CISSP-QUALIFIED GOOGLE WORKSPACE AUDITS FOR FINANCIAL ADVICE, MORTGAGE & INSURANCE FIRMS
Your Clients' Wealth Runs Through Your Inbox. Don't Leave It On Default.
Superannuation transfers, insurance claims, investment instructions — your clients trust you to move their money safely, and that trust runs through Google Workspace. Default settings weren't built for that level of exposure. SecureMyEmail runs a specialist audit of your Workspace environment, checked against the CIS Google Workspace Benchmark and CISA SCuBA baselines, and hands you a plain-English report on exactly what to fix, in order of priority.

THE RISK YOU CAN'T SEE
One Impersonated Email Could Redirect A Client's Super
Financial advice, mortgage and insurance firms are high-value Business Email Compromise targets — a compromised login used to redirect a client's super or investment transfer, a fraudulent email impersonating you to authorise a payment, or a silent forwarding rule leaking sensitive financial plans and policy details. Most generalist IT providers manage uptime and support tickets — not dedicated security audits. If nobody has specifically checked your Google Workspace against a recognised security baseline, you don't actually know where you stand.
THE PROCESS
Four Steps From Enquiry To Answers
Submit your details
A few quick questions, no obligation — tell us your platform, rough user count, and what's prompting you to look into this now.
Neil confirms access
Neil Frick will call you within 1 business day to confirm access credentials and scope the right tier for your environment.
We run the audit
Using Workspace Audit, your Google Workspace environment is checked against the CIS Google Workspace Benchmark, CISA SCuBA Baselines and Cyber Essentials Plus — over 100 automated, read-only checks that never access the content of your emails, files or chats.
You get the report
A plain-English findings report, prioritised by risk, so you know exactly what to fix first — no jargon, no scare tactics.
IS THIS YOU?
Built For Financial Services Firms Without An In-House Security Team
- You're a financial advice firm, mortgage broker or insurance brokerage with 10–50 staff on Google Workspace
- You handle client superannuation, investment, or insurance/policy data daily
- You don't have a dedicated in-house IT security specialist
- You want a clear, independent check — not another subscription to manage
Not for: Individuals wanting help with a personal Gmail account, or large enterprises with an existing in-house security team.
COMPLIANCE CONTEXT
What Financial Services Firms Are Expected To Have In Place
Advice, mortgage and insurance businesses sit under some of the most explicit cyber obligations in Australia — and regulators have made clear that email compromise is treated as a failure of information-security controls.
ASIC RG 104 / s912A cyber resilience obligations
AFS licensees must have adequate technological and risk-management resources. ASIC has pursued licensees in court over inadequate cyber controls, including unprotected email and remote-access systems.
APRA CPS 234 (and supply-chain flow-down)
APRA-regulated entities must maintain information-security capability proportionate to their threats — and they push equivalent expectations onto brokers, advisers and service providers they deal with.
Privacy Act 1988 & the Australian Privacy Principles
APP 11 requires you to take reasonable steps to protect personal information from misuse, interference and unauthorised access. Mailbox access controls, MFA, external sharing settings and forwarding rules are all part of those reasonable steps.
Notifiable Data Breaches scheme
If personal information is accessed without authorisation and serious harm is likely, you must notify affected individuals and the OAIC. Knowing whether audit logging and alerting are switched on is the difference between detecting a breach and finding out from a customer.
AML/CTF program obligations
Reporting entities must securely retain customer identification and transaction records for seven years and protect them from unauthorised access.
General information about obligations commonly relevant to Australian businesses in this sector — not legal advice. The audit reports on how your email and collaboration environment is configured against recognised security baselines; it does not certify you as compliant with any of these frameworks, and your own obligations depend on your size, structure and services.
WHO'S BEHIND THE AUDIT
No Client Case Studies Yet — Full Transparency Instead
As a new service, we don't have client testimonials yet — but every audit is run personally by Neil Frick, a CISSP-qualified auditor with over 40 years in Information Technology, using the same tools and baselines trusted by security-focused MSPs across Australia. His background includes work in highly secure environments, with military clearance to Top Secret level. We'd rather tell you that plainly than invent a review that isn't real.
THE PERSON DOING THE WORK
Meet Neil Frick
I've spent over 40 years in Information Technology, including time in highly secure environments with military clearance to Top Secret level. I'm CISSP-qualified, and I founded SecureMyEmail because too many small and mid-sized Australian businesses assume their generalist IT provider is “handling security” — when in reality, nobody has run a dedicated audit against a recognised baseline. Every audit that goes out under this business has been run personally by me, using the same tools and standards trusted by security-focused MSPs. No jargon, no scare tactics — just a clear report on where you stand.
— Neil Frick, Founder, SecureMyEmail
THE DETAILS
Straightforward Pricing, No Ongoing Contract
This is a point-in-time audit, not an ongoing managed security service. Pricing is based on user count. Pay online now to lock in your slot, or answer a few quick questions and Neil will call you before you commit.
Starter
Up to 10 users
$99
Full audit of Google Workspace or Microsoft 365, mapped to CIS, NIST and CISA SCuBA baselines, plus a plain-English findings report.
Growth
Up to 25 users
$199
Same full audit scope as Starter, priced for larger teams.
Enterprise
25+ users
Request a quote
Custom-scoped audit for larger environments.
Email Us For A Quote →COMMON QUESTIONS
Before You Enquire
It's a point-in-time audit — a deep, specialist check of your environment against recognised security baselines, delivered as a plain-English report. It's not a subscription and there's no ongoing contract.
One audit. One plain-English report. Every gap accounted for.
It takes one enquiry to get started, and one call with Neil to confirm access and scope. No lock-in, no jargon, no guesswork about where your business actually stands.
Run personally by Neil Frick, CISSP-qualified — SecureMyEmail