Every serious breach we have seen in a small business had the same shape: one control was relied on, it failed, and nothing stood behind it. Our approach is built on the opposite principle. Several layers, so a single failure is contained rather than catastrophic.
Why small businesses are targeted
Attackers rarely pick targets by name. Automated tools scan the internet for any exposed system, leaked password or unpatched weakness, and exploit whatever they find. To that automation a twelve-person Geelong firm looks exactly like a large corporation, except with fewer defences. The Australian Cyber Security Centre reports a cybercrime every few minutes nationally, and small and medium businesses carry a disproportionate share of the damage because a single incident can be existential.
Layer one: keep threats out of the inbox
Email is the front door for the overwhelming majority of attacks. Our first layer is advanced email filtering that strips malicious attachments, blocks impersonation attempts and quarantines suspicious links before they ever reach a person. DNS and web filtering does the same job for browsing, stopping connections to known malicious sites regardless of how the link arrived.
Layer two: make stolen passwords useless
Passwords get stolen. It is not a matter of if. Multi-factor authentication means a stolen password alone achieves nothing, and conditional access adds a further check: a login from an unfamiliar country or an unmanaged device is challenged or blocked outright. Combined with single sign-on and a business password manager, this layer removes the single most common route to a compromised account.
Layer three: watch every device
When something does get through, endpoint detection and response is what catches it. Rather than matching known virus signatures, it watches for suspicious behaviour, such as a process starting to encrypt files, and isolates the device automatically. Every laptop, desktop and server is monitored around the clock, and mobile devices can be wiped remotely if they are lost.
Layer four: train the people
Technology cannot catch everything, so the team has to be part of the defence. Monthly phishing simulations, run with care rather than to catch people out, and short regular awareness sessions keep staff alert to current tactics. The goal is not to make everyone a security expert. It is to make pausing and verifying the normal reaction to an unexpected request.
Layer five: assume the worst and be ready
The final layer is the one that turns a disaster into an inconvenience. Immutable off-site backups that ransomware cannot alter, tested restores, and a documented recovery plan mean that even if every other layer fails, the business comes back. We have used this layer for real, and it is the reason those incidents are stories rather than closures.
Built to the Essential Eight
The Australian Cyber Security Centre’s Essential Eight gives every organisation a clear, practical benchmark, and our Diamond and Platinum tiers are built around it. We assess where you sit against each control, close the gaps under a managed plan and maintain the posture over time, because security that was set once and forgotten is not security at all.
None of this needs to be daunting. It is a set of sensible, proven layers, managed by a local team, at a monthly cost that is a fraction of what a single incident would cost. The businesses that fare best are simply the ones that put the layers in place before they needed them.
What this costs, honestly
Layered security sounds expensive, and for a large enterprise it can be. For a small business under a managed agreement it is not. The tooling is licensed per user at scale, the monitoring runs across our whole customer base, and the training is delivered in short sessions rather than expensive workshops. The monthly difference between basic support and an active security posture is typically less than the cost of a single staff lunch per person. Set against the average cost of a breach, which for an Australian small business runs well into the tens of thousands once downtime, recovery and reputational damage are counted, it is one of the clearest returns in the technology budget.
Where to start if you have nothing in place
If your business currently relies on a consumer antivirus and good intentions, do not try to fix everything at once. Turn on multi-factor authentication everywhere, today. Confirm you have a backup that is off-site and has been tested. Then book an assessment so the remaining layers can be added in order of impact rather than in a panic. That sequence alone closes the most common routes to harm, and it is exactly where our Essential Eight review begins.

