Kosmos IT
Menu

Cybersecurity

Small offices don't get targeted by anything exotic. They get caught by a fake invoice, a reused password or a machine two years behind on updates. We put the controls in place that stop the common attacks, then keep them working — because security that nobody maintains stops being security within a month.

What's included

  • Managed antivirus and endpoint protection on every machine
  • Multi-factor authentication across email, remote access and banking portals
  • Patching for Windows, macOS and the applications people actually use
  • Email filtering, plus SPF, DKIM and DMARC on your domain
  • Staff awareness training on invoice fraud and phishing
  • A written incident plan: who to call, what to unplug, what to say

Common problems we fix

  • “We got an invoice from a supplier with different bank details”
  • “Someone clicked a link and now they're worried”
  • “Staff use the same password everywhere”
  • “Our insurer is asking security questions we can't answer”
  • “A client wants proof we protect their data”
  • “We've had a login alert from another country”

Paying per callout? Clients on a monthly plan don't wait for things to break.

See our plans

What it costs, and what changes the price

Security is included in the managed plans rather than sold as a separate product, because controls that nobody maintains stop working within a month. A one-off security review for a business not on a plan is a fixed fee.

  • Number of users and devices, which is what most licensing is priced on
  • Whether multi-factor authentication already exists or has to be rolled out from scratch
  • Whether you need evidence for an insurer or a client questionnaire
  • How much remediation the review finds — the review price is fixed, the fixes are quoted
  • Whether staff awareness training is included or delivered separately

We do not sell fear or a product you cannot use. Multi-factor authentication, patching and a tested backup stop the overwhelming majority of what actually happens to small businesses.

For the wider picture, see what IT support costs in Brisbane.

What's not included

Worth knowing up front, so nothing on the invoice is a surprise. Where something falls outside what we do, we'll tell you who should do it.

  • Formal penetration testing and certification audits, which need a specialist firm
  • Legal advice on a notifiable data breach — we support the technical response
  • Cyber insurance itself, though we complete the technical sections of the questionnaire
  • Physical security, alarms and access control

A job like this

A Bundall agency was two days from paying a supplier invoice with altered bank details. The tell was a reply-to address one character different from the real one, and the only reason anyone checked was the payment-change rule we had put in writing a month earlier.

Questions about cybersecurity

Are small businesses really a target?

Yes, because they're easier. Most attacks on small offices aren't targeted at all — they're automated, or they're invoice fraud aimed at whoever pays the bills. A six-person accounting firm holds exactly the data that's worth stealing.

What's the single most useful thing we can do?

Turn on multi-factor authentication everywhere, starting with email. It's free, it takes an afternoon, and it blocks the overwhelming majority of account compromises. Everything else we do is built on top of that.

Will security make everything slower for staff?

It shouldn't. Done properly, staff sign in once in the morning and approve a prompt on their phone. If a control is annoying enough that people work around it, it isn't protecting you, so we tune it rather than leave it.

Can you help with a cyber insurance questionnaire?

Yes. We complete the technical sections with evidence from your environment — MFA coverage, patch status, backup test results and endpoint protection. Insurers increasingly check these answers, so it's worth having them documented and true.

How would we know if we had been compromised?

Often you would not, which is the problem. The usual signals are a sign-in alert from somewhere implausible, a client receiving something odd from your address, mail rules you did not create, or sent items you do not recognise. Monitoring catches most of it earlier — but if any of those has already happened, treat it as urgent and call rather than email.

How is this different from just having antivirus?

Antivirus is one control out of several, and it is the one that stops the attack nobody bothers using any more. What actually happens to small offices is a stolen password or an altered invoice, and neither is something antivirus sees. Multi-factor authentication, patching, mail authentication and a tested backup do the real work.

Most often for accountants and legal — though the underlying work is much the same whatever you do.

Available across Redland City, Brisbane, Logan City and Gold Coast City. See where we work.

Close the gaps before someone finds them.

Call 07 3824 6117Book a callout