See your security the way an attacker would.
Your cyber security stack, drawn as a building you can walk through. Tap any floor to see what runs there, what it stops, and what happens if the layer below it fails. Start in the basement and climb to the roof. By the time you reach the top, you'll know where your business would hold up and where the gaps are.
What it does
What runs it
ACSC Essential Eight
The Essential Eight, mapped to the floors above.
Plenty of providers can recite the Essential Eight. Reciting them is not the same as running them. Here every control sits on a named floor, runs on a named tool, and has someone accountable for it. We track each one against the ACSC maturity levels, ML1 to ML3, so your posture is a measured thing, not a gut feeling.
Ask us for a maturity snapshot and we will walk you through the evidence, control by control. Then put the same question to your current provider, and see what comes back.
SMB1001 · certified through CyberCert
Five tiers. We climb them with you, like floors.
SMB1001 is the multi-tier cyber security standard written for small and medium business. Dynamic Standards International maintains it (the current version is SMB1001:2026, certifiable since January 2026), CyberCert issues the certification as its official certifier, and a cyber insurance partner network sits behind it. Certification renews each year against the current version, so the badge proves you meet it today, not just the day you first passed.
The security basics every business needs, with clear ownership inside the business.
- Endpoint protection & patching
- Firewall rules
- Backups with named ownership
Builds on Bronze with MFA, a password manager and email security. Our per-seat kit lands most of this on day one.
- MFA on every account
- Password manager rolled out
- Secure remote access
- Email security filtering
Managed security: formal policies, an asset register, staff training and tested restores.
- Formal security policies
- Digital asset register
- Staff security training
- Incident response plan
- Tested backup restores
- Privileged access reviews
Audit-ready: validated controls, tracked remediation and supplier risk on the record.
- Documented access reviews
- Validated controls with evidence
- Tracked remediation
- Supplier risk on the record
- Regular internal audits
- Quarterly compliance reporting
- Annual control validation
The top tier: mature governance, independent validation and a tested response to whatever comes.
- Mature governance
- Independent validation
- Continuous monitoring
- Tested incident response
- Ongoing improvement program
- Board-level reporting
- Annual recertification managed for you
- Dedicated security lead from our team
Why SMB1001 before ISO 27001? Because it was written for businesses your size: reachable tiers, annual recertification, and insurers who recognise it. ISO is there when a contract demands it; SMB1001 is where most businesses should actually start. We assess where you sit, certify at the tier you can defend today, then climb. The same stack above carries you from Bronze to Diamond without re-platforming.
A stack is not a logo wall
What people think cyber security is, and what actually runs here.
What people think it is
- A firewall
- Antivirus
- Passwords on sticky notes
One product, bought once, then forgotten about until the incident. In the 2024-25 Annual Cyber Threat Report, the ACSC puts the average self-reported cost of a single cybercrime report for an Australian small business at $56,600, up 14 per cent on the year before.
What actually runs here
Eleven disciplines, engineered as one building, reviewed as one contract. You cannot buy this off a shelf, because it is not a product. It is how the products are run.
How to judge any provider, us included
What good actually looks like
The only way to separate a real provider from a slide deck is to ask for evidence. Here are eight things to ask, and what a good answer sounds like.
Ask to see the DMARC record on your domain. If it reads p=none, your domain is still spoofable. Good looks like p=reject with reports going somewhere a human reads them.
Ask for the last three restore tests, dated. "We back up nightly" is not a restore. Good looks like a monthly log showing a file, a mailbox and a server were recovered and opened.
Ask which staff still sign in with a texted code. SMS gets sim-swapped. Good looks like passkeys or number matching on every admin account, with SMS reserved for the lowest-risk users.
Ask what happens when a user runs unapproved software. "We get an alert" means nothing was blocked. Good looks like unknown executables stopped at the point of running, with a short allow list for what you genuinely need.
Ask how long a new starter takes and how fast a leaver is cut off. Good looks like a starter working within hours and a leaver locked out, email and personal device included, before they reach the car park.
Ask for last month's patch report by device. Good looks like a list of which machines hit the deadline and which did not, with a follow-up date for the stragglers, not a blanket "we patch everything".
Ask who answers at 2am and whether they have your runbook. Good looks like a named on-call rota and a number that reaches an engineer, not a service desk queue that opens a ticket and calls back in the morning.
Ask for the asset register, then walk the floor and count. Good looks like every laptop, phone, server and IoT device listed by serial, owner and location, updated when things move or retire, not a spreadsheet touched last year.
Ask for all eight. A provider who can show you each one on the spot is worth keeping. One who can only tell you it is "covered" is worth questioning.

Remote Support