- We've been asked to complete a principal contractor's security questionnaire. Can you help?
- Yes. We've done enough of them for mining services firms to know which questions are load-bearing. Typically the asks are MFA, EDR, patching, backups, offboarding, incident response, and cyber insurance. We answer with evidence, and where the answer is 'not yet,' we give you a remediation plan with dates the principal will accept.
- Our field laptops go between remote sites, home, and the office. How do we keep them safe?
- Treat the laptop as hostile to any network it's on, not trusted because it's behind an office firewall. Full-disk encryption, identity-based access to cloud platforms, EDR with an always-on posture, and no shared logins. Site-specific policies apply at the platform level, not by physical network. We set this up once and it scales as the fleet grows.
- We run drone and LIDAR survey work. The data is enormous. Where should it live?
- Depends on the principal's contractual restrictions and who your customers are. We'll help you pick a storage pattern that meets the data sovereignty requirements in your contracts, stays affordable as the raw-data library grows, and integrates with the analysis tools your team actually uses. We don't sell the storage, so we'll tell you which product is the best fit for your setup, not whichever one pays us the most.
- Do you cover 24/7 incident response? Our operations run around the clock.
- For CCP clients on Managed IT Complete, critical incident response is handled by our Australia-based team with defined SLAs for after-hours. We're not a 24/7 SOC, and if that's what you need we'll say so and help you pick one. For most mining services firms, the combination of an always-on monitoring stack, a defined IR playbook, and a responsive Australia-based team is the right fit. The outlier cases we'll flag upfront.
- Mining services firms work with overseas principals and offshore contractors. Does that create issues?
- It creates work, not issues. Cross-border data flow, export control on geospatial data in some jurisdictions, identity federation with overseas tenants, vendor risk assessments for offshore subcontractors. We've set this up for firms that operate across Australia, South-East Asia and Africa. It's detail work that benefits from being done properly once rather than patched later.