SME Australian cyber security consultancy

Plain-English Essential Eight for Australian SMEs.

Most small businesses do not need a security department. They need someone to find the handful of gaps a real attacker would use, close them, and keep checking. That is the whole job, and we do it without jargon.

No certifications claimed. No scare tactics. Fixed fee before we start.

Essential Eight maturityIllustrative
Patch applications72%
Patch operating systems64%
Multi-factor authentication88%
Restrict admin privileges46%
Application control28%
Restrict Office macros55%
User application hardening38%
Regular backups80%

Illustrative layout only — the figures above are placeholders, not data about any business. Your audit reports your actual maturity level (0–3) for each control against the ASD model.

What we do

Three pillars, one engagement.

Security, the data you are legally responsible for, and getting rid of data safely when you are done with it.

Cyber security

We assess your Essential Eight maturity against the ASD's own model, tell you the level you are actually at, and close the gaps in priority order.

  • Essential Eight maturity assessment (levels 0–3)
  • MFA, patching and admin-access review
  • Backups that get restore-tested, not just scheduled
  • Prioritised fix list with effort estimates
Cyber security in detail →

Data protection

What personal information you hold, whether the Privacy Act applies to you, and whether you could actually meet the 30-day breach assessment deadline.

  • Personal information mapping
  • Privacy Act and APP applicability check
  • Notifiable Data Breaches readiness
  • Breach response plan you could follow under pressure
Data protection in detail →

Data destruction

Secure sanitisation and disposal of drives, laptops, phones, tapes and paper — with a certificate of destruction for every asset.

  • Cryptographic erase and verified overwrite
  • Physical destruction of failed media
  • Serial-tracked chain of custody
  • Certificate of destruction per asset
Data destruction in detail →
How it works

Audit → Fix → Monitor.

A one-off audit that finds and closes your breach gaps, then a monthly subscription that keeps them closed.

01

Audit

One engagement that covers both halves of the problem: your Essential Eight maturity and your Privacy Act / Notifiable Data Breaches readiness. You get a findings report in plain English, a prioritised remediation plan, and a fixed-fee quote for the work.

02

Fix

We close the gaps that matter most first — MFA everywhere, patching that actually runs, admin rights trimmed back, backups restore-tested. You can do the work yourself with our plan, or we do it. Either way you keep the documentation.

03

Monitor

A monthly subscription that re-checks your controls, tracks what drifted, keeps your breach-response plan current and reports what changed. Security is not a project that finishes; it is a state you hold.

The numbers

Why this is worth an afternoon of your time.

Every figure below is from an Australian government source and linked. We do not use statistics we cannot point you to.

$56,571
Average self-reported cost of cybercrime per report for an Australian small business in FY2024–25 — up 14% on the year before.
Every 6 min
How often a cybercrime report was made to ReportCyber in FY2024–25 — more than 84,700 reports in the year.
1,205
Data breach notifications received by the OAIC in the 2025 calendar year — an all-time high, up 8% on 2024.
Sources
  1. Australian Signals Directorate, Annual Cyber Threat Report 2024–25 — small business average self-reported cost of cybercrime $56,571 (up 14%); over 84,700 cybercrime reports to ReportCyber, an average of one report every 6 minutes; ASD's ACSC responded to over 1,200 cyber security incidents, an 11% increase; 11% of those incidents included ransomware.
  2. Office of the Australian Information Commissioner, Data breach notifications increase to all-time high in 2025 (published 6 July 2026) — 1,205 notifications in the 2025 calendar year, an 8% increase on 2024 (1,112); 716 of those (around 59%) attributable to malicious or criminal attack; health service providers the most affected sector at 19% of notifications. Ongoing figures: OAIC Notifiable Data Breach statistics dashboard.
  3. Australian Institute of Criminology, 2024 Australian Cybercrime Survey, as cited in the ASD report above — 22% of surveyed SME owners said their business was impacted by cybercrime in 2024.

What we are not claiming. We have no idea what your risk is until we look, and neither does anyone else quoting you a percentage. These numbers describe the Australian SME population, not your business. The point of the audit is to replace averages with facts about you.

Questions

Straight answers.

What is the Essential Eight, in plain English?

The Essential Eight is a list of eight practical things the Australian Signals Directorate says stop most cyber attacks: patch your apps, patch your operating systems, turn on multi-factor authentication, limit who has admin rights, control which programs can run, restrict Office macros, harden browsers and apps, and keep backups you have actually tested.

That is the whole idea. It is not a certification and it is not a product — it is a checklist with maturity levels 0 to 3 so you can see how far along you are. See the ASD's own pages: Essential Eight and the Essential Eight Maturity Model.

Do you hold any certifications or accreditations?

No, and we will not pretend otherwise. oowl is not ISO 27001 certified, not IRAP assessed, not ASD-endorsed and not government-accredited. We hold no security certifications at all.

What we do is apply frameworks the Australian government publishes for free — the ASD's Essential Eight Maturity Model and the OAIC's privacy guidance — to your business, and show you in plain language where you sit and what to fix first.

If a contract, tender or insurer requires a certified or accredited assessor, we will tell you that up front and point you to one. Losing the work is better than misleading you about what our sign-off is worth.

What happens in the free security check?

A 30-minute call, no charge and no obligation. We walk through how your business actually works — what systems you use, who has admin access, where customer data lives, what your backups look like, and whether anyone has ever tested them.

At the end you get a plain-English summary of the gaps we can already see and what an audit would cover. If your setup is already in decent shape, we will say so rather than invent work.

What does the one-off audit cover?

Two things in one engagement. First, your Essential Eight maturity — we assess each of the eight controls against the ASD maturity model and report the level you are genuinely at, not the level you hoped for.

Second, your Privacy Act and Notifiable Data Breaches readiness — what personal information you hold, whether the Privacy Act applies to you, whether you could detect a breach, and whether you could actually meet the 30-day assessment obligation if one happened.

You get a findings report, a prioritised remediation plan with effort estimates, and a fixed-fee quote for anything you want us to close ourselves.

What does the monthly subscription include?

Continuous monitoring and auditing instead of a report that goes stale. Each month we re-check your Essential Eight controls, track patch and MFA coverage, watch for new exposure, keep your breach-response plan current, and send you a short report showing what moved and what still needs attention.

It is a subscription, not a lock-in contract. You can stop it and keep every document we produced.

Does the Privacy Act even apply to my small business?

Maybe not — and that is worth knowing either way. The Privacy Act generally does not apply to businesses with an annual turnover of $3 million or less. But there is a long list of exceptions that pulls small businesses back in: private health service providers (including allied health and gyms with health data), anyone who buys or sells personal information, Commonwealth contractors, credit reporting bodies, businesses accredited under the Consumer Data Right, residential tenancy database operators, and more. See the OAIC's list of who the Act covers.

Plenty of businesses that assume they are exempt are not. We check this early, because it changes what you are legally required to do.

If we have a breach, what are we actually required to do?

If the Privacy Act applies to you and you suspect an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to finish it within 30 calendar days of becoming aware of the grounds for suspicion (s 26WH(2) of the Privacy Act). If it is an eligible data breach, you notify both the affected individuals and the OAIC.

The OAIC states it expects entities to treat 30 days as a maximum, not a target. Details: OAIC — Notifiable Data Breach scheme and about the NDB scheme.

Most businesses we speak to could not currently tell whether a breach had happened at all, let alone assess it in 30 days. That is the gap we close.

How does data destruction work, and do we get proof?

Yes — a certificate of destruction for every asset, listing the make, model and serial number, the sanitisation or destruction method used, the date, and who witnessed it. That certificate is the evidence you keep for your own records, your auditor or your insurer.

The method depends on the media. Self-encrypting drives can be cryptographically erased, standard drives get a verified overwrite or a firmware secure erase, failed and end-of-life drives are physically destroyed, and tapes and magnetic media are degaussed or shredded. We follow the sanitisation guidance in the ASD's Information Security Manual. See data destruction for the full matrix.

What does it cost?

The security check is free. The audit is quoted as a fixed fee once we know your scope — how many staff, how many devices, how many systems — and you see that number before any work starts. The monthly subscription is priced off the same scope.

We do not publish a price list because a five-person business and a fifty-person business are not the same job, and a number on a page would be guesswork. Ask on the call and you will get a real figure.

Who is behind oowl?

oowl is a Melbourne-based consultancy operating as Mohamed Arshad Shafan trading as oowl, ABN 35 545 025 212. We work with small and medium businesses across Australia, remotely and on site where it is needed. More on about.

Find out where you actually stand.

A 30-minute security check, free, no obligation. If your setup is already solid we will tell you that.

Book a free security check