THE OMEKATECH SECURE360 FRAMEWORK
See the whole security picture - and know what to improve first.
Cybersecurity is not a single product, policy or technical project. It depends on leadership, people, identities, devices, information, monitoring, response and recovery working together.
The OmekaTech Secure360 Framework helps growing businesses understand their current position, identify material risks and create a practical security-improvement roadmap based on business priorities.
A practical, risk-based security framework for Brisbane businesses with 5–150 staff.
OMEKA
SECURE360
Govern
Identify
Protect
Detect
Respond
Recover
SECURITY FROM EVERY ANGLE
Security gaps often appear between systems, people and responsibilities.
A business may have antivirus software, backups and multifactor authentication while still carrying significant risk.
Technology controls can be weakened by unclear ownership, unmanaged devices, excessive access, inconsistent processes, untested recovery arrangements or nobody reviewing security alerts.
Leadership and ownership
Security decisions become reactive when responsibilities, acceptable risk, priorities and reporting arrangements have not been clearly established.
People and access
Security decisions become reactive when responsibilities, acceptable risk, priorities and reporting arrangements have not been clearly established.
Technology and information
Unsupported systems, unmanaged devices, unsafe information sharing and inconsistent configuration can create avoidable exposure.
Incident and recovery readiness
An organisation may have security tools and backups but still be unprepared to contain an incident, communicate under pressure or restore safe operations.
Omeka Secure360 brings these connected areas into one business-focused view so improvement decisions can be made in the correct order.
THE COMPLETE FRAMEWORK
Six connected areas of business cybersecurity.
The Omeka Secure360 Framework examines how the organisation directs, understands, protects, monitors, responds to and recovers from cybersecurity risk.
The six areas are reviewed together because weakness in one can reduce the effectiveness of the others.
01 - GOVERN
Lead and govern
Establish ownership, policies, decision-making responsibilities, risk priorities, supplier accountability and regular security review.
LEADERSHIP • POLICY • OWNERSHIP • OVERSIGHT
02 - IDENTIFY
Understand and prioritise
Identify important services, information, users, devices, systems, suppliers, dependencies, vulnerabilities and potential business impacts.
ASSETS • INFORMATION • DEPENDENCIES • RISK
03 - PROTECT
Prevent and limit exposure
Apply practical controls across identities, administrator access, email, devices, applications, updates, information sharing, staff practices and backups.
IDENTITY • DEVICES • EMAIL • DATA
04 - DETECT
Recognise suspicious activity
Improve visibility across sign-ins, administrator changes, endpoints, email, cloud services, security alerts and unusual user or system behaviour.
LOGGING • ALERTS • MONITORING • ESCALATION
05 - RESPOND
Contain and coordinate
Prepare roles, escalation paths, investigation steps, containment actions, evidence requirements and internal and external communication procedures.
CONTAINMENT • EVIDENCE • COMMUNICATION • ACTION
06 - RECOVER
Restore and improve
Establish recovery priorities, test backups, restore safe operations, review lessons learned and incorporate improvements into the security roadmap.
RECOVERY • CONTINUITY • LESSONS • IMPROVEMENT
Omeka Secure360 is a continuous cycle. Changes to people, suppliers, systems and business operations can create new risks even after earlier improvements have been completed.
ASSESSMENT COVERAGE
A structured review across people, process and technology.
The scope is adjusted to suit the size, complexity, industry and existing environment of the business.
Business and governance
Identity and access
Devices and systems
Email, cloud and information
Monitoring and incident readiness
Continuity and recovery
Not every control is appropriate for every organisation. Recommendations are based on the business’s risks, operating requirements, existing technology, available licensing and budget.
THE OMEKA SECURE360 PROCESS
From an incomplete security picture to a prioritised improvement plan.
01
Understand the business
We begin with the organisation’s services, people, locations, information, critical systems, suppliers, operating pressures and leadership concerns.
02
Review the environment
Relevant controls, configurations, processes, responsibilities and available evidence are reviewed across the six Secure360 areas.
03
Identify material gaps
We identify missing, inconsistent or unverified controls and consider how each issue could affect operations, information, finances and reputation.
04
Prioritise the risks
Findings are prioritised according to business impact, likelihood, urgency, dependencies, implementation effort and available resources.
05
Build the roadmap
Recommended improvements are arranged into a practical sequence with clear priorities, responsibilities and decision points.
06
Implement and improve
OmekaTech can implement agreed controls, coordinate existing providers and review progress as the business and threat environment change.
The objective is not to produce the longest possible list of security recommendations. It is to help leadership understand what matters, why it matters and what should happen next.
CLEAR, EVIDENCE-BASED FINDINGS
Separate assumptions from controls that can be demonstrated.
Controls are reviewed using a simple implementation status so leadership can distinguish confirmed protection from areas requiring investigation or improvement.
Not confirmed
The control, responsibility or evidence could not be verified during the review.
Improvement required
A material weakness or missing control has been identified and action is recommended.
Partially implemented
The control exists but is incomplete, inconsistent or not applied across the required environment.
Implemented and evidenced
The control is operating within the reviewed scope and supporting evidence was available.
Not applicable
The control does not apply to the reviewed environment or business requirement, with the reason documented.
Omeka Secure360 findings are designed to support business decisions. They do not represent a formal certification, legal opinion or guarantee that an incident will not occur.
PRACTICAL OUTPUTS
Security findings translated into business priorities.
The level of detail depends on the agreed engagement. Outputs can include the following.
Executive security summary
A clear overview of the current position, material risks and important decisions requiring leadership attention.
Prioritised findings
Identified gaps arranged according to business impact, urgency and the value of the recommended improvement.
Security roadmap
A practical sequence of immediate, near-term and longer-term actions with responsibilities and dependencies.
Responsibility map
Clearer ownership across management, staff, OmekaTech, internal teams and existing technology providers.
Implementation guidance
Recommended controls, configuration changes, process improvements and supporting documentation appropriate to the agreed scope.
Review and progress tracking
A structured way to record completed actions, outstanding risks, evidence and future review requirements.
Executive Assessment and detailed Omeka Secure360 work
The initial Executive Technology and Security Assessment provides a high-level current-state summary, priority risks and recommended next steps. Detailed technical assessment, remediation, documentation, implementation and ongoing monitoring may require a separately agreed Secure360 engagement.
INFORMED BY RECOGNISED GUIDANCE
A business-focused approach informed by established security practices.
Omeka Secure360 is OmekaTech’s practical delivery framework. It helps translate recognised cybersecurity guidance into priorities suitable for a growing business.
NIST Cybersecurity Framework
The six Secure360 areas reflect the continuous security lifecycle represented by Govern, Identify, Protect, Detect, Respond and Recover.
ASD Essential Eight
Essential Eight mitigation strategies are considered where appropriate as an important baseline for reducing exposure to common cyber threats.
Microsoft security capabilities
Microsoft 365 identity, device, email, endpoint and information-protection capabilities are considered according to the organisation’s licensing and requirements.
Business continuity and incident readiness
Security is connected to incident response, communication, backup, recovery and the organisation’s ability to continue important operations.
Omeka Secure360 is not a government standard, NIST certification, Essential Eight certification, Microsoft certification or guarantee of regulatory compliance. References to recognised frameworks explain the sources of relevant security practices and do not imply endorsement or accreditation.
DESIGNED FOR GROWING BUSINESSES
Structured cybersecurity without unnecessary enterprise complexity.
Omeka Secure360 is designed for organisations that depend on technology and sensitive information but may not have an experienced internal cybersecurity leader.
Security has developed reactively
Individual controls have been added over time, but leadership lacks a reliable view of the complete security position.
Microsoft 365 has not been independently reviewed
The organisation uses Microsoft 365 but is uncertain about identity, administrator access, email protection, device management and security monitoring.
Multiple providers share responsibility
Internal staff, an IT provider, software vendors and telecommunications companies each manage part of the environment while overall accountability remains unclear.
Clients or insurers are asking security questions
The business needs clearer evidence of security activities, responsibilities, priorities and ongoing improvement.
The business has experienced an incident
Leadership wants to address the immediate cause while also improving wider detection, response, recovery and governance arrangements.
Technology or business change is planned
A move, acquisition, cloud project, provider change, new system or workforce change creates a suitable point to reassess security risk.
The scope is tailored for the organisation rather than applying the same technical checklist to every business.
THE BEST PLACE TO START
Establish your Secure360 starting position.
The Executive Technology and Security Assessment gives leadership an independent view of the current technology environment, material risks and recommended priorities.
It provides a practical starting point for determining whether a deeper Secure360 review, targeted improvement project or ongoing security-management program is appropriate.
The review is valued at $795 and is available at no cost to qualified businesses.
No obligation to proceed with an ongoing service.
FREQUENTLY ASKED QUESTIONS
Questions about the OmekaTech Secure360 Framework
What is the OmekaTech Secure360 Framework?
Secure360 is OmekaTech’s practical approach to reviewing and improving cybersecurity across governance, business risk, identities, devices, email, information, monitoring, incident response and recovery. It connects technical controls to business priorities and produces a structured improvement roadmap.
Is Omeka Secure360 a cybersecurity certification?
No. Omeka Secure360 is an assessment and improvement framework, not a government, industry or vendor certification. Findings describe the reviewed environment and available evidence at a point in time. They do not guarantee that the business will not experience an incident.
Does Omeka Secure360 replace the Essential Eight?
No. The Essential Eight provides important mitigation strategies for reducing exposure to common cyber threats. Secure360 considers those controls where appropriate while also examining areas such as governance, business priorities, supplier responsibility, monitoring, incident response and recovery.
Is Omeka Secure360 only for Microsoft 365 businesses?
No. Microsoft 365 is often an important part of the review because many growing businesses use it for identity, email, collaboration and information sharing. Secure360 can also examine other approved cloud services, devices, business applications, providers and operational dependencies.
Your TitleCan OmekaTech work with our current IT provider? Goes Here
Yes. OmekaTech can provide independent assessment, security expertise, implementation or ongoing oversight while working alongside an existing IT provider, internal team and software vendors. Responsibilities and communication paths are agreed at the beginning.
What size business is Omeka Secure360 designed for?
The framework is particularly suitable for growing organisations with approximately 5–150 staff that depend on technology but may not have experienced internal cybersecurity leadership. The depth and scope are adjusted to the organisation.
How often should the framework be reviewed?
The security position should be reviewed regularly and after material business or technology changes. Examples include adding locations, changing providers, implementing new cloud systems, acquiring another business, changing information-handling requirements or responding to a security incident.
How do we get started?
The recommended starting point is an Executive Technology and Security Assessment. It provides a high-level view of the current environment and helps determine the most appropriate Secure360 scope and priorities.
