Business

Beyond Antivirus: Building a Stronger Cyber Security Strategy

The Australian Signals Directorate’s Australian Cyber Security Centre wrapped up the 202425 financial year with a pretty daunting number: 1,253 cyber security incidents, an 11% jump from the year before. And if that wasn’t enough, over 84,700 cybercrime reports were filed during the same time frame, that’s an average of one every six minutes. The average self-reported cost for Australian businesses of a cybercrime incident was $80,850. These figures are not some pie-in-the-sky estimates, but rather actual numbers straight out of the government’s own tracking data. But rather than striking fear into the hearts of Australian businesses, these numbers call for a reality check on posture, not some knee-jerk panic.

How the Threat Landscape Changed In 2024-25?

The government’s report has some pretty telling insights into the shift in the way attackers operate, and it’s all directly relevant to managed cyber security for Australian businesses. Phishing emails generated by AI tools are getting better and better at sounding like they came from the real deal, the kind of thing that would need a human to sift through manually. And because of this, the generic red flags we were using to detect them aren’t as reliable as they used to be.

Business email compromise was still the top reason for financially impactful cybercrime for Australian businesses, and phishing cropped up in 60% of the government’s responses to incidents. DDoS attacks exploded by more than 280% year on year. Ransomware too seems to have got out of control, the government introduced a new rule on May 25, requiring businesses with an annual turnover of over $3 million to report any ransomware attacks, and their own data suggests that ransomware is now big enough that it’s worth keeping an eye on.

What Does Security Software Get You, And What Else Is There?

Antivirus software and a firewall aren’t going to cut it on their own, they aren’t a proper security posture. Managed cyber security is an ongoing process, threat monitoring, detection, response coordination, and reporting aren’t just tools that run in the background until something breaks. They’re an active function that needs people to keep working at it. What’s important is that the most costly incidents in the 202425 data weren’t the result of some tech vulnerability that software alone couldn’t detect, they were the result of people getting tricked into handing over their passwords or falling for a phishing email. It’s stuff that requires a human eye to spot.

Now, if you have enterprise-grade security tooling and someone who knows what to do with them, great, it’s highly effective. But if you just install the tools and leave them to run in the background, all you get is noise. Managed cyber security services, on the other hand, give you both the tools and the expertise you need to turn all that raw alert data into something you can actually do something with.

The Essential Eight as Australia’s Practical Baseline

The eight mitigation strategies covered by Australia’s Essential Eight include application control, patching applications, patching operating systems, restriction of administrative privileges, multi-factor authentication, restriction of Microsoft Office macros, user application hardening, and backups. This risk reduction model, rather than a compliance checklist, is based on documented attack vectors identified through actual incidents in Australia.

Level 1 focuses on the most common ways in which the system can be breached. Levels 2 and 3, respectively, tackle progressively more advanced methods. For any non-critical Australian business, the primary aim is to attain and maintain Level 1. Implementation of the Essential Eight controls by a managed cyber security provider is carried out as an ongoing process, adapting to the evolving technological landscape of the client.

What Happens During Incident Response When There Is No Plan?

The first six hours following a breach are the time in which all decisions regarding containment of the incident will influence the total costs incurred. Companies without a documented plan of incident response will have to make their containment decisions with incomplete information available: the systems to isolate, logs to protect, personnel authorised to make certain decisions, as well as Notifiable Data Breaches notification deadlines. Correct decision in each case shrinks the blast radius. Every incorrect decision enlarges it.

Managed providers’ plans of incident response take care of all of these issues in advance. Having a plan for responding to a breach tested in simulations, in managed cyber security for Australian businesses, leads to drastically different first six hours in comparison to an improvised response.

Evaluating A Managed Cyber Security Provider: What Should You Really Check?

Certifications and frameworks are a good starting point: ISO 27001 certification, partnering with government cybersecurity bodies, and capabilities of Essential Eight implementation are relevant. Reporting transparency plays a more prominent role in practical assessment: a security report that presents monthly threat activity and the number of alerts and actions undertaken is a sign of actual monitoring. Saying all is well without supporting information is not.

An integration of managed IT and managed cybersecurity services is worth considering. Fragmentation of services between two providers, managing the infrastructure and the security respectively, creates opportunities for loss of visibility. A company that provides both types of services retains the complete picture of the environment that fragmentation undermines.

Donald Wicks
the authorDonald Wicks