Skip to main content

IT Start

Fix 3 Brisbane SMB Gaps: Hire or Outsource a Cyber Security Architect

Secure business infrastructure monitoring environment

If your business has 10 to 50 staff, no tested backup, and MFA switched off on half your accounts, outsourcing a cyber security architect isn’t optional anymore. It’s the fastest fix. The right engagement delivers three things fast: identity hardening (MFA and conditional access), backups you can actually restore from, and detection that tells you when something’s wrong before a client does.


TL;DR:

  • Most SMBs with 10 to 50 staff lack tested backups, have MFA only on some accounts, and rely on outdated firewalls, significantly increasing breach risk.
  • An effective security architecture focuses on identity hardening, tested immutable backups, endpoint detection, Microsoft 365 cloud hardening, and centralized logs, aligning with Essential Eight.
  • Outsourcing a cybersecurity architect is recommended, with providers evaluated based on SMB experience, clear frameworks, SLAs, and specific questions about MFA, backups, logging, and incident handling.
  • Implementation of basic security measures like MFA, backup testing, and endpoint protection can be achieved in four to eight weeks at a cost driven by licensing, engineering, and ongoing monitoring, providing rapid risk reduction.
  • Most SMBs uncovered during assessments exhibit critical gaps such as unmanaged backups and disabled MFA, highlighting the importance of a quick security review to identify and fix immediate vulnerabilities.

IT Start
Strengthen Your Business Security
IT Start helps Brisbane businesses manage IT, cloud solutions, and cybersecurity with proactive support and local expertise.
Visit IT Start

Table of Contents

What does a cyber security architect service actually cover?

Honestly, most business owners think “cyber security” means antivirus and a firewall. It doesn’t. A proper architecture engagement is about designing how your systems, accounts, and data connect, and closing the gaps attackers actually use. We see this a lot: a business has a firewall from 2018 and calls itself “covered.”

Here’s what a real scope looks like for an SMB:

  • Identity first. MFA on every account, conditional access rules, and separating admin accounts from daily user accounts. This is the single biggest lever for reducing breach risk.
  • Endpoint protection that actually detects things. Legacy antivirus checks a signature list. Endpoint Detection and Response (EDR) watches behaviour, which is what catches ransomware before it spreads.
  • Backups that are tested, not just “running.” Immutable backups (ones an attacker can’t delete or encrypt) plus a written recovery playbook your team can follow at 2am.
  • Microsoft 365 and cloud hardening. Conditional access, mailbox rules audits, and blocking legacy authentication protocols that attackers still exploit.
  • Logging and a SIEM-lite setup. You don’t need a full security operations centre. You need identity logs, EDR alerts, and email security logs centralised somewhere someone actually looks at.

The ASD/ACSC small business guidance frames the Essential Eight as the baseline here, and it maps cleanly onto this scope: patching, MFA, backups, and admin restriction cover most of it.

Pro Tip: Ask any provider to show you their logging setup during the sales call, not after signing. If they can’t describe what they’d centralize and why, they’re selling a product, not designing an architecture.

Where do small businesses actually go wrong?

We’ve walked into more SMB environments than we can count, and the same three failures show up constantly.

  1. MFA half-enabled, legacy auth still on. A finance manager gets phished, the attacker logs in from overseas because legacy authentication bypasses MFA entirely, and nobody notices for six weeks.
  2. Backups that exist but don’t restore. A backup job runs every night. Nobody’s tested a restore in two years. Then ransomware hits, and the “backup” turns out to be three months stale, or was sitting on the same network the attacker just encrypted.
  3. Buying products instead of designing architecture. A vendor sells a firewall upgrade because that’s what they sell, not because it’s the highest-priority gap. Meanwhile, admin accounts still don’t have separate credentials from daily logins.

Most SMBs we assess sit at Essential Eight Maturity Level 0. Some think they’re at Level 1 because they have antivirus. Maturity Level 1 is a genuinely achievable target for a small team, and it’s built almost entirely from MFA, patching, and restricting admin privileges, not expensive tooling.

The gap between what businesses think is protected and what’s actually protected is where breaches live. Nobody finds out their backup doesn’t work until the week they need it.

How do you hire or outsource a cyber security architect?

This is where most owners get stuck, because the market is full of people selling boxes rather than designing systems. Here’s a working checklist.

Selection criteria to look for:

  • Evidence of actual SMB delivery, not just enterprise case studies that don’t translate to a 20-person team
  • A named framework they work against, whether that’s NIST CSF for explaining priorities to you, or CIS Controls for deciding what to actually build
  • A clear ongoing operating model, not a one-off project with no plan for who watches the alerts next Tuesday
  • Defined SLAs: response times, what’s monitored, and what happens during an incident

Five questions to ask on the call:

  1. “What’s your MFA and conditional access approach for our size business?” A vague answer is a red flag.
  2. “How do you test our backups, and how often?” If they can’t describe a restore test cadence, walk away.
  3. “What logs do you centralise, and where do they go?” Silence here means no detection capability.
  4. “What happens if we want to leave? Can we take the architecture with us?” Vendor lock-in with no documentation is a warning sign.
  5. “Can you show me an example of an incident you’ve handled for a business our size?” Specifics beat polish.

Red flags worth walking away from: a provider whose main deliverable is a PDF binder, no logging plan, no backup restore test scheduled, or no handover process if you switch providers later.

For a business with genuinely nothing in place, a short fixed-scope uplift (get MFA, backups, and EDR sorted in weeks) makes more sense than jumping straight into an ongoing managed contract. You can decide on ongoing architecture once the basics are fixed.

What does a typical SMB engagement cost and how long does it take?

Timelines and costs vary, but the shape is fairly consistent across a 10 to 50 staff business.

  • Discovery (1 to 2 weeks): Mapping what you’ve actually got, not what the last provider’s invoice says you’ve got. This usually surfaces the gap between assumed and actual coverage.
  • Quick wins (2 to 4 weeks): MFA rollout, admin account separation, basic conditional access, legacy auth disabled. This is where most of the risk reduction happens, fast.
  • Build phase (4 to 8 weeks): EDR deployment, backup architecture rebuild, logging setup, Microsoft 365 hardening per the ACSC cloud security guides.
  • Operate (ongoing): Monitoring, tuning, patch management, incident response readiness.

Cost drivers are licensing (EDR/MDR platforms, backup subscriptions), engineering hours to configure things properly, and ongoing monitoring. The ACSC notes some of these protections need at least Microsoft 365 Business Premium licensing, not the base tier most SMBs are sitting on.

A minimal practical package for most 10 to 50 staff businesses: identity and MFA, tested immutable backups, EDR on every endpoint, basic centralised logging, and a written incident response plan. Skip any one of those and you’ve got a gap someone will eventually find.

What does a typical SMB engagement cost and how long does it take? — overview diagram

What we actually see across Brisbane SMBs

We work with trades businesses, professional services firms, and healthcare clinics, and the pattern repeats: no MFA on the finance inbox, a backup nobody’s tested, and zero visibility into what’s actually happening on the network. When we design architecture, identity comes first, backups second, detection third. Everything else waits.

If you do one thing this week, check whether your backup has actually been restored in the last three months. Most businesses assume it has. Most haven’t tested it. Ask whoever manages your IT to prove it, not describe it.

— Matt

Get a straight answer on where your gaps are

There are consultants who’ll sell you a report and disappear, and there are vendors who’ll sell you a box because that’s what’s in stock. There are providers who’ll sell you a report and disappear, and vendors who’ll sell you a box because that’s what’s in stock. As a Brisbane-based provider holding SMB 1001 Gold certification, we design and operate the architecture ourselves, identity, backups, and detection included, rather than handing you a binder and walking away.

A first engagement typically starts with a short security review: we look at your MFA coverage, backup restore capability, and what’s actually being logged, then hand you an evidence pack showing exactly where the gaps sit and what to fix first. From there it’s your call whether you want a fixed-scope uplift or ongoing managed cyber security support.

Security review process and service options

If you want a straight answer on where your business actually stands, get in touch and book a quick review. No binder, no upsell, just a clear picture of your risk.

FAQ

Should a 10 to 50 staff business outsource cyber security architecture?

Yes, for most SMBs without a dedicated security team, outsourcing is the practical option because it delivers MFA, tested backups, and detection faster than building it in house. The Essential Eight framework gives a clear, low-cost starting target most providers can reach within weeks.

What certifications should a cyber security architect or provider hold?

Look for evidence of frameworks like NIST CSF and CIS Controls in how they explain their approach, plus recognised industry standards such as SMB 1001 Gold certification for the provider itself. Certifications matter less than whether they can show a working backup test and a real incident response plan.

How much does a cyber security architecture engagement cost for an SMB?

Costs depend on licensing (EDR, backup subscriptions), engineering hours, and whether you choose a fixed-scope uplift or ongoing managed support. This service’s current pricing is available by contacting the provider directly for a quote based on your environment.

What’s the difference between a cyber security architect and a cyber security analyst?

An architect designs the systems, identity structure, and controls that prevent and detect attacks, while an analyst typically monitors alerts and responds to incidents day to day. For a 10 to 50 staff business, one outsourced provider usually covers both roles under a single managed arrangement.

How long does it take to fix the basics like MFA and backups?

Quick wins like MFA rollout and legacy authentication removal typically take two to four weeks once discovery is done. Backup architecture and endpoint protection usually take another four to eight weeks to build and test properly.

Related Posts