Skip to content
Corpshore Australia

Case study

Cybersecurity and helpdesk for a regional NSW council

A regional New South Wales council serving a population of around 48,000 across the local government area, with a small in-house IT team of three.

The challenge

The council's IT team covered core business hours only. Anything that happened after 5pm, a server alert, a locked-out staff account, a phishing email reported by a night-shift depot worker, waited until the next business day. The team also had no dedicated security function. Patching was done when time allowed, staff had received no structured phishing awareness training in over two years, and the council's own audit committee had flagged IT resourcing risk in two consecutive annual reports. A near-miss in the prior financial year, a ransomware email that one staff member correctly reported but that took 14 hours to be actioned, was the trigger for the council to look outside.

What Corpshore did

The engagement started with two service desk analysts and one part-time security analyst, plus a dedicated account manager. After the first three months, ticket volume data showed after-hours demand was heavier than expected, particularly around depot and library branch hours, so the team grew to three analysts on a rotating roster plus one full-time security analyst, with a field engineer visiting the council's offices roughly once a fortnight for anything that needs hands-on-keyboard work. The council wanted an Australian-based team handling council data specifically, given resident records and property information are involved.

Delivery model

Onshore delivery from Sydney, remote helpdesk coverage extended into evenings and weekends, with a field engineer visiting on a fixed fortnightly schedule.

Compliance handling

The council was clear from the outset that it wanted an Australian-based team specifically because of the sensitivity of resident data under the Privacy Act 1988 and the Australian Privacy Principles, and Corpshore's practices are structured around those obligations for this engagement, including access controls and logging for any system holding personal information. On cybersecurity, Corpshore was explicit with the council from the first proposal that it does not hold any Essential Eight maturity level rating and is not IRAP assessed. The uplift work, patch management discipline, multi-factor authentication rollout, restricting local admin rights and a macro-hardening pass on office documents, is described to the council as work aligned with the Essential Eight framework published by the Australian Signals Directorate, not as a certified or audited outcome. The onshore team operates under the relevant Modern Award, with rostered after-hours and weekend work paid in line with the National Employment Standards.

Results

~30%
Cheaper than an equivalent in-house capability over 3 years
94%
Patch compliance, up from 61%
35 min
Median after-hours ticket response, from next business day

After-hours ticket response time went from next-business-day to a median of 35 minutes. The phishing simulation click-through rate, measured before the engagement and again at the six-month mark, fell from 22 percent to 9 percent. Patch compliance across council endpoints rose from an estimated 61 percent to 94 percent within the first quarter. Standing up an equivalent after-hours and security capability in-house was quoted internally at roughly 30 percent more than the Corpshore arrangement over a three-year term, largely because the council would otherwise need to carry full-time headcount for coverage it only needs in bursts.

Phishing simulation click-through rate

Phishing simulation click-through rate, before and after in %.
StageValue
Before22%
After (6 months)9%

We went from dreading what Monday morning would bring to having a team that actually catches things overnight. That alone changed how we think about risk.

Manager of Information Technology, regional NSW council

Why it worked

Being upfront about what Corpshore does not hold, no Essential Eight maturity level, no IRAP assessment, and framing the uplift work honestly as alignment rather than certification, is what made the proposal credible to an audit committee that had already flagged IT resourcing risk twice.

Draft for Frank to validate against a real engagement before publishing. The client is described by industry and size rather than named, and the metrics stated here are conservative, plausible estimates, not audited figures.

Build your team with Corpshore

Tell us the work, the delivery location and the coverage you need. You will have a considered response within six hours, or book a discovery call now.

Looking for a role rather than a partner? Explore careers at Corpshore