Managed cyber security · Brisbane and Australia wide

Cyber security that holds up to an audit, an insurer, and an actual attack.

Most cyber security pages sell fear. This one will not. Here is what an Australian business actually needs from cybersecurity services brisbane or anywhere else: controls that work, evidence you can hand to a client or an insurer, and someone who picks up the phone at 2am.

ACSC certified Network PartnerCyberCert GoldMicrosoft PartnerNo lock-in contracts
Reviewed by Blake Bath, General Manager
Entry pointPick one

Start where you actually are

Three doors. Nearly everyone arrives through one of them.

Procurement pressure

A client or insurer wants proof we are secure

You need certification and evidence, not more tools. Start with SMB1001. Bronze in weeks, Gold when the contract demands it.

Get certified
Live incident

Something has happened, or we think it has

Stop reading and call 07 3114 2808. If you want to know what the first hour should look like before you need it, read the guide.

Read the first hour guide
Unknown posture

We honestly do not know where we stand

Neither do most businesses. A risk review takes about a week and gives you a written picture of your exposure against the Essential Eight.

Book a risk review
Control stackEight layers

Not a product list

This is what we deploy and manage, and what each layer is actually for.

Identity threat detection

User behaviour is benchmarked and monitored so a sign-in that does not look like your staff member gets flagged before an account takeover.

Endpoint security

Laptops, desktops and servers protected against malware and ransomware, with detection and response running around the clock.

Email protection

One in three business incidents starts here. Filtering, DMARC and SPF enforcement, impersonation detection, and a quarantine staff can use.

Cloud data protection

Visibility over what is shared outside the business, with controls that keep collaboration working instead of shutting it down.

Awareness training

Short, regular training that makes staff the first line of defence rather than the reason you are filing a breach notification.

Phishing simulation

Safe test emails that mimic real attacks. Anyone who clicks gets coached, not disciplined. It shows you where the weak spots actually are.

Secure browsing

Browser-level protection against malicious sites and drive-by downloads, on managed and unmanaged devices alike.

External risk and dark web

Continuous scanning of your public footprint and breach data, so leaked credentials get reset before they get used.

What it catches

Phishing

Malicious emails caught before they reach a staff member.

Data exfiltration

Sensitive files leaving the business flagged and stopped.

Unauthorized sign-in

Logins from new locations or devices blocked at the door.

Risk alerts

Anomalies ranked by severity so critical ones surface first.

Ransomware

File encryption behaviour detected and isolated in seconds.

Credential theft

Leaked passwords found on the dark web and reset before use.

Most businesses are strong in two layers and blind in six

Eight layers, one shape
Security control coverageA radar chart comparing typical unmanaged coverage against a fully managed control stack across eight security layers.IdentityEmailEndpointCloud dataAwarenessPhishingBrowsingExternal

Almost everyone has antivirus and a spam filter, so endpoint and email look respectable. The gaps sit where modern attacks actually land: identity, external exposure, and the people using the systems.

  • Typical unmanaged businessIndicative shape from the gaps we find on assessment, not a measurement of your business.
  • Fully managed stackAll eight layers deployed, monitored and evidenced quarterly.

Antivirus stopped being the answer when attackers started logging in instead of breaking in.

One in three Australian business incidents now starts with a compromised email account. ASD, FY2024-25.
Self assessment60 seconds

Assess your own posture

Tick anything that is true. Nothing is sent anywhere, this runs in your browser.

0 of 7 gaps identified

Tick the statements that apply to your business.

Book a cyber risk review
EvidenceASD and OAIC

The numbers, from the source

Skip the American statistics. This is what the Australian Signals Directorate and the Office of the Australian Information Commissioner actually reported.

$0Average self-reported cost of a cybercrime report for an Australian small business+14%
$0The same figure for a medium business+55%
0Cybercrime reports to ReportCyber, roughly one every six minutesFY24-25
1 in 3Business cybercrime reports that begin with a compromised email accountEmail first
Top 3Queensland is one of the three highest reporting states in the countryBy volume
0Data breaches notified to the OAIC in calendar 2025, the highest since the scheme began in 2018+8%
0%Australians who now rank data breaches as their top privacy concern, up from 74 per cent in 2023Your customers

ASD Annual Cyber Threat Report 2024-25, October 2025. OAIC Notifiable Data Breaches 2025, published 6 July 2026. OAIC Community Attitudes to Privacy Survey 2026.

Three things worth saying plainly. Those costs are self-reported and direct, so they exclude the fortnight your team spends rebuilding and the client who quietly does not renew. The figure rose in every business size band. And that last number is the commercial one: your customers are now paying attention to this whether you are or not.

Email filtering flow diagram showing total email processed and split into clean, spam, phishing and malicious attachment streams
Every email processed and sorted. The thin stream at the bottom is the one that would have encrypted your server.
Sector exposureOAIC, calendar 2025

Who is actually getting breached

Data breach notifications to the OAIC in calendar 2025, by sector. The threats are similar across all of them. The obligations are not.

OAIC Notifiable Data Breaches, calendar year 2025. 1,205 notifications in total, 716 of them malicious or criminal.

Two sectors on that list changed status this year. Legal and accounting firms came under the Privacy Act on 1 July 2026 through the AML reforms, and they are already fifth by breach volume. If that is you, the obligation arrived before the controls did.

Nobody chose you. They scanned everyone, and you answered.

84,700 cybercrime reports to ReportCyber in FY2024-25. One every six minutes.
CertificationSMB1001:2026

Certification is now a sales issue

Cyber certification stopped being a compliance chore and became a procurement requirement. Enterprise buyers and government tenders are asking. Insurers are asking. The Queensland Law Society has formally endorsed SMB1001 for firms handling client data. If you cannot answer, you lose the work.

Level 1

Bronze

Basic hygiene. The controls that stop the overwhelming majority of opportunistic attacks.

Verification
Director self-attestation
Best for
Micro business, sole traders
Typical time
2 to 4 weeks
What it asks for
  • Engage technical support, in-house or an IT provider
  • Multi-factor authentication on email
  • Automatic updates on devices and software
  • Backups running, with a nominated owner
CyberCert Bronze Level 1 badge

SMB1001:2026 is the current edition, certifiable since January 2026. Controls sit across five domains: technology management, access management, backup and recovery, policies and processes, and education and training.

Where we sit

We hold the standard we sell

Real Bytes is CyberCert Gold accredited. We prepare the evidence, close the technical gaps, and walk your director through attestation. For Platinum and Diamond we manage the independent verification.

SMB1001 certification
Framework

Essential Eight

Eight ASD mitigation strategies across four maturity levels. Free to read, hard to implement, harder to evidence. We assess where you actually sit, not where you assume you sit.

Essential Eight compliance
Decision

Which one do you need?

Usually SMB1001 for proof and Essential Eight for substance. They overlap heavily. We have written the comparison so you can work it out before you talk to us.

Compare the frameworks
Insurance

Cyber insurance readiness

Underwriters now ask for MFA, endpoint detection, tested backups and staff training before they quote, then ask again at claim time. Getting the controls right lowers the premium and keeps the policy from being void when you need it.

Insurance readiness
Worth knowingASD announcement, 24 June 2026

The Essential Eight is being retired. The ASD has confirmed it will be replaced over roughly two years by a broader Essentials series, beginning with a chapter on enterprise IT. Consultation closed in July 2026.

This does not change what you should do now. The Essential Eight and its maturity model remain published and in force, they are still what insurers, tenders and assessors measure against, and the ASD has said investment made under the Essential Eight stays relevant. No control-by-control mapping to the new series has been published yet. We are tracking it, and any uplift we scope is built so it carries across rather than needing to be redone.

ObligationsIn force and pending

What the law now asks of you

Australian cyber and privacy obligations are arriving in stages, which is exactly why businesses miss the one with their name on it. Here is the whole calendar.

10 Jun 2025

Anyone can sue for a serious invasion of privacy

The statutory tort under the Privacy Act applies regardless of your turnover. The small business exemption does not protect you from it.

In force
30 May 2025

Ransomware payments must be reported in 72 hours

Cyber Security Act 2024. Applies at $3 million turnover and above, and to critical infrastructure at any size. Civil penalty up to $19,800. Enforcement stepped up from 1 January 2026.

In force
1 Jul 2026

Over 100,000 small businesses lost their Privacy Act exemption

AML/CTF reforms brought accountants, tax and BAS agents, lawyers, conveyancers, real estate professionals, trust and company service providers and precious metals dealers under the Privacy Act for their AML data handling, regardless of turnover.

In force
10 Dec 2026

Automated decision-making must be disclosed

If you use automated systems to make decisions that significantly affect people, your privacy policy has to say so. The Children's Online Privacy Code must also be registered by this date.

15 weeks
Not dated

Removal of the $3 million small business exemption

Part of a second tranche of Privacy Act reform. Government supports it in principle, no Bill has been introduced. Treat any specific date you read as commentary, but note the OAIC has publicly called the exemption no longer appropriate.

Proposed
Ransomware window
72 hours
Breach assessment
30 days
Infringement notice
$66,000
Serious breach penalty
Up to $50m

The practical read. If you are over the ransomware threshold, the decision to pay is now also a reporting decision and it belongs in your incident plan before the day arrives. If you are a professional services firm, 1 July 2026 already moved you and most firms have not noticed. And if you are under every threshold, you are still in someone else's supply chain, and they will ask.

Read the security incident playbook

From the field

Why identity, not antivirus, is where we start on every tenant we inherit

Mason Wise, MSP Practice Lead at Real Bytes

Mason Wise

MSP Practice Lead · Microsoft 365 migrations & infrastructure takeovers

On the tenant migrations, the recurring pattern was not the mailbox move itself, it was everything sitting around it. Shared mailboxes with stale delegations, Teams meetings with calendar invites pointing at the old tenant, SharePoint sites with broken external sharing links, conditional access policies that had been built up over years and nobody could explain. Each cutover was treated as a discovery exercise first, migration second. For the island NFP takeover, the network had grown organically. Mixed vendor switching, undocumented VLANs, a satellite link that was the only path off the island, and a server rack that had not had a backup tested in over a year. The risk profile was unusual because if anything went wrong, the next engineer was a boat ride away.

Tenant cutovers ran on documented runbooks with pre-stage, delta sync, and weekend cutover windows. Conditional access and identity governance were uplifted as part of the move rather than carried across as-is, so each client landed on a cleaner posture than they started with. Users opened Outlook on Monday and kept working. For the island NFP, did a full site audit in person, rebuilt the documentation from the ground up, replaced the end-of-life core switching and firewall, and put proper monitoring and remote access in place so future work does not require a site visit unless it genuinely does. The NFP now has a documented network, tested backups, and a support model that matches the realities of where they operate.

Meet the engineers behind this work
ObjectionsAnswered plainly

Straight answers

We already have antivirus

Antivirus covers one layer, the device. The current problem is identity. Attackers log in with credentials they bought or phished, and antivirus never sees it because nothing malicious runs. You need identity monitoring and email controls sitting alongside the endpoint agent.

This sounds expensive

Managed IT with security included starts around $85 per user per month. The ASD average for a single small business incident is $56,571. Run your headcount through the calculator above and compare. You are not paying for six separate licences either, it is one stack and a team to run it.

We have never had a problem

That is exactly why you are attractive. Attackers assume smaller businesses are not actively defending themselves, and most attacks now are automated and untargeted. Nobody chose you. Security by obscurity stopped working a long time ago.

We are only a small team

Small teams are the preferred target. Five people or fifty, one compromised mailbox redirects one invoice and the money is gone.

We are already using some security tools

Probably true, and probably not integrated. The gap between three tools that do not talk to each other is where incidents live. We will audit what you already have before suggesting you replace any of it.

I do not want something complicated

You will not manage anything. Setup, monitoring, updates and response are ours. Your staff are involved twice: their scheduled awareness training, and releasing the occasional email from quarantine.

We are in the middle of other projects

Security does not wait, but the rollout can work around you. We can give you visibility of your current risks without touching production, then you decide how fast to move.

Our industry does not require compliance

It might not, but your clients will. Supply chain security questionnaires are now routine for anyone selling into a larger organisation.

We do not want to be locked in

No lock-in contracts. If we are not worth keeping, leave.

Cyber servicesExplore
FAQSchema marked up

Common questions

What does managed cyber security actually include?

Continuous monitoring of your identities, email, endpoints, cloud services and data, with a team that investigates and responds when something looks wrong. It also includes the unglamorous parts: patching, backup verification, access reviews, staff training, and the reporting you need to prove any of it happened.

How much does cyber security cost for an Australian small business?

Real Bytes managed IT with security included starts from approximately $85 per user per month. Standalone certification work such as SMB1001 is quoted separately based on tier. Use the pricing calculator for an estimate.

What is the difference between SMB1001 and the Essential Eight?

SMB1001 is a certification you can hold and show to clients, insurers and tender panels. It has five tiers and is certified through CyberCert. The Essential Eight is an ASD framework of eight technical controls measured across four maturity levels. It is not a certification, though it is often what a client means when they ask about your security posture. Most businesses benefit from doing both, because the controls overlap heavily.

Do we have to report a ransomware payment in Australia?

If your business turns over $3 million or more per year, yes. The Cyber Security Act 2024 requires reporting to the Australian Signals Directorate within 72 hours of making a ransomware or extortion payment, with penalties up to $19,800 for failing to report. Businesses under the threshold have no legal obligation, but reporting to ReportCyber is still recommended.

Is the Essential Eight being replaced?

Yes, over time. On 24 June 2026 the ASD confirmed the Essential Eight will be retired within roughly two years and replaced by a broader Essentials series. It remains published and in force today, and it is still the benchmark insurers, tenders and assessors use. No control-by-control mapping to the new series has been published. Work done under the Essential Eight is expected to remain relevant, and we scope uplift so it carries across.

Does the Privacy Act apply to my small business?

It depends, and the answer changed on 1 July 2026. The general exemption for businesses under $3 million turnover still exists, but AML reforms brought accountants, tax and BAS agents, lawyers, conveyancers, real estate professionals, trust and company service providers and precious metals dealers under the Act for their AML data handling, regardless of turnover. Health information, trading in personal data and Commonwealth contracting were already covered at any size. Separately, since 10 June 2025 any individual can sue for a serious invasion of privacy whether or not you are covered by the Act.

Does Real Bytes support businesses outside Brisbane?

Yes. Our cybersecurity services brisbane team is the same team that supports every other state, with an Australian helpdesk and we support businesses in every state. On-site attendance is available across South East Queensland and arranged through partners elsewhere.

How quickly can you respond to an incident?

Detection and containment run 24/7. For confirmed incidents we isolate affected endpoints and suspend compromised accounts immediately, then contact you by phone. If you are not a client and you are in an incident right now, call 07 3114 2808.

Will cyber security slow our team down?

Done badly, yes. Done properly, staff notice MFA at login and very little else. Where a control creates real friction we tell you the trade-off rather than imposing it quietly.

What is the difference between red teaming and penetration testing?

A penetration test finds and reports vulnerabilities in a defined scope over a fixed window. A red team exercise simulates a real adversary against your people, processes and technology to test whether your defences actually detect and respond. Most Australian SMBs need a penetration test first, and managed detection in place, before a red team exercise tells them anything useful. Penetration testing covers what we offer and when each is worth doing.