Security
The scammers got AI. Most small businesses didn't get the memo.
Fake invoices that look real. Phone calls that sound like your supplier. Emails written specifically for your staff. AI has made attacks on small businesses cheap and convincing — and the old "we're too small to be a target" defence is dead. Small businesses are now the easiest target precisely because nobody's watching.
Aligned with the ACSC Essential Eight · Independence disclosure →
What this means
You don't need to understand the technology. You need answers to three questions:
If you can't answer all three confidently, that's what we fix.
1. If someone tricked one of your staff today, what could they get to?
Your bank details? Client records? The ability to send emails as you?
2. If your systems went down tomorrow, how long until you're trading again?
Hours? Days? Do you actually know, or are you hoping?
3. Would you even know if someone was already inside?
Most breaches at small businesses are discovered months later — usually by accident.
What I do
Find the risk. Fix what matters. Keep it that way.
Security Health Check
I review how your business actually works — email, payments, staff logins, customer data — and show you where you're exposed. You get a one-page summary a non-technical owner can read, plus a prioritised fix-it list. No scare tactics, no padding.
Fix What Matters
Most businesses don't need to spend big. They need the right five things done properly: locking down logins, protecting email, backing up what matters, limiting who can access what, and making sure staff can spot a con. I set these up or work with your existing IT provider to get them done.
Keep It That Way
Security isn't a one-off project. For businesses that want it, I offer a periodic check-in — a few hours a quarter to review what's changed, catch new risks, and keep your protections current as your business grows.
For the technically inclined: my work aligns with the Australian Cyber Security Centre's Essential Eight — the Australian government's own baseline for protecting organisations. If an insurer, client, or tender ever asks about your security posture, you'll have a real answer.
Sample engagements
Sample engagements
Security Health Check
One-page executive summary + prioritised fix list.
From $1,500 + GST
1 week · fixed price
Essential Eight Uplift (Maturity Level 1)
Lock down MFA, patching, backups, admin privileges, macros.
From $4,500 + GST
3–4 weeks · fixed price
Cyber Insurance / Client Questionnaire Support
Straight answers to the questions you've been dodging.
From $600 + GST
2–3 days · fixed price
Quarterly Security Check-in
What's changed, what's new, what to do about it.
From $400 + GST per quarter
Quarterly · fixed price
The outcome
What you walk away with
A clear picture of your risk, in plain English. A prioritised action list with rough costs. The confidence to answer "are we secure?" without guessing. And if you ever face a cyber insurance form or a client security questionnaire — the answers ready to go.
Book a free security chat