Antivirus is not enough. Your business needs MDR.
Modern attackers do not trip alarms. They log in with stolen credentials, use the tools already on your network, and reach ransom in under 24 hours. Traditional antivirus does not see any of it.
Managed detection and response is the core of our business cybersecurity model, and our cyber-first engineering approach. 24/7 SOC, human threat hunters, and rapid response across endpoints, Microsoft 365, identity and cloud. We do not just sell you a licence, we operate the security.
The 2026 picture
< 24 hrs
average time from initial access to ransomware deployment in 2025. Huntress 2026 Threat Report
83%
of email threats now carry credential-harvesting phishing. Acronis, H1 2025
$2M
average global ransom payment in 2025. Recovery costs are typically much higher. Acronis
EDR, MDR, XDR, SIEM. What do they actually mean?
Every cybersecurity vendor uses these acronyms differently. Here is what they actually are, in the order they build on each other, and where each one fits in a real Australian SMB environment.
AV
Traditional Antivirus
What it is
Signature-based software that compares files on a device against a list of known malware.
Catches
Known viruses and well-documented malware.
Misses
Anything new, fileless, identity-based, or that uses legitimate tools. About 70% of modern attacks.
Verdict: Necessary baseline, not sufficient on its own.
EDR
Endpoint Detection & Response
What it is
Software on every laptop, desktop and server that watches behaviour: what processes run, what files change, what network connections open.
Catches
Suspicious behaviour, ransomware patterns, fileless attacks, living-off-the-land techniques and zero-day exploits.
Misses
Without people watching the alerts, EDR is just a noisy dashboard. It still needs a human to interpret and respond.
Verdict: The technology layer. Required, but not a complete service.
MDR
Managed Detection & Response
What it is
EDR plus a 24/7 security operations centre (SOC) of human analysts who watch, triage, hunt and respond on your behalf.
Catches
Everything EDR catches, plus the slow-burn intrusions and quiet attacker behaviour that automated rules miss.
Misses
Visibility outside the endpoint, like email and identity, unless extended with XDR or ITDR.
Verdict: The full service. What an SMB actually needs.
XDR
Extended Detection & Response
What it is
MDR extended beyond endpoints to also cover email, Microsoft 365 identity, cloud workloads and network. Signals are correlated into one incident view.
Catches
Multi-stage attacks that cross from phishing email to identity to endpoint to cloud, which is how most modern breaches actually unfold.
Misses
Nothing significant when implemented properly. Adds cost and complexity if you do not have multiple surfaces to protect.
Verdict: The modern standard for any business on Microsoft 365 or with cloud infrastructure.
SIEM
Security Information & Event Management
What it is
A central log collection and correlation platform. Every security event from endpoints, firewalls, Microsoft 365 and cloud feeds into one place for analysis and retention.
Catches
Patterns across systems, compliance evidence, forensic timelines after an incident, and the audit trail your insurer and auditor want.
Misses
Traditional SIEM is heavy and needs tuning. Modern SMB-focused SIEM (like Huntress) hides that complexity.
Verdict: The evidence and correlation layer. Critical for Essential Eight and cyber insurance.
What you actually get with managed detection and response.
A licence is not a service. MDR is the combination of the right technology, a 24/7 human team, and a documented response process. Here is exactly what is included when Real Bytes runs your MDR.
Continuous monitoring
Every endpoint, every server, every Microsoft 365 mailbox and identity is watched in real time. No business hours gap, no weekend blind spot.
Human SOC analysts
Real people, not just dashboards. A dedicated security operations centre triages every alert and decides what is real before it lands on your desk.
Active response
When a confirmed threat appears, we contain it. Isolate the device, kill the session, revoke the token, lock the account. Stop the bleeding first, investigate after.
Proactive threat hunting
Analysts go looking for adversary behaviour that automated rules miss. Persistence mechanisms, credential harvesting, dormant beacons and supply chain abuse.
Incident response
If something gets through, we lead the response. Forensics, root cause analysis, eradication, recovery and communication with your insurer and regulators.
Reporting and evidence
Monthly security reports, quarterly business reviews, and audit-ready evidence for Essential Eight, SMB1001, ISO 27001 and your cyber insurance renewal.
And every month, we also
Translate the latest threat intelligence into your environment.
MDR is not a set-and-forget service. The attacker playbook shifts every quarter, so the detections, baselines, training and procedures shift with it.
Tune detections to the current playbook
ITDR rules and Microsoft 365 alert policies reviewed against the latest threat reports. AiTM, malicious OAuth and inbox rule abuse get priority.
Harden the identity baseline
Conditional Access, named admin accounts, token protection and phishing-resistant MFA. Configuration drift caught and corrected.
Train staff on lures that actually work
Security awareness training and simulated phishing focused on e-signature, voicemail and invoice lures, not generic content.
Document a payment verification process
Out-of-band verification for new bank details and dual approval thresholds. The procedural control that consistently breaks the BEC chain.
Why MDR beats running it yourself.
Running an in-house SOC is realistic for a bank or a federal agency. For a 20 to 200 person Australian business, the maths does not work. MDR delivers the same outcome at a fraction of the cost.
Dimension
DIY or EDR-only
Managed MDR
Coverage hours
Business hours, gaps overnight and on weekends
24 / 7 / 365 including public holidays
Detection capability
Whatever the EDR console surfaces, often missed in the noise
Triaged by analysts, correlated with threat intelligence
Response time
Hours to days, depending on staff availability
Minutes for containment, hours for full investigation
Cost of a real SOC
3 to 5 FTE analysts, around $500k to $900k per year fully loaded
From around $25 per endpoint per month
Skills and retention
Hard to hire, hard to retain, single-person dependency risk
Backed by a vendor SOC with hundreds of analysts
Threat intelligence
Generic feeds, manual research
Curated intelligence from millions of monitored endpoints globally
Ransomware reporting readiness
You find out about the 72-hour rule during the incident
Reporting obligations built into the incident response playbook
Cyber insurance answers
Difficult to evidence at renewal
Documented controls and 24/7 monitoring directly addresses insurer questions
Cost estimates based on Australian average salaries for security analysts (PayScale, Hays) and Real Bytes managed service pricing. Specific costs vary by environment.
Modern attacks follow a predictable pattern.
The 2026 ConnectWise Cyber Research Unit threat report, drawn from real incident response cases, says it plainly: cybercriminals are no longer breaking in. They are logging in, then exploiting normal business activity to avoid detection. Most successful intrusions follow these four steps.
Log in, not break in
Attackers buy or phish valid credentials. They arrive as a trusted user, not a hacker punching through a firewall.
Move with trusted tools
PowerShell, RMM, RDP and VPN. Living off the land means no signature for traditional antivirus to catch.
Disable your recovery
Backups, EDR agents and monitoring tools are targeted first so you cannot restore or detect the rest of the attack.
Steal data and encrypt
Data exfiltration first, then ransomware. Often within hours of the first login, well inside any business-hours response window.
Source: ConnectWise Cyber Research Unit, 2026 MSP Threat Report. Compiled from real-world incident response investigations and customer telemetry.
You have hours, not days
Ransomware is no longer a slow-burn intrusion. The Huntress 2026 Cyber Threat Report found average time to ransom dropped to under a day in 2025, with the fastest crews under 10 hours. That makes 24/7 monitoring and rapid containment the difference between a contained incident and a business-stopping event.
20 hrs
Average time to ransom in 2025 (up from 17 hrs in 2024)
< 10 hrs
Fastest crews (RansomHub, INC/Lynx, Akira) reach ransom
6 hrs
Average time from data exfiltration to encryption
51%
Of 2025 incidents linked to just 4 groups: Akira, RansomHub, Qilin, Medusa
Pre-ransom signals
Identity threats often show up first
Day -14
Suspicious identity activity often visible
Day -7
Shady logins typically spotted before ransomware deploys
Day -0
Day ransom note appears, encryption complete
Identity
Shady logins, OAuth abuse and AiTM token theft are the early warning we instrument with Huntress ITDR.
Endpoint
Living-off-the-land binaries, ProcessHacker, AnyDesk and abnormal admin tool use trigger SOC review.
Containment
Confirmed compromise gets the host isolated, the account session revoked and your incident playbook activated.
Sources: Huntress 2026 Cyber Threat Report, ACSC Annual Cyber Threat Report. Aligned to the ACSC Essential Eight and the OAIC Notifiable Data Breaches scheme for response obligations.
Cyber incidents are not IT problems. They are business crises.
Operational downtime, lost revenue, customer trust damage, regulatory exposure under the Privacy Act, and recovery costs that routinely exceed the original ransom. The financial maths is stark: prevention costs a fraction of recovery.
$56,600
average cost of a cybercrime incident for a small Australian business, up 14% year on year.
ASD Annual Cyber Threat Report 2024 to 2025
78%
of SMBs fear a serious cyberattack could put them out of business.
ConnectWise State of SMB Cybersecurity, 2025
58%
of SMBs spent more on cybersecurity in 2024 than planned, most of it reactive, not preventive.
ConnectWise SMB Cybersecurity Trends, 2025
$2M
surge in average ransom payment, with ransomware victims globally up 500%.
Acronis Cyberthreats Report H1 2025
What Australian law now expects when you are attacked
Global threat stats explain the attacker. These are the Australian obligations that apply to you, the defender, and they are built into how we run incident response.
The local cost of getting it wrong keeps rising
The ASD puts the average cybercrime cost at $56,600 per incident for small businesses (up 14%) and $97,200 for medium businesses (up 55%), against more than 84,700 cybercrime reports in a single year. Roughly one every six minutes.
Source: ASD Annual Cyber Threat Report 2024 to 2025
Ransomware payments must be reported within 72 hours
Under the Cyber Security Act 2024, businesses with annual turnover above $3 million must report any ransomware or extortion payment to the government within 72 hours. The education-only grace period ended on 1 January 2026 and enforcement is active. Our incident response playbooks include this clock from minute one.
Data breaches likely mean the OAIC
A breach exposing personal information that risks serious harm triggers the Notifiable Data Breaches scheme. In the OAIC's latest reporting period there were 532 notifications, with human error's share rising from 29% to 37%. Containment speed directly shapes whether an incident crosses the notification threshold.
The Essential Eight is the benchmark everyone measures against
Insurers, auditors, tenders and now the AI standards all reference ACSC controls. Every MDR deployment we run maps to Essential Eight evidence, so monitoring pays off at renewal and audit time, not just during incidents.
Even your office hardware is regulated now
Since 4 March 2026, smart devices supplied in Australia must meet mandatory security standards for default passwords and update policies. Connected cameras, sensors and door controllers are part of your attack surface and we include them in scope.
General practitioner summary, not legal advice. Sector obligations (SOCI Act, APRA CPS 234 and CPS 230) may add further requirements. Confirm scope with your legal counsel before rollout.
The numbers behind why MDR exists
The Verizon 2026 DBIR makes the case for managed detection in three figures: vulnerability exploitation is now the top way in, edge-device CVEs reach mass exploitation in zero days, and the human element is still involved in most breaches. None of these are caught by antivirus alone. They are exactly what a 24/7 SOC is built to see and stop.
Read the Verizon 2026 DBIRTop vector
Vulnerability exploitation now the leading initial access vector for breaches
Overtook stolen credentials in 2026. The patch backlog has become the front door.
0 days
0 days median time from edge-device CVE disclosure to mass exploitation
Firewalls, VPN gateways and remote-access appliances are now hit at internet speed.
62%
62% of breaches still involved a human element across all sectors
Identity, awareness and process discipline remain the controllable variables.
16%
16% of breaches started with social engineering, with voice and mobile pretexting on the rise
Voice phishing inside the workday is now common enough to warrant its own playbook.
Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.
Software alone is not security.
EDR, email security, identity protection and vulnerability scanners are capable, but they do not make decisions. Strong cybersecurity needs both: capable tools and an active security operation that triages alerts, hunts for threats, and runs the response when it matters.
Security tools
EDR, email security, vulnerability scanning, identity protection
Strengths
- Catches known threats on devices in real time
- Automates blocking before damage can spread
- Builds an activity trail for later investigation
Limits on their own
- Cannot connect endpoint activity to identity, email or cloud
- Automated responses can disrupt legitimate work if untuned
- Tools alone do not triage, hunt, or remediate
Security operations
24/7 SOC, threat hunting, MDR, incident response
Strengths
- Triages and prioritises alerts so nothing critical gets missed
- Continuously tunes detection rules to reduce noise
- Investigates and responds to threats tools flag but cannot resolve
Limits on their own
- Only as effective as the tools and integrations feeding it
- Building and staffing an internal SOC is expensive and slow
- Without clear playbooks, response can stall under pressure
Real Bytes runs the operation around the tools. Huntress, CrowdStrike, SentinelOne, Microsoft Defender and ThreatLocker do the detection. Our team and the Huntress SOC handle triage, hunting, response and reporting, so a tool alert turns into a contained incident, not a missed one.
Identity is the new endpoint
Most attacks now start with stolen credentials and session tokens, not malware on a laptop. Real Bytes deploys Huntress Managed ITDR across Microsoft 365 and Google Workspace to spot identity attacks the moment they happen, then shut them down before money or data leaves.
Location & VPN anomalies
Flag unusual login locations, impossible travel and known malicious VPN providers so only the right people get in.
Malicious inbox & forwarding rules
Detect rules that hide attacker emails, auto-forward invoices or quietly delete payment notifications, the classic BEC moves.
Session hijacking
Catch stolen session tokens being replayed from a different device or country, the way attackers bypass MFA in 2025.
Credential theft
Monitor for credential-stealing malware, AiTM phishing kits and password spray patterns against Microsoft 365 and Google Workspace.
Rogue OAuth apps
Find and remove unauthorised OAuth applications and shadow workflows installed by attackers to keep persistent access.
Mass outbound phishing
Stop compromised mailboxes being used to phish your customers and contacts, and clean up the resulting mess fast.
Huntress reports the following from their Managed ITDR platform across more than 10 million identities they protect globally. Numbers are vendor-published, not Real Bytes claims. Source: Huntress Managed ITDR datasheet and the 2026 Cyber Threat Report.
10M+
Identities monitored by Huntress globally
37%
Of 2025 ITDR incidents were suspicious logins
19%
Of 2025 incidents involved mailbox manipulation
67%
Increase in identity threats vs 3 years ago (Huntress)
The first 60 minutes of a cyber incident
What to do the moment you suspect a compromise. Print this, put it where people can find it when screens are locked.
Print-friendly timeline
Minute 0 to 10
Do not destroy evidence, do cut access
Disconnect affected machines from the network (pull the cable, kill the wi-fi). Do not wipe, reboot or "clean" anything. Forensics needs it intact. Do not pay anything, promise anything or reply to any demand.
Minute 10 to 20
Call for help, off the compromised systems
Call your MDR provider or IT partner by phone. If email or Teams might be compromised, assume the attacker is reading them. Real Bytes clients: 07 3114 2808, any hour.
Minute 20 to 40
Contain the identity layer
Reset passwords and revoke active sessions for affected accounts, starting with admin accounts. Check for new inbox rules, forwarding rules and unfamiliar OAuth apps. Freeze any payments queued for release, and verify no bank details were changed recently.
Minute 40 to 60
Start the record
Write down what was seen, when, by whom, on which systems. Note the exact time of first detection. The regulatory clocks (72 hours for any ransom payment, 30 days for OAIC breach assessment) run from what you knew and when. Notify your insurer's cyber hotline, as late notification can affect coverage.
Then: Hand over to the professionals. A proper response covers forensics, eradication, recovery, and your regulator and insurer communications. That is what an incident retainer or MDR agreement exists for.
Business cybersecurity built on proven platforms, matched to your environment.
We are vendor-neutral. Good business cybersecurity starts with the right platform for your environment, not the one with the biggest margin. The right MDR or EDR platform depends on your environment, headcount, compliance obligations, and budget. Every platform below is one we actively deploy and manage in Australian businesses.
MDR · ITDR · SIEM
Huntress MDR
Primary PlatformOur primary MDR platform. Combines automated threat hunting with a 24/7 human SOC that reviews every alert. Used by 100,000+ SMBs globally. Includes ITDR, SIEM and security awareness training in one platform.
EDR · XDR
CrowdStrike Falcon
Enterprise TierEnterprise-grade EDR and XDR for larger organisations and regulated industries. AI-powered detection, adversary intelligence and a cloud-native architecture at scale.
EDR · XDR
SentinelOne Singularity
Autonomous AIAutonomous AI-driven EDR with patented rollback that can reverse damage from ransomware without relying on backups. Strong fit for high-availability environments.
XDR · Email · Identity
Microsoft Defender XDR
M365 IntegratedFor Microsoft 365 environments, Defender XDR unifies email, endpoint, identity and cloud app protection into a single correlated detection platform. Included with M365 Business Premium and managed by Real Bytes.
EDR · MDR
Sophos Intercept X
Deep LearningDeep learning endpoint protection with anti-ransomware and exploit prevention. Sophos MDR adds a fully managed option backed by their own threat response team. Strong fit for mid-market and healthcare.
Zero Trust · Allowlisting
ThreatLocker
Zero Trust LayerDefault-deny application control that stops unauthorised software from executing at all. Neutralises ransomware and malware at the point of execution, before detection even needs to occur.
The questions we get asked the most.
Cyber security: a one-page brief for Australian directors
Forward this to your board. Print it, attach it to a board paper, or use it to frame the conversation at your next risk committee meeting.
Printable one-pager
The situation
The ASD received over 84,700 cybercrime reports last year. Average incident cost: $56,600 for a small business, $97,200 for a medium one, both rising. Attackers now reach ransomware deployment in around 20 hours from first access, and they increasingly log in with stolen credentials rather than breaking in. In 2026 the victims have included an accounting firm, a home builder and a food processor, not just airlines and universities.
Why this is a board matter
Directors carry the risk on three fronts. Legal: ransom payments must be reported within 72 hours (enforced since January 2026), and breaches of personal information engage the OAIC. Financial: recovery costs routinely exceed any ransom, and insurers now decline claims where basic controls were missing. Operational: manufacturers and processors have been stopped mid-production this year. This is a continuity risk, not an IT line item.
The questions to ask management
- 1.If an attacker logged in with a stolen password at 2am Saturday, who would notice, and when?
- 2.Are our backups immutable, off-tenant, and when did we last actually restore from them?
- 3.Is MFA enforced on every mailbox and remote access point, with no exceptions for executives?
- 4.Do we have an incident plan that covers the 72-hour ransomware reporting clock and OAIC notification?
- 5.What would our cyber insurer say about our controls at next renewal?
What good looks like
Essential Eight Maturity Level 1 or better, evidenced. 24/7 monitored detection and response across endpoints and identity. Immutable, tested backups. A one-page incident plan people have rehearsed. Evidence for all of it, ready for insurer and auditor.
The ask
A 30-minute security assessment maps current exposure and produces a prioritised remediation order. It is free, and the findings are yours either way.
Real Bytes · Brisbane · realbytes.au · 07 3114 2808. General practitioner summary, not legal advice.
Specialist work that sits alongside Managed Detection & Response
Essential Eight Compliance
ACSC Essential Eight uplift, evidence collection, and maturity-level reporting for cyber insurance, tenders, and board reporting.
SMB1001 CyberCert
The Australian SMB cyber certification we recommend most often. Bronze through Platinum. Real Bytes runs the implementation and the audit prep.
Penetration Testing
External, internal, web application, and Microsoft 365 penetration tests delivered against ACSC and OWASP methodologies. Findings paired with remediation, not just a report.
Virtual CISO (vCISO)
Fractional CISO capability for organisations that need security leadership but cannot justify a full-time hire. Board reporting, risk register, vendor reviews, and incident response oversight.
Email Security & Anti-Phishing
DMARC, DKIM, SPF, Microsoft Defender for Office 365, Sendmarc partnership, and phishing simulation for the most common attack surface.
Managed Password Management
Keeper Security business password management, breach monitoring, and shared vault governance. Often the first lift after SMB1001 Bronze.
Free downloads
Anatomy of a Cyberattack
How modern attacks unfold across five stages, and where EDR, MDR and a human SOC intercept each one.
2-page visual guide · Real Bytes
Standard EDR vs Managed EDR
One-page comparison. What standard EDR detects, what Managed EDR stops, and the 15-minute response SLA difference.
2-page one-pager · Real Bytes
Remote Work Cybersecurity Checklist
15-item checklist for staff working remotely. Device, Wi-Fi, passwords, MFA, phishing and approved apps.
1-page printable checklist · Real Bytes
Stop ransomware before it starts.
Attackers are already inside networks like yours, moving quietly and escalating privileges. A free 30-minute security assessment maps your real exposure, recommends a best-fit MDR platform, and gives you a clear remediation order. No obligation.
Brisbane based. Australian engineers. No obligation. Also delivering managed IT services Hobart and across Tasmania.

Remote Support