A client or insurer wants proof we are secure
You need a certificate and evidence, not more tools. SMB1001 gives you a certificate you can show. We get you ready and handle the paperwork.
How SMB1001 certification worksMost attacks on small businesses start with one stolen login or one fake invoice. We watch your logins, email and devices day and night, and when something happens, we own it until it is fixed. You also get the paperwork that proves it to clients and insurers.
You need a certificate and evidence, not more tools. SMB1001 gives you a certificate you can show. We get you ready and handle the paperwork.
How SMB1001 certification worksStop reading and call 07 3114 2808. If you want to know what the first hour should look like before you need it, read the guide.
Read the first hour guideMost businesses do not. An engineer checks your setup against the Essential Eight and gives you a written list of what to fix first.
Talk to an engineerWe set it up, watch it and run it. You do not manage any of it.
We watch every staff sign-in. When one comes from an odd place or device, we block it and lock the account before anyone can read your email.
Protection on every laptop, desktop and server, watched day and night. If ransomware starts, we cut that machine off from the rest of the business.
We filter email, stop others sending mail that pretends to be you, and flag lookalike senders, so fake invoices and scam links are caught before staff see them.
We can see what leaves the business through OneDrive, SharePoint and Teams, and set sharing rules that keep work moving without leaking client files.
Short, regular training plus safe practice scam emails. Anyone who clicks gets a quick lesson, not a telling off, and you see where the weak spots are.
We check leaked password lists and your public footprint. When a staff password appears, we reset it before it is used.
Tick anything that is true. Nothing is sent anywhere, it runs in your browser.
0 of 7 gaps identified
Tick the statements that apply to your business.
Australian figures from the Australian Signals Directorate and the privacy regulator.
ASD Annual Cyber Threat Report 2024-25. OAIC Notifiable Data Breaches statistics, calendar year 2025.
Those costs are only what businesses reported losing directly. They leave out the weeks spent rebuilding and the clients who quietly do not come back.

Bigger clients, government tenders and insurers now ask for evidence. We give you something you can hand over.
Basic hygiene. The controls that stop the overwhelming majority of opportunistic attacks.
What it asks for
We hold SMB1001 Gold ourselves through CyberCert. We prepare your evidence, fix the gaps and walk your director through sign-off.
SMB1001 certificationEight controls from the Australian Signals Directorate, scored at four maturity levels. We check where you really sit and lift you to the level you need.
Essential EightUsually SMB1001 for the certificate and the Essential Eight for the protection underneath. Our guide compares them side by side.
Compare the frameworksInsurers ask about sign-in checks, device protection, tested backups and staff training before they quote, and again when you claim. We make sure your answers are true.
Insurance readinessYour legal obligations, such as ransomware payment reporting and the Privacy Act changes, are set out on our Australian regulatory hub.
From the field
Mason Wise
MSP Practice Lead · Microsoft 365 migrations & infrastructure takeovers
On the tenant migrations, the recurring pattern was not the mailbox move itself, it was everything sitting around it. Shared mailboxes with stale delegations, Teams meetings with calendar invites pointing at the old tenant, SharePoint sites with broken external sharing links, conditional access policies that had been built up over years and nobody could explain. Each cutover was treated as a discovery exercise first, migration second. For the island NFP takeover, the network had grown organically. Mixed vendor switching, undocumented VLANs, a satellite link that was the only path off the island, and a server rack that had not had a backup tested in over a year. The risk profile was unusual because if anything went wrong, the next engineer was a boat ride away.
Tenant cutovers ran on documented runbooks with pre-stage, delta sync, and weekend cutover windows. Conditional access and identity governance were uplifted as part of the move rather than carried across as-is, so each client landed on a cleaner posture than they started with. Users opened Outlook on Monday and kept working. For the island NFP, did a full site audit in person, rebuilt the documentation from the ground up, replaced the end-of-life core switching and firewall, and put proper monitoring and remote access in place so future work does not require a site visit unless it genuinely does. The NFP now has a documented network, tested backups, and a support model that matches the realities of where they operate.
Meet the engineers behind this workWe watch your staff logins, email, laptops, servers and Microsoft 365 around the clock, and step in when something looks wrong. We also patch, check backups, review who has access, train your staff, and give you the reports that prove all of it happened.
Real Bytes managed IT with security included starts from approximately $85 per user per month. Standalone certification work such as SMB1001 is quoted separately based on tier. See the Pricing page for detail.
SMB1001 is a certificate you can show clients, insurers and tender panels, issued through CyberCert across five tiers. The Essential Eight is a set of eight technical controls from the Australian Signals Directorate, measured across four maturity levels. It is not a certificate. The two overlap heavily, so most businesses do both.
Yes, gradually. In June 2026 the Australian Signals Directorate said it will retire the Essential Eight over about two years and replace it with a broader Essentials series. For now it is still what insurers, tenders and assessors measure against. Work you do on it now still counts, and we plan every uplift so it carries across.
If your business turns over $3 million or more a year, yes. The Cyber Security Act 2024 requires you to report a ransomware or extortion payment to the Australian Signals Directorate within 72 hours. Smaller businesses have no legal duty, but reporting through ReportCyber is still worth doing.
Antivirus protects the device. Most attacks now start with someone logging in using a stolen password, and antivirus never sees that because nothing harmful runs on the laptop. You also need someone watching logins and email, which is what we do.
Yes. Brisbane is home, but we are a fully remote team with people and partners in Brisbane, Sydney, Melbourne, Adelaide and Albury. A business in any Australian city gets the same engineers, the same service and the same phone number.
We cut off the affected laptop or account straight away, then call you. From there we own it until it is fixed: cleaning up, restoring what was lost, and helping with any reporting you need to do. If you are not a client and you have an incident now, call 07 3114 2808.
Done properly, staff notice an extra sign-in check on new devices and very little else. Where a control does get in the way, we explain the trade-off and let you decide.
Talk to a senior engineer. We look at what you have today, tell you plainly what an attacker would try first, and what to fix first. Same service wherever you are in Australia.
Cookie Preferences
We use cookies to improve your experience, analyse site traffic, and personalise content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy
Privacy Act 1988 compliant. Your data is never sold.