Business Connected — IT & CommunicationsBook an assessment
Home  /  Services  /  Cyber security
SEC — Cyber security services

Most breaches here aren’t clever. They’re a password.

Australian small business is not being targeted by nation states. It is being targeted by automated credential stuffing, invoice fraud and a staff member who clicked something at 4:50 on a Friday. The controls that stop that are unglamorous, well documented, and mostly things you already own a licence for.

What we actually see.

What you sayWhat it actually is
“We’ve got antivirus. Isn’t that enough?”

Antivirus matches known bad files. The attacks that get through use your own tools — a valid login, PowerShell, a legitimate remote access agent. That is what endpoint detection and response looks for, and why the Essential Eight starts with control, not detection.

“We’d know if something happened.”

The median time an Australian SMB takes to notice an unauthorised mailbox rule is measured in weeks, because nobody is reading the audit log. Detection is not a product you install. It is someone whose job is to look.

The programme

Essential Eight, in the order that actually helps.

The ACSC Essential Eight is the baseline every Australian security conversation refers back to. We work through it as a sequence, not a scorecard — and we tell you which ones matter most for a business your size.

Control what runs

Application control & macro settings

Stop unapproved executables and Office macros from running at all. The single highest-value control, and the one most often skipped because it takes work to do properly.

Close the known holes

Patch applications & operating systems

Two of the eight are just patching, split by what you are patching. Automated, scheduled, and reported — including the third-party apps that never prompt anyone.

Reduce what an attacker gets

Restrict administrative privileges

Separate admin accounts, no daily driver with domain rights, and privileged access that is requested and logged rather than permanently held.

Make a stolen password useless

Multi-factor authentication

On email, on remote access, on anything internet-facing — with conditional access so it is enforced by policy, not by hoping people enrolled.

Harden the browser

User application hardening

Block the plugins, ads and script paths that deliver most drive-by compromise, without breaking the web apps your team actually needs.

Be able to come back

Regular backups — tested

Immutable where possible, offsite always, and restored on a schedule so you find out it works before you need it to.

Beyond the eight

The rest of what we run.

  • Email securitySPF, DKIM and DMARC moved to enforcement, impersonation protection, and external-sender warnings
  • Identity protectionconditional access, risk-based sign-in policies, and legacy authentication switched off
  • Endpoint detection and responseHuntress managed EDR on every device
  • Managed detection and responsea 24/7 SOC investigating what the EDR finds
  • DNS filteringmalicious and unwanted destinations blocked before the page loads
  • Security awareness trainingshort, regular, and phishing-simulated
  • Incident response planningwho rings whom, in what order, with the numbers printed out
  • Notifiable Data Breach readinessso an assessment happens in hours, not a fortnight
Certification

If you need to prove it, that’s SMB1001.

Doing the work and being able to demonstrate it are two different jobs. SMB1001 turns your controls into a certificate your customers and insurers will accept.

Controls at this level

    Start with a security assessment.

    We test what is actually in place against the Essential Eight and SMB1001, and give you a prioritised list — what to fix this month, this quarter, and this year.

    No obligation. We will tell you if you do not need us.