Skip to main content

IT Start

Stop Breaches: 30, 90 and 180 Day Cyber Security Mitigation Techniques for SMBs

White business team reviewing cyber mitigation plan

The mitigations that cut risk fastest are multi factor authentication, tested offline backups, prioritised patching, endpoint detection and response, and tightly restricted admin privileges. These map directly to the Essential Eight, the baseline both the Australian Signals Directorate and NIST point to for SMBs. Where you start depends on what you actually have to protect. Honestly, most businesses we meet haven’t done the basics.


TL;DR:

  • Most SMBs fail to implement the basic controls recommended by the Essential Eight, such as MFA, patching, and backups.
  • Phishing-resistant MFA methods, like FIDO, should be prioritized for high-risk accounts like admins and VPN access.
  • Internal patch cycles can be slower for non-critical systems, but internet-facing systems must be patched within 48 hours of known vulnerabilities.
  • Offline, encrypted, and tested backups are critical, with restoration rehearsals performed at least annually to confirm data integrity.
  • Early detection relies on centralized, tamper-proof logs and managed EDR solutions, with regular testing against attacker techniques like MITRE ATT&CK.

IT Start
Strengthen Your Business Cybersecurity
IT Start helps Brisbane businesses manage cybersecurity risks with tailored support, cloud solutions, and proactive managed IT services.
Explore IT Start

Table of Contents

What mitigation actually means and the Essential Eight baseline

Cyber security mitigation is the practical work of making an attack harder to pull off and less damaging when it happens anyway. It’s not about stopping every threat. It’s about closing the doors attackers walk through most often and having a way back up when one gets through regardless.

The Essential Eight from the Australian Signals Directorate is the clearest baseline going. It groups eight controls that, together, stop most of the compromise attempts we see land on SMB networks.

  • Patch applications: fix known vulnerabilities in software before someone exploits them.
  • Patch operating systems: the same logic, applied to Windows, macOS, and server platforms.
  • Multi factor authentication: a stolen password alone should never be enough to get in.
  • Restrict administrative privileges: fewer people with keys to everything means fewer ways in.
  • Application control: only approved software gets to run, which blocks a lot of malware outright.
  • Restrict Microsoft Office macros: macros are still a common way malicious code gets executed.
  • User application hardening: turn off features in browsers and Office apps that attackers love to abuse.
  • Regular backups: the difference between a bad day and a business-ending event.

The Essential Eight isn’t optional guidance, it’s the baseline auditors, insurers, and increasingly clients expect you to meet. ASD structures it into maturity levels, and even Maturity Level One (the lowest tier) blocks a meaningful share of opportunistic attacks. Most SMBs we assess sit at Maturity Level Zero without realising it. Prioritise which controls you tackle first based on what you’re actually protecting. A firm handling client financial data has a very different risk profile to a five person design studio, even though both need every one of these eight controls eventually.

For a Brisbane specific breakdown of how the maturity levels apply, we’ve written up a complete guide to the Essential Eight that goes deeper than we can here.

Technical controls you can actually configure this month

This is where the rubber hits the road. These are the specific, technical moves that make the biggest dent in your exposure, and they’re the ones we implement first in almost every new engagement.

  1. Turn on phishing resistant MFA everywhere it counts. Push notification MFA is better than nothing, but SIM swapping and push bombing attacks are becoming common enough that agencies including CISA and ASD now recommend phishing resistant methods like FIDO or PKI based authentication over SMS codes. Cover admin accounts, VPN access, RDP, and webmail first. Those are the four doors attackers try hardest.
  2. Triage patches by exposure, not by convenience. Internet facing systems (your firewall, VPN gateway, public web apps) get patched first, and ACSC guidance suggests critical vulnerabilities on high risk systems should be patched within 48 hours. Internal, non-critical systems can follow on a slower weekly or fortnightly cycle.
  3. Deploy EDR and application allowlisting together. EDR helps detect suspicious behaviour, and allowlisting aims to stop unapproved software from running. Attackers increasingly use memory only loaders and portable executables specifically to dodge traditional antivirus, so allowlisting matters more than it used to.
  4. Segment your network and lock down remote access. RDP should never be exposed directly to the internet. Put it behind a VPN with MFA, use just in time access where you can, and log every session.
  5. Fix your backups properly. Offline, encrypted, and immutable copies, with a documented restore runbook and a test schedule you actually follow. Agencies recommend testing restoration at least annually or after any major infrastructure change, not just checking that the backup job says “success” in a dashboard.

Pro Tip: A backup job that reports success tells you nothing. Restore a real file into an isolated environment every quarter and confirm it opens.

Getting the order right when budget is tight

Nobody fixes everything at once, and trying to is how projects stall. We run this rough timeline with clients who are starting from a low baseline, which honestly is most of them.

  • First 30 days: enable MFA everywhere, prioritising admins and those accessing sensitive systems. Get high value data backed up properly, even if the rest waits. Pull excessive admin rights from the accounts that clearly don’t need them, which we find on almost every first audit.
  • Next 90 days: roll out EDR across all endpoints, stand up a real patch management cadence, and pilot application control on a small group before going wide.
  • By 180 days: segment the network properly, bring in centralised logging or a managed detection service if you don’t have the in-house skill, and start putting security requirements into vendor contracts.

Triage by risk first: identify your high value targets (finance staff, anyone with domain admin, internet facing servers) and your most exposed assets, then work outward from there. A finance manager with no MFA is a bigger problem than an unpatched printer driver, even though both show up on a vulnerability scan.

Finding attacks early and proving your controls actually work

Prevention fails eventually. Detection is what limits the damage when it does. Centralised, tamper protected logging is the foundation, because ACSC guidance is clear that centralised logs and event analysis through SIEM or EDR tooling are required for real detection and response, not optional extras.

Most SMBs don’t have the in-house skill to run a SIEM properly, and that’s fine. Managed detection through an EDR platform with a human reviewing alerts covers most of the gap.

  • Map your testing to MITRE ATT&CK so you know which attacker techniques your controls actually stop, rather than guessing.
  • Run table-top exercises at least yearly to check your team knows what to do, not just what the plan says.
  • Track mean time to detect and mean time to respond as your core metrics, and push both down over time.

Agencies including CISA, the FBI and ASD jointly recommend testing controls against real world attacker techniques mapped to MITRE ATT&CK, because a control that looks good on paper often fails against the specific method an attacker actually uses.

What to do in the first hour of an incident and how to recover safely

The first sixty minutes of a security incident decide how bad the story gets. Panic makes it worse. A clear checklist makes it survivable.

  1. Isolate affected systems immediately, pulling them off the network rather than shutting them down, since a shutdown can destroy evidence you’ll need later.
  2. Preserve evidence before you touch anything else, which means resisting the urge to reimage a machine the moment you find it.
  3. Stand up emergency communications, following something like the Business Continuity in a Box approach, which walks through provisioning a temporary Microsoft 365 tenant and a catch-all mailbox so critical email keeps flowing while your main systems are down.
  4. Validate backup integrity before restoring anything into production, because restoring a compromised backup just reintroduces the problem you’re trying to fix.
  5. Test the restored environment in isolation first, confirming systems are clean before reconnecting them to the live network.

We’ve written a full walkthrough of Microsoft 365 hardening and continuity alignment if you want the tenant level detail. For continuity planning outside the Microsoft 365 specifics, Ready Accounting’s guide for SMEs is a solid practical reference too. Recovery isn’t finished until you’ve confirmed, not assumed, that what you restored actually works.

What most businesses get wrong (and what we fix)

We see the same failures on almost every new client audit. No MFA on at least one admin account, always. Backups that look fine on paper but turn out to be a file pointer to a cloud sync folder, not an actual backup. Outdated hardware still running production workloads because “it still works.” Former staff with admin rights nobody remembered to remove.

  • Missing MFA on legacy accounts that someone forgot existed, usually a shared mailbox or an old service account.
  • Backups that were never restore tested, which we only discover when a client needs them and they don’t work.
  • Admin rights sprawl, where half the office has local admin because it was easier than fixing permission errors properly.

During a typical 90 day engagement we pull admin rights back to a documented list, rebuild the backup strategy around an offline immutable copy, and put EDR on every endpoint including the ones IT never officially inventoried. If a vendor promises a security tool will “block everything,” walk away. Ask instead what it actually logs and how you’d know if it failed.

Pro Tip: Always request evidence of restore tests on your actual data before trusting a backup product, not just a demo environment.

Illustration of verified backup restoration process

A short take from Matt

Honestly, most of the damage we clean up traces back to two or three missing controls, not some exotic attack. Fix MFA, backups, and admin access first. If you don’t have the time or people to do it properly, that’s exactly what an MSP is for.

— Matt

How IT Start helps you close these gaps

We build our Cyber Security service around exactly the controls in this article: endpoint protection, firewall and segmentation management, patch cadence, and risk and compliance reviews. Paired with our Managed IT Support offering, we handle backups, Microsoft 365 hardening, and incident response so you’re not piecing it together alone. Get in touch through our contact page for a free assessment of where your business actually stands.

FAQ

What are the Essential Eight mitigation strategies?

The Essential Eight are patching applications, patching operating systems, multi factor authentication, restricting administrative privileges, application control, restricting Office macros, user application hardening, and regular backups. ASD designed them as the practical baseline for reducing compromise risk in Australian organisations. Our guide to the Essential Eight breaks down how to apply the maturity levels.

What are the five methods of mitigation?

Definitions vary depending on the framework, but a common grouping covers preventing, transferring, accepting, avoiding, and reducing risk. In cyber security practice this usually plays out as prevention through controls like MFA and patching, risk transfer through cyber insurance, and reduction through detection and response capability.

How do you mitigate cyber security attacks in practice?

Start with the controls proven to stop the most common attack paths: MFA on every privileged account, tested offline backups, and prioritised patching of internet facing systems, following the Essential Eight baseline. Layer EDR and network segmentation on top once the basics are solid. IT Start’s cyber security services are built to implement this order for SMBs directly.

What are the 5 C’s of cyber security?

There’s no single agreed definition of the “5 C’s” backed by a major standards body like ASD or NIST, so treat any version you find online with caution. Rather than chasing a mnemonic, anchor your planning to a recognised framework like the Essential Eight or the NIST Cybersecurity Framework instead.

Related Posts