Cyber security, Australia wide

Attackers now log in with stolen passwords. We catch them before they reach your money.

Most attacks on small businesses start with one stolen login or one fake invoice. We watch your logins, email and devices day and night, and when something happens, we own it until it is fixed. You also get the paperwork that proves it to clients and insurers.

Reviewed by Blake Bath, General Manager
Start here

Where are you right now?

A client or insurer wants proof we are secure

You need a certificate and evidence, not more tools. SMB1001 gives you a certificate you can show. We get you ready and handle the paperwork.

How SMB1001 certification works

Something has happened, or we think it has

Stop reading and call 07 3114 2808. If you want to know what the first hour should look like before you need it, read the guide.

Read the first hour guide

We honestly do not know where we stand

Most businesses do not. An engineer checks your setup against the Essential Eight and gives you a written list of what to fix first.

Talk to an engineer
What we do

When one of these happens, we deal with it

We set it up, watch it and run it. You do not manage any of it.

Someone logs in who should not

We watch every staff sign-in. When one comes from an odd place or device, we block it and lock the account before anyone can read your email.

A laptop picks up something nasty

Protection on every laptop, desktop and server, watched day and night. If ransomware starts, we cut that machine off from the rest of the business.

A fake invoice lands in the inbox

We filter email, stop others sending mail that pretends to be you, and flag lookalike senders, so fake invoices and scam links are caught before staff see them.

Files get shared too widely

We can see what leaves the business through OneDrive, SharePoint and Teams, and set sharing rules that keep work moving without leaking client files.

A staff member clicks the wrong link

Short, regular training plus safe practice scam emails. Anyone who clicks gets a quick lesson, not a telling off, and you see where the weak spots are.

A password turns up in a breach

We check leaked password lists and your public footprint. When a staff password appears, we reset it before it is used.

Self check

Check your own setup in a minute

Tick anything that is true. Nothing is sent anywhere, it runs in your browser.

0 of 7 gaps identified

Tick the statements that apply to your business.

Book a cyber risk review
The numbers

What it costs when it goes wrong

Australian figures from the Australian Signals Directorate and the privacy regulator.

$0Average reported cost of one cybercrime to an Australian small business, up 14%
$0The same figure for a medium business, up 55%
0Cybercrime reports to ReportCyber in a year, about one every six minutes
0Data breaches reported to the OAIC in 2025, the most since reporting began in 2018

ASD Annual Cyber Threat Report 2024-25. OAIC Notifiable Data Breaches statistics, calendar year 2025.

Those costs are only what businesses reported losing directly. They leave out the weeks spent rebuilding and the clients who quietly do not come back.

Email filtering report showing all incoming email sorted into clean mail, spam, phishing and harmful attachments
Every email sorted before it reaches staff. The thin stream at the bottom is the one that would have locked your files.
Proof for clients

When a client, tender or insurer asks how you are secured

Bigger clients, government tenders and insurers now ask for evidence. We give you something you can hand over.

Level 1

Bronze

Basic hygiene. The controls that stop the overwhelming majority of opportunistic attacks.

Verification
Director self-attestation
Best for
Micro business, sole traders
Typical time
2 to 4 weeks
What it asks for
  • Engage technical support, in-house or an IT provider
  • Multi-factor authentication on email
  • Automatic updates on devices and software
  • Backups running, with a nominated owner
CyberCert Bronze Level 1 badge

SMB1001 certificate

We hold SMB1001 Gold ourselves through CyberCert. We prepare your evidence, fix the gaps and walk your director through sign-off.

SMB1001 certification

Essential Eight

Eight controls from the Australian Signals Directorate, scored at four maturity levels. We check where you really sit and lift you to the level you need.

Essential Eight

Which one do you need?

Usually SMB1001 for the certificate and the Essential Eight for the protection underneath. Our guide compares them side by side.

Compare the frameworks

Cyber insurance

Insurers ask about sign-in checks, device protection, tested backups and staff training before they quote, and again when you claim. We make sure your answers are true.

Insurance readiness

Your legal obligations, such as ransomware payment reporting and the Privacy Act changes, are set out on our Australian regulatory hub.

From the field

Why identity, not antivirus, is where we start on every Microsoft 365 setup we take over

Mason Wise, MSP Practice Lead at Real Bytes

Mason Wise

MSP Practice Lead · Microsoft 365 migrations & infrastructure takeovers

On the tenant migrations, the recurring pattern was not the mailbox move itself, it was everything sitting around it. Shared mailboxes with stale delegations, Teams meetings with calendar invites pointing at the old tenant, SharePoint sites with broken external sharing links, conditional access policies that had been built up over years and nobody could explain. Each cutover was treated as a discovery exercise first, migration second. For the island NFP takeover, the network had grown organically. Mixed vendor switching, undocumented VLANs, a satellite link that was the only path off the island, and a server rack that had not had a backup tested in over a year. The risk profile was unusual because if anything went wrong, the next engineer was a boat ride away.

Tenant cutovers ran on documented runbooks with pre-stage, delta sync, and weekend cutover windows. Conditional access and identity governance were uplifted as part of the move rather than carried across as-is, so each client landed on a cleaner posture than they started with. Users opened Outlook on Monday and kept working. For the island NFP, did a full site audit in person, rebuilt the documentation from the ground up, replaced the end-of-life core switching and firewall, and put proper monitoring and remote access in place so future work does not require a site visit unless it genuinely does. The NFP now has a documented network, tested backups, and a support model that matches the realities of where they operate.

Meet the engineers behind this work
Questions

Straight answers

What does managed cyber security actually include?

We watch your staff logins, email, laptops, servers and Microsoft 365 around the clock, and step in when something looks wrong. We also patch, check backups, review who has access, train your staff, and give you the reports that prove all of it happened.

How much does cyber security cost for an Australian small business?

Real Bytes managed IT with security included starts from approximately $85 per user per month. Standalone certification work such as SMB1001 is quoted separately based on tier. See the Pricing page for detail.

What is the difference between SMB1001 and the Essential Eight?

SMB1001 is a certificate you can show clients, insurers and tender panels, issued through CyberCert across five tiers. The Essential Eight is a set of eight technical controls from the Australian Signals Directorate, measured across four maturity levels. It is not a certificate. The two overlap heavily, so most businesses do both.

Is the Essential Eight being replaced?

Yes, gradually. In June 2026 the Australian Signals Directorate said it will retire the Essential Eight over about two years and replace it with a broader Essentials series. For now it is still what insurers, tenders and assessors measure against. Work you do on it now still counts, and we plan every uplift so it carries across.

Do we have to report a ransomware payment in Australia?

If your business turns over $3 million or more a year, yes. The Cyber Security Act 2024 requires you to report a ransomware or extortion payment to the Australian Signals Directorate within 72 hours. Smaller businesses have no legal duty, but reporting through ReportCyber is still worth doing.

We already have antivirus. Is that not enough?

Antivirus protects the device. Most attacks now start with someone logging in using a stolen password, and antivirus never sees that because nothing harmful runs on the laptop. You also need someone watching logins and email, which is what we do.

Do you support businesses outside Brisbane?

Yes. Brisbane is home, but we are a fully remote team with people and partners in Brisbane, Sydney, Melbourne, Adelaide and Albury. A business in any Australian city gets the same engineers, the same service and the same phone number.

What happens if something goes wrong?

We cut off the affected laptop or account straight away, then call you. From there we own it until it is fixed: cleaning up, restoring what was lost, and helping with any reporting you need to do. If you are not a client and you have an incident now, call 07 3114 2808.

Will this slow our team down?

Done properly, staff notice an extra sign-in check on new devices and very little else. Where a control does get in the way, we explain the trade-off and let you decide.

In more detail
Next step

Find out where your gaps are

Talk to a senior engineer. We look at what you have today, tell you plainly what an attacker would try first, and what to fix first. Same service wherever you are in Australia.

Cookie Preferences

We use cookies to improve your experience, analyse site traffic, and personalise content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy

Privacy Act 1988 compliant. Your data is never sold.