Why every Australian business needs a cyber security posture check
Cyber attacks on Australian businesses are at record highs, and small and medium businesses are now the most common target. The Australian Signals Directorate receives a cybercrime report roughly every six minutes, and a single incident can cost an SME tens of thousands of dollars in downtime, recovery and lost customer trust. Most breaches don’t rely on sophisticated hacking — they exploit everyday gaps like missing multi-factor authentication, unpatched software, weak or untested backups, and staff who were never trained to spot a phishing email.
A security posture assessment gives you a clear, honest picture of where those gaps are — before an attacker, or an auditor, finds them first. CyberSafeCheck turns the recognised Australian and international security frameworks into plain-English questions, scores your answers instantly, and hands you a prioritised action plan you can act on today. It’s free, takes about five minutes, and there’s no sales call required.
What the assessment covers
Every organisation, regardless of size or industry, shares the same security fundamentals. The standard CyberSafeCheck assessment measures your posture across six core control areas:
- Access & identity — multi-factor authentication, admin privileges, strong passwords and prompt offboarding when staff leave.
- Devices & patching — operating system and application updates, endpoint protection, full-disk encryption and application hardening.
- Email & phishing — advanced filtering, SPF, DKIM and DMARC, security-awareness training and protection against invoice and payment fraud.
- Backup & recovery — automated, tested and offline or immutable backups, plus a documented disaster-recovery plan.
- Governance & risk — written security policies, an incident-response plan, third-party and vendor risk, and an up-to-date asset inventory.
- Data protection & privacy — knowing where personal and sensitive data lives, encrypting it, and being ready to meet your breach-notification obligations.
Prefer something tailored? Choose your industry for a version that adds the compliance obligations and threats specific to your sector — from PCI-DSS for retailers, to patient-data handling for healthcare, to trust-account protection for legal and accounting firms.
The compliance frameworks we check against
CyberSafeCheck maps your answers to the standards Australian businesses are most often measured against — so you can see not only where you’re exposed, but which obligations you’re already close to meeting.
The Essential Eight
Developed by the Australian Signals Directorate (ASD), the Essential Eight is the baseline set of eight mitigation strategies every Australian organisation is encouraged to implement, measured across maturity levels zero to three. It covers application control, patching applications and operating systems, configuring Microsoft Office macros, user application hardening, restricting administrative privileges, multi-factor authentication and regular backups. Read our plain-English Essential Eight guide.
ISO 27001
ISO/IEC 27001 is the leading international standard for an information security management system (ISMS). Certification is increasingly demanded in tenders and enterprise contracts, and signals to customers that you manage information security in a structured, audited way. Learn what ISO 27001 means for Australian SMBs.
The Privacy Act & Notifiable Data Breaches
The Privacy Act 1988 and the Australian Privacy Principles govern how you collect, store and use personal information, while the Notifiable Data Breaches (NDB) scheme requires eligible breaches to be reported to the OAIC and affected individuals. Understand your Privacy Act and NDB obligations.
SMB1001
SMB1001 is a tiered cyber security standard designed specifically for small and medium businesses, with five progressive levels — Bronze, Silver, Gold, Platinum and Diamond. It offers an achievable, affordable path to demonstrable cyber maturity. See how the SMB1001 tiers work.
PCI-DSS
If your business accepts card payments, the Payment Card Industry Data Security Standard (PCI-DSS) sets the security requirements for handling cardholder data, whether in-store or online. Find out what PCI-DSS requires.
Who CyberSafeCheck is for
CyberSafeCheck is built for Australian small and medium businesses across every sector. As well as a standard test for any organisation, we offer industry-specific assessments tailored to the risks and obligations of:
- Finance & accounting — trust accounts, client financial data and payment-fraud defences.
- Healthcare & medical — patient records, My Health Record requirements and health-data privacy.
- Legal & professional — client confidentiality, legal privilege and settlement-fraud protection.
- Retail & eCommerce — PCI-DSS, online storefronts, POS systems and customer data.
- Construction & trades — large progress payments, mobile site devices and project IP.
- Manufacturing & industrial — operational technology, legacy machinery and supply-chain links.
- Education & training — student data, learning platforms and online safety.
- Professional services — client data confidentiality, contractual obligations and remote work.
- Technology & SaaS — source code, cloud infrastructure and customer data at scale.
What you get
- An instant posture score out of 100, with a clear Strong / Good / Fair / Needs-attention rating.
- A breakdown by area so you can see exactly where your strengths and weaknesses lie.
- A prioritised action plan that tells you what to fix first, mapped to the relevant framework.
- A downloadable PDF report you can keep, share with your team or take to your IT provider.
- Optional expert help — request a callback and one of our trusted security partners will review your results and help you remediate, at no cost or obligation.
How it works
- Answer the questions. Honest yes / partly / no answers across the key control areas, scored instantly with no sign-up required.
- Get your score. An instant 0–100 posture score, a breakdown by area, and a prioritised action plan mapped to recognised frameworks.
- Act on it. Download your PDF report, or request a callback and have a specialist walk you through the priority fixes.
Frequently asked questions
Is CyberSafeCheck really free?
Yes. The assessment, your instant score and your downloadable PDF action plan are completely free, with no sales call required.
How long does it take?
The quick check is about 20 questions and takes roughly five minutes. The comprehensive assessment is more detailed and takes around 12–18 minutes.
Is this a formal audit or certification?
No. CyberSafeCheck is an educational self-assessment that highlights likely gaps and compliance exposure. For formal certification — such as ISO 27001 or SMB1001 — or a formal Essential Eight maturity assessment, you’ll need a qualified assessor, which our partners can arrange.
What happens to my answers?
Your results — your score and answers — are shared with our team when you complete an assessment, so we can see how the tool is helping and follow up if you’d like. Your personal contact details are only included if you choose to provide them or request a callback, and we never sell your data.
Who will contact me if I request help?
If you request a callback, one of our trusted security partners will review your results and contact you to help you remediate the gaps — with no cost or obligation.
Which frameworks does it cover?
Depending on the test you choose: the Essential Eight, ISO 27001, the Privacy Act and Notifiable Data Breaches scheme, SMB1001 and PCI-DSS.
Ready to see where you stand?
Take the free CyberSafeCheck assessment now and get your security posture score, compliance check and action plan in about five minutes.