← Our workCase studyCase studyClient: Gridware Cyber Security
Case study

Cyber Health Check.

A web app for Sydney cybersecurity firm Gridware that turns its onboarding audit into a 30-question health check with an instant scored report, and lets insurance brokers send it to their own clients.

Client
Gridware Cyber Security
Deliverable
Web app, design + build
Year
2019
Cybersecurity Health Check report: a Gridware Score of 4.1 out of 5, rated Adaptive, with a low-to-high risk scale
Cue 01

The brief

Gridware works with some of the biggest names in Australia on governance and compliance, incident response, phishing training and penetration testing. Every new client starts with an audit of how ready they are for a cyber attack, and a report showing which areas need support first based on the biggest threats. That audit was done by hand.

Cue 02

The approach

We built a tool that asks the same questions a Gridware consultant would and scores the answers into a report. It also needed to work for insurance brokers, who manage many clients: they log in, send health checks out and watch the results come back.

Cue 03

The result

Clients answer 30 questions and get a scored report straight away, with a risk breakdown and a comparison against their industry. Brokers send checks on a credit system and see every result from one dashboard.

Question 2 of 30 on staff security training, with Yes, No, Partial and Not Applicable answers and keyboard shortcuts
One question at a time, answerable from the keyboard: y, n, p or x

Two ways in

Cue 01

Clients

A client takes the health check, gets their report and can download it. The same login gives them a library of policy documents filtered by framework, and an incident response guideline to follow if they are breached.

Cue 02

Brokers

A broker invites clients by name, company and email, spending one credit per check. Completed checks appear on their dashboard with the score and rating, and each links to the full report.

Cue 03

The report

Scores run from 1 to 5, each with a named maturity level. The report explains the method, which references ISO 27001, the NIST Cyber Security Framework, OSSTMM and PTES, then shows the risk distribution and where the client sits among its peers.

Broker dashboard: credits remaining and a client's completed health check scored 4.1, with a View report buttonClient report scored 5.0, rated Risk Informed, with a percentile chart comparing the client to its industry
Broker dashboard · a client report with an industry percentile chart
My Documents library filtered by document type, framework (PCI DSS, ISO 27001, NIST CSF, ASD Essential 8), status and business sizeIncident Response Guideline page, starting with containing the breach in the first 0–3 hours
Document library filtered by framework · Incident Response Guideline

Technology

Cue 01

Frontend

Next.js, the React framework, with pages generated ahead of time so they load quickly.

Cue 02

Backend

The backend APIs ran on Firebase.

Cue 03

Hosting

Served on Vercel’s Now platform.

Tech & tools
  • Next.js
  • React
  • Firebase
  • Vercel
Next case studyStaff Management Platform →
View all work
Cue 04 — Get in touch

What’s slowing your team down?