Cyber security coaching for Melbourne small and medium business owners

Cyber Security

Just enter your password here.

Check My Business Is Protected

You are already a target

Cyber Security — Don’t Be The Target

It’s no secret that small and medium businesses are targets for attackers. The question is what you actually need at a minimum to get the best security bang for your buck, without buying a defence budget you can’t justify.

I have extensive experience providing and educating hundreds of businesses across multiple industries and sizes on how to improve their security posture. I ran a managed services provider for fifteen years with 160 clients on the books, and I now run a managed IT and cyber business as well. This is the pillar I know best.

If you’re thinking “who would bother hacking us?”, think again. Nobody picked you personally. Attacks are automated and indiscriminate — if you’re connected to the internet, you are in scope. Small businesses get hit precisely because they assume they’re too small to be worth the effort.

Cybercrime is rising and you are on the list. Don’t be scared about it — be organised about it. I’ll introduce you to the techniques, systems and education that stop the overwhelming majority of attacks, and I’ll tell you plainly which products are worth the money and which are fear dressed up as a subscription.

Contact Rob

The bill if it goes wrong

What A Breach Actually Costs A Small Business

Owners picture a dramatic hacking scene. The reality is duller and more expensive: a fake invoice paid, a mailbox quietly forwarding to someone else, or a server encrypted on a Friday night.

  • The money you sent to the wrong account. Invoice fraud is the most common attack on Australian small business, and banks rarely get it back.
  • Days of downtime. Not one bad afternoon — rebuilding systems and restoring data takes days, and you still have wages to pay while nothing bills.
  • The clients you have to tell. Explaining that their data was in your system when it was taken is a conversation that ends some relationships.
  • Your notification obligations. Depending on what was taken, you may have legal reporting duties and a lawyer’s invoice to go with them.
  • Insurance that doesn’t pay. Plenty of cyber policies require controls like multi-factor authentication. No controls, no claim.
  • Your own time. Weeks of it, at exactly the moment you can least afford to stop running the business.

The work

The Security Basics I Put In Place First

In order, and mostly cheap. If you do nothing else on this page, do these six. They stop the vast majority of what actually happens to businesses your size.

  1. 1

    Multi-factor authentication everywhere

    Email first, then banking, accounting and your remote access. It is the single highest-value control available to a small business and it is usually included in what you already pay for.

  2. 2

    Backups you have actually restored

    An untested backup is a hope, not a backup. We test a restore, and we make sure at least one copy is somewhere ransomware cannot reach.

  3. 3

    Lock down the money process

    Never change bank details on an emailed request. Verify by phone on a number you already had. This one rule prevents the most common and costly attack outright.

  4. 4

    Patch and remove what you don’t use

    Updates applied on a schedule, old accounts disabled the day someone leaves, and software nobody uses uninstalled rather than left running.

  5. 5

    Educate your team, briefly and often

    Ten minutes every couple of months beats an annual lecture. Your staff are the control that catches what the software misses.

  6. 6

    Write the one-page plan

    Who you ring, in what order, if it happens on a Saturday. Deciding that while systems are down is how small incidents become disasters.

Book Your Free 30 Minutes

Know the enemy

The Four Attacks I See Most

Business email compromise

Someone reads your mailbox for weeks, then sends your client an invoice with different bank details. Nothing looks broken until the money is gone.

Ransomware

Files encrypted, a demand attached. Survivable if your backups are real and tested. Business-ending if they aren’t.

Credential stuffing

Your staff reused a password that leaked from some unrelated website. Automated tools try it against your systems in bulk.

The fake supplier or boss

An urgent request from the “CEO” or a familiar supplier, timed for a Friday afternoon. It targets your process, not your technology.

The payoff

What Changes In The First 90 Days Of Cyber Security Coaching

In three months a typical client goes from “we assume the IT bloke has it covered” to knowing exactly what is protected, what isn’t, and what it would cost to close the remaining gaps. Certainty is most of the value here.

Practically: multi-factor authentication is on, a test restore has actually been done, the payment-verification rule is written down and known by whoever pays the bills, and there is a one-page plan on the wall for when something goes wrong.

You’ll also stop overpaying. I regularly find businesses licensed for security features they already own and never enabled, sitting alongside a separate product sold to them for the same job. Reviewing that with your IT systems often pays for the coaching on its own — one client went from $3,500 a month in IT spend to $500.

None of this makes you bulletproof, and anyone who promises that is selling something. It makes you a harder target than the business next door, which is genuinely how this works. Read why owners pick me for this, or see the full 6 Pillars framework.

Get A Straight Answer On Your Risk

Nobody picked you personally. The attacks are automated — being small just means nobody is watching.

Robert Adelman — The No Bullshit Business Coach

Straight answers

Cyber Security Questions, Answered

We’re too small to be worth attacking, aren’t we?

That belief is exactly why small businesses get hit. Attacks are automated and scanning constantly — nobody sat down and chose your company. You are simply an address that answered.

Being small also means you are cheaper to attack and slower to notice, which makes you a better return on effort than a large company with a security team. Size is not protection.

Isn’t this my IT provider’s job?

Partly, and a good provider handles a lot of it. But the two most expensive attacks I see — fake invoices and fraudulent payment requests — target your finance process, not your network. No IT provider can fix that for you.

It also matters that someone independent reviews what your provider is actually delivering versus what you are being billed for. I’ve run a managed services provider, so I know exactly where those contracts hide gaps.

What should we spend on cyber security?

Far less than most people fear, if you spend it in the right order. Multi-factor authentication, tested backups and a written payment-verification rule cost almost nothing and stop most of what actually happens.

Beyond that, spend in proportion to what you would lose. A business holding client health or financial data needs more than a two-person landscaping company, and pretending otherwise in either direction wastes money.

Do we need cyber insurance?

For most businesses it’s worth having, but read the conditions before you rely on it. Insurers increasingly require specific controls, and if you declared you had multi-factor authentication and you don’t, expect a declined claim.

Insurance covers the cost of an incident, not the disruption or the client relationships. It is a backstop, not a strategy.

How do I get my staff to take security seriously without terrifying them?

Stop lecturing and start making it normal. Short, regular, specific reminders about the things that actually happen — an unexpected invoice, a login prompt that appeared out of nowhere — work far better than an annual policy sign-off.

Critically, never punish someone for reporting a mistake. The moment staff hide a bad click, your detection time goes from minutes to weeks and a small problem becomes an expensive one.

What do we do in the first hour if we think we’ve been breached?

Disconnect the affected machine from the network but do not wipe it. Change passwords from a different, clean device. Ring your IT provider and, if money has moved, ring the bank immediately — speed matters more than anything else at that point.

Then follow the one-page plan we wrote, which names who calls whom. Making those decisions under pressure with systems down is how people make the situation worse.

Can you look at our current setup and tell us what’s missing?

Yes, and it’s usually one of the first things I do onsite. I look at your accounts, your backups, your access, your suppliers and your payment process, and I give you a short list ranked by risk and cost.

There is no separate fee. It’s included in the flat monthly coaching arrangement set out on the business coaching cost page.

Do you sell the security products you recommend?

I’ll tell you what I think is genuinely worth buying and what isn’t, and where you already own a licence for something you never switched on. My interest is your result, not a margin on a product.

Where you need hands-on delivery I’ll point you at vetted providers from my partner network and make sure the scope and price are fair before you sign.

Let’s chat business

Free 30 Min Chat

Enter your details to book your one-on-one consultation — the first one’s on me.

No spam, no mailing list, no sales pitch. Straight to Rob.

Real business coaching client testimonials

What Clients Say About Working With Rob

Let’s chat business

Free 30 Min Chat no strings

Tell me where you’re at. The first one’s on me — no contract, no sales pitch.

No spam, no mailing list, no sales pitch. Straight to Rob. Or call 1300 59 00 82.

Call RobLet’s Chat →