Cyber Security

SMB 1001 Certification Support

Servicing businesses all over Australia.

SMB 1001 is the Australian cyber security standard built specifically for small and medium businesses. We get you certification-ready across the Bronze, Silver, Gold, Platinum and Diamond tiers.

Why it matters

Cyber certification sized for real businesses

Large frameworks can be overwhelming for a 10 or 50 person business. SMB 1001 offers tiered, practical controls that grow with you — and increasingly it is what insurers, larger customers and tender panels want to see before they sign.

  • Gap assessment against your target SMB 1001 tier
  • Practical control implementation, not paperwork theatre
  • Evidence pack ready for certification and insurers
  • Policies and staff awareness material written for you
  • Ongoing monitoring so certification stays valid
SMB 1001 cyber security certification badge illustration

Controls

The SMB 1001 controls

SMB 1001 is built around practical controls that every small business can understand. Here is what we assess, implement and maintain.

Multi-factor authentication

Stops stolen passwords from being enough to access your email, cloud apps and remote systems — the single biggest cause of SMB breaches.

Patching and updates

Closes the known vulnerabilities attackers scan for every day, from operating systems to browsers and third-party apps.

Backups and recovery

Makes ransomware and hardware failures recoverable instead of catastrophic. We test restores so you know they work.

Access control

Ensures staff only reach the data and systems they need, and that access is removed when roles change.

Endpoint protection

Detects and blocks malware on laptops, servers and mobile devices before it spreads across your network.

Email and web security

Filters phishing, malware and malicious links before your staff see them, because most attacks still arrive by email.

Staff awareness

Turns your team into a defensive layer. Even the best tools fail when someone clicks the wrong link.

Incident response

Gives you a clear plan to contain, investigate and recover from an attack instead of making it up under pressure.

Logging and monitoring

Lets you spot suspicious activity early and provides the evidence insurers and auditors expect after an incident.

The tiers

Bronze through Diamond, one step at a time

Bronze

The foundations: MFA, patching, backups, unique passwords and basic staff awareness. A realistic starting point for very small teams.

Silver

Documented policies, access control, device management and incident response basics — the tier most SMBs are asked for.

Gold

Formal risk management, logging, vendor review and tested recovery procedures for businesses handling sensitive data.

Platinum

Continuous monitoring, hardened endpoints, privileged access management and measured improvement cycles.

Diamond

Independently verified maturity with governance reporting suitable for enterprise and government supply chains.

Managed maintenance

We keep the controls running with Guardz 24/7/365 MDR, SentinelOne, patching, backup verification and monthly reporting.

Our process

From assessment to certified

1

Scope & tier selection

We confirm which SMB 1001 tier your customers, insurers or contracts require and scope your environment.

2

Gap assessment

Every control is checked against the standard and scored, with evidence captured as we go.

3

Remediation

We implement the missing controls — MFA, patching, backups, hardening, policies and training.

4

Certification & upkeep

We prepare your submission, support the certification process and maintain the controls afterwards.

FAQ

SMB 1001 questions

Ready to get SMB 1001 certified?

Talk to our Australian cyber security team about the fastest practical path to your target tier. We work with businesses in Perth, Sydney, Melbourne, Brisbane, Adelaide, Canberra, Hobart and across regional Australia.