Geeks360 — Managed IT Services

Cyber Security

Security that holds up when somebody asks you to prove it

Layered cyber security for Sydney businesses — protecting your accounts, devices and data, aligned to the ACSC Essential Eight, with the evidence behind it if an insurer or auditor asks.

The Problem

The risk most businesses actually carry

Very few of the incidents we deal with involve anything sophisticated. Almost all of them involve one of these three things.

The attack arrives by email

Not a breach of your firewall — a convincing message to someone in accounts about a changed bank account, or a login page that looks exactly like the real one. The technology is rarely what fails first.

Nobody is watching between incidents

Antivirus is installed and that is where it ends. If an account were being accessed from overseas at 3am, there is no realistic mechanism by which anyone would notice.

You cannot evidence any of it

The insurance renewal or client questionnaire asks how access is controlled and how quickly you would detect a breach. The honest answer involves a certain amount of guessing.

Our Solution

Layers, because any single control will eventually fail

Good security assumes something will get through. The aim is not one impenetrable barrier but several independent layers, so that a person clicking a link does not become an incident, and an incident does not become a business-stopping event.

We work to the ACSC Essential Eight, which gives Australian businesses a recognised reference point rather than a vendor's opinion. It also gives you something concrete to show an insurer or a client instead of a general assurance that security is taken seriously.

Just as importantly, we plan for the day something does happen. Knowing who to call, what gets isolated and how you keep operating is the part most businesses have never thought through.

Get a Free IT Health Check

The layers we put in place

  • Multi-factor authentication across every account that supports it
  • Endpoint detection that identifies behaviour, not just known viruses
  • Email filtering for phishing, impersonation and malicious attachments
  • Conditional access rules based on location, device and risk
  • Patching, because unpatched software is the most exploited weakness there is
  • Staff awareness training in plain language, repeated rather than one-off
  • Monitoring and alerting so unusual activity is seen while it matters
  • An incident response plan agreed before you need it

What's Included

What cyber security covers

Delivered as an ongoing programme rather than a one-off hardening exercise, because the threat does not hold still.

Endpoint protection

Detection and response on every laptop, desktop and server — watching for suspicious behaviour rather than only matching a list of known threats.

Email and phishing defence

Filtering that catches impersonation and credential-harvesting attempts before they reach an inbox, since email remains where most of this starts.

Identity and access control

Multi-factor authentication and access rules so a stolen password on its own is not enough to get into anything that matters.

Proactive monitoring

Alerting on the activity that indicates a problem — impossible travel, unusual sign-ins, mass file changes — so it is investigated while it is still small.

Staff awareness training

Short, practical sessions and simulated phishing that teach people what to look for, without making anyone feel foolish for having been caught out.

Essential Eight alignment

Your controls mapped against the ACSC framework, with a documented view of where you sit and what would move you forward.

How We Deliver

How a security engagement runs

We start by finding out where you genuinely stand, not by selling you a product.

  1. Assessment

    We document what you actually have — devices, licences, access, and where the risks sit. Nothing is proposed before this is done.

  2. Planning

    We agree what changes, in what order, and when. Anything that will interrupt your team is scheduled around your working week.

  3. Implementation

    Work is done in stages so your business keeps operating. You know what is happening on any given day before it happens.

  4. Documentation

    Configurations, credentials and procedures are written down and kept current — so support does not depend on one person's memory, including ours.

  5. Monitoring

    Systems are watched continuously rather than checked when something is reported. Most issues are picked up before anyone raises them.

  6. Ongoing Improvement

    We review what is working at agreed intervals and adjust. Technology that suited you last year may not suit you at twice the headcount.

Business Outcomes

What improves

Security rarely announces itself. These are the changes you would actually be able to point to.

01

A stolen password is not enough

Credentials get compromised — that is normal. With authentication and access rules in place, that event stops being the start of an incident.

02

Someone is actually watching

Unusual activity is surfaced and investigated rather than sitting unnoticed in a log nobody reads until after the fact.

03

Staff raise things instead of hiding them

When people are trained without being blamed, they report the suspicious email — and early reporting is worth more than most technical controls.

04

Questionnaires stop being a scramble

Insurance renewals, client security reviews and tender responses can be answered from documentation that already exists.

05

You know what happens next

If something does get through, there is an agreed plan — who is called, what is isolated, how the business keeps operating — rather than improvisation on a bad morning.

06

A defensible position

If the worst happens, you can demonstrate the controls you had in place and the reasoning behind them. That matters commercially and legally.

Who It Is For

Who needs this most

Businesses holding sensitive records

Participant, patient, client or financial information where a breach would be a notifiable event rather than an inconvenience.

Anyone facing a security questionnaire

Cyber insurance renewals, enterprise clients and government tenders increasingly ask specific questions. Vague answers now cost real work.

Businesses that have had a near miss

A fraudulent invoice, a compromised mailbox or a staff member who clicked something. The scare is usually what turns security from a someday item into a this-month one.

Typical Engagements

What usually prompts the call

Situations we are called into most often. One of these will probably sound familiar.

A cyber insurance renewal

The questionnaire is more demanding than last year, and answering it honestly has revealed gaps nobody had looked at.

Recovering from an incident

A mailbox was compromised or an invoice was redirected. The immediate job is containment; the real work is making sure it cannot happen the same way twice.

A client security review

A larger customer has sent a supplier assessment, and continuing to work with them depends on the answers.

Tender or funding requirements

A contract requires demonstrable security controls, and the response needs evidence rather than intent.

An audit or accreditation ahead

A quality or sector audit will examine how information is protected, and the technical side of the answer needs to exist first.

Growth that outpaced the controls

Headcount rose quickly, access was granted as needed, and nobody has since asked who can still reach what.

Optional

Available alongside

None of these are required. They are here because clients regularly ask whether we can cover them.

  • Essential Eight maturity assessment

    A documented review of where you currently sit against each of the eight strategies, and what moving up a level would realistically involve.

  • Simulated phishing programme

    Ongoing safe tests that show which messages people fall for, used to guide training rather than to catch anyone out.

  • Incident response planning

    A written plan covering who is contacted, what is isolated, notification obligations and how the business continues operating during a response.

  • Security documentation for audit

    The evidence pack auditors, insurers and enterprise clients typically request, maintained between reviews rather than assembled under pressure.

Technology

Technology we commonly support

Platforms we work with day to day. If something you rely on is not listed, ask — this is not an exhaustive list.

  • Microsoft 365
  • Windows
  • macOS
  • Microsoft Azure
  • Microsoft Teams
  • SharePoint
  • OneDrive
  • Hyper-V
  • UniFi
  • Synology

These are platforms we work with day to day. Product names are trademarks of their respective owners and their inclusion here does not indicate a partnership, affiliation or endorsement.

FAQ

Questions about cyber security

Most attacks are not targeted at all. They are automated and opportunistic — scanning for exposed accounts and unpatched systems regardless of who owns them. Being small removes you from nobody's list; it usually just means fewer defences when something arrives.

No, and you should treat any provider who says otherwise with caution. What layered security does is reduce how often something gets through, limit the damage when it does, and make recovery a planned process rather than a crisis. Anyone promising immunity is selling something.

It is a set of eight mitigation strategies published by the Australian Cyber Security Centre — things like patching, application control, multi-factor authentication and backups. It is a practical baseline rather than a certification, and it gives Australian businesses a common reference point when discussing security.

Some of it adds a step — multi-factor authentication is the obvious one. Configured sensibly it is a prompt on a phone rather than a daily obstacle. Where a control would genuinely impede how people work, we will say so and look at the alternatives rather than imposing it and hoping.

Antivirus addresses one layer, and it works by recognising things already known to be malicious. It does not cover a stolen password, a convincing fraudulent email, or an account being accessed from another country at 3am. Those are the situations we see most.

You get visibility of what is being blocked and what has been investigated, and the documentation is kept current so it is there when a questionnaire or audit arrives. Security work is easy to sell invisibly, so we would rather you could see it.

Find out where you actually stand

We will review your current position — how accounts are protected, what is being monitored, and where the realistic gaps sit — as part of the free consultation. The findings come to you in writing, with no obligation attached.

0468 927 427 Free IT Health Check