Multi-factor authentication
Stops stolen passwords from being enough to access your email, cloud apps and remote systems — the single biggest cause of SMB breaches.
Servicing businesses all over Australia.
SMB 1001 is the Australian cyber security standard built specifically for small and medium businesses. We get you certification-ready across the Bronze, Silver, Gold, Platinum and Diamond tiers.
Why it matters
Large frameworks can be overwhelming for a 10 or 50 person business. SMB 1001 offers tiered, practical controls that grow with you — and increasingly it is what insurers, larger customers and tender panels want to see before they sign.

Controls
SMB 1001 is built around practical controls that every small business can understand. Here is what we assess, implement and maintain.
Stops stolen passwords from being enough to access your email, cloud apps and remote systems — the single biggest cause of SMB breaches.
Closes the known vulnerabilities attackers scan for every day, from operating systems to browsers and third-party apps.
Makes ransomware and hardware failures recoverable instead of catastrophic. We test restores so you know they work.
Ensures staff only reach the data and systems they need, and that access is removed when roles change.
Detects and blocks malware on laptops, servers and mobile devices before it spreads across your network.
Filters phishing, malware and malicious links before your staff see them, because most attacks still arrive by email.
Turns your team into a defensive layer. Even the best tools fail when someone clicks the wrong link.
Gives you a clear plan to contain, investigate and recover from an attack instead of making it up under pressure.
Lets you spot suspicious activity early and provides the evidence insurers and auditors expect after an incident.
The tiers
The foundations: MFA, patching, backups, unique passwords and basic staff awareness. A realistic starting point for very small teams.
Documented policies, access control, device management and incident response basics — the tier most SMBs are asked for.
Formal risk management, logging, vendor review and tested recovery procedures for businesses handling sensitive data.
Continuous monitoring, hardened endpoints, privileged access management and measured improvement cycles.
Independently verified maturity with governance reporting suitable for enterprise and government supply chains.
We keep the controls running with Guardz 24/7/365 MDR, SentinelOne, patching, backup verification and monthly reporting.
Our process
We confirm which SMB 1001 tier your customers, insurers or contracts require and scope your environment.
Every control is checked against the standard and scored, with evidence captured as we go.
We implement the missing controls — MFA, patching, backups, hardening, policies and training.
We prepare your submission, support the certification process and maintain the controls afterwards.
FAQ
Talk to our Australian cyber security team about the fastest practical path to your target tier. We work with businesses in Perth, Sydney, Melbourne, Brisbane, Adelaide, Canberra, Hobart and across regional Australia.