Cyber Security

Most businesses get cyber security wrong in one of two ways: doing nothing because it’s overwhelming, or overspending on controls they don’t need. Both come from the same place — no clear way to match security investment to actual risk. We fixed that with three defined security tiers, so you always know where you stand, what’s next, and why.

1 every 6 min
Cyber incident reports received by the Australian Signals Directorate from businesses
$55,000
Average self-reported cost of cybercrime per incident for Australian businesses
94%
Of SMBs reported experiencing at least one cyber incident in 2024

Source: Australian Signals Directorate, Annual Cyber Threat Report

Three tiers. One honest conversation about risk.

Frameworks are confusing by design — Essential Eight, NIST, ISO 27001, CIS, CPS 234 all overlap and none tells you where to start. Our tiers translate them into a practical path. You start where your risk actually sits, and step up only when your business needs it.

Our minimum standard

Baseline

The essential protections every business needs. If you’re a 3rdmill managed services client, this is where you start — not an optional extra.

  • Device patching across workstations and servers
  • Endpoint detection & response (next-gen antivirus)
  • Advanced email protection against phishing and malware
  • Offsite backup of your Microsoft 365 data and servers
  • Microsoft 365 Business Premium security features
  • User awareness training, phishing simulations and dark web monitoring
For regulated organisations

Stealth

For organisations with formal compliance obligations — CPS 234, ISO 27001 — or boards that want cyber risk managed like every other business risk.

  • A formal Cyber Governance Program with monthly committee meetings
  • Continuous monitoring of exposures and threats across your tenant
  • Gap assessment and tracking against your chosen framework (CIS, NIST, ISO, CPS 234)
  • Ongoing remediation targeting your highest-risk exposures
  • Formal executive and board reporting, built for non-technical stakeholders

Security that fits how you actually buy it

Insurance-driven? Cyber insurers increasingly demand evidence of specific controls before they’ll write or renew a policy. Our gap assessment maps exactly what your insurer expects against what you have, and the roadmap closes the difference — documented, so renewal time is paperwork rather than panic.

Compliance-driven? Whether it’s Essential Eight for government work, CPS 234 for financial services, or a client security questionnaire holding up a deal, we’ve run the process: assess, remediate, evidence. Start with our plain-English guide to the Essential Eight.

Just want to be safe? Then Baseline plus a conversation is the right start. Security is a shared responsibility — we bring the technical controls, monitoring and guidance; you bring the internal policies and processes. We’ll tell you honestly which side needs work.

Frequently asked questions

What is the Essential Eight and do we need it?

The Essential Eight is the Australian Cyber Security Centre’s recommended set of baseline mitigation strategies. It’s government-recommended rather than mandatory for most private businesses, but it’s increasingly used by insurers and enterprise clients as the yardstick for whether you take security seriously. Our Baseline and Fortify tiers are designed to move you up its maturity levels pragmatically.

What does a cyber security gap assessment cost?

A 3rdmill gap assessment typically costs $3,000 to $5,000 depending on the size of your environment and target framework. You get a clear baseline of where you stand and a prioritised, costed roadmap – so every dollar you spend afterwards is justified by risk, not fear.

Can you help with cyber insurance requirements?

Yes. We map your insurer’s control requirements against your current environment, close the gaps, and document the evidence. For many clients this is the difference between being insurable and not, or a meaningful premium reduction.

Do we need 24/7 monitoring?

Not every business does. Baseline includes endpoint detection with alerts actioned by our team. 24/7 managed detection and response with a security operations centre becomes worthwhile when you hold sensitive data, face compliance requirements, or can’t tolerate the response gap outside business hours. We’ll tell you which one you actually need.

We haven’t done anything about security yet. Where do we start?

Start with Baseline: patching, endpoint protection, email security, backups and user training. It covers the attack vectors behind most SMB incidents and doesn’t require a big program to stand up. From there, a gap assessment tells you whether you need more.

Not sure which tier you are? That’s the point of the conversation.

A 30-minute call, or a gap assessment if you want it in writing. Either way you’ll know where you stand and what it should cost — before you spend a dollar.

Enquire today