Cyber security
Cyber security for small business, without the scare campaign.
Most Australian small businesses are not breached by anything clever. They are breached by a password with no second factor, a Microsoft 365 setting nobody ever turned on, or an email that looked close enough. We go through your tenant, your devices and your website control by control, close those doors, and clean up when someone has already walked through one.
Where it actually goes wrong
You are not too small to be a target. You are the easiest one.
Nobody picked your business out of a list. Attacks on small businesses are almost entirely automated: software scans the whole internet for a known-vulnerable plugin or a login with no second factor, and takes whatever answers. Being small does not make you invisible to a script, it just means nobody is watching the door.
The damage is rarely the hack itself. It is the week your website is offline or flagged as dangerous, the invoices that quietly stopped arriving because your domain is now on a blocklist, and the customer who googled you and saw a warning page.
- Outdated plugins, themes and PHP versions
- Passwords reused across accounts, with no second factor
- Phishing and fake invoices that look like a supplier
- Old staff logins and API tokens nobody revoked
- Backups that exist on paper and have never been restored
What we do
Six things that stop most of it
No appliances to buy, no jargon and no annual scare review. These are the measures that actually prevent the incidents we get called about, whether we host you or not.
Security assessment
Where a consultant always starts. You cannot fix what nobody has measured, and most businesses have never had this done once.
- Microsoft 365 or Google Workspace tenant reviewed control by control
- Users, admin rights, old accounts and API tokens audited
- Website, hosting and DNS configuration checked
- Backup and recovery position confirmed, not assumed
- Plain-English findings ranked by what they would actually cost you
Identity & access
The front door. Stolen credentials, not clever exploits, are how the overwhelming majority of businesses get breached.
- Multi-factor authentication enforced on every account, admins first
- Conditional Access rules, so a login from nowhere near you is refused
- Legacy authentication blocked, because it walks straight past MFA
- Admin accounts reduced, separated and documented
- Self-service password reset and a banned-password list
Email & phishing defence
Business email compromise costs Australian companies more than any other kind of incident, and it rarely involves malware at all.
- Safe Links and Safe Attachments turned on and scoped properly
- Impersonation protection for your domain and your executives
- External auto-forwarding blocked, the rule attackers add first
- SPF, DKIM and DMARC taken to an enforcing policy, not left at p=none
- Staff trained on what a fake invoice actually looks like
Devices & endpoints
A laptop in a car park is a data breach if it is not encrypted, and a personal phone with work email on it is your problem too.
- Disk encryption enforced and recovery keys held safely
- Managed antivirus and endpoint detection, monitored not just installed
- Company data on personal phones wiped without wiping the phone
- Local admin rights removed and updates on a schedule
- Lost or stolen devices wiped remotely
Backup & recovery
A backup you have never restored is not a backup. This is also the single biggest blind spot in Microsoft 365 and Google Workspace.
- Hourly Acronis backups on Webics hosting, held offsite
- Proper third-party backup of Microsoft 365 or Google Workspace
- Restores actually tested, not assumed to work
- Recovery from ransomware, a bad update or a deleted mailbox
Website security & recovery
Your website is the one asset that is exposed to the entire internet every second of the day.
- Core, plugin and theme patching kept current
- Hardening baseline, admin lockdown and file-edit controls
- Continuous malware scanning and uptime monitoring
- Hacked site recovery, with the entry point proven from the logs
- Google Search Console warnings cleared and reindexed
We work on sites we built and sites we did not. Request a quote and tell us what you are running.
Inside your tenant
Microsoft 365 and Google Workspace, control by control
This is the part most businesses have never had done. Nearly all of these controls are already sitting inside the licence you pay for every month, switched off or left at a default that was chosen for convenience rather than for you. Turning them on properly is the single highest-value security work available to a small business, and it does not cost a cent in new software.
Identity (Microsoft Entra ID)
- MFA enforced on every account, administrators first
- Conditional Access: block legacy authentication, restrict by location, device and risk
- Microsoft Authenticator with number matching, phishing-resistant methods where it matters
- Global Administrator count cut down, separate admin accounts, a documented break-glass account
- Self-service password reset and a banned-password list
- Guest and external access reviewed
Email (Defender for Office 365)
- Safe Links and Safe Attachments enabled and scoped
- Anti-phishing with impersonation protection for your domain and your executives
- External auto-forwarding blocked, and existing mail flow rules audited for hidden forwards
- SPF, DKIM and DMARC taken to an enforcing policy
- External sender tagging, quarantine policies and mailbox auditing on
Devices (Intune & Defender for Business)
- Enrolment with compliance policies that actually block non-compliant devices
- BitLocker enforced, recovery keys escrowed
- Next-generation antivirus, endpoint detection and attack surface reduction rules
- App protection on personal phones: wipe company data without wiping the phone
- Local admin rights removed, update rings configured
Data (Microsoft Purview)
- SharePoint and OneDrive external sharing scoped to what you meant
- Sensitivity labels and data loss prevention on the data that matters
- Retention policies set deliberately rather than left at defaults
- A genuine third-party backup, because Microsoft do not provide one
Monitoring & governance
- Microsoft Secure Score baselined, then worked upward and re-measured
- Unified audit log enabled and alert policies configured
- OAuth app consent reviewed and an admin consent workflow turned on
- Sign-in and audit logs reviewed, not just collected
Identity
- 2-Step Verification enforced, security keys for administrators
- Context-Aware Access where your edition supports it
- Advanced Protection Program for high-risk accounts
- Super admin count reduced and admin roles properly scoped
- Password strength, reuse and recovery settings
Gmail
- Enhanced pre-delivery scanning and the security sandbox
- Attachment, link and external-image protections
- External recipient warning banners
- Auto-forwarding and mailbox delegation restricted
- SPF, DKIM and DMARC taken to an enforcing policy
Devices
- Endpoint management enrolment and policies
- Screen lock, encryption and remote wipe
- Company data on personal devices kept separate
Data
- Drive sharing defaults and link-sharing controls
- Data loss prevention rules on Drive and Gmail
- Vault retention and legal holds
- A genuine third-party backup, same reasoning as Microsoft
Monitoring & governance
- Alert Center and the investigation tool put to use
- OAuth app allowlisting, so staff cannot hand a random app your mail
- Login and admin audit logs reviewed
Two things worth knowing before you buy anything. Most of the Microsoft controls above come with Microsoft 365 Business Premium, which many businesses are already paying for and using as though it were the cheaper plan. And neither Microsoft nor Google back up your data in the way people assume: their retention is a short recovery window, not a backup, and under their own shared responsibility model your data is your responsibility. We will tell you which licence you actually need, including when it is a cheaper one than you have.
Already hacked? Ring us, today.
Defaced, redirecting somewhere strange, serving content you did not write, or flagged by Google. The longer it sits, the more of your search ranking and email reputation goes with it.
How a clean-up runs
Cleaning the mess is the easy half
Plenty of people will remove the malware they can see. If nobody works out how it got in, you are hacked again within the month, which is exactly why so many of these jobs arrive as second opinions.
- 1
Contain
We take the immediate pressure off: the site is stabilised, the bleeding stops and Google stops being fed the bad version.
- 2
Find everything
A full sweep for backdoors, web shells, injected database content and modified core files. Cleaning the visible damage and missing one shell means you are hacked again next week.
- 3
Prove the entry point
We read the server logs and work out how they actually got in. Without this you are guessing, and a guess is why sites get reinfected.
- 4
Close it
The vector is patched, credentials and API tokens are rotated, rogue users are removed and the Webics hardening baseline goes on.
- 5
Clear your name
Search Console and browser warnings resolved, reindexing requested, and your email reputation checked so your invoices still land.
Every clean-up finishes with the hardening baseline and a written note of what was found and how it got in. Moving your hosting to us is optional, not a condition.
Worth ten minutes
Start here if you are working out where you stand
Written for business owners, not IT departments. No product pitch in any of them.
Multi-factor authentication for Australian small business
What to turn on, what to skip, and why SMS codes are the weakest option people still reach for first.
Read the guide →Ransomware protection for small businesses in Australia
What actually stops it, what the reporting obligations now are, and why paying is the worst of the options.
Read the guide →What are phishing emails, and how to avoid them
The tells that give a fake away, and the one habit that stops invoice fraud costing you real money.
Read the guide →Good to know
Cyber security questions
My website has been hacked. What do I do first?+
Ring us on 1300 932 427 before you start deleting things. The damage you can see is rarely all of it, and a half clean-up usually means you are reinfected within weeks. Do not change passwords from a computer you suspect is compromised, and do not take the site down entirely if it can be avoided, because that costs you search ranking on top of everything else.
Do you only work on websites you built?+
No. We clean up, harden and audit sites built by anyone, on any host. You do not have to move your hosting to us to get the work done, and we will tell you honestly if moving would or would not actually help.
How do I know if my site is actually compromised?+
Common signs are redirects to sites you do not recognise, pages or spam content you did not create, a Google warning in search results or in the browser, a sudden drop in traffic, admin users you do not recognise, or your email suddenly landing in spam. Some compromises show none of these and only appear in the server logs, which is why an audit looks at more than the front page.
What is multi-factor authentication and do we really need it?+
It is a second proof of identity on top of your password, usually a code from an app on your phone. It is the single highest-value thing most small businesses can turn on, because the overwhelming majority of account compromises start with a password that was reused, guessed or phished. Cyber insurers increasingly expect it, and some now exclude claims where it was not enabled.
Is Microsoft 365 secure out of the box?+
It is secure enough to sell, not secure enough to rely on. Microsoft ship most tenants with the convenient defaults rather than the safe ones, and the strongest controls are switched off until somebody turns them on. Conditional Access, blocking legacy authentication, blocking external auto-forwarding, impersonation protection, device compliance and DMARC enforcement are all things we routinely find unconfigured in businesses that assumed they were covered because they pay Microsoft every month.
Do I need to buy anything to improve our Microsoft 365 security?+
Usually not. Most of the controls that matter are already included in Microsoft 365 Business Premium, and a lot of businesses are paying for that licence while using it as though it were the cheaper plan. The first thing we do is work out what your existing licences already entitle you to. Where a different licence genuinely is needed we will say so, and sometimes the honest answer is that you are on a more expensive plan than you need.
Does Microsoft or Google back up our data?+
Not in the way most people assume, and this is the single most common gap we find. Both provide a short recovery window for deleted items, which is not the same as a backup, and both operate a shared responsibility model where protecting your data is explicitly your responsibility rather than theirs. If a mailbox is wiped, a ransomware attack syncs to your files, or someone deletes a site and nobody notices for a couple of months, that window will not save you. A proper third-party backup of Microsoft 365 or Google Workspace is inexpensive and we set it up as a matter of course.
What is Microsoft Secure Score and does it matter?+
It is Microsoft own measure of how well your tenant is configured, scored against the controls you have available. It matters as a starting point and as a way to show progress, because it turns a vague feeling about security into a number you can move. It is not the whole picture, and chasing the score for its own sake will push you toward changes that annoy your staff for little real gain, so we use it as a baseline rather than a target.
Does Webics hosting already include security?+
Yes. Every Webics hosting plan includes free SSL, hourly Acronis backups with 30 day retention held offsite, server-level firewalls and DDoS mitigation, continuous malware scanning and uptime monitoring. That covers the hosting layer. It does not patch a plugin you have not updated or add MFA to your email, which is what the rest of this page is about.
Do you do staff training?+
Yes, practical sessions on what a phishing email and a fake invoice actually look like, run for your team rather than as a generic slideshow. Most incidents we are called about started with a person, not a server, so this is usually better value than more software.
What does it cost?+
It depends entirely on what you are running and what state it is in, so we quote each job rather than publishing a package price. An audit is a fixed price and tells you where you stand. A hacked site clean-up depends on how deep it went. Ask us for a quote and you will get a scope and a number, not a subscription.
Are you accredited?+
Webics is an ACSC partner under the Australian Signals Directorate, as well as a Google Partner and a Microsoft Partner. We have been looking after Australian business websites and IT since 2008.
Don't take our word for it
rating 5.0 ★★★★★ from 50+ reviews
★★★★★
My new website and hosting service are great. The Webics team were excellent in developing the website and taking on board feedback. I felt they communicated very well and a range of staff expertise was involved in the development phase. I recommend them particularly for Illawarra and South Coast businesses.
Ione Lewis
3 months ago
★★★★★
We have been working with Ory and the team at Webics for quite some time now for our website, marketing, and ongoing support needs. Their service has consistently been outstanding. Whenever we've had an issue or needed assistance, the team has simply worked it out with no fuss and no unnecessary delays. Their communication is excellent, keeping us informed throughout the process, and their attention to detail gives us confidence that everything is being handled properly. It's refreshing to work with a team that is professional, responsive, and genuinely focused on delivering results. We highly recommend Ory and the Webics team to anyone looking for reliable website and marketing support.
Bumpy Road Catering and Events
3 months ago
★★★★★
Couldn’t recommend Webics more. We had an urgent issue with one of our social media accounts and they handled it quickly and seamlessly. No stress, no back and forth — just results. Super knowledgeable team and we’ll definitely be working with them again.
carly pont
4 months ago
★★★★★
Thank you Ory and team for getting my ecom site live. Great communication, smooth process, definitely recommend.
Amber Hadfield
5 months ago
★★★★★
I had the pleasure of working with Ory from Webics, and I couldn't be more thrilled with the services provided. Ory's expertise and professionalism made the entire process seamless. He assisted in registering domains and configured our email.
Tiffany Ellis
2 years ago
★★★★★
Ory and the team at Webics are a one stop shop! They took the time to listen to my needs and came up with personalised solutions for my website and graphics. My website looks amazing, professional and the logo that was created was perfect.
Nadine Stevens
3 years ago
★★★★★
Lydia and Hayden have made the process of upgrading and refreshing our existing website an easy and enjoyable process. We had struggled for a few years to find a team that we trusted and could easily relate to that understood our business.
Jamieson Civil
5 years ago
★★★★★
It has been a pleasure dealing with Webics, the way the staff and Ory have conducted themselves has been so professional for my business. They always have new ideas and ways to get in front of the local area marketing on Google.
Adam Sturt
5 years ago
★★★★★
Absolutely fantastic service, end to end. Very impressed with the branding side of things, and the creative lead Sam is highly talented. The team were able to guide me through the concept stage of my website and able to really create a design that resonated with me. Hayden was highly responsive with my many requests for changes and committed to helping me get things just right. I will be using their service for SEO also. Having a local team like Webics that was available to me daily was invaluable. Will be using again in the future. Thanks Ory & team!
Zainib cheema
5 years ago
★★★★★
Webics would have to be the most creative and talented bunch of people I've met in a long time. They make the experience of setting up a webpage easy from start to finish.
Adam Straney
11 years ago
Trusted by 900+ Australian businesses
Find out where you actually stand, before someone else does.
Tell us what you are running and we will tell you what is exposed, what it would cost you, and what to fix first. If nothing needs doing, we will say so.



























