The problem — the box can't be patched, and the VPN is the target
Your firewall just became the most attacked device you own.
Three things landed at once in 2026: your edge hardware crossed end of support, firewall and VPN appliances became the number one way Australian businesses get breached, and both Cisco and Fortinet raised their renewal prices. We replace the edge with licence-free hardware, delete the internet-facing VPN, and hand you the evidence pack your insurer now asks for.
Trigger 1 · It cannot be patched
Past end-of-support
Cisco ASA 5506-X loses all support on 31 August 2026, Catalyst 2960-Plus and 2960-L on 31 October, FortiOS 7.2 on 30 September. Essential Eight Maturity Level 1 requires internet-facing services no longer supported by a vendor to be removed — so an unsupported firewall is an automatic fail, not a deduction.
Trigger 2 · It is being actively exploited
Your VPN is the front door
In June 2026 ASD's ACSC issued a Critical “act now” alert over the FortiBleed campaign against Fortinet firewalls and VPN gateways — credentials harvested from roughly 86,600 devices worldwide, embedded across Australian corporate, government, healthcare and critical infrastructure environments. Exploiting an edge device is now the leading way in, ahead of stolen passwords.
Trigger 3 · You are paying more for it
Renewals went up. Again.
Cisco adjusted list pricing through 2026 and Fortinet reset its price grid in March, with increases applying to subscriptions and services rather than hardware alone. The platform we deploy carries no per-device, per-port or per-access-point licence fee — which is where the five-year saving actually comes from.
Australian cyber insurers are now writing exclusions for incidents involving unsupported systems. An out-of-support firewall can turn a covered claim into an uncovered one.
60-second exposure self-check
Tick every box that applies
Tick anything that sounds familiar.
Start here — one price, no surprises
We price the assessment. We quote the rest once we've seen it.
Exposure Assessment
Find out exactly what you are running, what it exposes you to, and what it will cost to fix — in writing, before anyone touches anything.
Single site · $2,800 for 2–4 sites
Credited in full against any work that follows.
What you get
- Device-by-device inventory — model, part number, serial, firmware, support status
- End-of-support dates verified against each vendor's own bulletin, not a reseller tracker
- Known-exploited vulnerability exposure per device
- Internal application and flow inventory — what needs remote access, who uses it, over which protocols
- What is undocumented — rules, routes and tunnels with no recorded owner or purpose
- Gap list against your cyber-insurance proposal form and typical client security questionnaires
- Five-year cost comparison: stay as you are, refresh, or replace
- Hardware bill of materials so you can price the equipment yourself
- Prioritised remediation plan with indicative effort and cost bands
- A written recommendation — including doing nothing, if that is the right answer
- Read-only. No configuration changes, no production impact, no maintenance window required.
- No agents installed, no credentials retained. Read-only access or exported configs are enough.
- You keep the report whether or not you engage us for anything further.
What happens after the assessment
Remediation is scoped and quoted from the assessment's findings, against your actual estate rather than an assumption about it. That is the only honest way to price work on a network nobody has documented in five years, which is why you will not find a fixed migration price on this page, or on any credible provider's.
- Design and migration work quoted per site, fixed price, once the scope is known
- Rollback plan written and walked through before the migration plan
- Changes inside a contracted maintenance window, never ad hoc
- Hardware bought by you directly — we take no margin and hold no stock
We do not sell hardware. Equipment is specified in the assessment and bought by you directly, from whichever supplier you like. We take no margin on it and hold no stock, so there is no incentive for us to over-specify.
Single office, up to 25 staff
$2,800–4,000
Single office, 25–75 staff
$6,200–8,600
Multi-site
from $8,000 per site
Indicative budgets only, for a gateway, PoE switching and Wi-Fi 7 access points at current Australian street pricing. No per-device, per-port or per-access-point licence fee. Intrusion detection and prevention is included with rules updated daily; enhanced threat intelligence is an optional subscription at roughly a tenth the cost of a comparable incumbent bundle. Actual cost is confirmed in the assessment.
Afterwards, if you want it
Network Care
Network Care
The unglamorous work that stops you ending up here again: someone tracking firmware, end-of-life dates and what actually changed.
From, per estate. Scoped after the assessment.
- Quarterly firmware review and vendor end-of-life calendar tracking
- Configuration backup weekly and before every change, with version history
- Change management — every change documented, no undocumented drift
- As-built documentation kept current as the estate changes
- Named engineer for escalation during business hours
- Annual re-assessment against the original baseline
Scope
What this is not
Scope discipline is why the price holds. Here is what sits outside it, stated up front rather than discovered at invoice time.
The assessment is not a remediation
It is a read-only exercise that produces a document. Nothing is changed, patched, replaced or reconfigured. If you want the findings acted on, that is quoted separately once we both know what we are dealing with.
Not an Essential Eight assessment or compliance program
We report your position on the two Essential Eight patching controls as they apply to internet-facing network devices. Application control, Microsoft Office macro settings and backups are outside our scope, and no maturity level is conferred — ASD determines that from your lowest-scoring strategy across all eight.
Not a certification or audit opinion
The report records what was true on the date it was produced. It is not an audit, not a certification against any framework, and not a guarantee that an insurance claim will be paid.
Not an endpoint, identity or backup project
Endpoint patching, application allowlisting, macro policy, EDR, mailbox security and backup platforms stay with your existing IT provider or internal team.
Not a managed IT contract
We sit beside your existing provider, not in place of them. Helpdesk, user support, procurement and device management are not in scope.
We will tell you to do nothing if that is right
If you run heavy TLS inspection, sit in a regulated supply chain, or hold client contracts naming specific vendors, staying where you are and refreshing may be the correct answer. You keep the report either way.
Straight talk — three things most quotes won't tell you
1. No platform is CVE-free, including the one we install. Every modern edge vendor ships critical vulnerabilities. What decides whether you get breached is whether someone patches them within days — which is what the monthly service is for, and the honest reason this is not a one-off purchase.
2. Some firms should not move. If you run heavy TLS inspection, sit in a regulated supply chain, or have client contracts naming specific vendors, the right answer may be to stay put and refresh. If the audit says that, it says that — you keep the report either way.
3. We don't sell hardware at all. You buy it directly, wherever you like. We sell the design, the cutover and the tested rollback — the part that decides whether your Monday morning goes well.
Why Oramatel: 20+ years of enterprise network and security engineering, delivered by the senior engineer who scoped it — not a rotating helpdesk queue. We sit beside your existing IT provider, not in place of it.
Indicative pricing, AUD, excluding GST. End-of-support dates verified per part number against the vendor's official bulletin before any quote is issued — verified as at 2026-08-01. Prices cover engineering services only and exclude hardware. Cisco, Catalyst and ASA are Cisco Systems products; FortiGate and FortiOS are Fortinet products; UniFi is a Ubiquiti product; Cloudflare One, Access, Gateway and WARP are Cloudflare products.