For most Brisbane SMBs with 10 to 50 staff, hiring a full internal security team is the wrong move. Outsourcing or running a hybrid model, with one internal owner and an external managed security provider, gives you better coverage for less money than trying to build cyber security graduate roles into a standalone department. Every business still needs someone internal who owns the relationship, reads the reports, and makes the calls. The talent shortage and the true cost of internal hires make outsourcing the practical default.
TL;DR:
- Small businesses under 20 staff should prioritize fully outsourcing security rather than hiring a full internal team due to the high costs and staffing complexity involved.
- Most SMBs need multiple specialized roles, such as security administrators, SOC analysts, and governance managers, but rarely require full-time hires for all functions.
- Outsourcing options, including MSSPs and vCISO services, can be onboarded in two to four weeks at a cost of $3,000 to $8,000 monthly or $80,000 to $200,000 annually.
- Internal owners should review provider reports regularly, prioritize remediation based on business risk, and ensure critical patches and backups are tested frequently.
- Entry-level cybersecurity roles typically start below mid-level analyst salaries, with realistic expectations on their capabilities and the need for ongoing mentorship and process development.
Table of Contents
- What cyber security graduate roles actually cover in an SMB
- How do you decide: hire, outsource or hybrid?
- What to look for in candidates or security providers
- Who inside your business needs to own this
- How long does hiring or onboarding actually take?
- What career progression actually looks like in these roles
- Interview questions and how to actually assess a graduate candidate
- What graduates get wrong, and what SMBs should expect from them
- What do entry level cyber security jobs actually pay?
- IT Start’s perspective: what we actually see and how we tackle it
- How IT Start can help with managed security, vCISO and hybrid engagements
- Sources
- FAQ
What cyber security graduate roles actually cover in an SMB
Most SMB owners we talk to think “cyber security” is one job. It is not. It is a handful of distinct functions, each needing different skills, and most of them do not need a full time person sitting in your office. Here is the shortlist we actually see work in Brisbane businesses.
- Security administrator or security engineer — handles day to day configuration, patching, and rolling out endpoint detection and response (EDR). This is hands on keyboard work.
- SOC analyst or MDR analyst — triages alerts and contains incidents. For an SMB, this is almost always outsourced because running your own security operations centre requires round the clock coverage.
- vCISO or security manager — owns governance, risk, and compliance. This is a part time, senior function for most SMBs, not a full time hire.
- Vulnerability assessor or penetration tester — runs periodic testing, usually annually or after major changes, with a defined scope.
- Internal integrator or IT security generalist — the person inside your business who owns the provider relationship and chases remediation work.
Honestly, the mistake we see most is businesses hiring a single junior person and expecting them to cover all five of these. That is setting someone up to fail, and it leaves gaps a real attacker will find.
Pro Tip: If you’re only going to hire one internal person, make it the integrator role, not a technical specialist. You can rent the specialist skills. You can’t rent someone who understands your business and chases things down.
How do you decide: hire, outsource or hybrid?
There is no single right answer here, but there is a wrong first move, and we see businesses make it constantly: buying a penetration test before they have basic controls in place. That is like getting a building inspection before you have put a lock on the front door.
Work through this in order:
- Count your staff and your IT maturity. Under 20 staff with no dedicated IT person, you almost always outsource everything, including the internal owner role sitting with the office manager or ops lead.
- Check your regulatory exposure. Legal, financial, healthcare and professional services clients handling sensitive data usually need a hybrid model with more governance, closer to what RSM’s operating models research describes.
- Assess data sensitivity. If a breach means client trust issues or compliance breaches, lean toward MSSP coverage, not a DIY internal setup.
- Look at existing IT maturity. If your current setup has no multi factor authentication and nobody has tested a backup restore in the last twelve months, you have bigger problems than which org chart box to fill.
For a 15 person Brisbane accounting firm, that usually means fully outsourced security bolted onto your existing managed IT support. For a 45 person engineering firm with government contracts, that is often one internal IT manager plus an external MSSP for detection and response, which matches what RSM found about hybrid models being common once risk profile drives the decision rather than headcount alone.
- Under 20 staff, low regulatory exposure: outsource fully.
- 20 to 50 staff, moderate exposure: hybrid, one internal owner plus MSSP.
- Any size with heavy compliance obligations: hybrid or internal, governed closely.
What to look for in candidates or security providers
Whether you are interviewing a candidate or reading an MSSP proposal, the checklist is basically the same. We have sat through plenty of vendor pitches that sound great and fall apart on the technical detail.
Technical checklist:
- EDR deployed across every endpoint, not just servers
- Identity and access controls, including conditional access and MFA enforcement
- Regular vulnerability scanning with a documented patch cadence
- Logging that actually covers your email, endpoints, and network, not just one system
Business skills that matter more than people expect:
- Can they explain a risk in plain English to your finance manager, not just to another IT person
- Do their reports lead with business impact, not a wall of technical jargon
Certifications and standards are useful reference points, not magic tickets. Look for job descriptions aligned to ASD guidance and providers who can map their work back to the Essential Eight, rather than badges alone.
Pro Tip: Ask any provider “what does your SOC coverage actually look like at 2am on a Sunday?” If the answer is vague, that is your red flag. We see providers quote impressive sounding SLAs that fall apart the moment you ask who is actually watching alerts overnight.
Other red flags: no reference clients your size, unclear scope documents, and no mention of tested backup restores anywhere in their proposal.
Who inside your business needs to own this
Outsourcing security does not mean walking away from it. Someone inside your business has to own the relationship, or remediation work becomes a vendor’s to do list that nobody actions. We see this constantly: a provider flags twelve critical patches, sends the report, and nothing happens because no one internally has the authority or time to prioritise it.
That internal owner needs to:
- Review provider reports monthly at minimum, weekly if you are in a regulated industry.
- Prioritise remediation work based on actual business risk, not just severity scores.
- Escalate genuine incidents immediately, with a clear internal contact list.
- Sit in on quarterly reviews covering incident trends, patch compliance, and budget for the year ahead.
Budget for remediation work separately from your retainer. Annual assurance testing, like a penetration test, is a separate line item too. The businesses that get burnt are the ones who assume the monthly fee covers everything, including the hours needed to actually fix what gets found.
How long does hiring or onboarding actually take?
Recruiting a mid level security analyst in Brisbane typically takes eight to twelve weeks from job ad to start date, longer if you are competing against banks and government for the same shortlist. Onboarding an outsourced MSSP is faster, usually two to four weeks from signed agreement to live monitoring, assuming your environment is not a mess.
| Option | Typical cost | Timeframe to value |
|---|---|---|
| Internal mid level analyst | $90,000 to $160,000 salary, plus 20% loaded costs | 8 to 12 weeks to hire |
| vCISO retainer | Part time monthly retainer, scoped to business size | 2 to 4 weeks to onboard |
| MSSP or MDR service | $3,000 to $8,000 per month depending on scope | 2 to 4 weeks to onboard |
| Full outsourced programme (vCISO plus MDR plus assurance) | $80,000 to $200,000 per year | 4 to 8 weeks fully operational |
These figures come from independent cost comparison research and Cliffside’s outsourcing analysis. What actually moves the price is your number of endpoints, how many log sources you need monitored, your SLA response times, and how many retained incident response hours you want on standby.
A sensible onboarding checklist runs: initial assessment, deploy EDR across all endpoints, tune detection rules against your normal business traffic, then run a tabletop exercise so your team knows what an actual incident response looks like before it happens for real.
What career progression actually looks like in these roles
Graduates coming into cyber security roles inside an SMB, or through an MSP servicing SMBs, usually start in a generalist support or junior analyst position handling ticket triage, basic patching, and EDR alert review under supervision. That first 12 to 18 months is where the real learning happens, because SMB environments are messier than textbook examples and graduates see genuine misconfigurations, not simulated ones.
From there, progression typically splits into two tracks. The technical track moves toward security engineer, then senior analyst or SOC lead, eventually specialising in areas like cyber security analyst roles with deeper incident response or threat hunting responsibility. The governance track moves toward risk and compliance work, eventually toward a vCISO or security manager position, which suits graduates who are strong communicators as much as technical operators.
What we see in practice is that graduates who progress fastest are the ones who get exposure to real client environments early, not just lab simulations. An MSP setting is genuinely good for this because a graduate might see fifteen different business environments in their first year rather than one static internal network. That breadth builds judgement faster than staying inside a single organisation’s IT team.
The ceiling for a strong performer, five to seven years in, is a senior consulting or vCISO type role, often working across multiple SMB clients rather than sitting inside one business.

Interview questions and how to actually assess a graduate candidate
Technical certifications tell you almost nothing about whether someone can actually do the job on day one. We would rather see a graduate walk through a scenario than recite a definition.
Useful interview questions include: “Walk me through how you would triage this alert” (give them a realistic, slightly ambiguous log excerpt), “A user reports a suspicious email, what do you do in the next ten minutes?”, and “How would you explain a critical vulnerability to a business owner who has no technical background?”
That last question matters more than most hiring managers realise. A graduate who can only talk in acronyms is going to struggle in an SMB setting where they are often the only technical person in the room. Assessment methods worth using beyond the standard interview: a short practical exercise using a sandboxed environment, a written incident summary exercise scored for clarity rather than jargon, and a reference check that specifically asks about how the candidate handled ambiguity, not just whether they hit deadlines.
Watch for candidates who have done real entry level cyber security groundwork such as home lab projects, capture the flag competitions, or genuine internship exposure, rather than certifications alone. A certificate proves someone can pass an exam. It does not prove they will notice something odd in your logs at 4pm on a Friday.
What graduates get wrong, and what SMBs should expect from them
The biggest mismatch we see is graduates expecting cyber security work to look like what they studied: clean, well documented environments with modern tooling already in place. Real SMB environments are rarely like that. We regularly walk into businesses with no MFA enabled, backups that have never had a test restore, and network diagrams that exist only in someone’s head. Graduates need to be ready for messy reality, not textbook scenarios.
Expectation mismatches run both ways. SMB owners sometimes expect a graduate hire to instantly plug every security gap in the business, which is unrealistic for someone one or two years out of study. A graduate is not going to replace a full security programme. They can absolutely handle patching, monitoring, and first line triage under a senior analyst or an outsourced provider’s guidance, but they should not be your only line of defence in a business with real regulatory exposure.
The other common friction point is pace. Graduates trained on structured coursework often expect clear escalation paths and defined processes. Many SMBs do not have that yet, which means a graduate’s early months often involve helping to build the process, not just following one. That is genuinely valuable experience, but it needs an employer or MSP willing to mentor rather than just delegate and hope.
Realistic expectation setting on both sides avoids the common outcome we see: a graduate leaves within twelve months because the role did not match what they were promised, or the business gets frustrated because a junior hire could not single handedly fix years of accumulated technical debt.

What do entry level cyber security jobs actually pay?
Salary expectations matter for SMB owners weighing an internal hire against an outsourced arrangement. Entry level graduate positions in cyber security roles typically sit well below the mid level analyst range, with junior or graduate positions commonly starting lower and building toward the $90,000 to $160,000 mid level analyst salary band over several years of experience.
Total compensation for graduate roles usually includes superannuation on top of base salary, and increasingly includes structured training budgets, since certifications and ongoing skill development are expected as part of the role rather than something graduates fund entirely themselves. Some SMBs and MSPs also offer study leave or exam cost coverage as part of the package, which matters given how quickly the threat landscape shifts.
Here is the honest bit most job ads skip: a graduate’s true value to a small business in year one is rarely equal to their fully loaded cost once you add superannuation, training, tooling, and management time. That is not a knock on graduates. It is simply why hiring one specialist graduate rarely solves an SMB’s whole security problem, and why pairing junior internal talent with an outsourced provider for coverage gaps is usually the smarter structure.
IT Start’s perspective: what we actually see and how we tackle it
Honestly, the gaps we find on a first assessment are rarely exotic. No MFA on email. Backups nobody has test restored in years. Local admin rights handed out like lollies. We see this a lot, and it is almost never because a business does not care, it is because nobody made cyber security someone’s actual job.
We start every engagement with an assessment, not a sales pitch. Baseline controls first, then monitoring, then governance. What gives us confidence in a new client relationship is a business willing to name an internal owner, even part time, and act on what we find rather than filing the report away.
— Matt
How IT Start can help with managed security, vCISO and hybrid engagements
If your business is trying to work out whether to hire, outsource, or run a hybrid setup, There are local alternatives in Brisbane to building an internal security team from scratch. We deliver managed IT support and cyber security services with SMB 1001 Gold certified standards, meaning you get proactive monitoring and governance without the twelve week recruitment cycle or the six figure loaded cost of a specialist hire.
For a business under 20 staff with no dedicated IT resource, our managed security and risk assessment services cover endpoint protection, firewall management, and compliance groundwork as one package. For a 20 to 50 staff business already running internal IT, an MSSP can slot in as the external half of a hybrid model, working alongside the existing team rather than replacing them.
The first step is straightforward: get a proper assessment of where your gaps actually are, not a generic checklist. Reach out to IT Start and we will walk you through what a hybrid or fully outsourced setup would realistically look like for your business.
Sources
For deeper detail, see Cliffside’s SME outsourcing analysis, RSM’s operating models report, and the Small Business Cyber Resilience Service for free support if you have under 20 staff.
- Cybersecurity Outsourcing for SMEs | Cliffside
- Managed Security vs In-House IT Security | Cost Comparison
- Cyber Security Operating Models | In-house vs Outsourced Security | RSM
FAQ
Should a small business hire an internal cyber security person?
For most businesses under 20 staff, no. Outsourcing to a managed security provider gives better coverage per dollar than one internal hire, since running even a basic SOC needs five to seven analysts for proper shift coverage.
What is the difference between an MSP and an MSSP?
An MSP manages your general IT, including networks, devices, and Microsoft 365. An MSSP focuses specifically on security monitoring, detection, and incident response, often working alongside your existing MSP in a hybrid setup.
How much does outsourced cyber security cost for an SMB?
Managed security services for Australian SMEs typically run $3,000 to $8,000 per month depending on scope, while a full outsourced programme with vCISO and assurance testing can run $80,000 to $200,000 annually. IT Start’s cyber security pricing is available on request through its cyber security services page.
What does a vCISO actually do for a small business?
A vCISO provides part time governance, risk, and compliance oversight without the cost of a full time executive hire, reviewing your security posture and guiding decisions on budget and priority.
How long does it take to onboard an outsourced security provider?
Most MSSP onboarding takes two to four weeks from signed agreement to live monitoring, assuming your existing environment does not need significant remediation first.

