Australian organisations are increasingly asked to show their cyber security position: by insurers, by boards, by customers and by regulators. Good intentions are not a record. Most small and mid-sized organisations have no practical way to organise their controls, keep evidence of the steps they take, and train their people, without engaging specialists.