top of page
Child learning physical therapy

Get Right Fit for Risk ready without hiring a cyber security team.

Provider Springboard helps Employment Services and Disability Employment Services (DES) providers navigate DEWR's Right Fit for Risk (RFFR) accreditation - from your first gap analysis through to audit-ready documentation and ongoing compliance. We manage the process and the paperwork; your IT provider (or ours) handles the technical build.
IMG_7669.JPG

What is Right Fit For Risk?

Right Fit for Risk (RFFR) is the Department of Employment and Workplace Relations' (DEWR) cyber security accreditation requirement for contracted Employment Services and Disability Employment Services providers.

 

​It requires your organisation to design, implement and maintain an Information Security Management System (ISMS) consistent with ISO 27001 and the Australian Government Information Security Manual (ISM),  including a Statement of Applicability (SoA) specific to your organisation.​

 

For many providers, RFFR isn't optional — it's a condition of your Deed with the Department.

 

And for a small or medium provider without an in-house security team, the requirements can feel like a foreign language.​That's where we come in.

Services

Working Cafe

Consulting & Advice

Understand what RFFR actually requires of your organisation, in plain English, and what pathway makes sense for your size and risk profile.

Man Signing

ISMS Review

An honest assessment of your existing Information Security Management System (if you have one) against ISO 27001 and RFFR requirements.

Therapy Session

Gap Analysis

A clear picture of where you stand today versus where you need to be, with a practical roadmap to close the gaps.

Rows of Binders

Audit Documentation Preparation

We prepare and organise the documentation your accreditation audit requires, including your Statement of Applicability, so you walk into your audit prepared and confident.

Laptop and Paperwork

ISMS Implementation

Hands-on project management as your ISMS is built out: policies, procedures, risk registers and controls.  All coordinated with your ICT provider.

Image by Amina Atar

Ongoing Compliance Support

RFFR isn't a one-off tick-box. We help you stay accredited, year after year, as requirements evolve.

What we do

We're your compliance and project management partner for RFFR, not a cyber security firm.

 

That distinction matters: it means you get someone who understands audit documentation, gap analysis and government accreditation processes end-to-end, working hand-in-hand with the people who actually build and manage your IT environment.

We work with your IT Provider

You don't need to replace your existing IT provider to get RFFR-ready - and we'd usually prefer you didn't. We work alongside whoever manages your technical environment now, translating RFFR and ISO 27001 requirements into practical technical actions they can implement.

If you don't currently have an IT provider, or yours isn't able to take this on, we can connect you with a trusted partner to deliver the technical side.

Either way, your project stays coordinated under one roof — with us managing the compliance journey from start to finish.

Book a free 
consultation

Please complete the form to schedule a free 15 minute consultation. 

Thanks for submitting, we'll be in contact soon.

Free RFFR Audit Ready Checklist

Enter your email address and join our mailing list to receive the free checklist

photo.JPG

Every organisation's RFFR journey is different

Because your existing systems, provider type, and risk profile all affect what RFFR requires of you, we don't offer fixed packages for this service - we scope every engagement individually.

bottom of page