Skip to content
Business Services

Cyber Security for Geelong Businesses

GravIT assesses your infrastructure, recommends what's actually worth doing, then implements and maintains it, aligned with the Australian Cyber Security Centre's Essential Eight. Practical protection for small and medium businesses, from a Geelong owned and operated team you can ring when something looks wrong.

Why these controls

How an attack actually unfolds

Not a hooded figure and a progress bar. A slow, patient, fairly boring sequence, which is good news, because a sequence can be interrupted. Here is where each control does its work.

The usual order of events, and what breaks the chain.
StageWhat they doWhat stops itWhere your money goes
Getting inA convincing email, a reused password from someone else’s breach, or an unpatched system facing the internet.Email filtering, MFA, patching, and staff who have seen the trick before.
Looking aroundDays or weeks of quietly mapping your network, your files and who has the keys. Nothing appears to be wrong.Logging and alerting, so “nothing appears to be wrong” is not the same as nobody looking.
Getting the keysHunting for an administrator account, because one of those turns a foothold into the run of the place.Restricted admin privileges and a password manager. Fewer keys, and none of them reused.
Killing the backupsDelete or encrypt every backup they can reach, before touching your live data. A business that can restore does not pay.Immutable backups: copies that cannot be deleted with any password, including ours.
The encryptionThe part everyone pictures, and the last step rather than the first. By now the damage is already done.Endpoint protection and application control, plus everything above, which should have ended it earlier.
The demandPay, or lose it. Increasingly: pay, or we publish your client data anyway.Being able to restore, and being able to show what was and was not taken.

Read down that last column and you have the security roadmap. It is also why we will not sell you one expensive product as an answer. There is no single stage where a single tool ends the story.

The volume

There has never been more to patch

Two of the Essential Eight are just “keep your software current”, which sounds like padding until you see the volume it is holding back. Every point below is a publicly documented way into software, numbered, catalogued and loaded into an automated scanner within hours of disclosure.

22k44k66k88k202018,3232021202220232024202548,18520262027~99,000WordPress

Every CVE record published, with the WordPress ecosystem as the lower band. WordPress sits inside the total rather than beside it, so the two together are the whole. Which is the striking part: WordPress was 3% of all disclosed vulnerabilities in 2020 and is now roughly a quarter of them. Solid to 2025 is published; 2026 and 2027 are projections, the first from this year’s observed pace and the second continuing recent growth. Totals from the CVE Program record; WordPress figures from Patchstack. Starts at 2020 because no 2019 WordPress total was published.

WordPressAll other softwareDotted: projected
The severity

And the serious ones are spiking

Volume is only half the story. This is the severe end of it, the flaws rated high or critical, month by month, and it is where the last year has gone strange.

5001,0001,5002,0002,500Apr 2026 · AI finds flaws2022202320242025202620271,906 high606 criticaltrend continued →

High- and critical-severity CVEs disclosed each month by 21 major vendors (Microsoft, Google, Apple and the like), not the whole CVE corpus. Data from Epoch AI (CC BY). Solid to July 2026 is measured, a dot per month. The dotted lines continue at the growth rate of the last four months, which is why they leave the top of the chart almost at once. Follow that rate to December 2027 and it reaches roughly three million a month, more than every CVE ever catalogued, so it plainly will not run that far: this is a backlog being found, and it should level off. Read the dotted lines as direction of travel rather than destination. Even if they flattened tomorrow at July’s level, 2027 would still bring about 30,000 serious vulnerabilities from these vendors, against 4,359 in the whole of 2025.

CriticalHighDotted: current growth rate continued
In July 2026, the 21 biggest software vendors disclosed 2,512 high- or critical-severity vulnerabilities in a single month, about nine times their long-running average and 62% above the record set the month before.
10→24%The mix got worse as well as the volume. Critical-rated flaws held steady at about a tenth of the serious total for four years. Since June 2026 they are a quarter of it, up 29-fold since 2022, while high-rated grew 12-fold.
1,665Yet only this many vulnerabilities, of the hundreds of thousands ever published, are on CISA’s list of those known to be actively exploited. That is the list worth losing sleep over, and it is a small one.

What happened in mid-2026?

Software did not suddenly get worse. What changed is who is looking. From April 2026, AI models became capable enough to find security flaws on their own, and the large vendors began running them across their own code deliberately, to get there before anyone hostile did. The spike is the sound of a very large backlog being discovered, not created.

Which is genuinely good news, with one catch. Those flaws already existed in software you are already running; the difference is that now they get found, published and fed into automated scanners. The gap between a fix existing and you applying it is where the risk actually lives, and that gap is the same length it always was while the volume arriving has multiplied.

Worth knowing too: these are only the ones disclosed publicly. Anthropic alone has reported finding more than 10,000 high- and critical-severity vulnerabilities through its own programme. If the published line looks steep, it is the conservative view.

Severity data from Epoch AI (CC BY), covering 21 major vendors. Exploited count from CISA’s Known Exploited Vulnerabilities catalogue, 1,665 entries as at 14 August 2026. Neither figure is projected.

The framework

The Essential Eight, in plain English

Australia’s baseline, published by the Australian Cyber Security Centre. Eight strategies, chosen because they stop the overwhelming majority of what actually happens to small businesses, not because they are exciting. Increasingly, insurers and larger customers ask which of them you have.

Multi-factor authentication

A stolen password on its own stops being enough. The single most effective control on this list, and usually the cheapest.

Patch applications

Keep software current. Attackers rarely need a clever new exploit when a known hole from eight months ago is still open.

Patch operating systems

The same argument, one layer down. An unpatched server is the door people walk through, not the window they break.

Restrict administrative privileges

Fewer people with the keys, and only when they need them. It limits how far an intruder gets once they are in as somebody.

Regular backups

The one that decides whether an incident is a bad week or the end of the business. Only counts if the copies survive the attack (see below).

Application control

Only approved software runs. Sounds heavy-handed; it is what stops a downloaded executable from ever getting started.

Configure Office macro settings

Macros in documents are still a favourite delivery route. Blocked by default, allowed only where the business genuinely needs them.

User application hardening

Turn off the parts of browsers and Office that are mostly used against you. Removing what you never needed removes the risk with it.

Our plain-English write-up goes further: the Essential Eight explained for small business.

How you get scored

Maturity levels, and the catch nobody mentions

Each of the eight is assessed against four levels. Most small businesses sit somewhere between zero and one when we first look, and that is a normal place to start rather than something to be embarrassed about.

Level 0

Not really aligned

The control is largely absent. Common, and fixable.

Level 1

Partly aligned

Enough to frustrate opportunists using off-the-shelf tools and mass phishing, which is most of what a small business meets.

Level 2

Mostly aligned

Stands up to attackers willing to spend time and effort on you specifically.

Level 3

Fully aligned

Built for adversaries who are adaptive and targeted. Rarely the right goal for a small business.

The catch

Your overall maturity is the lowest score of the eight, not the average. Seven strategies at level two and one at level zero makes you level zero. That sounds unfair and is completely correct, because an attacker only needs the weak one. It is also why we sequence the work by what is furthest behind rather than by what is easiest to finish.

How a GravIT cyber security engagement works

Four steps, no scare tactics:

  1. Assess. We review your infrastructure: accounts, email, devices, network, backups and how staff actually work.
  2. Recommend. You get tailored recommendations in plain English, prioritised by risk and cost, mapped against the ACSC Essential Eight.
  3. Implement. We roll out the agreed measures, tested before they touch your production systems.
  4. Maintain. Security isn't a one-off. We keep patching, monitoring and adjusting, with ongoing consultation as your business changes.

The Essential Eight, and why we align to it

It is the Australian Cyber Security Centre's baseline and the sensible national yardstick for small business security: proportionate, auditable, and increasingly the thing insurers and larger customers ask about before they sign. We use it as the framework for every assessment and roadmap, which is why it gets its own section further down rather than a footnote here. See the eight, in plain English.

What we actually put in place

The specific controls, in the order they usually earn their money:

  • Multi-factor authentication. The single most effective control against a stolen password. We roll it out across email, remote access and banking, including the awkward accounts people forget, and set it up so staff aren't fighting it ten times a day.
  • DNS and web filtering. Blocks known-bad websites before a browser ever loads them, on the office network and on laptops that leave it. It stops a surprising share of attacks at the first click.
  • Password management. A business password manager, so staff stop reusing passwords or keeping them in a spreadsheet, and your logins stay with the business when they leave.
  • Firewall management. Rulesets, threat protection and monitoring on the device between your network and everything else, kept current rather than configured once and forgotten.
  • Endpoint detection and response (EDR). SentinelOne on every computer and server. Traditional antivirus checks files against a list; EDR watches for the behaviour of an attack as it happens, and can isolate a machine from the network or roll a system back to before the damage. It is also the control cyber-insurance questionnaires now ask for by name, and ours lets you tick that box honestly.
  • Dark web and breach monitoring. We watch for your staff addresses and passwords turning up in breach dumps, so a credential leaked somewhere else doesn't quietly become your problem.
  • Vulnerability scanning. Regular scans for the misconfigurations and unpatched gaps attackers actually use, with findings prioritised by risk rather than handed over as a 200-page report.
  • Microsoft 365 compliance and data governance. Who can see what, retention and sensitivity rules applied, and the evidence to show it. The same tidy-up that makes Copilot safe to switch on.
  • Staff awareness training. The control that covers what the others miss. See cyber security awareness training.

We also collect logs and alert on suspicious activity, and our own staff work to least-privilege access on your systems, holding no more access than we need to do the job.

Checking the dark web for what has already leaked

Most businesses have staff passwords circulating in criminal marketplaces right now, not because they were hacked but because an employee reused a work email on some website that was. Attackers buy those lists and simply try the passwords. It is the least glamorous and most common way in.

Our dark web exposure check answers the question with specifics: which of your staff addresses appear in known breach data, what was exposed alongside them, and which of it still matters. Then we fix it: the exposed passwords rotated, MFA in front of what matters, and a password manager whose monitoring alerts us when a new breach names your domain. The check is included in a free IT health check, no strings on it.

When something gets through anyway

Everything above is about keeping attackers out. Assume, for a moment, that one day something gets in regardless. The businesses that recover well are the ones that planned for that day rather than the ones with the most controls.

What decides the outcome is whether you can restore. That is why ransomware crews hunt the backups before they encrypt anything: a business that can restore does not pay. The counter is a copy that cannot be deleted even with your administrator password in hand. See immutable backups, which is the part of the security conversation people skip until the week they need it.

Cyber security and the Privacy Act

If you hold customer data, the Privacy Act applies to how you collect, store and secure it. We help you put reasonable safeguards in place and document them, so you can answer confidently when a client, insurer or regulator asks.

What's included

  • Infrastructure security assessment
  • Tailored, prioritised recommendations
  • Essential Eight alignment
  • SentinelOne endpoint detection and response (EDR)
  • Privacy Act compliance assistance
  • Ongoing maintenance and consultation
FAQ

Frequently asked questions

What is the ACSC Essential Eight?

The Essential Eight is the Australian Cyber Security Centre's baseline of eight practical mitigation strategies, such as patching, multi-factor authentication, application control, restricting admin privileges and regular backups. GravIT aligns small-business security work to it because it's proportionate, well-documented and recognised across Australian industry and government.

How much cyber security does a small business actually need?

Enough to cover how you really work, rather than an enterprise product catalogue. We start with an assessment of your infrastructure, give you tailored recommendations in plain English, and implement in priority order. Most Geelong small businesses get the biggest wins from MFA, patching, tested backups and staff awareness.

What security products do you use?

We curate rather than resell everything: our endpoint protection standard is SentinelOne, and everything we deploy is tested before it goes on site. If a product isn't worth your money, we'll say so.

Can you help with Privacy Act compliance?

Yes. We help you understand what the Privacy Act means for the customer data you hold, get sensible controls in place, and document what you've done, which is useful for insurers and enterprise customers who ask.

Can you check if our passwords are already leaked?

Yes. That is the dark web exposure check: we look up your staff email addresses against known breach data and tell you exactly what is circulating and whether it still matters, then fix what does. It is included free in an IT health check, and ongoing monitoring alerts us when a new breach names your domain.

Is a one-off security audit enough?

It's a good start, but threats and staff change. We offer implementation and ongoing maintenance of security measures plus ongoing consultation, so the protection keeps pace with the business.

Find out where your security stands

A security review tells you exactly what's exposed and what to fix first, in plain English, with no scare quotes.