THE OMEKATECH SECURE360 FRAMEWORK

See the whole security picture - and know what to improve first.

Cybersecurity is not a single product, policy or technical project. It depends on leadership, people, identities, devices, information, monitoring, response and recovery working together.

The OmekaTech Secure360 Framework helps growing businesses understand their current position, identify material risks and create a practical security-improvement roadmap based on business priorities.

A practical, risk-based security framework for Brisbane businesses with 5–150 staff.

OMEKA
SECURE360

Govern

Identify

Protect

Detect

Respond

Recover

SECURITY FROM EVERY ANGLE

Security gaps often appear between systems, people and responsibilities.

A business may have antivirus software, backups and multifactor authentication while still carrying significant risk.

Technology controls can be weakened by unclear ownership, unmanaged devices, excessive access, inconsistent processes, untested recovery arrangements or nobody reviewing security alerts.

Leadership and ownership

Security decisions become reactive when responsibilities, acceptable risk, priorities and reporting arrangements have not been clearly established.

People and access

Security decisions become reactive when responsibilities, acceptable risk, priorities and reporting arrangements have not been clearly established.

Technology and information

Unsupported systems, unmanaged devices, unsafe information sharing and inconsistent configuration can create avoidable exposure.

Incident and recovery readiness

An organisation may have security tools and backups but still be unprepared to contain an incident, communicate under pressure or restore safe operations.

Omeka Secure360 brings these connected areas into one business-focused view so improvement decisions can be made in the correct order.

THE COMPLETE FRAMEWORK

Six connected areas of business cybersecurity.

The Omeka Secure360 Framework examines how the organisation directs, understands, protects, monitors, responds to and recovers from cybersecurity risk.

The six areas are reviewed together because weakness in one can reduce the effectiveness of the others.

01 - GOVERN

Lead and govern

Establish ownership, policies, decision-making responsibilities, risk priorities, supplier accountability and regular security review.

LEADERSHIP • POLICY • OWNERSHIP • OVERSIGHT

02 - IDENTIFY

Understand and prioritise

Identify important services, information, users, devices, systems, suppliers, dependencies, vulnerabilities and potential business impacts.

ASSETS • INFORMATION • DEPENDENCIES • RISK

03 - PROTECT

Prevent and limit exposure

Apply practical controls across identities, administrator access, email, devices, applications, updates, information sharing, staff practices and backups.

IDENTITY • DEVICES • EMAIL • DATA

04 - DETECT

Recognise suspicious activity

Improve visibility across sign-ins, administrator changes, endpoints, email, cloud services, security alerts and unusual user or system behaviour.

LOGGING • ALERTS • MONITORING • ESCALATION

05 - RESPOND

Contain and coordinate

Prepare roles, escalation paths, investigation steps, containment actions, evidence requirements and internal and external communication procedures.

CONTAINMENT • EVIDENCE • COMMUNICATION • ACTION

06 - RECOVER

Restore and improve

Establish recovery priorities, test backups, restore safe operations, review lessons learned and incorporate improvements into the security roadmap.

RECOVERY • CONTINUITY • LESSONS • IMPROVEMENT

Omeka Secure360 is a continuous cycle. Changes to people, suppliers, systems and business operations can create new risks even after earlier improvements have been completed.

ASSESSMENT COVERAGE

A structured review across people, process and technology.

The scope is adjusted to suit the size, complexity, industry and existing environment of the business.

Business and governance

  • Business priorities and critical services
  • Security roles and decision-making
  • Policies and responsibilities
  • Technology-provider accountability
  • Risk and improvement reporting

Identity and access

  • Multifactor authentication
  • Administrator accounts
  • Conditional Access
  • Onboarding and offboarding
  • Third-party and remote access

Devices and systems

  • Device inventory and ownership
  • Updates and patching
  • Endpoint protection
  • Security configuration
  • Lifecycle and unsupported technology

Email, cloud and information

  • Email protection
  • Microsoft 365 configuration
  • Information sharing
  • Application access
  • Backup and retention arrangements

Monitoring and incident readiness

  • Security logging and alerts
  • Escalation responsibilities
  • Incident-response procedures
  • Evidence preservation
  • Insurance, legal and communication dependencies

Continuity and recovery

  • Critical-system dependencies
  • Recovery priorities
  • Backup protection and testing
  • Alternative communication
  • Post-incident improvement

Not every control is appropriate for every organisation. Recommendations are based on the business’s risks, operating requirements, existing technology, available licensing and budget.

THE OMEKA SECURE360 PROCESS

From an incomplete security picture to a prioritised improvement plan.

01

Understand the business

We begin with the organisation’s services, people, locations, information, critical systems, suppliers, operating pressures and leadership concerns.

02

Review the environment

Relevant controls, configurations, processes, responsibilities and available evidence are reviewed across the six Secure360 areas.

03

Identify material gaps

We identify missing, inconsistent or unverified controls and consider how each issue could affect operations, information, finances and reputation.

04

Prioritise the risks

Findings are prioritised according to business impact, likelihood, urgency, dependencies, implementation effort and available resources.

05

Build the roadmap

Recommended improvements are arranged into a practical sequence with clear priorities, responsibilities and decision points.

06

Implement and improve

OmekaTech can implement agreed controls, coordinate existing providers and review progress as the business and threat environment change.

The objective is not to produce the longest possible list of security recommendations. It is to help leadership understand what matters, why it matters and what should happen next.

CLEAR, EVIDENCE-BASED FINDINGS

Separate assumptions from controls that can be demonstrated.

Controls are reviewed using a simple implementation status so leadership can distinguish confirmed protection from areas requiring investigation or improvement.

t

Not confirmed

The control, responsibility or evidence could not be verified during the review.

Improvement required

A material weakness or missing control has been identified and action is recommended.

Partially implemented

The control exists but is incomplete, inconsistent or not applied across the required environment.

R

Implemented and evidenced

The control is operating within the reviewed scope and supporting evidence was available.

O

Not applicable

The control does not apply to the reviewed environment or business requirement, with the reason documented.

Omeka Secure360 findings are designed to support business decisions. They do not represent a formal certification, legal opinion or guarantee that an incident will not occur.

PRACTICAL OUTPUTS

Security findings translated into business priorities.

The level of detail depends on the agreed engagement. Outputs can include the following.

Executive security summary

A clear overview of the current position, material risks and important decisions requiring leadership attention.

Prioritised findings

Identified gaps arranged according to business impact, urgency and the value of the recommended improvement.

Security roadmap

A practical sequence of immediate, near-term and longer-term actions with responsibilities and dependencies.

Responsibility map

Clearer ownership across management, staff, OmekaTech, internal teams and existing technology providers.

Implementation guidance

Recommended controls, configuration changes, process improvements and supporting documentation appropriate to the agreed scope.

Review and progress tracking

A structured way to record completed actions, outstanding risks, evidence and future review requirements.

Executive Assessment and detailed Omeka Secure360 work

The initial Executive Technology and Security Assessment provides a high-level current-state summary, priority risks and recommended next steps. Detailed technical assessment, remediation, documentation, implementation and ongoing monitoring may require a separately agreed Secure360 engagement.

INFORMED BY RECOGNISED GUIDANCE

A business-focused approach informed by established security practices.

Omeka Secure360 is OmekaTech’s practical delivery framework. It helps translate recognised cybersecurity guidance into priorities suitable for a growing business.

NIST Cybersecurity Framework

The six Secure360 areas reflect the continuous security lifecycle represented by Govern, Identify, Protect, Detect, Respond and Recover.

ASD Essential Eight

Essential Eight mitigation strategies are considered where appropriate as an important baseline for reducing exposure to common cyber threats.

Microsoft security capabilities

Microsoft 365 identity, device, email, endpoint and information-protection capabilities are considered according to the organisation’s licensing and requirements.

Business continuity and incident readiness

Security is connected to incident response, communication, backup, recovery and the organisation’s ability to continue important operations.

Omeka Secure360 is not a government standard, NIST certification, Essential Eight certification, Microsoft certification or guarantee of regulatory compliance. References to recognised frameworks explain the sources of relevant security practices and do not imply endorsement or accreditation.

DESIGNED FOR GROWING BUSINESSES

Structured cybersecurity without unnecessary enterprise complexity.

Omeka Secure360 is designed for organisations that depend on technology and sensitive information but may not have an experienced internal cybersecurity leader.

Security has developed reactively

Individual controls have been added over time, but leadership lacks a reliable view of the complete security position.

Microsoft 365 has not been independently reviewed

The organisation uses Microsoft 365 but is uncertain about identity, administrator access, email protection, device management and security monitoring.

Multiple providers share responsibility

Internal staff, an IT provider, software vendors and telecommunications companies each manage part of the environment while overall accountability remains unclear.

Clients or insurers are asking security questions

The business needs clearer evidence of security activities, responsibilities, priorities and ongoing improvement.

The business has experienced an incident

Leadership wants to address the immediate cause while also improving wider detection, response, recovery and governance arrangements.

Technology or business change is planned

A move, acquisition, cloud project, provider change, new system or workforce change creates a suitable point to reassess security risk.

The scope is tailored for the organisation rather than applying the same technical checklist to every business.

THE BEST PLACE TO START

Establish your Secure360 starting position.

The Executive Technology and Security Assessment gives leadership an independent view of the current technology environment, material risks and recommended priorities.

It provides a practical starting point for determining whether a deeper Secure360 review, targeted improvement project or ongoing security-management program is appropriate.

The review is valued at $795 and is available at no cost to qualified businesses.

  • A high-level current-state security summary
  • Priority risks and improvement opportunities
  • Recommended next steps and service options

No obligation to proceed with an ongoing service.

FREQUENTLY ASKED QUESTIONS

Questions about the OmekaTech Secure360 Framework

What is the OmekaTech Secure360 Framework?

Secure360 is OmekaTech’s practical approach to reviewing and improving cybersecurity across governance, business risk, identities, devices, email, information, monitoring, incident response and recovery. It connects technical controls to business priorities and produces a structured improvement roadmap.

Is Omeka Secure360 a cybersecurity certification?

No. Omeka Secure360 is an assessment and improvement framework, not a government, industry or vendor certification. Findings describe the reviewed environment and available evidence at a point in time. They do not guarantee that the business will not experience an incident.

Does Omeka Secure360 replace the Essential Eight?

No. The Essential Eight provides important mitigation strategies for reducing exposure to common cyber threats. Secure360 considers those controls where appropriate while also examining areas such as governance, business priorities, supplier responsibility, monitoring, incident response and recovery.

Is Omeka Secure360 only for Microsoft 365 businesses?

No. Microsoft 365 is often an important part of the review because many growing businesses use it for identity, email, collaboration and information sharing. Secure360 can also examine other approved cloud services, devices, business applications, providers and operational dependencies.

Your TitleCan OmekaTech work with our current IT provider? Goes Here

Yes. OmekaTech can provide independent assessment, security expertise, implementation or ongoing oversight while working alongside an existing IT provider, internal team and software vendors. Responsibilities and communication paths are agreed at the beginning.

What size business is Omeka Secure360 designed for?

The framework is particularly suitable for growing organisations with approximately 5–150 staff that depend on technology but may not have experienced internal cybersecurity leadership. The depth and scope are adjusted to the organisation.

How often should the framework be reviewed?

The security position should be reviewed regularly and after material business or technology changes. Examples include adding locations, changing providers, implementing new cloud systems, acquiring another business, changing information-handling requirements or responding to a security incident.

How do we get started?

The recommended starting point is an Executive Technology and Security Assessment. It provides a high-level view of the current environment and helps determine the most appropriate Secure360 scope and priorities.