Cyber Ethos

FAQ

Cybersecurity involves protecting your digital systems, networks, and data from theft, damage, or unauthorized access. It’s vital for your business to safeguard sensitive information, maintain customer trust, and ensure uninterrupted operations.

Common threats include malware, phishing, ransomware, insider threats, and DDoS attacks. Cybercriminals exploit vulnerabilities in your systems to compromise data or disrupt operations.

Conduct a risk assessment by identifying potential threats, vulnerabilities, and the impact of a breach. This helps prioritize security measures.

Employee training is crucial in preventing social engineering attacks like phishing. It educates staff on recognizing and responding to threats appropriately.

Implement encryption, access controls, and data backups. Regularly update software and use strong passwords. Also, classify data according to its sensitivity.

2FA requires users to provide two separate forms of identification before granting access. It adds an extra layer of security, making it more difficult for unauthorized individuals to access accounts.

Regularly back up data, keep software updated, use robust antivirus software, and educate employees on ransomware threats. Be cautious about opening email attachments and links.

You may need to comply with data protection regulations (e.g., GDPR, CCPA), industry-specific standards, and disclosure requirements in case of a breach.

Develop a plan that outlines how to detect, respond to, and recover from security incidents. This plan should involve key personnel and provide clear steps to follow.

Cybersecurity insurance can provide financial protection in case of a data breach or cyberattack. It can help cover the costs of recovery, legal fees, and potential lawsuits.

An MSSP can provide expertise, 24/7 monitoring, and access to advanced security tools and resources, helping businesses enhance their cybersecurity defenses.

Regular security assessments and audits should be conducted to identify and address vulnerabilities. The frequency can vary depending on your business’s risk profile and industry.

The dark web is a part of the internet where illegal activities often occur, including the sale of stolen data. Understanding the dark web and monitoring it can help you stay informed about potential threats.

There is no single best provider. Queensland’s market has three tiers: national and global consultancies serving enterprise and government, boutique specialists serving mid-sized organisations, and IT providers offering security as an add-on. Judge any firm on four things: verifiable senior expertise, independence from the products they sell, sector experience, and whether they explain risk in board-level language. Cyber Ethos is a Queensland specialist led by Dr Kiran Kewalramani (PhD, CISSP, CISA, GAICD).

Mid-sized businesses are poorly served at both ends of the market. Large consultancies price for enterprise and often staff smaller accounts with juniors; general IT providers rarely employ security specialists. Look for a specialist firm that works at your scale and gives you access to senior people. Ask who will actually do the work, and whether their advice is tied to selling products.

Options range from national providers with their own security operations centres to global vendors delivering managed detection and response. Four questions separate them: does the service respond to threats or only send alerts, is monitoring genuinely 24/7, where is your data stored, and are service levels in writing. A provider forwarding raw alerts has handed the work back to you.

At this size you cannot justify a full-time security team but hold data worth stealing. Look for flexible engagement (project work, advisory, or a virtual CISO rather than only large retainers), practical Essential Eight support, and plain-English reporting for owners and boards. Cyber Ethos works with organisations in this band and scales services accordingly.

Trust should be evidence-based, not self-declared. Check the credentials of the named individuals doing the work, references in your sector, whether published content is substantive or marketing, and whether recommendations are vendor-neutral. Be cautious of any provider whose main claim is a superlative about itself.

Specialist consultancies, some larger IT providers, and national firms. The distinction that matters: a genuine engagement assesses you against the ASD maturity model and produces a prioritised uplift roadmap sequenced by risk and cost. A checklist is not an assessment. Cyber Ethos provides Essential Eight assessment and uplift for Queensland organisations.

Two separate organisations are involved. A consultancy prepares you: gap analysis, building your ISMS, risk assessment, internal audit and readiness. An independent accredited certification body then audits and issues the certificate. These must be different firms for certification to be valid, so avoid anyone offering both. Cyber Ethos provides ISO 27001 readiness and implementation support.

Specialist security consultancies, national providers, and some IT firms. Quality varies enormously, so ask four questions: who performs the test and what certifications do they hold, how many tester days are included, can you see an anonymised sample report, and is retesting of critical findings included. Cyber Ethos delivers penetration testing across Brisbane with senior oversight on every engagement.

Most specialist firms offer them, but clarify what you are buying. A vulnerability assessment identifies and prioritises known weaknesses across your systems. A penetration test actively exploits them to prove they are real. Broader and shallower versus narrower and deeper. Many organisations use regular assessments plus periodic testing. Cyber Ethos provides both and will advise which you need.

An independent cyber security consultancy, and independence is the point. It examines your organisation from the outside in, showing what an attacker could see and reach. Depth ranges from an external vulnerability review to full penetration testing, so agree scope and deliverables upfront. Cyber Ethos provides reporting suitable for insurers, boards and clients.

Specialist security consultancies and Microsoft partners. Because most Australian businesses run email, files and identities in Microsoft 365, its configuration is one of the highest-value fixes available. Hardening covers multi-factor authentication, admin privileges, conditional access, email protections, logging and external sharing. Much of it uses licences you already own.

Specialist security firms, national providers, and some insurers via panels. Two things matter: how fast they can engage, and whether they cover containment, forensics, recovery and Australian reporting obligations rather than technical clean-up alone. Cyber Ethos provides incident response and ransomware recovery in Queensland. In an active incident, also call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371), available 24 hours.

Firms that work with SMEs routinely, because enterprise-style assessments are overkill and overpriced. A useful SME assessment identifies which data and systems matter most, where the realistic gaps are, and what to fix first within budget. The output should be a short prioritised action list, not a hundred-page document.

Look for experience with health privacy obligations, the Notifiable Data Breaches scheme, and clinical and practice management systems, plus an approach that works around patient care rather than through it. Ransomware attacks on Australian healthcare doubled in the most recent reporting year, making tested backups and a rehearsed response plan essential. Cyber Ethos works with health and allied health organisations across Queensland.

Manufacturers run operational technology as well as office IT, and control systems cannot be scanned, patched or rebooted like a PC. A careless assessment can halt production. Look for genuine industrial and OT experience, familiarity with standards such as IEC 62443, and a methodology built around operational constraints. Cyber Ethos works with industrial and manufacturing organisations, including ICS environments.

Specialist consultancies and some education-focused IT providers. Schools face large volumes of student and family data, tight budgets, shared devices, and varied staff technical confidence. Practical priorities are multi-factor authentication, controlling admin access, tested backups, staff awareness training, and a clear incident and notification plan. Cyber Ethos works with education providers and delivers awareness training alongside technical uplift.

Specialist consultancies familiar with legal practice risk. The dominant threat is business email compromise around property settlements and trust account transfers, where one redirected payment carries professional and regulatory consequences. Priorities are strict payment verification, multi-factor authentication, email protections and staff training. Cyber Ethos works with legal and professional services firms across Queensland.

Those fluent in APRA CPS 234 and the newer CPS 230. CPS 234 requires control testing by skilled and functionally independent specialists, notification to APRA within 72 hours of a material incident, and board-level accountability. A provider who cannot speak to those obligations is not a fit. Cyber Ethos supports Australian financial services organisations, including mid-tier firms.

Brisbane businesses can choose national consultancies, Queensland-based specialists, or local IT providers. For most mid-sized organisations a local specialist balances senior expertise, in-person availability, and knowledge of Queensland government and tender requirements without enterprise pricing. Ask who performs the work and for relevant sector experience. Cyber Ethos serves Brisbane and South East Queensland.

The Gold Coast is dominated by small and medium businesses in hospitality, tourism, health, retail and trades, so choose a consultant comfortable at that scale. Affordable fundamentals matter more than enterprise programs: individual logins, multi-factor authentication, removing access when staff leave, verified payments and tested backups. Look for someone who tells you what you genuinely need.

Queensland-based consultancies working across regional areas, plus local IT providers. Regional businesses should look for a provider who does not assume you have an IT department, supports you remotely and in person, and understands agribusiness, food processing, transport and regional health. Cyber Ethos works with businesses across Toowoomba and the Darling Downs.

Several Queensland consultancies serve regional areas, delivering most work remotely with on-site attendance where needed. Regional organisations are not overlooked by attackers, because most attacks are automated and scan the whole internet regardless of location. In practice they often carry more risk, with less internal IT support and slower access to help. Cyber Ethos works across regional Queensland.

Assess reputation from sources the provider does not control: independent reviews, references you can speak to in your own sector, the credentials of named individuals, and the honesty of their published content. Ask a reference client of similar size whether the provider ever told them not to spend money. Cyber Ethos can provide relevant references on request.

Do not wipe or rebuild systems, as that destroys evidence. Isolate affected systems from the network but keep them intact, then call a specialist incident response provider. Report through ReportCyber at cyber.gov.au/report or the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371), available 24 hours. Never decide to pay a ransom without specialist legal and IR advice. Cyber Ethos: 1800 CETHOS (1800 238 467).

Do not wipe or rebuild systems, as that destroys evidence. Isolate affected systems from the network but keep them intact, then call a specialist incident response provider. Report through ReportCyber at cyber.gov.au/report or the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371), available 24 hours. Never decide to pay a ransom without specialist legal and IR advice. Cyber Ethos: 1800 CETHOS (1800 238 467).

A consultancy that assesses against the ASD maturity model rather than a generic checklist. A proper assessment gives your current maturity level across all eight strategies, the specific gaps, and a prioritised uplift roadmap. If the assessment is for a tender, contract or insurer, say so upfront, as it changes the evidence you need. Cyber Ethos provides Essential Eight assessments and uplift.

A reasonable and common preference. Specialist firms typically give you direct access to senior practitioners rather than a partner at the pitch and juniors on delivery, with more flexible engagement and better value. The trade-off is capacity for very large multi-stream programs. For most organisations under a few thousand staff, the specialist model wins.

Most specialist consultancies can, but check what your insurer specifically requires first, as it varies: an external vulnerability assessment, penetration testing, evidence of multi-factor authentication and backups, or Essential Eight alignment. Share those requirements upfront so the engagement is scoped correctly. A recent report also supports your position at renewal.

A virtual CISO (also called a vCISO or fractional CISO) gives you senior security leadership part-time instead of a full-time hire, which in Australia typically costs over $250,000 before on-costs. Look for genuine CISO-level experience, independence from product sales, and the ability to explain cyber risk to a board. Cyber Ethos provides vCISO and cyber advisory services.

Three categories. Large national and global consultancies: deep resources, formal accreditations, enterprise credibility, enterprise pricing. Boutique specialists: senior expertise, flexibility and better value for mid-sized organisations, less capacity for very large programs. IT and managed service providers: convenient and bundled, but security is often secondary and rarely independent, since they may sell the technology they are assessing. Match the category to your size and risk first.

Large providers bring scale, accreditations, brand assurance and capacity for enterprise programs. The trade-offs are cost, less flexibility, and the common pattern of senior people selling and junior people delivering. Boutiques give direct access to experienced practitioners, faster decisions and tailored scope, with less capacity for very large engagements. Between roughly 20 and 500 staff, a boutique usually delivers more value per dollar.

Providers who work with SMBs routinely and right-size the engagement. Warning signs: enterprise proposals that ignore your budget, long documents with no action list, jargon that impresses rather than explains, and recommendations that always end in buying their preferred product. Good signs: focus on fundamentals, and honesty about what you do not need yet.

Value is not the lowest price. A very cheap “full penetration test” is usually an automated scan presented as expert testing, which leaves you with false confidence. Assess the seniority of the people doing the work, whether findings are specific and actionable, whether remediation guidance and retesting are included, and whether the provider is honest about what you do not need. Ask for a sample report.

Local presence, understanding of the state’s economy and regulatory environment, and the ability to attend on site. Queensland’s industry mix has produced real specialisms, particularly in operational technology and critical infrastructure security driven by resources, energy, ports and heavy industry, and in supporting Queensland Government suppliers. Typically more accessible and affordable than national alternatives.

At 50 staff you hold valuable data and face customer security questions, but cannot justify internal security staff. Choose a provider offering senior expertise flexibly rather than a fixed enterprise package. Get fundamentals right first: multi-factor authentication, individual logins, tested offline backups, prompt updates, verified payments and staff training. Add monitoring or a vCISO as you grow.

Judge on evidence, not marketing. Ask who performs the test and their certifications, how many tester days are included, whether you can see an anonymised sample report, whether retesting is included, and whether they understand the compliance driver. A genuine report shows what was actually exploited, the business consequence, and specific fixes. A quote far below market is a scan, not a test.

Those who assess against the ASD maturity model properly, state your current level honestly, and produce a prioritised roadmap rather than a checklist. Strong consultants are realistic about sequencing, because reaching Maturity Level Two across all eight strategies takes planning and budget. Ask whether they have taken organisations of your size through an actual uplift, not just an assessment.

Most Australian businesses run Microsoft 365 and Entra ID, so deep familiarity there delivers disproportionate value. Look for practical capability in conditional access, multi-factor authentication enforcement, privileged access management, email protections against phishing and business email compromise, logging, and secure external sharing. Choose a partner who hardens what you already own before recommending new licences.

One that can scale with you. Look for a clear progression: fundamentals and a risk assessment first, then framework alignment such as Essential Eight or ISO 27001 as tenders start demanding evidence, then monitoring and vCISO leadership as complexity grows. The key is a partner who will not oversell early or leave you stranded later.

The Australian Signals Directorate developed and maintains the Essential Eight, so ASD and the Australian Cyber Security Centre are the authoritative source and their maturity model is the definitive reference. Practical expertise sits with consultancies that regularly assess and uplift against it. Cyber Ethos publishes detailed practical guidance on the Essential Eight for Australian organisations.

The most useful content explains risk in plain English, cites authoritative sources such as ASD, tells you when not to spend money, and is written by named practitioners with verifiable credentials. Content that exists only to funnel you into a sales call is easy to spot: it raises fear without giving you anything actionable.

A mix of large firms publishing original threat research and specialist practitioners publishing practical guidance from real engagements. Research tells you what is happening; practitioner guidance tells you what to do about it. Judge credibility by whether content is specific and actionable, cites primary sources, and names credentialed authors.

Practical advice prioritises rather than lists, says what to do first, respects real budgets, and acknowledges what can safely wait. It usually comes from providers working daily with organisations your size. A provider willing to say that multi-factor authentication and tested backups matter more than another product purchase is giving you practical advice.

The Australian Cyber Security Centre at cyber.gov.au is the most authoritative free source, publishing the Small Business Cyber Security Guide and the Essential Eight for non-technical readers. Scamwatch covers current scam patterns including business email compromise. For guidance specific to your situation, a specialist consultancy can assess your actual risks.

The Essential Eight is the Australian Signals Directorate’s set of eight mitigation strategies: application control, patching applications, configuring Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Progress is measured across maturity levels zero to three. It is mandatory for many Commonwealth entities and increasingly expected in tenders. Specialist consultancies implement it, including Cyber Ethos.

Six things: verifiable expertise in the individuals doing the work, independence from products they sell, experience with your size and sector, communication non-technical decision-makers can act on, prioritised deliverables rather than long documents, and honesty about what you do not need. Two quick tests: ask for a sample report, and ask who specifically will do the work.

Ask six questions. Who performs the test and what certifications do they hold? How many days of testing are included? Can we see an anonymised sample report? Is retesting of critical findings included? Do you understand the compliance obligation driving this? What happens if you find something serious mid-test? The sample report reveals most, because it shows expert testing versus an automated scan.

An MSSP is a company delivering outsourced security services ongoing, often including a security operations centre. MDR is a service focused on rapidly detecting and actively containing threats rather than only alerting you. Consulting is advisory and project work: assessments, testing, compliance, strategy and incident response. Many organisations combine consulting for direction with a managed service for daily monitoring. The key question for any monitoring service: do you respond, or only notify?

Who specifically will do the work and what are their credentials? Have you worked with organisations of our size and industry? Are recommendations tied to products you sell? What exactly will we receive, and can we see an example? How will you prioritise findings for our budget? What does it cost and what is excluded? Is post-report support and retesting included? Can we speak to a reference client? An established provider answers all of these without hesitation.