// Cyber Security for Small Business, Sydney

Keep the little green men out of your network.

The internet's full of little green men with bad intentions. Firewalls, MFA, endpoint protection and real-time monitoring that tracks unauthorised access attempts, malware and ransomware, threats caught and killed before they hurt you.

No fear-mongering, no enterprise theatre, just the controls that actually stop attacks on businesses your size, with plain-English reporting so you know exactly where you stand.

  • 24/7 network and endpoint monitoring
  • Ransomware and malware protection (EDR)
  • Email security, spam filtering and phishing protection
  • Multi-factor authentication and access policies
  • Security reviews with plain-English risk reports

// Endpoint security

Endpoint security for Sydney business: EDR, not antivirus.

The antivirus that came with the laptop matches files against a list of known-bad ones. That was enough when an attack arrived as an obvious virus. Modern attacks mostly do not. They abuse tools that are already on the machine, so a plain file scanner never sees them. Endpoint detection and response (EDR) watches behaviour instead: what a process does, what it touches, and whether that pattern looks like an attack.

  • Every device, not most devices. Workstations, laptops and servers, including the ones that never come into the office. The device that is not covered is the one that gets used.
  • One console. Every device reports to one place, so a problem is visible rather than sitting on a machine nobody logs into. Coverage and visibility beat brand names.
  • Not quietly switched off. The usual failure is the agent disabled on the one machine that matters.
  • What happens on an alert. It lands in the same monitoring that watches everything else I run, and a suspected security incident jumps the queue ahead of routine work. What that means in hours is spelled out under managed security below.
  • What it costs. $11 per device per month for EDR on its own, or from $16.50 per user per month for security essentials, which is EDR, MFA and patching together.

You do not need the most expensive tier on the market. If someone is quoting SIEM, SOC, XDR and EDR to a six-person business and cannot explain in one plain sentence what each one stops, that is product they want to resell. The question to ask is what it stops, on your machines, and who reads the alert.

// Network security

Network security: firewalls, VLANs and remote access.

The router your internet provider sent was built to a price. It puts your accounts PC, your server, the EFTPOS terminal, the lunchroom TV and a visitor's laptop on one flat network where they can all see each other. If one of them picks up something nasty, nothing stands between it and the rest.

  • A firewall that gets patched. One business-grade router/firewall, supplied and hardened from $880, replacing the ISP box. It does internet failover, network separation, call priority and remote access in one device, with one place to look when something misbehaves.
  • VLANs that police the traffic between them. Office, servers, phones and guest, each on its own segment. Office PCs reach the server and the internet and nothing else. A staff laptop that picks up malware from an email cannot reach the EFTPOS gear and cannot crawl server shares it was never allowed to see. "The whole business is infected" becomes "one laptop needs rebuilding".
  • Guest WiFi separated from the tills. Visitors and staff phones get internet only, with no path to anything of yours. Hand out the password freely; the guest segment was designed on the assumption that everything on it is untrusted.
  • Remote access terminated on the router. Staff working from home connect through a VPN on the firewall itself, with proper credentials, and the same rules an office laptop gets. Not a remote-control app on the server, and not a port opened straight to a desktop. One thing to audit, one thing to switch off when someone leaves.
  • Site-to-site links. Site-to-site VPN from $440 per site for offices that share a server or a phone system. Managed network monitoring and support from $165 per month.

The full build, including the MikroTik or pfSense question, is written up in what a proper small-business router and firewall build looks like. Cabling, WiFi and switching live on the networking page.

// Managed security

Managed security: someone reads the alerts.

Monitoring is only worth what happens when it fires. Here is what the "24/7 monitoring, included with managed IT" line in the price table actually means, with the hours stated rather than implied.

  • What is watched. Endpoint alerts, missed patches, failing drives and full disks, and the errors that show up weeks before an outage does. Servers, network and workstations, around the clock.
  • What normal looks like. Put a server on the internet and the login attempts arrive within minutes: SSH password guessing, WordPress probes whether or not you run WordPress, credential stuffing against mail. It is untargeted background noise, not a campaign against you. A tool like fail2ban bans the repeat offenders, the noise collapses, and a real anomaly stands out. I published a real day of that traffic in a day in the life of a server under attack.
  • What gets escalated. Two things: failed logins using real staff names rather than generic ones, which suggests someone researched you, and any successful login nobody can account for. The second means assume compromise, change credentials from a machine you trust, and get help immediately.
  • Who responds, and when. Angus does, not a rotating pool. Alerts are actioned during support hours, Monday to Friday, 8:30am to 5:30pm, and a suspected security incident is picked up ahead of routine work. There is no 24/7 overnight desk on the Essentials plan. Emergency support outside business hours is available to customers on a managed plan.
  • What the report says. A plain summary of what broke, what was patched and what was blocked, so you can see you are getting what you pay for.

Managed security is part of the managed IT agreement, alongside helpdesk, patching and backup. On its own, the security stack is from $16.50 per user per month. SPF, DKIM and DMARC are set up as part of business email setup, because a domain without them is a domain anyone can send as. The records are explained in why business email lands in spam.

// Before the clean-up

Think something got in? Do not wipe it yet.

Call me before starting a clean-up. The things that make a device feel fresh can also erase the records needed to explain what happened. I can help work out what to preserve and what needs isolating before repair work begins.

  • Reinstalling the computer. A reinstall can overwrite files and remove system logs, installed software and settings. Those may help show what changed and when. Let me assess what needs keeping first.
  • Factory-resetting the phone. A reset removes local data, apps and settings that may help explain account or device activity. A cloud copy may not contain the same material. Ask me before resetting it.
  • Deleting the unknown account. Deleting an account can remove its local files, settings and useful history. Record what you noticed and let me assess how to restrict access while preserving the relevant material.
  • Binning the hardware. Throwing out a computer, drive or router puts its storage, configuration and remaining records beyond reach. Keep the hardware available until I have checked whether it matters.

See how a technical investigation runs.

// The review

The security review, and what the report looks like.

You cannot defend what you have not mapped, which is why the review comes first. From $1,650 you get a written report, in plain English, that says where you stand and what to fix in what order.

  • What it covers. Identity and MFA, patching on operating systems and applications, admin rights, endpoint protection, email authentication, backups and whether a restore has ever been tested, the firewall and what is exposed to the internet, and who at the business holds the domain, DNS and Microsoft 365 administrator logins.
  • How it maps to the Essential Eight. The eight controls the Australian Signals Directorate says stop most of what happens to Australian businesses: application control, patching applications, Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. If a tender, an insurer or the board is asking for it formally, the Essential Eight gap assessment is a fixed $2,750 ex GST and rates you control by control against Maturity Level One.
  • What the fix list looks like. Ordered by risk reduced per dollar, not alphabetically. The first three items usually matter more than the other twelve combined, and most of them are the free controls below.
  • The one-page summary. A page a board, an insurer or a tender assessor can read without a translator.
  • Who can act on it. Anyone. The report is written so any competent provider can execute it, including your current one. If you would rather we did not do the fixing, that is a legitimate outcome and the report is still yours.

// Start here

Start with the four free controls.

You do not need a six-figure security programme. Almost every attack on a small business is automated: nobody hand-picked you, a script found an open door. These four cost nothing and close the doors the scripts look for.

  • MFA, everywhere it is offered. Email first, then Microsoft 365 or Google Workspace, then accounting, then the bank. A stolen password is then a dead end. Use an authenticator app over text-message codes where you can, and use SMS anyway if that is all a service offers.
  • Automatic updates, left on. When a vendor ships a fix, the flaw becomes public and the scanners start hunting for machines that have not applied it. Let Windows restart overnight. Budget to replace anything a supported version will not install on.
  • Admin rights only where needed. Day-to-day accounts should not be administrators. Restricting administrative privileges is one of the Essential Eight for a reason: what lands on a standard account can do far less.
  • A backup ransomware cannot reach, that you have restored from. A drive left permanently plugged in gets encrypted alongside everything else. Keep a copy off-site or offline, and pull a few files back once a quarter to confirm they open. The detail is on the backup and disaster recovery page.

The full walk-through, in the order I would do it and with an honest word on cost, is cyber security for small business in Sydney: where to start. The people side, because most breaches start with a person, is covered by staff phishing-awareness training from $550 per session and by the guide to fake invoice and payment redirection scams.

// Indicative pricing

What it roughly costs.

Real numbers, because "contact us for pricing" is code for "brace yourself." These are honest ballparks, your fixed quote comes after a free consult.

Security essentials, EDR + MFA + patchingfrom $16.50per user / month
Endpoint protection (EDR) only$11per device / month
Email security & phishing protection$5.50per mailbox / month
24/7 monitoringincludedwith managed IT
Security review & written reportfrom $1,650one-off
Staff phishing-awareness trainingfrom $550per session

Indicative pricing ex GST at market rates +10%. Start with the review, you can't defend what you haven't mapped.

// Questions

Security, your questions answered.

How do I protect my small business from ransomware?

Layered controls that actually stop attacks on businesses your size: endpoint protection (EDR), multi-factor authentication, email and phishing filtering, and 24/7 monitoring. Security essentials start at $16.50/user/month.

How much does cyber security cost for a small business?

Security essentials (EDR, MFA and patching) start at $16.50/user/month, endpoint protection alone at $11/device, and email security at $5.50/mailbox. A full security review with a written report is from $1,650.

Do you offer staff cyber-security training?

Yes. Phishing-awareness training sessions from $550 help your team spot the scams that get past the filters, people are the most common way attackers get in.

What is endpoint security, and is it the same as antivirus?

No. Antivirus matches files against a list of known-bad ones. Endpoint detection and response (EDR) watches behaviour, so it catches attacks that abuse legitimate tools already on the machine and never drop an obvious virus. It covers every device, reports to one console, and alerts get read by a person. EDR is $11 per device per month, or from $16.50 per user per month with MFA and patching included.

Do you provide managed security for small business in Sydney?

Yes. Endpoint protection, multi-factor authentication and email filtering run as standard under a managed IT agreement, watched by someone who reads the alerts. Alerts are actioned during support hours, Monday to Friday 8:30am to 5:30pm, a suspected security incident jumps the queue, and emergency support outside business hours is available to customers on a managed plan. There is no 24/7 overnight desk on the Essentials plan, and we say so rather than imply otherwise.

What does a security review include?

A written, plain-English report from $1,650 covering identity and MFA, patching, admin rights, endpoint protection, email authentication, backups and whether a restore has ever been tested, the firewall and what is exposed to the internet, and who holds your domain and Microsoft 365 admin logins. The fix list is ordered by risk reduced per dollar, and the report is written so any competent provider can act on it, including your current one.

Do you help with Essential Eight compliance?

Yes. The Essential Eight gap assessment is a fixed $2,750 ex GST and gives you a control-by-control rating against Maturity Level One, a prioritised fix list, and a one-page summary a board, an insurer or a tender assessor can read. Uplift projects to Level One start at $4,950 ex GST for up to 20 staff. Details are on the Essential Eight compliance page.

Want the exact number for your business?

Tell me what you're working with and I'll come back with a fixed quote. No pressure, no jargon, no probing.

Beam us a message ๐Ÿ›ธ