What are cyber security services, and which ones does a small business actually need?
Cyber security services are the defensive functions a business buys rather than staffs: protective controls, around-the-clock monitoring, testing and incident response. A small Australian business does not need the whole menu. It needs the Essential Eight controls implemented properly, someone watching when nobody is in the office, backups that have actually been restored, and a plan for the bad day.
The menu really is confusing, and not by accident: it is sold in acronyms. So here is the translation, and it holds regardless of who you buy from. The industry's offerings fall into four groups, and every acronym you have been quoted lives in one of them. None of the four is optional knowledge for a buyer; each shows up on quotes with its own initials and its own price tag.
Group one is protective controls, the locks on the doors. Application control (tools such as ThreatLocker) means unapproved software cannot run. Patching keeps known holes closed. Multi-factor authentication (tools such as DUO) means a stolen password is not enough. Endpoint protection (Microsoft Defender and its peers) watches each computer. This is where the Essential Eight lives, and it is where most small-business risk is actually decided. If a proposal names none of these and leads with a dashboard screenshot instead, you have learned something useful about it.
Group two is watching: monitoring and detection. A SOC, or security operations centre, is the team watching alerts around the clock; MDR, managed detection and response, is that team acting on what it sees, with tools such as Huntress underneath. Group three is testing: automated vulnerability scans, human penetration tests, and audits that check your controls against a standard. Group four is the bad day: incident response, forensics, and recovery from backups with tools such as Veeam. The groupings matter more than the acronyms: once you know whether a quoted term protects, watches, tests or recovers, you can ask what it does for your business, and the sales fog lifts.
So which of it does a ten-person business need? The Australian Government has effectively already answered: the Essential Eight, implemented to Maturity Level 1, is the published baseline, and it maps to group one plus tested backups. Add monitoring, because controls without eyes on them fail silently, and a one-page plan for who you call when something gets through. That is the short list, and everything on it is buyable as a bundled monthly service. Note what is not on the list, too: nothing here requires hiring a security employee. The functions have to exist; the headcount does not.
Now the list of what you probably do not need yet: a quarterly penetration test on an environment without multi-factor authentication, an enterprise SIEM platform, or a sixty-page strategy document. Those are real services with real value at the right scale; bought too early, they are expensive ways to be told to do the basics. Apply the plain-English test to anything you are quoted: if a proposal cannot say in ordinary words which controls you are getting, the jargon is doing the selling.
On how it is bought: at small-business scale, security is usually bundled with managed IT support rather than purchased separately, which is how we price it. Our tiers map straight onto the government framework: Sentinel at $79 per user per month configures the Essential Eight foundations already inside Microsoft 365 licensing (not full Maturity Level 1), Fortress at $139 delivers complete Maturity Level 1, Knox at $179 reaches Level 2 and Titan at $199 reaches Level 3.
The honest caveat: bigger and regulated businesses do need the deeper menu. If you hold defence contracts under DISP, operate across many sites, or face contractual security obligations, testing and formal assurance stop being optional. And whoever you buy from, ask three plain questions: which Essential Eight controls are included, who is watching at 2am, and when were the backups last test-restored. Providers who welcome those questions are the ones worth shortlisting; the ones who answer with adjectives have answered anyway.
If you want the starting point measured rather than guessed, our Essential Eight Cyber Security Scorecard is free, or call us on 1800 456 567.
Which of these do you already have?
The free Essential Eight Cyber Security Scorecard measures your business against the government's own baseline and names the gaps, control by control.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business