Skip to main content

Accounting firm locks down 30 devices and hits Essential Eight in 3 months

How CIO Tech helped FTC Consultants transform their IT operations.

30 Devices deployed
3 months Project timeline
E8 L1 Security baseline
Zero Disruption to clients

15 years of IT without a plan

FTC Consultants is a chartered accounting and tax advisory firm in Bella Vista. They handle ATO lodgements, BAS, SMSF portfolios, and payroll records for their clients, and have done so for over 15 years.

The firm had 20 staff working across 30 devices on Google Workspace. None of the devices were centrally managed. There was no standard build, no security hardening, and no path to meeting Australian cyber security standards. Every machine was configured differently, and IT had grown without a plan.

For a firm that lodges directly with the ATO and holds client financials, that situation was getting harder to justify.

30 unmanaged devices

No standard build, no central visibility, no way to enforce security policies across the fleet.

No security baseline

Google Workspace with no hardening. No alignment with Essential Eight or any Australian cyber security framework.

Every machine different

IT had grown without a plan. Different configurations, different software versions, no consistency.

Sensitive data at risk

ATO lodgements, SMSF portfolios, BAS returns, payroll records. All sitting on uncontrolled devices.

Full infrastructure modernisation in 3 months

CIO Tech ran a structured modernisation project covering platform migration, device deployment, security hardening, and collaboration tools.

1

Google to Microsoft 365 migration

Email, calendars, files, and collaboration tools moved to M365 with no data loss. Staff were working in the new environment within the first month.

2

30 new devices deployed

Every machine replaced and built to a standard operating environment. Same build, same security baseline, same experience across the firm. Physical office setup included.

3

Microsoft Intune device management

All 30 devices enrolled in Intune for remote management, policy enforcement, and compliance monitoring. Every machine visible and controlled from a single dashboard.

4

SharePoint, Teams, and Loop rolled out

Shared document libraries replaced scattered files. Teams gave the firm a single place for internal communication. Loop replaced ad-hoc task tracking with structured task management.

5

Essential Eight Level 1 hardening

Application control, patching, macro restrictions, MFA, admin access lockdown, and backup controls applied across the entire environment. The security baseline the ASD recommends, implemented end to end.

From scattered to locked down

Before CIO Tech

  • 30 devices with no standard build and no central management
  • Google Workspace with no security hardening
  • No alignment with Australian cyber security standards
  • Scattered files across individual machines

After CIO Tech

  • All 30 devices on a standard build, managed through Intune
  • Microsoft 365 secured and hardened
  • Essential Eight Level 1 achieved
  • Every device, user, and policy visible from a single dashboard
  • SharePoint, Teams, and Loop for structured collaboration

The project was delivered in 3 months with no disruption to FTC's client work. Staff came out of it with a faster, simpler environment that was locked down from day one.

“We handle sensitive financial data every day. CIO Tech gave us confidence that it’s actually protected. The whole project was done without disrupting our client work, which was the main thing I was worried about.”

Andrew Romano

Director, FTC Consultants

See if we can do the same
for your firm.

Every engagement starts with a IT Audit. We assess your environment, fix the urgent risks, and hand you a clear roadmap.

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.