Sydney · Bella Vista · Western Sydney

Cybersecurity for Sydney Small Businesses

Most small-business breaches do not involve anything exotic. They involve an account with more access than it needed and a password nobody had changed.

What you get

What you are actually deciding

Before the quote. None of this is about us.

Multi-factor authentication on anything that can install software

It is the single highest-value control available to a small business and it is free with most business licences. The scope that matters is not just email: it is every account that can install software, change permissions or reach a payment system. The Australian Signals Directorate puts it in the Essential Eight for the same reason.

Your exposure is a response time, not a checklist

The useful number is not whether you are patched today. It is how many hours pass between a vulnerability being disclosed and it being closed on your systems. Most small businesses have never measured it, and the honest answer is usually whenever somebody next logs in.

A backup nobody has restored is an assumption

Almost every business has backups and far fewer have opened one. A successful backup notification tells you a job ran, not that the file it produced can be restored. One deliberate restore to a test environment, timed, converts an assumption into a fact.

Why us, specifically

Every claim below is something we did to our own systems and can show you.

1080° adversarial audit — 59 findings

Run against our own social-media-autopost plugin, then remediated in tracked batches. The findings and the fixes are both in the commit history.

Six IDORs, MFA takeover, brute-force and DoS guards fixed in one push

On our own CardGamePro codebase. We audit our own software adversarially before we advise anyone else on theirs.

A worked example

A 1080° adversarial audit of our own software found 59 issues

Before advising anyone else on their security posture, we ran an adversarial audit against our own shipped software — and then fixed what it found, in tracked batches.

  • 59 findings in one audit
  • 6 idors closed in one push
  • MFA takeover, brute-force, DoS also fixed
  • 4 remediation batches shipped

Questions we get asked

What is the single most valuable security change for a small business?
Multi-factor authentication. It is the highest value per minute of anything on a small-business security list, and it is usually free with software you already pay for.
Do we need to meet the Essential Eight?
Only some organisations are formally required to. Most SMBs use it as a sensible order of operations rather than a compliance obligation — it is a good list even when nobody is auditing you.
Is a backup enough?
A backup limits what a bad day costs. It does not stop the bad day, and a backup nobody has restored is an untested assumption. Restore one, once a year, and time it.

Talk to someone who will answer

We are in Bella Vista. Tell us what is not working and we will tell you whether we are the right people to fix it.

Get a Quote