Cyber security

The ones who get hit are the ones nobody was watching.

Almost none of it is personal. Attacks are automated, they sweep for anything reachable and out of date, and a small business is the least likely to notice.

Counted at the reported national average of one every six minutes. Almost none of them were aimed at anybody in particular.

The numbers

Small businesses are the cheapest target and they know it.

These are the government's own figures, not ours, and the source is printed underneath so you can go and read it.

  • $56,600

    What a cybercrime report costs an Australian small business, on average

  • 34%

    Of business cybercrime reports are email compromise, with or without money lost

  • +50%

    Rise in the average cost across all Australian businesses in one year

Source: Australian Signals Directorate, Annual Cyber Threat Report 2024-25.

How it happens

Four ways in, and what closes each one.

Nearly every incident at this size arrives through one of these. None of them require anybody to have chosen your business in particular.

  1. 01

    Through an email account

    Someone gets into a mailbox, watches for a while, then sends an invoice with their own bank details on it from an address your accounts team trusts. It is the most reported business cybercrime in the country.

    What closes it Enterprise mail filtering, multi factor on every account, and staff who have been taught what this looks like.

  2. 02

    With a password you already lost

    A site your staff signed up to years ago gets breached, the passwords go up for sale, and somebody tries the same one against your Microsoft 365. Most people reuse passwords, and attackers know it.

    What closes it Dark web monitoring on your domain, multi factor, and a password changed before the login is tried.

  3. 03

    Through something unpatched

    A firewall on firmware from three years ago, or a server missing an update that was published months back. Scanning for these is automated and constant, and nobody has to have singled you out.

    What closes it Patching to a schedule, firmware kept current, and monitoring that flags what is falling behind.

  4. 04

    By convincing a person

    A phone call from your bank, a text from the boss asking for gift cards, a login page that looks exactly right. No software failure involved, which is why technology alone never covers it.

    What closes it Security awareness training, web protection that blocks the fake page, and a culture where checking is normal.

What we cover

Nine areas, and none of them optional.

Security is not one product. It is a set of things that each close a different door, and leaving one open tends to be how it happens.

  • Email security

    Enterprise filtering ahead of the mailbox, plus SPF, DKIM and DMARC set correctly so nobody can send mail that looks like it came from you.

  • Identity and access

    Multi factor authentication across your accounts, admin rights kept to the people who need them, and joiners and leavers handled properly.

  • Managed endpoint protection

    Protection on every device, managed and monitored rather than installed and forgotten, with encryption and local admin exposure checked.

  • Network perimeter

    Firewall rules that are reviewed rather than inherited, firmware kept current, and remote access paths that are deliberate.

  • Web and DNS protection

    Filtering so a convincing fake login page does not open, and DNS health monitoring so your own records stay correct and unhijacked.

  • Patching and maintenance

    Workstations and servers patched to a plan, so the window between a fix being published and it being applied is short and known.

  • Backup and recovery

    Daily cloud backups of your servers and of your Microsoft 365 tenancy, with restores tested. Ransomware is survivable when the backups are real.

  • Staff training

    Security awareness training, because the most expensive incidents start with someone doing exactly what they were asked to do by someone they trusted.

  • Monitoring and response

    A cyber security team watching around the clock, and dark web monitoring on your domain. Alerts come to us rather than sitting in a console nobody opens.

What it costs

All of that is in the standard agreement.

Not a security tier, not a bolt on, and not something we come back and sell you after a bad week. The business that cannot justify the security add on is the one that ends up needing it, so there is no add on.

From $119 per user, per month

excluding GST

Book a free IT strategy call
  • Email security
  • Identity and access
  • Managed endpoint protection
  • Network perimeter
  • Web and DNS protection
  • Patching and maintenance
  • Backup and recovery
  • Staff training
  • Monitoring and response

The same figure whether you take one area or all nine, because you take all nine.

How it is measured

Aligned to the Essential Eight.

The ACSC's eight mitigation strategies are the Australian benchmark, and the one your insurer, your larger clients and any government tender will ask about. We align your environment to it and keep the evidence, so answering a questionnaire is a task rather than a week of guessing.

Australian rules

What applies to a Gold Coast business is the Privacy Act 1988, the Notifiable Data Breaches scheme if personal information is exposed, and the ACSC Essential Eight as the practical standard to work to. Those are the three we hold your environment against, and the three we can show you evidence for.

Questions we get asked

Is security really included, or is it a premium tier?

Included. Every area set out on this page is in the standard managed agreement, at the same published price. The reasoning is straightforward: the business that cannot justify the security add on is the one that ends up needing it, so selling it separately means the people most at risk go without.

What is the Essential Eight and do we have to do it?

It is a set of eight mitigation strategies published by the Australian Cyber Security Centre, and it is the benchmark your insurer, your larger clients and any government tender are most likely to ask about. There is no legal obligation for most small businesses, but it is a sensible target and it is what we align your environment to.

We are small. Are we actually a target?

Not personally, and that is the point. Almost none of this is aimed at you specifically. It is automated, it sweeps for anything reachable and unpatched, and a smaller business is simply the one least likely to notice or to have anybody watching.

What happens if something does get through?

We contain it, work out how it happened and what was reached, and get you running again. A security alert on anything we monitor is acted on that night rather than in the morning, because containment is the one part of this where the hour genuinely matters. If it is a notifiable data breach under the Privacy Act 1988 we will tell you plainly and help you work through what the Notifiable Data Breaches scheme requires.

Will this help with our cyber insurance?

Considerably, and in two ways. Insurers now price on controls rather than on goodwill, and multi factor, tested backups, managed endpoint protection and patching are the questions on nearly every application, so a business that can answer yes to all of them sits in a very different bracket from one that cannot. The second way matters more. Those answers become part of your policy, and a claim can be cut back or refused outright if a control you said you had turns out not to have been there. We keep all of it running and documented, so what you told your insurer stays true and the evidence exists on the day you need it.

Can you work with our existing security tools?

Usually, and we will tell you honestly when something you are paying for is not worth keeping. The starting point is what you already have rather than a rip and replace, unless replacing it is genuinely the cheaper answer.

Find out what is actually exposed.

Thirty minutes, no obligation, plain answers. We will go through what you are running and where the gaps are, and tell you which ones matter.

Or ring us

1300 025 110 (07) 5638 1255

Monday to Friday, 9am to 5pm

Click here if the booking form is not loading

Or send us a message

We get back to you within one business hour, Mon to Fri

Call now Book a call