Cyber security

Cyber security services, checked every quarter

24/7 threat monitoring and response, Essential Eight controls and a security score you see every quarter, not set and forgotten. Plain English advice from a Perth team that is ISO 27001 certified and protects more than 150 Australian organisations.

Or call 1300 787 429. Under attack right now? Call, do not email.

Not sure where you stand? Take the five minute scorecard, or check your email security in seconds.

Austin Technology security engineer reviewing alerts
Threats come from anywhereMost start with something ordinary: an email, a password, a missed update
  • 150+Organisations protected by Austin SecureShield
  • 24/7Threat monitoring and response on every device
  • ISO 27001Certified information security management
  • QuarterlySecurity review and report for every client

Protecting organisations including

thyssenkruppFLSmidthInterContinental EnergyAlliance NickelCarers WAAcclaim AccountingKoch SolutionsCallidus Process Solutions

01Where businesses get caught out

Four gaps behind most attacks on SMBs

Most incidents we clean up start with something ordinary. These are the four we see most often, and what closes each one.

  1. A password gets stolen

    Staff reuse passwords or type them into a convincing fake Microsoft 365 login. Without multi factor authentication, one password opens email, files and finance systems.

    FixPhishing resistant MFA, identity threat detection on Microsoft 365 and a password manager for every user.

  2. A fake invoice gets paid

    Business email compromise is one of the most costly attacks Australian businesses report. An attacker sits quietly in a mailbox, then changes the bank details on a real invoice.

    FixEmail security that checks links, attachments and sender behaviour, plus staff training on how to verify payment changes.

  3. A device misses its updates

    An unpatched laptop, server or firewall is an open door. Attackers scan for known flaws within days of a patch being released.

    FixAutomated patching, vulnerability scanning and endpoint detection and response on every device, watched 24/7.

  4. The backup has never been tested

    Ransomware goes after backups first. Many businesses only find out their backup is incomplete when they try to restore from it.

    FixImmutable cloud backups kept separate from your network, and restores tested on a schedule.

Not sure which of these applies to you? Tell us what you run and who is asking the questions. A free security assessment gives you an Essential Eight score and a short list of what to fix first.

Talk to us

02What we look after

Managed security services, one accountable team

Your IT support and your security sit with the same team, so nothing falls between two providers. Each service has its own page if you want the detail.

2.1

24/7 monitoring and response

A security operations centre watches your devices and Microsoft 365 day and night, and contains threats before they spread.

MDR / SOC / identity threat detection
2.2

Endpoint detection and response

Every laptop and server runs detection that spots ransomware behaviour, not just known viruses.

EDR / device encryption / patch management
2.3

Email security and phishing protection

Filters that catch phishing, impersonation and invoice fraud before it reaches the inbox.

Microsoft 365 / link and attachment analysis / account takeover
2.4

Essential Eight

We score you against the ASD Essential Eight, close the easy gaps first and maintain the maturity level you need.

Gap assessment / ML1 and ML2 uplift / evidence for insurers
2.5

Firewall and network security

Managed firewalls, secure remote access and segmented networks, kept patched and reviewed.

Firewalls / VPN / intrusion prevention
2.6

Application control

Only approved software can run, which stops most malware and unapproved tools outright.

Allow listing / an Essential Eight control
2.7

Security awareness training

Short, regular training and simulated phishing, so your staff spot the next attack.

Phishing simulations / training / reporting
2.8

Penetration testing

Independent testing that shows how an attacker would get in, and what to fix first.

External and internal testing / retesting
2.9

DISP and compliance

Support for Defence Industry Security Program membership, ISO 27001 and client security questionnaires.

DISP / ISO 27001 / SMB1001
2.10

Cyber security audit

A point in time review of your security, with a prioritised report written in plain English.

Audit / risk report / remediation plan

03Managed detection and response

Managed detection and response, watched 24/7

Antivirus blocks what it already recognises. Managed detection and response adds people: analysts in a security operations centre who watch your devices, accounts and logs around the clock, confirm what is real and stop it. Every alert is checked by a person before it reaches you, and our own engineers handle the clean up.

Austin Technology engineer at a workstation in the Subiaco office
Engineering team, Level 2, 541 Hay Street, Subiaco
Devices

Endpoint detection and response

A light agent on every computer and server looks for how attackers behave, not only for known viruses.

  • Hidden persistence and misused admin tools
  • Early signs of ransomware
  • Affected devices isolated from the network
Accounts

Identity threat detection and response

Most attacks on small businesses now start with a stolen Microsoft 365 sign in. We watch the accounts as closely as the devices.

  • Stolen sign in sessions and tokens
  • Sign ins from unusual places, hidden inbox rules and forwarding
  • Accounts disabled and sessions ended
Logs

Security event logging

Firewall, Microsoft 365 and server logs in one place, so analysts see the whole picture and you have a record when an insurer or auditor asks.

  • Logs from your key systems in one place
  • Alerts reviewed by analysts, not left in a queue
  • Included from SecureShield Control

04Austin SecureShield

Three security levels, one clear path

Start at Core and step up as your risk grows. Every level includes the 24/7 security operations centre, and every managed device runs our endpoint protection as a minimum even without a level.

Level 1Recommended minimum

Core

$25per person per month
ex GST

24/7 security operations centre, detection and response on every device and Microsoft 365 account, security awareness training and vulnerability scanning.

Best forEvery business, on any support plan.

Level 2

Control

$60per person per month
ex GST

Everything in Core plus email filtering, Microsoft 365 baseline, application control, logging, a password manager, policies and a monthly report, maintained at Essential Eight Maturity Level One.

Best forBusinesses with an insurer, client or tender asking for evidence.

Level 3

Command

$100per person per month
ex GST

Everything in Control plus a virtual CISO, quarterly board reviews and controls maintained at Essential Eight Maturity Level Two.

Best forBusinesses with a board, a compliance obligation or a certification target.

Prices exclude GST and cover every person and device. SecureShield maintains the controls at the stated level; the assessment, gap closure and any uplift to a maturity level are quoted as fixed price projects. Compare every control.

05Frameworks in plain English

Essential Eight, SMB1001, ISO 27001 and DISP, explained simply

Insurers, clients and tenders ask for different things. Here is what each framework is, who tends to ask for it and how we help.

ASDMost asked for

Essential Eight

Eight controls from the Australian Signals Directorate that stop the most common attacks, scored from Maturity Level 0 to 3. ASD is moving to a broader Essentials series over the next two years and says Essential Eight work still counts. Download our free Essential Eight checklist.

Who asks for itCyber insurers, boards and government or enterprise clients.

  • Maturity assessment
  • ML1 and ML2 uplift
  • Evidence for insurers
Essential Eight
Certification

SMB1001

An Australian certification standard written for small and medium businesses, with five tiers from Bronze up to Diamond. It gives you a certificate you can show clients and insurers.

Who asks for itSMBs that want a recognised standard without the cost of ISO 27001.

  • Gap check against your tier
  • Controls put in place
  • Help preparing to certify
Compliance and risk
InternationalWe hold it

ISO 27001

The international standard for running information security as a managed system of policies, risks and audits. We are certified ourselves, so we know what auditors look for.

Who asks for itBusinesses selling to enterprise, government or overseas clients.

  • Readiness review
  • Technical controls
  • Evidence from your systems
Security and governance
Defence

DISP

The Defence Industry Security Program, needed for many Defence contracts. It covers governance, personnel, physical and cyber security. The cyber part is where we help.

Who asks for itEngineering, manufacturing and services firms in the Defence supply chain.

  • Cyber security requirements
  • Essential Eight alignment
  • Supporting documentation
DISP compliance
Harman KaurKrishna MoothooJamie WebbGregory Ashley

Not sure where you stand?

Answer 18 questions and see your score straight away, with the gaps that matter most. No email needed.

06How we get you secure

From first assessment to monitored 24/7

We fix the gaps that stop the most attacks first, then build from there. You see the score move every quarter.

  1. Week 1

    Security assessment

    We check your Microsoft 365, devices, email, backups and network against the Essential Eight and give you a score and a plain English report.

  2. Weeks 2 to 4

    Close the easy gaps

    MFA, patching, admin rights and email protection come first. They stop most attacks and cost little to fix.

  3. Week 4 on

    Monitored 24/7

    Detection and response goes live on every device and your Microsoft 365 tenancy, with our security operations centre watching around the clock.

  4. Quarterly

    Review and report

    A security report shows what we blocked, your current score and the next steps, written for owners and boards rather than engineers.

Patch panel in a server rack with looped network cables, lit from the side
Austin Huang, Managing Director of Austin Technology

07Why us

We run our own business on the same security

“We do not just sell security, we run our business on it. Every control we recommend is one we use on our own systems and our private cloud. If it is not good enough for us, it is not good enough for our clients.”
Austin HuangFounder and Managing Director, ISO 27001 certified business

08Security incident

Think you have been hacked?

Act quickly, but do not wipe anything. This is what to do in the first hour.

  1. 01
    Disconnect, do not power off. Unplug affected devices from the network or turn off Wi-Fi. Leaving them on keeps the evidence.
  2. 02
    Do not pay or reply to the attacker. Ransom notes and fake emails are designed to rush you.
  3. 03
    Call us on 1300 787 429. We contain the incident, protect what is still clean and start recovery. See cyber incident response.
  4. 04
    Report it. Use ReportCyber. If your business turns over more than $3 million and pays a ransom, the payment must be reported to ASD within 72 hours. If personal information is involved, you may also need to notify the OAIC.
Call now 1300 787 429

Existing clients can also raise an urgent ticket in the client portal.

09Recognised and certified

A top 50 MSP in Australia, three years running

Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.

Cloudtango Top 50 MSP in Australia 2026, 2025 and 2024
Top 50 MSP in Australia Cloudtango, 2024, 2025 and 2026. Assessed on client satisfaction, growth and the depth of our security, support and infrastructure services. Read our client reviews on Cloudtango
Austin Technology engineers at work on the service desk in Subiaco
ISO 27001 certified by Compass Assurance Services

ISO 27001

Information security

Our information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.

How we protect your data
ISO 9001 certified by Compass Assurance Services

ISO 9001

Quality management

Support tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.

10Questions

Cyber security questions

Straight answers for business owners and IT managers. Anything else, call 1300 787 429.

01

How much does managed cyber security cost for a small business?

Our Austin SecureShield levels are priced per person per month excluding GST: Core is $25, Control is $60 and Command is $100, added to your IT support plan. Without a level, every managed device runs our 24/7 endpoint protection at $6 a device. The initial assessment and any uplift to a maturity level are quoted as fixed price projects, so you know the full number before you start.

02

Is the Essential Eight being retired?

Yes, over time. In June 2026 the Australian Signals Directorate announced it will replace the Essential Eight with a broader Essentials series over roughly two years, starting with Essentials for enterprise IT. ASD has said the work organisations have done under the Essential Eight stays relevant.

We keep scoring you against the Essential Eight today and will map your controls across as the new guidance is finalised, so nothing you do now is wasted.

03

Is the Essential Eight mandatory for my business?

Not for most private businesses. It is mandatory for non corporate Commonwealth entities, and it is increasingly expected by cyber insurers, boards and government or enterprise clients. For most small and medium businesses, Maturity Level 1 is the sensible first target.

04

Is Microsoft 365 security enough on its own?

Microsoft 365 includes good security features, but many are off or only partly configured by default, and someone still has to watch the alerts. We harden your tenancy to a security baseline, add identity threat detection and email protection, and our security operations centre responds to what it finds.

05

We are a small business. Are we really a target?

Yes. Most attacks are automated and do not check how big you are. Smaller businesses are often hit because they have fewer controls in place, and a single fake invoice or ransomware attack can take weeks of cash flow. Our levels cover teams from 10 to 500 staff.

06

Can you help with our cyber insurance questionnaire?

Yes. Insurers now ask detailed questions about MFA, backups, endpoint detection and patching. We complete the technical answers with you and give you the evidence to back them up, which matters for your premium and for whether a claim is paid.

07

What happens if we are breached while on a SecureShield level?

Our security operations centre contains the threat, usually by isolating the affected device or account, and our engineers work through recovery with you. Control and Command include a documented incident response plan that is tested every year, so everyone knows their role before anything happens.

08

How long does it take to reach Essential Eight Maturity Level 1?

For most small and medium businesses it takes three to six months, depending on how many devices you have, your line of business applications and what is already in place. The quick wins, such as MFA, patching and admin rights, are usually done in the first few weeks. Reaching the level is a fixed price project; SecureShield Control then maintains it and keeps the evidence current.

Client feedback

What our clients say

1,800+ reviews from the people who call our Perth service desk every day.

  • Simplesat1,800+
  • Cloudtango25
  • Google60+
01 / 08
  • “Turns every IT problem into a non-issue”

    Arthur turns every IT problem into a non-issue and does it with real patience and professionalism. He explains things in a way that makes the process easy and always leaves us feeling supported. We appreciate the way he handles every request.

    Bronte J.Indian Ocean Hotel
  • “Patient, capable and a genuine listener”

    The support was outstanding. Patient, capable and a genuine listener, which is rare in support calls. He took the time to understand the issue and work through it with care. You are fortunate to have him on your team and the level of service was impressive.

    Peter MidgleyPowertech
  • “Steady, thoughtful and stress free”

    Jamie put in a great deal of effort to resolve the problem and it showed in the result. His approach was steady and thoughtful and the support was appreciated. It made the whole experience smooth and stress free.

    Jason CavallaroCallidus Process Solutions
  • “Resolved the issue within minutes”

    The consultant knew exactly what to do and resolved the issue within minutes. He talked through each step so I understood what was happening and made the process simple. The clear communication and fast resolution made a real difference.

    Kirk LentonPilbara Construction
  • “The extra guidance made it more valuable”

    Brady tracked down an email I could not locate and took the time to show us how to search more effectively in the future. The extra guidance was helpful and made the experience more valuable. His support was straightforward and appreciated.

    Tony YoungOptimus Real Estate
  • “Resolved quickly, with none of my work lost”

    They resolved my issue quickly and efficiently, which meant I didn’t lose any of the work I had done today. The support was clear and straightforward, and the outcome made a real difference to my day. Thank you.

    Warner PriestInterContinental Energy
  • “Calm, patient and always willing to help”

    Dev Sandhu is outstanding in his knowledge and support. He has a calm and patient way of working through any IT issue and is always willing to help at short notice. His positive attitude makes the whole experience easier and more reassuring. Thank you to Dev and the team at Austin for the consistent support.

    Peter AlexanderKoch Solutions
  • “Refreshing after two unreliable IT providers”

    After dealing with two unreliable IT providers in recent years, it has been refreshing to place my trust in Greg and the team at Austin. They have been professional and highly competent, even under pressure. Their support has made a real difference. Thank you, and keep it up.

    Mark HutchisonLifewood
Trusted by 300+ organisations
Thyssenkrupp FLSmidth InterContinental Energy Koch Solutions Callidus Process Solutions Carers WA Powertech Acclaim Visagio Roshana OGS Global Genus Lifewood

11Get started

Talk to us
about your security.

Tell us what your insurer, clients or board are asking for, or what worries you. You get a plain English view of where you stand, what to fix first and what it costs. If you want the numbers before you decide, a free security assessment gives you an Essential Eight score.

Or call 1300 787 429

Level 2, 541 Hay Street, Subiaco WA 6008 Protecting businesses across Perth, regional WA and Australia.

Results for businesses like yours

Powertech engineers reviewing plans on a tablet at an industrial site

Engineering · Cyber security

Powertech case study

Essential Eight ML2 alignment and approval to start work with a new client.

Two Palisades consultants working together at a laptop

Consulting · Cyber security

Palisades case study

Met a prospective client's security requirements and won the partnership.

Cyber security guides from our team