The attack arrives by email
Not a breach of your firewall — a convincing message to someone in accounts about a changed bank account, or a login page that looks exactly like the real one. The technology is rarely what fails first.
Cyber Security
Layered cyber security for Sydney businesses — protecting your accounts, devices and data, aligned to the ACSC Essential Eight, with the evidence behind it if an insurer or auditor asks.
The Problem
Very few of the incidents we deal with involve anything sophisticated. Almost all of them involve one of these three things.
Not a breach of your firewall — a convincing message to someone in accounts about a changed bank account, or a login page that looks exactly like the real one. The technology is rarely what fails first.
Antivirus is installed and that is where it ends. If an account were being accessed from overseas at 3am, there is no realistic mechanism by which anyone would notice.
The insurance renewal or client questionnaire asks how access is controlled and how quickly you would detect a breach. The honest answer involves a certain amount of guessing.
Our Solution
Good security assumes something will get through. The aim is not one impenetrable barrier but several independent layers, so that a person clicking a link does not become an incident, and an incident does not become a business-stopping event.
We work to the ACSC Essential Eight, which gives Australian businesses a recognised reference point rather than a vendor's opinion. It also gives you something concrete to show an insurer or a client instead of a general assurance that security is taken seriously.
Just as importantly, we plan for the day something does happen. Knowing who to call, what gets isolated and how you keep operating is the part most businesses have never thought through.
Get a Free IT Health CheckWhat's Included
Delivered as an ongoing programme rather than a one-off hardening exercise, because the threat does not hold still.
Detection and response on every laptop, desktop and server — watching for suspicious behaviour rather than only matching a list of known threats.
Filtering that catches impersonation and credential-harvesting attempts before they reach an inbox, since email remains where most of this starts.
Multi-factor authentication and access rules so a stolen password on its own is not enough to get into anything that matters.
Alerting on the activity that indicates a problem — impossible travel, unusual sign-ins, mass file changes — so it is investigated while it is still small.
Short, practical sessions and simulated phishing that teach people what to look for, without making anyone feel foolish for having been caught out.
Your controls mapped against the ACSC framework, with a documented view of where you sit and what would move you forward.
How We Deliver
We start by finding out where you genuinely stand, not by selling you a product.
We document what you actually have — devices, licences, access, and where the risks sit. Nothing is proposed before this is done.
We agree what changes, in what order, and when. Anything that will interrupt your team is scheduled around your working week.
Work is done in stages so your business keeps operating. You know what is happening on any given day before it happens.
Configurations, credentials and procedures are written down and kept current — so support does not depend on one person's memory, including ours.
Systems are watched continuously rather than checked when something is reported. Most issues are picked up before anyone raises them.
We review what is working at agreed intervals and adjust. Technology that suited you last year may not suit you at twice the headcount.
Business Outcomes
Security rarely announces itself. These are the changes you would actually be able to point to.
Credentials get compromised — that is normal. With authentication and access rules in place, that event stops being the start of an incident.
Unusual activity is surfaced and investigated rather than sitting unnoticed in a log nobody reads until after the fact.
When people are trained without being blamed, they report the suspicious email — and early reporting is worth more than most technical controls.
Insurance renewals, client security reviews and tender responses can be answered from documentation that already exists.
If something does get through, there is an agreed plan — who is called, what is isolated, how the business keeps operating — rather than improvisation on a bad morning.
If the worst happens, you can demonstrate the controls you had in place and the reasoning behind them. That matters commercially and legally.
Who It Is For
Participant, patient, client or financial information where a breach would be a notifiable event rather than an inconvenience.
Cyber insurance renewals, enterprise clients and government tenders increasingly ask specific questions. Vague answers now cost real work.
A fraudulent invoice, a compromised mailbox or a staff member who clicked something. The scare is usually what turns security from a someday item into a this-month one.
Typical Engagements
Situations we are called into most often. One of these will probably sound familiar.
The questionnaire is more demanding than last year, and answering it honestly has revealed gaps nobody had looked at.
A mailbox was compromised or an invoice was redirected. The immediate job is containment; the real work is making sure it cannot happen the same way twice.
A larger customer has sent a supplier assessment, and continuing to work with them depends on the answers.
A contract requires demonstrable security controls, and the response needs evidence rather than intent.
A quality or sector audit will examine how information is protected, and the technical side of the answer needs to exist first.
Headcount rose quickly, access was granted as needed, and nobody has since asked who can still reach what.
Optional
None of these are required. They are here because clients regularly ask whether we can cover them.
A documented review of where you currently sit against each of the eight strategies, and what moving up a level would realistically involve.
Ongoing safe tests that show which messages people fall for, used to guide training rather than to catch anyone out.
A written plan covering who is contacted, what is isolated, notification obligations and how the business continues operating during a response.
The evidence pack auditors, insurers and enterprise clients typically request, maintained between reviews rather than assembled under pressure.
Technology
Platforms we work with day to day. If something you rely on is not listed, ask — this is not an exhaustive list.
These are platforms we work with day to day. Product names are trademarks of their respective owners and their inclusion here does not indicate a partnership, affiliation or endorsement.
Industries
Participant records, rostering and claiming systems kept secure, available and ready for audit scrutiny.
Clinical systems, practice software and patient data handled with the privacy obligations of the sector built in.
Matter files, client confidentiality and retention obligations supported by controlled access and tested backups.
Works With
These are the services clients most often run alongside this one, and why.
Backups that are monitored and test-restored, because one nobody has tested is only an assumption.
Email, Teams, SharePoint and OneDrive set up with sensible permissions and data that stays protected.
We take ownership of your technology day to day, so problems get dealt with before they reach your team.
Independent advice on what to invest in, what to retire and what can wait another year.
FAQ
Most attacks are not targeted at all. They are automated and opportunistic — scanning for exposed accounts and unpatched systems regardless of who owns them. Being small removes you from nobody's list; it usually just means fewer defences when something arrives.
No, and you should treat any provider who says otherwise with caution. What layered security does is reduce how often something gets through, limit the damage when it does, and make recovery a planned process rather than a crisis. Anyone promising immunity is selling something.
It is a set of eight mitigation strategies published by the Australian Cyber Security Centre — things like patching, application control, multi-factor authentication and backups. It is a practical baseline rather than a certification, and it gives Australian businesses a common reference point when discussing security.
Some of it adds a step — multi-factor authentication is the obvious one. Configured sensibly it is a prompt on a phone rather than a daily obstacle. Where a control would genuinely impede how people work, we will say so and look at the alternatives rather than imposing it and hoping.
Antivirus addresses one layer, and it works by recognising things already known to be malicious. It does not cover a stolen password, a convincing fraudulent email, or an account being accessed from another country at 3am. Those are the situations we see most.
You get visibility of what is being blocked and what has been investigated, and the documentation is kept current so it is there when a questionnaire or audit arrives. Security work is easy to sell invisibly, so we would rather you could see it.
We will review your current position — how accounts are protected, what is being monitored, and where the realistic gaps sit — as part of the free consultation. The findings come to you in writing, with no obligation attached.