per user / month
Security Assessment Advisor
ISM, Essential Eight and OWASP knowledge, where you need it.
Your AI. Running on a laptop, a server or a cloud you own. Security Assessment Advisor puts the ASD Information Security Manual, the Essential Eight and OWASP ASVS inside the assistant your team already uses. Look up a control, scope an assessment, be walked through it, and export the paperwork. Every answer quoted from the published release, never from the model’s memory.
- ASD ISM, all classifications, plus the OT overlay
- Essential Eight, Maturity Levels 1–3
- OWASP ASVS 5.0, Levels 1–3
- Canberra built, runs where you say
“Multi-factor authentication is used to authenticate human users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.”
Yes. It sits under Guidelines for system access › Multi-factor authentication and applies at every classification and all three Essential Eight maturity levels. Want to record how your system meets it?
Quoted from ISM release v2026.09.4, published 4 Sep 2026.
Why now
Stop running security assessments from a PDF, a spreadsheet and somebody’s memory.
The ISM changes several times a year. ASVS 5.0 rewrote most of 4.0. A general-purpose AI assistant will happily quote you a control number that no longer exists, and an assessor with a 1,100-row spreadsheet will happily miss one that does.
The standard moves. Your evidence doesn’t.
The Advisor loads the current ISM release, tells you when a newer one lands, and can show you exactly which controls were added, removed or reworded between two releases.
AI that can’t make things up.
Nothing is answered from training data. Every control id, requirement id and quoted sentence comes from the release the server has loaded, and the release is stamped on the answer.
Silence is not evidence.
A control you haven’t assessed is counted as a gap, not quietly dropped. Coverage percentages and top gaps are always complete, so nobody is surprised at the IRAP stage.
Built for Microsoft. (And for Claude.)
It lives where your people already work.
No new portal to log into. The Advisor connects over the open Model Context Protocol, so the same tools show up in Copilot, Claude and your developer tooling. Where the client can draw a form or a dashboard, you get one. Where it can’t, you get the identical workflow in plain text.
Ask AI anything
Ask the question you’d ask a senior assessor.
Plain English in. Real control ids out. Attach the SSP, policy, pen-test report or screenshot you already have and the Advisor maps it to controls, checking every id against the live catalogue and rejecting anything it can’t verify.
The assessment loop
One conversation, from scoping to paperwork.
An assessment is rarely finished in one sitting. Your progress comes back as a file you own. Hand it back tomorrow, next week or to a colleague, and pick up exactly where you left off.
Scope
Name the system, pick a baseline (PROTECTED, an Essential Eight level, or an ASVS level) and answer a few qualifying questions.
Walk through
The assistant puts each control in front of you in small batches and records your status, justification and evidence.
Save and resume
Get the work-in-progress back as a file. No server-side session to time out, nothing lost to a dropped connection.
See where you stand
Coverage, counts by status and the top gaps, as a live dashboard or as text.
Export
SSP annex, OSCAL POA&M, ASVS checklist, or a Word / PowerPoint report, stamped with release and classification.
From connected to a draft SSP annex
One week. Not one quarter.
Connect
Add the connector to Copilot or Claude, sign in with your Entra ID, ask your first question.
Scope your first system
Baseline chosen, qualifying questions answered, the control set in front of you.
Draft from what you already have
Attach the existing SSP and pen-test report. Watch the coverage figure move as the assistant maps them.
Paperwork out
SSP annex workbook and POA&M in the assessor’s inbox, gaps assigned with owners and target dates.
- ISM-1490Application control on serversPartial
- ISM-1504MFA for online servicesUnassessed
- ISM-0580Event logging retentionUnassessed
Stop guessing your posture
The paperwork your assessor actually asked for.
The gap analysis is the intelligence. The exports are what you put in front of your board, your IRAP assessor or your CISO. Both come out of the same conversation.
Essential Eight
Know your maturity level before the auditor does.
The Essential Eight is where most Australian agencies and their suppliers start, and where most of the reporting pressure sits. The Advisor treats each maturity level as a baseline in its own right: scope an assessment against ML1, ML2 or ML3, walk the controls that apply, and see the coverage figure for that level, not the whole ISM. Move up a level and only the extra controls appear.
Every Essential Eight question is answered from the same live ISM release, so when ASD reworks a mitigation strategy your assessment picks it up on the next release check.
Counts from ISM release v2026.09.4. They change as ASD publishes, and so does the Advisor.
Operational technology
Built for the plant floor, not just the data centre.
ICS, SCADA and building-management systems get assessed against the same ISM, but the context is different. The Advisor overlays IEC 62443, NIST SP 800-82, Purdue reference levels and the ASD Principles of Operational Technology Cyber Security on the ISM controls, so you can filter by Purdue level or 62443 requirement and see exactly which controls carry it.
IEC 62443
Filter ISM controls by the 62443 requirement they satisfy.
Purdue levels
Ask what applies at Level 2 versus Level 3.5 and get controls, not a diagram.
NIST SP 800-82
Cross-referenced to the US ICS guidance your vendors quote.
ASD OT principles
Mapped to the published Australian principles, with the applicability spelt out.
The difference
Assessment tooling, before and after.
The spreadsheet and a chatbot
- Control text copied from last year’s PDF
- AI answers from training data, ids invented
- Unassessed rows quietly drop off the count
- Re-keying the SSP annex by hand
- Another SaaS tenancy holding your security posture
- Per-seat pricing for every reviewer
Security Assessment Advisor
- Quoted from the current published release, stamped on the answer
- Every id verified against the live catalogue
- Unassessed means gap. Always.
- SSP annex, POA&M and reports generated from the conversation
- Runs in your Azure tenancy, on your laptop, or with the network cable out
- One licence per organisation, not per person
Hosted your way
Your AI. Your laptop, your server, or your cloud.
Your security posture is the most sensitive document you own, and it never touches a shared multi-tenant service. The Advisor runs on hardware you control, in whichever shape matches your accreditation boundary. Your house, your rules.
Your own Azure tenancy
One isolated instance per customer: your Azure resources, your Entra ID app, your container registry, your Copilot agent. Sign-in and authorisation enforced on every request. Nothing shared with us, or anyone else, at run time.
On the assessor’s laptop
Run it locally in VS Code or Claude Desktop. Nothing leaves the machine except the catalogue download, and exports land in the folder you ask for.
Air-gapped
A single container with both standards baked in. Delivered by file, verified by checksum, runs with no network at all. Built for the environments where “cloud” isn’t an option.
Pricing and plans
RRP pricing for every team size.
per user / month
per user / month
for volume pricing
Annual prepay saves 15%
Talk to usBook a chat
See it run against your own SSP.
Bring a system you’re assessing right now. In 25 minutes we’ll connect the Advisor to Copilot or Claude, scope the system, and show you the first gap analysis. No slides.
Or email contactus@mojoup.com.au.