FREQUENTLY ASKED QUESTIONS
Yes, and precisely because you're small. Attackers automate: they scan the whole internet and phish entire industries at once, then focus on whoever has the weakest defences. Small businesses are targeted because they hold valuable data (client files, payment details) with a fraction of the protection. Around 43% of cyber attacks are aimed at small businesses, and the Australian Signals Directorate receives a cybercrime report every 6 minutes.
We complement your IT provider, we don't replace them. Most MSPs are excellent at keeping systems running, but 24/7 threat detection, incident response, penetration testing and compliance are specialist disciplines with their own tooling and analysts. We work alongside your existing IT — they keep the lights on, we keep the attackers out.
A 30-minute conversation about your setup, followed by a light-touch review of your externally visible security posture and your alignment with the Essential Eight. You get a short plain-English report of your top risks and what fixing them would involve. No obligation, no scare tactics, no 40-page PDF of jargon.
Our packages are priced per user per month, fixed, and scale with headcount. As a rough guide, protecting a 20-person business costs less per month than one day of a security consultant's time. Tell us your headcount via the contact form and we'll send you an exact fixed quote within one business day.
The Essential Eight is the Australian Cyber Security Centre's baseline of eight mitigation strategies (patching, MFA, backups, application control and so on). It's not legally mandatory for most private businesses, but government tenders score it, insurers price against it, and enterprise customers audit it. Read our plain-English guide in Resources for the full picture.
Done badly, yes — that's why "IT locked everything down" horror stories exist. Done well, most controls are invisible day-to-day: MFA adds seconds, patching happens overnight, monitoring is silent. We sequence rollouts so nothing breaks and staff always know what's changing and why.
Call us. The first 24 hours decide most outcomes: isolate affected machines, preserve evidence, assess backups, and make notification decisions under the Privacy Act. We handle incident response for our managed clients as part of the package, and we take emergency engagements when capacity allows. Our "first 24 hours" guide in Resources walks through the immediate steps.
Yes — this has become one of the most common reasons SMBs call us. We get your controls to the point where you can truthfully answer "yes" to the questionnaire (MFA, EDR, backups, training), and we produce the evidence pack insurers ask for. Honest answers matter: misstating controls can void a claim.
Our Australian operation is based in Sydney (64 York St), and we're part of the international CyberSec360 group, which gives us follow-the-sun monitoring capability. Your account contact is local and answers in Australian business hours; the monitoring never sleeps.
About a week for a typical SMB: a scoping call, evidence collection with your IT provider, and a written report of your maturity level per strategy with a prioritised, costed uplift roadmap. It's a fixed-price engagement.
Absolutely. Pen tests, Essential Eight assessments and awareness-training programs are all available standalone with fixed-price quotes — no managed-services commitment required. Many clients start with a one-off test and expand later.
Our sweet spot is 5–200 staff: big enough to be a target, too small to justify an internal security team. If you're larger, the CyberSec360 group has enterprise capability we can bring in.
Still have questions? A real person from our Sydney team will answer them.
Ask Us Anything