News & Insights
Blog
Plain explanations of what Australia’s small-business cyber standard actually asks for, including when the cheap answer is the right one.
Series
The SMB1001 controls that aren’t about technology
Four of the standard’s controls are physical or about people, and they are the ones businesses most often over-buy for. Each of these explains what the control actually requires, the simple way to satisfy it, and when spending more is genuinely worth it.
Control 17 · Silver
SMB1001 wants a visitor register. A notebook will do.
Why a cyber standard cares about your front door, what the six-month retention means, and the one privacy reason to go electronic.
· 4 min read
Control 24 · Gold
Secure document destruction: what the standard actually requires
Cross-cut shredder and a written procedure, or an accredited service issuing certificates, and how to tell which you need.
· 5 min read
Control 25 · Gold
That old laptop you sold is still your problem
Deleting files does not remove them. Crypto-erase, ATA secure erase, and when you actually need a certified per-device report.
· 6 min read
Control 38 · Diamond
Police vetting: what SMB1001 asks for, and what it costs
An accredited online check, cheap and routine, and why the written policy matters more than the certificate.
· 4 min read
Interactive
Eight things wrong with this office
Find the SMB1001 failures hiding in an ordinary small business office, and what each one costs to fix. Six of the eight are free.
Start here
SMB1001 certification, end to end
The five tiers, what each one requires, how the process works and what a gap assessment costs.