Deciding the right level of cybersecurity for your business
Should my business align with a cybersecurity framework?
Will that extra investment give me the right protection?
Could stronger cybersecurity support new business opportunities?
There’s no single, mandatory cybersecurity standard in Australia. Instead, cybersecurity is generally about demonstrating that you’ve taken ‘reasonable steps’ to manage risks, particularly around data privacy, record-keeping and industry-specific regulations.
That’s where frameworks can help. They give you and your IT partner a structured way to assess risks, prioritise protections, and level-up your security posture over time.
Frameworks can also add credibility in the eyes of clients, partners and cyber insurers.
What can businesses learn from the Essential Eight?
The Essential Eight Maturity Model, developed by the Australian Signals Directorate, has been Australia’s most recognised framework. It was mandatory for government agencies and widely referenced in cybersecurity discussions. While the Essential Eight is now under review, it raised important cybersecurity considerations still relevant today.
On the surface, the Essential Eight was appealing: a government-recognised checklist of eight practical measures, organised into three maturity levels.
However, one of the challenges many SMBs faced was that the framework was designed with government environments in mind. It assumed:
- Large-scale, enterprise networks
- Microsoft-centric environments
- Budgets and risk appetites that reflect national-level assets and exposure
It was highly prescriptive, focusing on specific measures in that context. That means, while providing useful detail on configuring Microsoft security settings, it said little about protections for non-Microsoft platforms. The measures were also often disproportionate to SMB risk profiles and budgets.
The lesson for business leaders is an important one: a framework is only useful if it reflects your environment, priorities and risks. In practice, insurers and partners generally care more about evidence of sound risk management than strict framework compliance.
The real-world trade-offs
Let’s call it out: there’s no such thing as 100% protection. Even if there was, the benefits probably wouldn’t outweigh the costs, especially for SMBs.
Every cybersecurity decision involves a trade-off. Each potential security measure involves balancing three factors:
- Level of protection
- Budget
- Usability
The ideal balance is different for every business, and changes over time as your systems and risks evolve. That’s why cybersecurity is an always-on activity, not a one-off IT project.
For example, multi-factor authentication is considered one of the cheapest and most effective ways to protect access to your business assets. However, it does introduce an additional step in the sign-in process, reducing usability a little.
Other options, like password management applications, may improve usability, but at a higher cost. Ultimately, the proportional approach focuses on outcomes, not box-ticking.
Questions every leadership team should ask
Cybersecurity decisions should start with business priorities, not technology.
Before considering any framework, ask:
1. What are our most critical systems and data?
Not every system carries the same risk. Identify what would have the greatest operational, financial or reputational impact if it became unavailable, corrupted or exposed.
2. What level of disruption could we realistically tolerate?
How long could your business operate without email? Your line-of-business applications? Your client data?
Your answers help determine the level of protection and recovery capability that makes sense for your organisation.
3. What risks are we consciously accepting?
Every business accepts some level of cyber risk. Recognising we can’t completely eliminate risk, the goal is to understand which risks you’re prepared to accept, and ensure they align with your business priorities, obligations and budget.
A strong cybersecurity strategy is built on deliberate, informed and commercial decisions.
How can cybersecurity create business opportunities?
Risk management is a critical focus of cybersecurity frameworks, but it may not be the only objective for your business.
Aligning with a recognised framework or standard can provide an independent benchmark for continuous improvement. It gives leadership teams, staff and business partners assurance that your business is keeping pace with relevant security and governance expectations.
At Bigfish, this was an important motivation for committing to achieve ISO 27001 (Information Security Management) and ISO 9001 (Quality Management) certification.
Alignment with recognised frameworks can strengthen credibility and trust. It demonstrates to clients, partners and prospects that you’re taking a structured and accountable approach to your operations and the impact it may have on others.
Which cybersecurity frameworks are useful to SMBs?
One framework we reference at Bigfish is the NIST Cybersecurity Framework (NIST CSF). Originally developed in the US and updated in 2024 (version 2.0), NIST CSF provides guidance to business leaders that is accessible, flexible and outcome-focused.
It’s organised around six core functions:
- Govern –Establish and monitor your cybersecurity strategy, expectations and responsibilities
- Identify – Understand your assets, risks and vulnerabilities
- Protect – Put controls in place to mitigate risks
- Detect – Monitor for suspicious activity or breaches
- Respond – Have a clear plan for responding to incidents
- Recover – Restore normal operations and improve resilience
In our experience, many businesses underinvest in the first steps: Govern and Identify. Clarifying your objectives and priorities is critical for ensuring you’re not under or over-investing in certain measures. Secondly, you can’t protect what you can’t see.
Many businesses can tell you how many staff they employ, but not how many systems hold company data. Before investing in additional protections, understand:
- Where your data lives
- Who has access to it
- Which systems are business critical
- Which third-party platforms you rely on
- What recovery options exist if something goes wrong
That’s why we help clients map their assets, systems and risks: to build a complete picture of their security posture and opportunities to level up.
Expertise is essential
At Bigfish, we believe the right cybersecurity approach is one that fits your business, your risk profile, and your budget.
Your protections should:
- Be proportionate to your risk
- Evolve with the threat landscape
- Support your business goals
Most importantly, your leadership team should understand why those protections exist, what risks they address, and what trade-offs they involve.
Whether or not you choose to align with a specific framework, the right IT partner can help turn those decisions into an achievable security roadmap.