Employee Offboarding Checklist for Microsoft 365
A staff member leaving? Here's the Microsoft 365 offboarding checklist Perth businesses should follow to protect data, revoke access, and stay compliant.
Cybersecurity guidance for Perth SMBs covering MFA, ransomware, email security, endpoint protection, firewalls, and staff training.
A staff member leaving? Here's the Microsoft 365 offboarding checklist Perth businesses should follow to protect data, revoke access, and stay compliant.
Old computers and hard drives contain sensitive business data. Deleting files isn't enough. Here's how Perth businesses should securely wipe and dispose of IT equipment.
Windows 10 no longer receives security updates. If you're still running it, every unpatched vulnerability from here on stays open. Here's what to check and how to plan the move.
Unpatched software is the most exploited entry point in Australian cyber incidents. Here's what patch management actually involves and how Perth businesses should approach it.
Cybersecurity spend gets knocked back more often than it should - usually because of how the case is presented, not the risk itself. Here's how to build a request that gets approved.
Staff are already using AI tools at work, policy or no policy. Here's how to write a practical AI usage policy that protects client data without banning useful tools outright.
A practical, no-jargon checklist to help Perth small businesses reduce their risk of ransomware, phishing, and data breaches.
Staying on Google Workspace? Here are the security settings Perth businesses should have enabled - 2-Step Verification, context-aware access, Vault, and more.
Ransomware attacks on Australian businesses are up 60% in two years. Here's a practical guide on how ransomware gets in - and exactly how to stop it.
Traditional antivirus misses 20–40% of modern threats. Here's what Endpoint Detection and Response (EDR) does differently and why Perth businesses need to make the switch.
Over 90% of cyberattacks start with an email. Today's phishing attempts are convincing and targeted - here's how to protect your Perth business with proven email security layers.
No security tool stops a staff member from willingly handing credentials to an attacker. Here's how Perth businesses can build an effective phishing awareness program.
Your staff's business email addresses and passwords may already be for sale on the dark web. Here's what dark web monitoring is and what Perth businesses should do about it.
MFA is the single most effective control against account takeover. Here's how Perth businesses should implement it across Microsoft 365, email, and key systems.
If your Perth business has been hit by ransomware or a data breach, the decisions you make in the first few hours determine how bad the outcome will be. Here's exactly what to do.
An IT security audit identifies vulnerabilities before attackers do. Here's what a proper IT security audit covers across identity, endpoints, network, backups, email, and policies.
Most Perth businesses have BYOD happening whether they've decided to allow it or not. Here's how to manage personal devices accessing company data securely and compliantly.
Cyber insurance is becoming essential - but policies vary enormously and claims are increasingly denied. Here's what it covers, what it doesn't, and what insurers now require.
Zero Trust replaces 'trust everything inside the network' with 'verify every request, every time.' Here's what it means practically for Perth SMBs using Microsoft 365.
FortiGate is the most widely deployed next-generation firewall in Australian businesses. Here's what Perth businesses need to know about FortiGate setup, licensing, SSL inspection, and SD-WAN.
Your network is the foundation of your business IT. Here's what Perth businesses need to know about firewalls, VPNs, DNS filtering, and keeping attackers off your network.
Weak and reused passwords are behind most data breaches. Here's how Perth businesses should manage passwords across their team - without the headaches.
Emailing attachments, personal Dropbox, and USB drives are common but create real security risk. Here's how Perth businesses should share files internally and with clients.
Social engineering is the most common entry point for cyber attacks on Perth businesses. Learn how these attacks work and how to protect your team.
What is the Essential Eight, and why does it keep coming up in insurance forms and client questionnaires? A plain-English breakdown of all eight strategies, maturity levels, and where to start.
Cyber insurance applications increasingly reference the Essential Eight. Here's what insurers actually ask about, what happens if you fall short, and how to prepare for your next renewal.
Annual security training alone isn't enough - and tends to be forgotten within weeks. Here's how often Perth businesses should actually be training staff, and what an effective program looks like.
Phishing remains the starting point for most cyber incidents we see at Perth businesses. Here are the tactics attackers actually use, the red flags to watch for, and what to do if you spot one.
What is the NIST Cybersecurity Framework, and why do insurers and clients keep asking about it? A plain-English breakdown of the six core functions and where to start.
AI is making attacks more convincing and defences more capable at the same time. Here's how AI is actually changing the threat landscape for Perth businesses, and what to do about it.
Attack surface reduction means shrinking the number of ways into your systems before an attacker finds one. Here's what it covers, and how it relates to the Essential Eight.
A written incident response plan that's never been tested is a guess, not a plan. Here's how to run a simple tabletop drill that finds the gaps before a real breach does.
If your business has a data breach, the Privacy Act may require you to report it - to the OAIC and to the people affected. Here's what the Notifiable Data Breaches scheme actually requires.
Business Email Compromise is one of the costliest cybercrime categories for Australian businesses - and it doesn't need malware to work. Here's how it happens and how to stop it.
Not all MFA is equally safe from phishing. Here's the difference between SMS codes, app-based MFA, and phishing-resistant options like passkeys - and which is realistic for your business.
ISO 27001 sounds like an enterprise-only certification, but small businesses can pursue it pragmatically. Here's what it actually involves and whether it's worth it for your business.
A cloned voice asking for an urgent transfer is no longer science fiction. Here's how deepfake scams actually target businesses, the warning signs, and how to build a response process.
ASD has announced plans to retire the Essential Eight over the next two years in favour of a broader Essentials series. Here's what's changing, why, and what to do about it now.
If you're partway through an Essential Eight uplift, ASD's retirement plan doesn't mean stop. Here's what to check before you invest further.
If your Essential Eight assessment felt like a forced fit for a Microsoft 365 or SaaS-based business, you weren't imagining it. Here's the gap ASD's new Cloud chapter aims to close.
ASD is retiring the Essential Eight over the next two years. Here's a practical checklist for what Perth businesses should actually do during the transition.
ASD is already considering a fourth Essentials chapter for agentic AI. Here's what agentic AI security actually means, and why prompt injection is a new kind of threat.
A new cybercrime report shows AI already finding zero-day exploits and powering malicious AI marketplaces. Here's what it means for Perth businesses.
Gartner's Top 10 Strategic Technology Trends for 2026 is written for enterprise CIOs. Here's which parts actually matter for a Perth small business.
Verizon's 2026 breach report shows ransomware rising and SMBs squarely in the blast radius. Here's what it means for Perth businesses.
IBM's 2026 Cost of a Data Breach Report puts the average breach at nearly USD 5 million. Here's what the numbers actually mean for a Perth small business.
CrowdStrike's 2026 report shows attacks breaking out in under 30 minutes, often without malware at all. Here's what that actually means for a Perth business.
DNS filtering blocks malicious and risky websites before a connection is even made. Here's how it works, what it stops, and what it costs for Perth businesses.
Your security is only as strong as your weakest vendor. A practical, right-sized guide to third-party and supply chain risk for Perth SMBs.
Most security spending targets outside attackers - but a real share of incidents involve someone already inside. What insider risk actually looks like.
Most Perth businesses use Microsoft 365 for email and Teams but leave powerful built-in security features untouched. Here's what you should have enabled right now.
Conditional Access lets you control exactly when and how staff can sign in to Microsoft 365 - but it's not a replacement for MFA or good account hygiene. Here's what it actually does.
Intune lets Perth businesses manage all laptops, phones, and tablets from the cloud - enforcing security policies, deploying software, and wiping lost devices without on-premise infrastructure.
Not sure whether to choose Microsoft 365 Business Standard or Business Premium? Here's a plain-English comparison to help Perth businesses pick the right plan.
Most Perth businesses don't have a disaster recovery plan until they need one. Here's a practical guide covering RTO, RPO, recovery runbooks, and how to test your plan.
Sharing your main office WiFi with visitors is a serious security risk. Here's how to set up a proper guest network that keeps your business data completely separate.
A plain-English guide to business VPNs for Perth companies - remote access vs site-to-site, when you need one, platforms, costs, and common mistakes.
Dental practices run practice management software, digital imaging systems, and handle sensitive patient data. Here's what secure, compliant IT support looks like for a Perth dental clinic.
Law firms and accounting practices hold some of the most sensitive client data of any business. Here's what purpose-built, compliant IT support looks like for Perth professional services.
Perth schools manage hundreds of devices, sensitive student data, and complex networks. Here's what modern, compliant IT support looks like for independent and private schools.
Schools hold sensitive student and family data, making staff and admin accounts a real target. Here's a practical approach to MFA for school staff - and what to do about student accounts instead.
Physiotherapists, psychologists, chiropractors, and GPs face strict patient data obligations. Here's what compliant, reliable IT support looks like for Perth allied health practices.
Aged care and NDIS providers face strict data privacy obligations, clinical system requirements, and compliance pressures. Here's what specialist IT support looks like for this sector.
Perth mining services companies face unique IT challenges: FIFO staff, remote sites, and contractor compliance. Here's what good IT support looks like.
Perth accounting firms hold sensitive client financial data, access the ATO portal, and run specialist practice management software. Here's what proper IT support looks like for accountants.
Business Email Compromise targeting law firm trust accounts has a higher payout and lower detection rate than ordinary invoice fraud. Here's how it happens and how to stop it.
Contracts, Form 1s, and settlement documents move fast in real estate - and that speed is exactly what scammers exploit. Here's how Perth agencies secure the workflow.
POS terminals handling card data are a real target for skimming and network attacks. Here's what Perth cafes, restaurants, and hotels need for PCI-aware POS security.
Perth retailers depend on POS, payments, and stock systems as much as any office business. Here's what proper retail IT support actually covers.
Childcare centres hold some of the most sensitive family data of any small business, with lean admin teams. Here's what proper childcare IT support covers.
Ransomware, an outage, or a compromised account - the first hour matters most. Here's what Perth businesses should do before help arrives, and what to avoid doing.
Isolating systems, finding the last clean backup, and restoring - here's what actually happens during ransomware recovery, how long it takes, and why paying rarely helps.
Before you roll out ChatGPT or Copilot business-wide, check these six things first. A practical AI readiness checklist for Perth SMBs, plus a free self-assessment.
EDR is the technology. MDR is who's actually watching it at 2am. Here's what Managed Detection and Response covers, and whether your Perth business needs it.
NDIS Practice Standards audits check more than policy documents. Here's what auditors actually look for in your IT and data handling, and how to prepare.
October is Cyber Security Awareness Month in Australia. Here's a practical 4-week action plan Perth businesses can actually run, not just a poster on the wall.
Black Friday and Cyber Monday bring a spike in phishing and fake invoice scams. Here's how Perth businesses can protect staff and finances this shopping season.
QR codes bypass the link scanning most email security relies on. Here's how quishing scams work and how Perth businesses can defend against them.
MFA stops most account takeovers, but push-bombing attacks target the human approving the prompt, not the code itself. Here's how it works and how to stop it.
Staff are pasting client data into free AI tools whether there's a policy or not. Here's how to find out what's actually being used, and what to do about it.
These terms get used interchangeably, but they're different services at different price points. Here's what each actually covers, and which your business needs.
Entra ID (formerly Azure AD) controls who can sign in to everything in your Microsoft 365 tenant. Here's what it actually does in plain English.
Business Premium caps at 300 users, and E5's security add-ons aren't only for large enterprises. Here's when a growing Perth business should consider E3 or E5.
Vet clinics run practice management software, digital imaging, and lab integrations that can't go down mid-surgery. Here's what proper veterinary IT covers.
An empty office over the holidays is when attackers move fastest. Here's the IT shutdown checklist Perth businesses should run before closing up.
A disaster recovery plan gets your systems back. A continuity plan keeps the business running while that happens. Here's why Perth businesses need both.
Firewalls and MFA don't matter if anyone can walk up and unplug the server. Here's what proper physical security for a comms or server room actually covers.
Purview can stop a staff member emailing a client spreadsheet to their personal Gmail before it happens. Here's what data loss prevention actually covers.
One flat network means a compromised guest device can reach your file server. Here's how VLAN segmentation keeps guest, IoT, and business traffic apart.
Membership software, access control, and recurring payments all depend on IT that just works. Here's what proper IT support covers for a Perth gym or studio.
The ACSC advises against paying. Here's what Perth businesses actually need to weigh, backups, downtime cost, and why payment doesn't guarantee recovery.
Financial planning practices hold detailed client wealth data and carry AFSL obligations around record keeping. Here's what proper IT covers.
Anyone can send an email pretending to be you unless three DNS records say otherwise. Here's what SPF, DKIM, and DMARC each do, and where Perth businesses usually get them wrong.
Where your data physically sits and whose laws can compel access to it are two different questions. Here's what data sovereignty and residency actually mean for a Perth business.
CPS 234 directly regulates APRA-licensed entities, but its security requirements increasingly flow down to the advice practices and providers around them. Here's what it actually requires.
If your IT provider holds your domain, admin accounts, or licences in their name, you don't fully own your own business. Here's how to check and fix it.
Cybersecurity assessment pricing varies widely by scope, from a basic review to a full penetration test. A realistic cost breakdown for Perth businesses.
Hardware is just the starting cost - licensing and management usually add up to more over the firewall's life. The real cost for Perth businesses.
Permissions creep silently over years of role changes and shared links. Here's how Perth businesses can actually audit who has access to what in Microsoft 365.
The first 15 minutes after a compromised Microsoft 365 account matter most. Here's the exact sequence Perth businesses should follow, in order.
Ransomware increasingly targets backups first. Immutable backups can't be encrypted or deleted, even by an attacker with admin access. Here's how they work.
Admin accounts are the single highest-value target in your Microsoft 365 tenant. Here's how Perth businesses should actually lock them down.
Most small businesses run on unwritten IT rules until something goes wrong. Here's the core set of IT policies every Perth business should have in writing.
Copilot surfaces whatever your permissions already allow it to see, oversharing included. Here's what to check before rolling it out.
Files shared externally rarely get un-shared once the reason for sharing has passed. Here's how to find and clean up external sharing in Microsoft 365.
Financial planning practices hold detailed client wealth data and carry AFSL-linked obligations. Here's a practical cybersecurity checklist for the sector.