata, keywords and content
- Page speed and mobile performance testing
- Search indexing review
- Generative engine optimisation (GEO): structured data and an llms.txt so AI assistants describe your business accurately
- Branding and media consistency across web and social
- Analytics tracking set up or corrected
- Implementation of SEO and visibility updates
- Print-ready materials and digital marketing support
Who it’s for
Businesses with low search visibility, inconsistent branding across their channels, a site that loads slowly, or content that is not reaching the people it was written for. Also anyone replacing a site they can no longer maintain.
What you get
A clear report on what is holding the site back and what to do about it, then the implementation work to fix it. Because the same person handles the security side, hardening happens during the build rather than as a retrofit afterwards.
Where you stand, in writing.
SMB1001
Guidance on which tier applies and what its controls ask for. Not offered as certification support. The SMB1001 question below explains why.
NIST evaluation
The differences between your processes and NIST guidance, and how to bring them into line.
Incident resilience
Response plans, playbooks and tabletop assessments built on having helped clients through the real thing.
Questions about frameworks, compliance and cost.
What does the NIST Cybersecurity Framework actually cover?
It organises security around five functions: Identify, Protect, Detect, Respond and Recover. Rather than a checklist of controls, it is a structure for making sure nothing whole is missing. Most small businesses discover they have spent everything on Protect and almost nothing on Detect or Respond. A controls audit measures your systems against all five and produces a gap analysis for each.
What is SMB1001 and does my business need it?
SMB1001 is a cyber security certification standard written for small and medium businesses. It is multi-tiered, so you certify at a level that matches your size and work upward. It is worth pursuing if clients, insurers or tenders are asking you to demonstrate a security position. From 1 January 2027 the full 2027 edition is free to access at smb1001.org, including for any technical support specialist working with up to three client organisations. I do not offer SMB1001 certification as a paid service because of that three-client limit, but I am happy to talk through which tier fits you at no charge.
Is Microsoft 365 secure by default?
No. A default Microsoft 365 tenancy leaves multi-factor authentication optional, administrator rights broadly assigned and data loss prevention switched off. Microsoft provides strong security capability, but it has to be configured. Buying the licences does not turn it on. A tenancy health check finds what is exposed and tightens it.
Do you work with businesses outside the Sunshine Coast?
Yes. Security assessments, framework audits, Microsoft 365 reviews and web development are all delivered remotely, so location rarely matters. On-site work covers Mapleton, Nambour, Maleny, Montville, Maroochydore, Buderim, Noosa and Caloundra.
Not sure which of these you need?
Contact me with more information on your enquiry. I will come back with a short review of what I can see from the outside, and tell you honestly whether anything here is worth your money.