Is Your Cybersecurity Good Enough, and Can You Prove It?
The Cyber Maturity Session: What Certification Actually Proves
More organisations are being asked to prove their cybersecurity maturity, not just claim it. This session breaks down the difference between having good security and being able to demonstrate it, and walks through the two frameworks that make that proof possible for Australian small and medium businesses: the Essential Eight and SMB1001.
Ben and Cameron also share what Grassroots IT learned going through SMB1001 Gold certification themselves, including what actually changed, and what surprised them along the way.
Access This Webinar
In this practical webinar, Ben and Cameron share what it actually takes to move from having good cybersecurity to being able to prove it, using the two frameworks most relevant to businesses your size.
In this Webinar
- Why security is now a leadership conversation
It sits with owners and boards, not only the IT team.
- The difference between having it and proving it
Demonstrable maturity is what clients, insurers and procurement teams now ask for.
- How the Essential Eight and SMB1001 work together
One hardens your technical core, the other turns it into a certifiable credential.
- Which level is right for a business your size
SMB1001’s five tiers, Bronze to Diamond, let you climb at a sensible pace.
- What a gap assessment involves
A low-risk first step to find out exactly where you stand, with no obligation.
The following additional resources are mentioned or referenced in the webinar.
Ben founded Grassroots IT in 2005 and has spent close to two decades helping Brisbane businesses adopt technology that actually supports how they operate. He led Grassroots IT’s own SMB1001 Gold certification and is a regular voice on what practical cybersecurity leadership looks like for growing SMEs.
Cameron is Grassroots IT’s Senior Cybersecurity Engineer and led the business through its own SMB1001 Gold certification from the inside. He works with clients daily on Essential Eight uplifts, SMB1001 pathways and practical, non-scary cybersecurity roadmaps.
Ben Love [00:00:00]:
Morning, everybody, and welcome to today’s webinar here with Grassroots IT. We will be talking about, is your cybersecurity good enough? And importantly, can you prove it? So this question is one that we are getting asked more and more these days. So we thought it was a good idea to share a little bit of background on what we’re seeing in the industry. And across our clients and across the marketplace. So the question here is not just about whether cybersecurity is good enough, but when people ask that question, what can we, what can we respond with? So just some quick introductions, and I’m turning on Cameron there. Welcome to Grassroots IT. Grassroots IT is a Brisbane-based Microsoft-focused MSP. We specialise in complex and high compliance industries, and we recently achieved the SMB 1001 Gold certified standard ourselves.
Ben Love [00:01:05]:
We’ve been around since 2005. We’ve been doing this for a while, and we have also walked this path ourselves. I would like to introduce you to Cameron Fairfull, who’s here with me today. Cameron is our senior cybersecurity lead, and he will be walking through this presentation with me today. Good morning, Cameron.
Cameron Fairfull [00:01:24]:
How are you? Good morning, Ben. I’m well, thank you.
Ben Love [00:01:28]:
Excellent. So here’s a quick agenda for today. We will be taking no more than 45 minutes for what we’re talking through here. We do have room for Q&A at the end there. If you do have questions or comments as we go, please drop them into the Q&A chat thingy here in Microsoft Teams, and we will respond to those at the end in our Q&A time. This webinar is also being recorded, so we will make this recording available afterwards. You may find that this is a useful recording to share with other people on your team if you think some of these messages need to, need to be heard by other people on your team. So keep an eye out for that email letting you know when that recording is available.
Ben Love [00:02:14]:
So this is really one of the big shifts that everybody needs to be aware of at the moment. Cybersecurity really has become a leadership responsibility in recent years, not just an IT task. And what I would encourage you to think about there as business leaders is really your own risk register for the organisation. You’ll be keeping a very close, close eye on things such as cash flow, safety, reputation. Cybersecurity sits right along those— alongside those things these days. So a serious cybersecurity incident can It can disrupt cash flow. It can impact safety. It can impact reputation in a big way and all of the other risks that we look at.
Ben Love [00:02:59]:
So once a risk is really sitting at that level, it really becomes a governance issue. And this is where leadership needs to be owning the conversation and not have it delegated down to, down to an IT team. The key thing to keep in mind with all of this, though, is that it’s not just about technology. Is that you can’t outsource that responsibility. You can outsource some of the work. You can certainly seek external technical expertise, but the responsibility ultimately rests with you and business leadership. So a good IT partner is very critical to making all of this work. At Grassroots IT, we take this responsibility very seriously.
Ben Love [00:03:40]:
But the fact is that when an insurer, when an industry regulator, when one of your major clients comes asking about who is responsible and accountable for securing your business, the answer, the answer is that you are. Ultimately, this is a business leadership issue and not something that can be outsourced to the IT department, to the MSP, or what have you. The good news here, of course, is that you don’t— do not have to carry that responsibility alone. The right IT partner helps, and also cybersecurity frameworks really help carry a lot of that load as well. And that’s where we’re going to be talking about today. So more and more, the people you’ll be doing business with, whether this is upstream or downstream clients, suppliers, they’re not going to be asking as much anymore about whether you’re taking your cybersecurity seriously and asking you to complete checklists. They really are going to be asking that you can demonstrate the level of cyber maturity that you have in the business. And this is where cybersecurity certifications really start to, start to carry their weight.
Ben Love [00:04:54]:
So insurers can be asking these questions more and more, particularly around cyber insurance policies, but also in, in other more generalist and broader policies. So the The better positioned you are to navigate more— negotiate more favorable terms for yourself. Procurement teams are starting to hit these questions here. Supplier questionnaires are now asking for evidence and certification of these levels, and also larger partners that you may be doing business with are really scrutinizing their supply chains more and more. And they want to be doing business with business partners who themselves are cyber secure, who have a high level of cyber maturity, because as we’ve seen with some high-profile incidents over the last few years, that supply chain disruption risk is, is very, very real and something we all need to be very cognizant of. So what does Having good security look like versus being able to prove it? Well, having good security means that you have the controls in place. You have the cybersecurity software, you have the firewalls, you have the policies, you have the configurations, you have all of those things in place. So the protections are actually present in your organisation.
Ben Love [00:06:22]:
But as we’ve just touched on, that’s not necessarily enough anymore. You need to be able to prove it, right? And this can often just come down to having the same controls in place, but just having them documented within a recognised framework, and in some cases independently verified and demonstrable that these controls are actually in place and doing what they need to be doing. So this comes down to the evidence, the documentation, certification, and sometimes third-party verification. Cameron.
Cameron Fairfull [00:06:59]:
Thanks, Ben. So how do we, how do we do it? There’s plenty of frameworks out there. Some you may know, some you may not know. Some of the, some of the bigger names that stand out are NIST, ISO 27001, CIS SOC 2. These are all used worldwide and used in various different ways. But the 2 in particular that we wanted to talk about today were Essential 8 and SMB 1001. If you go to the next slide, Ben. So first, why bother with ISO? With a framework.
Cameron Fairfull [00:07:45]:
Why do frameworks exist? And without them, you’re chasing your tail. And a lot of the time you’re just chasing after what the most recently focused on security item was. And frameworks fix that. They give you a clear methodical path to be able to work through the framework from start to finish and know that when you come out the other end, you have achieved something that is recognised by most organisations. It lets you budget as well and spend your money where it counts. So rather than guessing or overbuying on products or, or implementing controls that may cover one particular item. It lets you budget and make sure that you are getting the biggest bang for your buck. And it’s demonstrable to third parties.
Cameron Fairfull [00:09:00]:
So you show to, you show to your third parties that the controls that you’ve put in place align with the framework, and it is very demonstrable to everybody that those controls are in place and working. So the first framework is the Essential 8. Now, before I talk about the Essential 8, a few of you may have heard recently that the Australian Signals Directorate has announced that they are changing the Essential 8 to a new framework called called the Essentials. The Essentials is currently under construction, and there will be some timelines released for when the Essential 8 will be retired and moved to Essentials. The, the total timeframe that’s being reported at the moment will be about 36 months. But if you’ve been working on Essential 8, you don’t need to worry because All of the frame— all of the groundwork that you’ve put in for your Essential 8 controls now will actually carry over to the new Essentials. So the Essentials is being designed to fit with more modern businesses. Essential 8 was built when a lot of businesses were on-prem, and now businesses have moved away from having You know, that server in the corner and all of those systems that are running out of their office, and instead everything is internet-based.
Cameron Fairfull [00:10:46]:
So if we go back and look at the Essential 8, it is a baseline from the Australian Cybersecurity Centre with 8 technical strategies that help you Cover most of the common attack paths that happen across organisations. The strategies fit into multi-factor authentication, patching, application control, restricting administrative rights, and regular backups. And if you’re doing them right, you stop the majority of the attacks. You stop the attackers being able to gain access to systems. You stop the attackers being able to make changes to systems if they do manage to get in. And these controls are measured across a number of levels. So organisations generally start at level 0, where they haven’t done any assessment at all, and then slowly progress through the 3 maturity levels. So level 1, level 2, and level 3.
Cameron Fairfull [00:11:58]:
These escalate in technical And monitoring controls as you progress through the levels, Level 1 being the baseline through to Level 3 having the most control in place to ensure that you are covered from every area. Next slide, please. And the second framework that we wanted to talk about And this is possibly a little bit newer for a lot of the people in here, is SMB 1001. And this is the one that we get a little bit more excited about now. So not only is Grassroots IT Gold Certified for SMB 1001— SMB 1001 is designed for, for small to medium enterprises. So it’s not the scaled-down version of an enterprise framework that is really designed for, you know, for that, for much larger businesses. It has 5 tiers. So it starts at Bronze, it goes Silver, Gold, Platinum, and Diamond, and you can climb through those tiers as you mature your cybersecurity in your organisation.
Cameron Fairfull [00:13:26]:
It covers a similar range of items that the Essential 8 does. So it covers technology, it covers access, it covers backup, but it also includes policies and training, which is something that the Essential 8 misses the mark on a little bit. And at the lower tiers, you don’t need to have any independent auditors complete them, complete these audits for you. It’s actually self-attested by a company director. So grassroots, it’s gold, and the gold level is something that is very easily achievable for all organisations. So what Which framework should you prioritise? Should it be Essential 8? Should it be SMB 1001? Or can you do both? Well, it really depends on what you’re trying to achieve. Are you trying to harden your technical controls and your technical core of your organisation? Or are you looking for something that has a little bit of mix, a little bit of a mix of everything? So it has some technical controls, it has some policy, And some, some other areas within the framework that spread across your organisation. Some industries are regulated and require a certain framework, and it’s easy to work to those.
Cameron Fairfull [00:15:10]:
There’s not really any wrong door when you’re looking at your framework and which one to prioritise. It just depends on what is driving that cybersecurity conversation for you and where the question came from of what cybersecurity framework do you have in place. So if we put them side by side, the Essential 8 was built for all organisations, and it’s government-aligned. SMB 1001 was built specifically for small and medium businesses. The Essential 8 focuses on the 8 technical mitigations, while the SMB 1001 is broader and it wraps up access, backup, policy, and training. Essential 8 has 3 maturity levels, whereas SMB 1001 Has the 5 tiers. And how do you prove it? Essential 8 is either self or independently assessed. SMB 1001 gives you a formal certificate at the end.
Cameron Fairfull [00:16:26]:
And then as you go through the tiers, is externally audited at, at the higher levels. So if you think about the Essential 8, it is 8 technical controls that give you a baseline, and SMB 1001 is the business credential that you can actually show people at the end to say, these are the controls that we have in place. And that leads me to the message that I really wanted to land here, is that they’re complementary and not competing. So the Essential 8 strengthens the technical core, and the SMB 1001 simply wraps it all up and turns it into something that you can show to an insurance agency or a business that you’re trying to work with that you are— you have those controls in place, and it’s Certified, and they fit together neatly to make sure that you have a good mix of both the technical control and the policy to help drive your cybersecurity for your organisation. That’s me. Oh no, apologies, wrong slide. So what does our Gold certification mean? So we went through this ourselves, and here’s what we actually learned when we went through OSMB 1001 Gold certification. It took us about 6 months start to finish.
Cameron Fairfull [00:18:19]:
When, when we completed our initial assessment, we realised that we were, we were doing things right. But we just simply hadn’t written things down. We, we were ticking all the boxes, but we had no documentation that showed, that showed the evidence and showed that what we were doing was actually being done the right way. And it also meant that we had some accountability to, to, to stand to as well. So we had to show that We’re not just doing this, but here’s the proof on how we’re doing it, and here’s the proof that we have all of those controls in place. None of the work that we, that we did was dramatic in any way. It was no real big shift. But it was all worthwhile.
Cameron Fairfull [00:19:18]:
It was, it was very much worthwhile for us to be able to show at the end what we were doing as far as SMB 1001. So here’s a few examples of some of the changes that we made. Cyber awareness training. Now, all of our engineers and technicians here at Grassroots IT, they can all spot a dodgy email a mile away. But how are we proving that our engineers could do that? We had no, no way of reporting on all of the, all of the training that our engineers were doing. So our cyber awareness training gave us, gave us that ability to be able to see a report at the end of the month and say, yes, all of our engineers completed the training. all of our engineers received a phishing email and none of it was opened. These people reported the email, and it let us show that we were taking our cyber awareness training seriously.
Cameron Fairfull [00:20:35]:
Password management governance as well. So we were already using one of the best-in-class solutions for all of our client passwords and all of those passwords that we use But how are we tracking the passwords that our engineers were using? How were we making sure that they were secure? How are we making sure that the passwords they were using weren’t weak or weren’t reused and they had the same password used in multiple systems? We had no way. We had no way of doing that. So we implemented a proper management system for password management. system to be able to report on all of the passwords that our engineers were using on a daily basis to access, to access the platforms that let us manage our clients, but making sure that they were secure and they weren’t reused across multiple, multiple different platforms. We completed an EDR, or extended detection and response uplift. So we moved away from the standard antivirus And we went to a platform that has both AI or automation and a human behind it and looked at the signals that were coming from all of our systems and highlighted those ones that needed further investigation. And we did this for both our devices and for our identity.
Cameron Fairfull [00:22:07]:
So identity is one of the bigger areas now where we’re being challenged to make sure that we are maintaining better visibility. And one of the simpler things that we implemented was a visitor register, and that’s simply knowing who came in and out of our office and making sure that if there was anything that ever happened, that we knew exactly what or who was in our office. So I’ve already said this, but mostly it was just writing down all the good practice that we already had in place and making sure that there were some real improvements along the way, and we just formalized and documented everything that we were doing. And then I just want to leave this here for a second and let everyone have a think about it. We put in SMB 1001 just to show how serious we were taking our cybersecurity at Grassroots IT, not just for ourselves, but also how we can help put that in place for all of our organisations. I’ll hand back to Ben.
Ben Love [00:23:30]:
Thanks, Cameron. So importantly, the question, of course, from all of this is what does it mean for your, for your business? That’s what we’re all here to understand, of course. So there’s a discussion here around what level is right for you. There’s the question, of course, about Essential 8, or the new Essentials as it’s going to become over the next couple of years, and the SMB 1001. And then within both of those frameworks, there are different levels. So the Essential 8, as it stands today, has got 3 different levels of maturity: 1, 2, and 3. And the SMB 1001 has got 5 levels of maturity from bronze through to platinum. So which level is right for you and your organisation? The answer is, of course, it depends, but there are some pretty good clues that we can look at when having that conversation.
Ben Love [00:24:18]:
The first one is your size. So quite simply, how many people and how many systems are you protecting? So if you are a smaller organisation, if you’ve got 5 or 10 or maybe 20 staff, you might be looking at a different level of sophistication with these frameworks than if you are a larger organisation with 50 or 100 or beyond. Size simply does bring complexity and increases the, the surface area for risk, if you will. The next thing to consider is the industry you’re in. Now, some industries themselves carry regulatory or contractual obligations. Some industries are just likely to be higher targets for, for the malicious actors here. And the third thing to consider is really just your risk profile. So how sensitive your data is, what a disruption would cost your business, and look, for some of us, how well we sleep at night.
Ben Love [00:25:12]:
So this risk profile is, is a very important consideration as well. In practice, most of the organisations we work with find a good balance on the SMB 1001 between bronze and gold, somewhere within that space is probably the sweet spot for most of you on the call today. And this is an important one to understand here, is where that regulation really does raise the bar, and that can come down to the industry you’re in. So for example, if you’re in financial services, you could be handling client funds, Financial data. Healthcare is an obvious one. There’s a lot of very confidential— excuse me— and personally identifying information held there. Resources and energy, engineering— these organisations not only have a high level of complexity with their IT, their systems, their infrastructure, but they are also very Very— not vulnerable, not the right word, but any sort of a security breach in these areas could have a very, very significant impact on the immediate daily operations of those organisations, not to mention longer-lasting financial or reputational damage. Government suppliers, education and early learning— these are just examples of industries or sectors where this cybersecurity and The cybersecurity governance in particular is particularly critical and getting more important every day.
Ben Love [00:26:55]:
Cyber insurance is, is, is really a big one. We’ve been talking about this for a couple of years now. You know, everybody just kind of groans quietly inside when their insurance broker reaches out and says it’s time for your annual renewal. Cyber insurance in particular is starting to make that process even more complicated, especially if you do not already align to one of these standards we’re discussing. So renewals are not only getting more complicated but also more expensive as the insurers themselves are building out their models, understanding where risk comes from, and obviously shifting that risk back onto premiums for us to, us to be paying here. Having a recognised certification standard in place for your organisation can really change that conversation. It can make renewals a lot simpler because you can answer the questionnaire that they give you with evidence. You already have that evidence on hand.
Ben Love [00:27:53]:
It is documented that you can already put straight back to the insurer or your insurance broker. It puts you in a better position to get better cover, to reduce your premiums. And just make the whole process a whole lot more manageable. And importantly here, what certification signals to others. So it’s worth being clear here about what a certification does and does not do for you. So on the positive side there, it says that you’ve met a defined recognised standard and that you take this very seriously enough and seriously, seriously enough to be checked by third parties. And also that you maintain it year on year. The big thing with this cybersecurity gig is that it’s not a once and done.
Ben Love [00:28:37]:
Cybersecurity needs to be on your standing agenda, and it needs to be renewed and monitored and refreshed on an ongoing basis. It’s not something we can just make a once-off quarterly project, park it, and, and consider ourselves, ourselves safe and done. What certification does not say Is that you can never be breached. It does not say that every risk has vanished, and as I said, that the work is actually finished because we never reach that point there. So anyone who tells you that this certification is the silver bullet, will make you bulletproof, they are overselling it. Certification is just one of the tools, one of the mechanisms that we need to have in our arsenal to, to move the business to where we need it to be. So the question here, and this is the one that I’d really like you to take away from the day. The question is no longer whether you need to align with some sort of framework or certification standard, because in our opinion you do.
Ben Love [00:29:40]:
This has already been answered anyway by your clients, the insurers, and the general world around you. But the question here is, is which framework and, and which level is, is right for you. And to be honest, the next step in that is simply having a conversation. So how do we get started here? This is essentially a gap assessment. Cameron? Thanks, Ben.
Cameron Fairfull [00:30:06]:
Correct. So the quickest way to get started is to understand where you currently sit. Gap assessments are great for that. They take a short amount of time and it helps you identify what the current controls are that you have in place. It lets you then prioritise what you need to achieve, where the gaps are, what’s missing from your cybersecurity, and then once you know that, you can then plan to, to deploy those gaps or those items that fill those gaps and complete that at a sensible pace. So as I mentioned earlier, it took Grassroots IT 6 months to get Gold certified. This is not something that you would put in place in, you know, 1, 2, or 3 months. This is something you would plan from, you know, 6, 12, 18 months depending on the number of controls that you need to implement to make sure that you’re hitting the mark with your cybersecurity.
Cameron Fairfull [00:31:22]:
And what’s the right path? So looking at an SMB 1001 certification, you would— that would simply be a certification engagement with Grassroots IT. There is a clear scope. And a clear outcome. And at the end of it, you’re certified. Again, year-on-year maintenance on your SMB 1001 certification. So making sure that you’re maintaining the right controls and making sure that you are achieving any uplift that is needed when the newer versions of that certification come out. The second option is a program that Grassroots IT offers called the Cyber Concierge Program. Now, the Cyber Concierge Program is designed to help organisations meet the challenges of cybersecurity.
Cameron Fairfull [00:32:22]:
So we help you manage your cybersecurity maturity on it as a continuous journey. We help you build a roadmap and include progress tracking with that roadmap building. We have monthly advisory meetings, and it’s better suited When security feels like a moving target and that you’d rather have someone there walking alongside you to help guide you through all of the, all of the confusion that can be implementing a cybersecurity program. And you’ll have guidance from a team that lives and breathes cybersecurity on a daily basis.
Ben Love [00:33:14]:
So there are 5 key things I think that we’ve touched on today that we really would like you to, to take away from this webinar. The first one is that security is well and truly now a leadership conversation. It is no longer just an IT conversation. Having the right IT partner in the room is obviously very important to executing and getting it done properly and effectively, but ultimately the ownership is with the business.
Cameron Fairfull [00:33:38]:
Yeah.
Ben Love [00:33:39]:
needs to, needs to sit with the business leadership. The second point, having cyber maturity and proving it are different things. Obviously, you need to have it. That is very important. But more and more, we are seeing the importance of being able to prove it, and that is where the frameworks and the certifications come into play. The third point there is that the Essential 8 and the SMB 1001 work together. They are not contradictory to each other. They are indeed complementary.
Ben Love [00:34:10]:
You can have one, you can have both. They both do wonderful things for your business. The key point here though is to get started, is to pick one and take the first steps there. The SMB 1001 is our preference and recommendation moving forward. It is built for businesses of your size, of the size organisations that Grassroots IT works with. It has 5 different maturity levels there. From bronze up to, up to platinum, and it has a broader scope covering things such as policy, staff training, and so on that the Essential 8 doesn’t go anywhere near. And the final point there is that a gap assessment is really the low-risk next step for you to take.
Ben Love [00:34:53]:
The gap assessment is, is very quick. It’s very easy. We will be with you on that journey, and it simply just gives you a very clear picture of what your current cyber maturity looks like. Mapped against these standards and what those gaps are that you would need to close if you do want to achieve certification or stronger alignment with one of these. So just as a parting note there, I would invite you to book that no-obligation chat with Grassroots IT. Reach out to myself or Cameron, and we will certainly get something in the calendar for you. It does not need to be a big scary thing. This is a very easy first step.
Ben Love [00:35:33]:
So I would encourage you, if you haven’t done this yet, drop us an email and we can get started on that point there. So a final call for any questions. If you have any, please pop them into the, the chat or the Q&A boxes up the top right now. And while we’re just checking on that, Cameron, any final thoughts before we sign off?
Cameron Fairfull [00:35:56]:
No, nothing from me. I think I think we’ve, we’ve covered everything. The big— the biggest takeaways are that your cybersecurity frameworks shouldn’t be fighting against each other. They should be complementary, which is why we’ve chosen the Essential 8 and the SMB 001 path. We think it works really well together.
Ben Love [00:36:19]:
Fantastic. Thank you, Cameron. Thank you, everybody. It was wonderful having you here, and we will see you next time.
Cameron Fairfull [00:36:26]:
Thank you, Ben. Thank you, everyone.