Why this guide exists
Cyber decision-support is a new tooling category and most procurement teams have not yet developed an evaluation playbook for it. This guide gives Australian buyers a structured matrix, a data-sovereignty checklist, and the questions to ask any vendor before signing.
The evaluation matrix
| Area | Must have | Nice to have |
|---|---|---|
| Output structure | Ranked options + tactical plan + decision log | Comparison view across decisions |
| Frameworks | Essential Eight, ISO 27001, NIST CSF, APRA CPS 234 | ISO 42001, SOCI, AI Ethics, OAIC |
| Data sovereignty | Australian or trusted-jurisdiction processing | Per-tenant region selection |
| Security posture | MFA, encryption at rest + in transit, RLS | SSO/SAML, audit log export |
| Auditability | Immutable decision log per mission | External audit export to GRC platform |
| Pricing model | Self-serve trial, transparent SaaS pricing | Volume discounting for teams |
| Support model | In-product support portal | Named CSM for enterprise tier |
Data sovereignty checklist
- Where is data processed? Australia, allied jurisdiction, or other?
- Where is data stored at rest? Same answer required.
- Is the model provider contractually prevented from training on your inputs?
- Is encryption applied in transit and at rest, with documented key management?
- Can you export and delete all your data on request (privacy + retention)?
- Is RLS or equivalent tenant isolation in place at the database layer?
Procurement questions to ask every vendor
- Show us a real defensible decision the platform produced (not a demo script).
- Which Australian frameworks does the platform anchor to natively?
- What does the decision log look like \u2014 can our auditor read it?
- How is end-user MFA enforced? Is SSO available?
- What is your breach notification commitment and timeframe?
- Can we trial the platform on a real decision before purchase?
FOR AUSTRALIAN BUYERS
Run the matrix against FORTE/CYBERx.
Two free missions on signup means you can validate output, audit trail and framework alignment before procurement engages. No credit card.
Run a free missionHow to justify the spend
Frame the business case as cost-per-defensible-decision, not licence cost. A fractional CISO retainer that produces four to six structured decisions per month costs roughly AUD 1,300\u20132,000 per decision. A SaaS decision-support platform drops that to single dollars per decision while keeping the audit trail. Volume of decisions, not headcount, is the right denominator.
FAQ
What should an Australian buyer evaluate first?
Framework coverage and data sovereignty. If the platform cannot anchor to ACSC Essential Eight, ISO 27001 and APRA CPS 234, it is not fit for Australian use. If your data leaves Australian or trusted-jurisdiction infrastructure, your privacy and CPS 234 obligations become harder to evidence.
Do I need a Privacy Impact Assessment (PIA) before adopting one?
For regulated entities and most public sector buyers, yes. The platform handles strategic information about your organisation’s security posture — which is itself sensitive. A PIA, plus a vendor questionnaire covering data residency, encryption at rest and in transit, retention and breach notification, is a sensible baseline.
Can I trial the platform on a real decision?
A platform that does not let you run a real decision before buying is hiding something. FORTE/CYBERx provides two free missions on signup with no credit card so you can validate the output against your board reporting bar before any commitment.
How do I justify the spend to procurement?
Compare cost-per-defensible-decision against the alternative. A fractional CISO at AUD 8,000 per month producing four to six structured decisions equates to AUD 1,300–2,000 per decision. SaaS decision-support drops that by an order of magnitude while keeping the audit trail.