Instant Asset Write-Off: Tax-Smart IT Buying for Australian SMEs

The instant asset write off lets an eligible small business immediately deduct the full cost of an eligible depreciating asset — a laptop, a server, networking gear — in the year it is first used, rather than claiming a slice of depreciation over several years. The catch: the thresholds, eligibility rules and timing change with almost every federal budget, so you must confirm the current position with your accountant and the ATO before you buy.

We are a Melbourne MSP, not a tax adviser. What follows is general information to help you plan IT purchases sensibly around end of financial year (EOFY) — it is not tax advice, and nothing here should be treated as the current law. Take it to your accountant.

What the instant asset write-off actually is

Normally, when a business buys a capital asset that lasts more than a year — a server, a stack of laptops, a managed switch — you cannot deduct the whole cost in the year you buy it. The Australian Taxation Office (ATO) treats it as a depreciating asset, and you claim its value as a deduction gradually over its “effective life”, often three to five years for IT hardware. Your taxable profit comes down a little each year rather than all at once.

The instant asset write-off changes that for eligible small businesses and eligible assets that cost less than a set threshold. Instead of depreciating over years, you claim the full cost as an immediate deduction in the year the asset is first used or installed ready for use. The asset still has to be a genuine business asset, but the tax benefit lands now rather than being strung out.

The appeal is cash flow and simplicity. A business buying $40,000 of hardware in a single year would, under standard depreciation, see only a fraction of that reduce its taxable income immediately. Under the write-off — assuming each asset and the business qualify — far more of it can be deducted in the same year, lowering that year’s tax bill and freeing up cash sooner.

Why this is the most caveated post we will write

Here is the part you cannot skip. The instant asset write-off is not a fixed, permanent feature of the tax system. It is a measure the government adjusts, extends, shrinks and re-legislates repeatedly — usually at budget time, sometimes retrospectively, and sometimes with the rules still before Parliament when the financial year is already underway.

Three things in particular move:

  • The threshold. The dollar cap on what counts as an “eligible asset” has changed several times in recent years, and it has been very different for different periods. A figure that was correct two years ago may be wrong today. We are deliberately not quoting a current dollar amount here, because by the time you read this it may have moved.
  • Eligibility. Which businesses qualify — usually defined by aggregated annual turnover — has its own threshold that also changes, and it is not the same as the asset cap.
  • Timing. The asset generally has to be first used or installed ready for use within a specific window. Ordering before 30 June is not the same as the asset being installed and operational before 30 June.

So the only correct way to use this measure is to confirm the current threshold, the current turnover eligibility, and the current timing rules with your accountant and on the ATO website before you commit to a purchase. We mean this genuinely, not as boilerplate. We have seen businesses buy in good faith against a number they half-remembered from last year and get a different outcome at tax time. Your accountant is the source of truth; we are the people who help you choose and deploy the kit.

What IT typically qualifies — and what does not

Subject to all the caveats above, the distinction that matters for IT is between a capital asset you buy and own, and an ongoing subscription you rent month to month. They are treated very differently.

Things that are usually capital assets

Tangible IT equipment your business buys and owns is the natural home of the write-off, where the asset and business qualify:

  • Laptops, desktops and monitors
  • Servers and storage hardware
  • Networking equipment — managed switches, firewalls, wireless access points
  • Phones, tablets and peripherals used for work
  • Some perpetually licensed software, and the labour to install and configure hardware, can form part of the asset’s cost — but this gets technical, and it is exactly the sort of thing to put to your accountant rather than assume

Things that usually are not

The big one is SaaS subscriptions. Microsoft 365, your cloud accounting platform, your CRM, a managed IT plan billed monthly — these are not capital assets you own. They are ongoing operating expenses. You generally deduct them as you incur them, as normal running costs of the business, and the instant asset write-off does not apply because there is no asset being acquired.

This trips people up because so much IT has shifted from “buy a box” to “pay a subscription”. A perpetual licence you purchase outright behaves more like an asset; a per-user monthly cloud service behaves like rent. If your spend has quietly moved from capital purchases to subscriptions over the last few years — and for most Melbourne SMEs it has — then a smaller share of your IT spend is even a candidate for the write-off than you might expect. That is not a problem; subscriptions are still deductible as operating costs. It just means the write-off is relevant to the hardware you buy, not the services you rent.

Capital asset versus SaaS subscription: the tax shorthand

AspectCapital asset (e.g. a server, laptops)SaaS subscription (e.g. Microsoft 365)
What you getEquipment you own outrightAccess to a service, billed monthly or annually
Standard tax treatmentDepreciated over its effective lifeDeducted as an operating expense when incurred
Instant asset write-offPotentially eligible (subject to thresholds and rules)Generally not applicable — it is not an asset
Cash-flow shapeLarge upfront outlaySmaller, predictable, recurring
Confirm withYour accountant and the ATOYour accountant and the ATO

This table is a rough orientation, not a ruling. Edge cases exist — bundled hardware-and-service deals, finance arrangements, mixed-use assets — and they are precisely where professional advice earns its fee.

Planning an EOFY refresh without buying junk

The right way to use the write-off is to let it influence the timing of purchases you were going to make anyway — not to manufacture purchases for the deduction. A deduction reduces tax; it does not make a thing free. Spending $30,000 to save some tax on it still leaves you out of pocket on the $30,000. If the kit is not genuinely needed, the write-off is a bad reason to buy it.

Where it works beautifully is bringing forward a refresh you already had on the roadmap. A professional services firm in Hawthorn we work with had a fleet of ageing laptops limping toward failure and a server approaching end of support. They were going to replace both within the year regardless. Their accountant confirmed the timing and eligibility, and we scheduled the rollout so the new hardware was installed and operational before EOFY rather than after. Same purchase they needed; the tax treatment simply landed in the more useful year. That is the sensible version.

The unsensible version is the December or June panic-buy of equipment nobody scoped, chosen on price-before-cutoff rather than fit, that sits in a cupboard or gets deployed badly because there was no plan. We have been called in to clean up plenty of those. A deduction on the wrong hardware is still the wrong hardware.

A few things keep the timing honest:

  1. Confirm the rules first. Before you spend, get your accountant to confirm the current threshold, your turnover eligibility, and the install-by timing for the period you are buying in.
  2. Buy to a plan, not a deadline. Know what you actually need — which machines are due, what the server is being replaced with, what the network requires — before the calendar drives the decision.
  3. Mind the install-by date. The asset generally has to be in use or ready for use, not merely ordered. Hardware on a boat or sitting unconfigured in a box may not count for the year you wanted. Build in lead time.
  4. Right-size it. Do not over-spec to chase a bigger deduction. Buy what the work needs.

Pair it with a proper hardware refresh plan

The businesses that get the most out of any EOFY incentive are the ones that already know their hardware lifecycle — because they are not deciding under pressure. A standing refresh plan tracks the age of every device, the support end-dates for servers and operating systems, and a rolling replacement schedule so equipment is renewed before it fails, not after.

With that in place, an instant asset write-off window becomes a simple question of timing: which planned replacements make sense to bring forward into this financial year? Without it, EOFY is a scramble and the write-off tempts you into bad buys. This kind of forward planning is core to good managed IT services, and it is the sort of thing a virtual CIO brings to a business with no internal IT leadership — a budget and a lifecycle, agreed in advance, instead of reactive spending. It also ties neatly into your wider IT budgeting: hardware is only one line, alongside your subscriptions, security and support, and seeing the whole picture is what stops any single tax lever distorting the plan.

For context on what end-of-support actually forces, our piece on the Windows 10 end of life walks through why some refreshes are not optional — and those are exactly the planned purchases a write-off window can help you time well.

TechAssist is a Melbourne-based MSP, founded in 2014, with thirteen Australian-employed engineers — not an offshore call centre. Because we bill per user at a fixed monthly rate rather than by the hour, hardware planning, procurement advice and EOFY refresh scheduling are part of the relationship, not a surprise project invoice. We will help you choose the right kit and get it deployed in time; your accountant tells you how it is treated.

Frequently asked questions

Is the instant asset write-off still available this financial year?

That is exactly the question to put to your accountant or check on the ATO website, because the answer genuinely changes. The measure has been extended, modified and re-legislated repeatedly, and the threshold and eligibility have moved with it. We will not state a current figure here because it may be out of date by the time you read this. Confirm before you buy.

Does my Microsoft 365 subscription qualify?

Generally no. A monthly or annual subscription is an operating expense, not a capital asset you own, so the instant asset write-off does not apply. The good news is that subscriptions are still deductible as ordinary running costs — they are just claimed differently from owned hardware. Your accountant can confirm the treatment for your situation.

Should I buy IT just to get the deduction?

No. A deduction reduces your tax; it does not make the purchase free. If you would not buy the equipment without the write-off, the write-off is the wrong reason to buy it. The measure is best used to bring forward purchases you genuinely need, with your accountant confirming the timing.

What is the difference between this and normal depreciation?

Normal depreciation spreads an asset’s deduction across its effective life — a few years for most IT hardware. The instant asset write-off, where it applies, lets you claim the full cost as an immediate deduction in the year the asset is first used. Same total deduction over time; the write-off just brings it forward.

If I order hardware before 30 June, does it count for this year?

Not necessarily. The rules generally turn on the asset being first used or installed ready for use within the window, not merely ordered or paid for. Stock in transit or sitting unconfigured may fall on the wrong side of the cutoff. Build in lead time and confirm the timing with your accountant.

Talk to us before your EOFY refresh

If you have hardware due for replacement and you are wondering how to time it around end of financial year, the smart move is to plan the refresh properly first and let your accountant handle the tax treatment. We will help you work out what genuinely needs replacing, choose kit that fits the work, and get it deployed and operational in time. Get in touch and we will give you a straight assessment of your hardware and a sensible refresh plan.

This article is general information only and is not tax advice. The instant asset write-off and its thresholds, eligibility and timing are set by legislation and change regularly — always confirm the current rules with a registered tax agent and the ATO before making a purchasing decision.

Deepfake scams use AI-generated voice clones and video to impersonate a real person — usually your CEO, CFO or a supplier — and trick staff into approving a payment or handing over credentials. They are already hitting Australian businesses, and they work because they exploit trust in a familiar voice or face rather than a dodgy link.

What changed: the technology caught up

For years, the weak link in business fraud was the writing. A scam email asking the accounts team to urgently pay a new supplier account often gave itself away — odd phrasing, a misspelt name, a tone the real boss would never use. Staff learned to spot it.

That tell has gone. Modern voice-cloning tools need only a few seconds of clean audio to produce a convincing copy of someone’s voice, saying anything you type. A LinkedIn video, a conference talk on YouTube, a podcast appearance, a voicemail greeting, even a recorded webinar — that is more than enough source material. The output is good enough to fool a colleague who speaks to that person every day, especially over a phone line or a slightly glitchy Teams call where audio quality is already degraded.

Video deepfakes have followed. The widely reported 2024 case in Hong Kong, where a finance worker paid out roughly AUD $39 million after joining a video call with what he believed were several senior colleagues — every one of them a deepfake — is the example everyone cites because it proves the technique scales to live, multi-person video. You no longer need to be a nation-state to run it. The tools are commodity, cheap, and getting easier to use by the month.

How the attack actually plays out

This is not theoretical, and it is not science fiction. It is a refinement of business email compromise (BEC), the fraud that the Australian Cyber Security Centre (ACSC) and ReportCyber already rank among the most costly facing Australian businesses. We wrote about the email side of this in our guide to business email security and BEC. Voice and video are the new front end on the same con.

The pattern is consistent. The attacker has done their homework — they know the names of your finance staff, who reports to whom, and often that a director is travelling or otherwise hard to reach. Then they apply pressure through a channel that feels personal:

  • A phone call or voicemail from “the managing director”, voice cloned, instructing accounts to release a payment before close of business because a deal is about to fall over.
  • A Teams or WhatsApp voice note from “the CFO” that sounds exactly right, authorising a transfer to a new account and asking the recipient to keep it quiet until it is done.
  • A short video call where the face and voice of a senior leader appear on screen, lending authority to an instruction that would normally need paperwork.
  • A “supplier” calling to confirm that their bank details have changed, following up an email you were already half-expecting.

Every version leans on the same three levers: authority (it is the boss), urgency (it has to happen now) and secrecy (don’t loop anyone else in). Those three together should be a red flag regardless of how convincing the voice is. Genuine executives almost never combine all three.

Why this supercharges BEC

Classic BEC relied on a spoofed or compromised email account and the victim not picking up the phone to check. The standard advice — “if in doubt, call the person directly” — was the defence. Voice cloning attacks that defence head-on. Now the phone call itself can be the fraud. When the verification channel and the attack channel are the same, the old safety net is gone, and you need a new one.

A Melbourne scenario

Picture a construction firm in Box Hill, mid-afternoon on a Friday. The accounts manager gets a voicemail that sounds unmistakably like the director, who everyone knows is on site at a job in Geelong and notoriously hard to reach. He says a subcontractor needs to be paid today to keep a pour on schedule, the bank details are in a follow-up email, and he is heading into a meeting so just get it done — he will sign off properly Monday. The email arrives moments later from what looks like his address. The voice was right. The story was plausible. The pressure was real.

The only thing that saves that firm is a process that does not depend on recognising the voice — because the voice was perfect. A business we work with in the eastern suburbs had a near-miss almost exactly like this. What stopped it was a boring rule: any change to payment details, or any new payee over a set dollar threshold, gets verified by calling the requester back on the number already in the contact system, never a number supplied in the request. The accounts manager rang the director’s real mobile, got no urgent payment story at all, and the fraud collapsed.

Defences that actually work

You cannot reliably train staff to detect a good deepfake by ear or eye any more — that race is lost, and pretending otherwise sets people up to fail. The defences that hold up are about process and verification, not detection. Technology helps at the edges; controls do the heavy lifting.

Out-of-band verification and callback procedures

This is the single most effective control. Any instruction to move money, change bank details or release sensitive data must be confirmed through a different channel than the one it arrived on — and a channel the attacker does not control. If the request came by call or voice note, verify by a different route: call back on the known number stored in your system, message them on an established internal channel, or confirm in person. Never use contact details supplied in the request itself. The whole point is that a cloned voice cannot also intercept the verification.

Payment controls and dual approval

No single person should be able to release a significant payment or change a payee unilaterally. Dual authorisation — a second, independent person who approves transfers over a threshold — means one fooled employee is not enough to lose the money. Set sensible thresholds, enforce them in your accounting and banking platforms, and make exceptions impossible rather than merely discouraged. Most banks support transaction limits and multi-signatory approval; use them.

A code word for fund transfers

Agree a verbal pass-phrase, known only to the people who authorise payments, that must be stated to confirm any urgent or unusual transfer. A deepfake can clone a voice but it does not know the secret word that was never written down or spoken online. It is low-tech, it costs nothing, and it works precisely because the attacker has no way to obtain it from public footage.

Staff awareness, framed correctly

Train people on the pattern, not the polish. Staff should treat any combination of authority, urgency and secrecy as a trigger to verify, full stop — regardless of how genuine the voice or face seems. Make it explicitly safe, even expected, for a junior staff member to slow down and check an instruction that appears to come from the CEO. The culture has to make verification normal, not insubordinate.

Limit your public voice and video footprint

Cloning needs source audio and video. The more of your executives’ voices and faces sit publicly online, the easier the job. You will never eliminate this — and senior people often need a public profile — but it is worth being deliberate about what gets posted, and aware that anyone with a prominent media presence is a higher-value target who warrants tighter payment controls.

Email security underneath it all

Most of these attacks still pair the voice or video with a supporting email, so the email layer matters. Properly configured SPF, DKIM and DMARC to stop domain spoofing, anti-impersonation rules that flag display-name lookalikes, and conditional access to lock down accounts all reduce the surface. This is core to our cybersecurity services, and we cover the email-specific side in detail in the BEC guide. Strong authentication matters too — if attackers cannot get into the real mailbox, they cannot send the convincing follow-up from the genuine address.

What to do if you have been hit

Speed matters enormously with payment fraud, because the money moves fast and recovery odds fall by the hour. If you suspect a deepfake or voice-clone scam has succeeded, or nearly has:

  1. Call your bank immediately. Ask them to attempt a recall or freeze on the transfer. The first hour or two is when funds are most likely to be recoverable.
  2. Report to ReportCyber (cyber.gov.au) and, for the scam itself, to Scamwatch (run by the National Anti-Scam Centre). These reports feed the national picture and can assist tracing.
  3. Lock down internally. Reset credentials on any account that may have been compromised, check mailbox rules for malicious forwarding, and review what else the attacker may have accessed.
  4. Tell your people. Warn staff that an attack is in progress so a second or third attempt does not land. These campaigns often target several employees.
  5. Check your obligations. If personal information was exposed, the Notifiable Data Breaches scheme under the Office of the Australian Information Commissioner (OAIC) may require notification. Get advice quickly.
  6. Preserve evidence. Keep the voicemail, the call records, the emails and any video. Do not delete anything — it matters for the bank, the police and your insurer.

If you carry cyber insurance, notify your insurer early; social-engineering and fund-transfer fraud cover varies widely between policies and many have strict notification windows.

Frequently asked questions

How little audio is really needed to clone a voice?

A few seconds of clear speech is enough for current consumer tools to produce a usable clone, and a minute or two yields something genuinely convincing. Given that most business leaders have video, podcast or webinar audio publicly available, attackers rarely struggle for source material. Assume any voice with a public footprint can be cloned.

Can we just train staff to spot deepfakes?

No, and relying on that is dangerous. Good deepfakes already fool people who know the real person well, and the quality keeps improving. Train staff to follow verification processes regardless of how authentic something seems. The defence is procedural — callback verification, dual approval, a code word — not human lie-detection.

Is this just a problem for big companies?

No. Small and mid-sized businesses are arguably easier targets because they often lack formal payment controls and have flatter structures where one person can authorise a transfer. Attackers go where the friction is lowest. A 15-person firm with no dual-approval rule is a softer target than a large enterprise with locked-down finance controls.

Does multi-factor authentication stop these scams?

It helps but does not solve it. Strong authentication stops attackers logging into your real accounts to send convincing emails, which is valuable. But a voice-clone scam can work entirely outside your systems — a phone call to your accounts team referencing a legitimate-looking email. You still need the payment-verification controls on top of good authentication.

The short version

Deepfake and voice-clone fraud is BEC with a far more convincing front end, and it is landing on Australian businesses now. You cannot train your way to spotting a perfect clone, so the answer is process: out-of-band callback verification on a known number, dual approval over a threshold, a code word for transfers, and email security underneath. Those controls do not care how good the fake is. As a Melbourne-based MSP founded in 2014, with 13 Australian-employed engineers and a 24/7 NOC in Tecoma, we set these controls up so a convincing voice on the phone is not enough to move your money. If you want a straight assessment of where your payment and email controls stand, get in touch.

AI data governance is how you stop staff pasting confidential, customer or regulated information into public AI tools where it can be retained and reused. The fix is not banning AI. It is steering people onto sanctioned, commercially protected tools and putting technical controls around the data itself.

Every Melbourne SME we work with has the same quiet problem: people are already using ChatGPT, Gemini and Copilot, whether or not anyone approved it. The data has already started moving. Governance is about catching up to that reality before it bites.

The actual risk: your data ends up in someone else’s model

When a staff member pastes a slab of text into a free, consumer AI tool, that text leaves your control. Depending on the product and the account tier, it may be stored on the provider’s servers, reviewed by humans for quality, and used to train future versions of the model. That is the part that catches people out — not a dramatic breach, just an employee trying to work faster.

The realistic scenarios are mundane and that is what makes them common:

  • A bookkeeper pastes a payroll export into a free chatbot to “summarise the anomalies” — names, salaries and Tax File Numbers go with it.
  • A lawyer drops a draft settlement deed in to “tighten the language” — privileged client material, now sitting on an external service.
  • A sales rep uploads the full customer list to “write a follow-up campaign” — personal information of hundreds of people, handed to a third party with no agreement in place.
  • A clinic manager pastes patient correspondence in to “make it sound friendlier” — health information, the most sensitive category there is.

None of these people are reckless. They are using a tool that is genuinely useful, on data they handle every day, without realising the back end works differently to Office or their line-of-business app. That is the gap governance closes.

Consumer AI vs commercial AI: the difference that matters

Not all AI tools treat your data the same way, and the difference is entirely about which account you are signed into. This is the single most important thing to get staff to understand.

Consumer tiers — a free ChatGPT account, a personal Gmail’s Gemini, a chatbot someone signed up for with their own email — generally reserve the right to retain prompts and use them to improve the model. The provider’s consumer terms, not a commercial contract, govern what happens to your data.

Enterprise and business tiers — the paid, commercially licensed versions tied to your organisation — come with explicit data-protection commitments. Prompts are not used to train the underlying models, data stays within a contractual boundary, and you get administrative controls. The same brand can sit on either side of that line depending on the plan.

ToolConsumer / free tierCommercial / enterprise tier
ChatGPTPrompts may be retained and used to improve modelsChatGPT Team / Enterprise — prompts not used for training, data stays in your workspace
Microsoft CopilotPersonal Copilot — consumer terms applyMicrosoft 365 Copilot — commercial data protection, prompts and data not used to train foundation models, stays within the Microsoft 365 service boundary
Google GeminiPersonal-account Gemini — may be reviewed and retainedGemini for Google Workspace — enterprise data protection, content not used for training

The practical instruction for staff is short: if AI work involves anything that is not already public, it goes through the sanctioned, organisation-signed-in tool — never a personal or free account. Microsoft 365 Copilot in particular sits inside the same service boundary as your existing Microsoft 365 data, which is why it is the natural starting point for most Melbourne SMEs already on Business Premium. Our guide to what is included with Microsoft 365 support in Melbourne covers where Copilot fits.

The Australian regulatory angle

This is not just a tidiness issue. Feeding personal information into an uncontrolled AND offshore service can put you on the wrong side of the Privacy Act 1988.

Under the Australian Privacy Principles (APPs), you must take reasonable steps to protect personal information (APP 11) and you carry obligations when personal information crosses borders to an overseas recipient (APP 8). Most consumer AI services process data offshore, which means an employee pasting customer data into a free tool can quietly trigger a cross-border disclosure you never assessed or agreed to.

The privacy reforms passed in late 2024 sharpened the picture. They introduced a statutory tort for serious invasions of privacy, strengthened enforcement powers for the Office of the Australian Information Commissioner (OAIC), and signalled tighter expectations around automated decision-making and transparency. The direction of travel is clear: regulators expect organisations to know where personal information goes and to be able to show they controlled it.

Sensitive information — health, biometric, and similar categories — attracts a higher bar again. A health service that lets staff paste patient details into a consumer chatbot has a genuine problem, not a theoretical one. If you operate in that space, our note on healthcare IT support and OAIC obligations is worth a read. The point for everyone else: regulated and customer data needs governance before it goes anywhere near a model.

The technical controls that actually work

A policy document on its own changes nothing. The control that holds is the one that does not depend on every employee remembering a rule at the moment they are busy. Here is the stack we put in place, roughly in order.

An AU-aligned AI acceptable use policy

You still need the policy — it sets the expectation, names the sanctioned tools, and gives you something to point to. The key is that it must be specific to your tools and your obligations, not a generic template. We have written separately about building an acceptable use policy that staff actually follow; the short version is that it should name which tools are approved, what data must never go into any AI tool, and who to ask when unsure. Treat the policy as the starting line, not the finish.

Sanctioned tools, properly licensed

Give people a good, approved option and most of the problem evaporates. Staff reach for free tools because nothing better was offered. Roll out Microsoft 365 Copilot or Gemini for Workspace on the right licence, sign them in under the organisation account, and the data stays inside the commercial boundary by default. Sanctioning a tool is cheaper than cleaning up after an uncontrolled one.

Microsoft Purview sensitivity labels and DLP

This is where governance gets teeth. Sensitivity labels tag and can encrypt your most sensitive files, and Data Loss Prevention (DLP) inspects content and acts on it. A DLP policy can warn or block when someone tries to send a document full of Tax File Numbers or Medicare numbers to an external destination — including, increasingly, paste actions into a browser-based AI tool via endpoint DLP. Labelling and DLP are also what govern what Copilot itself is allowed to surface internally. We cover the full setup in our piece on Microsoft 365 data governance, but the headline is that labels plus DLP are the data-layer control that does not rely on goodwill.

Conditional access

Identity controls decide who can reach the sanctioned tools and from where. Conditional access policies let you require a managed, compliant device and an MFA-verified identity before someone touches the corporate AI tools, and let you block access from unmanaged personal devices where you have no visibility. This is the difference between “we hope people use the right account” and “the wrong account simply cannot reach our data”.

Staff training

Controls reduce the blast radius; training reduces how often the trigger gets pulled. People need to understand, in plain terms, why a free chatbot is different from the signed-in corporate one, and what counts as data they must not paste. A fifteen-minute briefing that shows the consumer-versus-commercial difference does more than a fifty-page policy nobody reads.

Govern before you adopt

The mistake we see most is enthusiasm-first: a business rolls AI out across the company, then thinks about data governance when something goes wrong. Reverse it. Decide what data is sensitive, label and protect it, set DLP rules, pick and license your sanctioned tools, lock access with conditional access, then turn AI loose. Governance first is not slower — it is the only version that does not generate a clean-up project six months later.

A Box Hill scenario

An accounting firm in Box Hill we work with came to us after a partner noticed staff using personal ChatGPT accounts to draft client letters — pasting in figures, names and TFNs as they went. Nobody had done anything malicious; the firm had simply never offered an approved tool or said where the line was. We rolled out Microsoft 365 Copilot under their existing Business Premium licences, applied Confidential sensitivity labels with encryption to their client folders, set DLP rules on TFNs and Medicare numbers, and used conditional access so the corporate tools only worked from managed devices. We paired it with a short staff session on the consumer-versus-commercial difference. The firm now has a faster, sanctioned tool and a defensible answer if the OAIC or their professional indemnity insurer ever asks how client data is controlled.

TechAssist has run Microsoft 365 for Melbourne SMEs since 2008, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. The govern-then-adopt review has quietly become one of the more common pieces of work we do as AI tools spread through workplaces.

Frequently asked questions

Is it safe to use ChatGPT for work?

It depends entirely on the account. A free or personal ChatGPT account may retain your prompts and use them to improve the model, so it is not appropriate for confidential, customer or regulated data. ChatGPT Team or Enterprise, signed in under your organisation, does not use your prompts for training and is a reasonable sanctioned tool. The rule of thumb: anything not already public goes only through the approved, organisation-licensed tool.

Does Microsoft 365 Copilot use our data to train its models?

No. Microsoft 365 Copilot operates under commercial data-protection commitments. Your prompts, responses and organisational data are not used to train the underlying foundation models and stay within the Microsoft 365 service boundary. That is precisely why it is a safer default than a personal AI account for business data.

Can staff pasting data into AI tools breach the Privacy Act?

It can. Pasting personal information into a consumer AI service that processes data offshore can amount to a cross-border disclosure under APP 8 and a failure to take reasonable security steps under APP 11. Sensitive information such as health data raises the bar further. Sanctioned tools, sensitivity labels and DLP are how you keep that data inside controls you can demonstrate to the OAIC.

How do we stop people using free AI tools without banning AI entirely?

You give them a good sanctioned alternative and put controls around the data. License a commercial tool such as Microsoft 365 Copilot or Gemini for Workspace, apply Purview sensitivity labels and DLP, enforce conditional access so the corporate tools only work from managed devices, and back it with a short, specific acceptable use policy and training. Most uncontrolled use stops once a better, approved option exists.

Where to start

You do not need to solve everything at once. Decide which data is genuinely sensitive, license one sanctioned AI tool, switch on a couple of DLP rules in audit mode, and run a fifteen-minute staff briefing. That alone moves you from “people are doing whatever” to a defensible, governed position.

If you would like a hand scoping an AI data governance rollout — sanctioned tools, Purview labels and DLP, conditional access and a policy that fits your obligations — talk to our cyber security team, or get in touch with TechAssist. We will tell you plainly what to lock down first and what you can safely leave alone.

Shadow AI is the unapproved use of artificial intelligence tools by your staff — pasting company data into ChatGPT, running client calls through a free transcription app, installing a browser AI extension — without IT knowing or approving it. It is happening in your business right now, whether you have a policy or not.

The instinct is to ban it. That fails. This post covers what shadow AI actually looks like, the real risks, how to find what is already in use, and how to give staff a safe option instead of a locked door.

What shadow AI actually is

Shadow AI is the AI cousin of shadow IT — staff using software the business never sanctioned. The difference is that AI tools are free, browser-based, genuinely useful, and they ingest whatever you feed them. That makes adoption fast and the data exposure quiet. In a typical Melbourne SME it shows up as:

  • Public chatbots — staff pasting contracts, client emails, financials or source code into the free tiers of ChatGPT, Google Gemini or Claude to summarise, rewrite or debug.
  • Free transcription tools — meeting bots that join Teams or Zoom calls and quietly record and transcribe board meetings, HR discussions and client briefings to a third-party server.
  • Browser AI extensions — Chrome and Edge add-ons that promise to “summarise this page” while reading everything on screen, including data inside your line-of-business apps.
  • AI features bolted onto consumer apps — note-takers, design tools and PDF readers that have added an AI feature most users never think twice about.

None of this is malicious. It is a marketing manager hitting a deadline, an accounts clerk speeding up a reconciliation, a salesperson who wants their call notes written for them. The intent is fine. The data trail is the problem.

The real risks

The risks are concrete, and several carry legal weight in Australia.

Confidential and customer data leaving the business

When someone pastes a client list, a draft contract or a spreadsheet of personal details into a public AI tool, that data has left your control. On free and consumer tiers you generally have no contractual data-handling guarantees, no Australian data residency, and limited ability to demand deletion. Once it is out, it is out.

Your data becoming training data

Several consumer AI services reserve the right to use submitted content to improve their models unless you are on a paid plan that explicitly opts out. A confidential prompt today could influence an answer given to a stranger tomorrow. For a law firm, an accountant or anyone handling commercial-in-confidence material, that is a genuine professional problem.

Intellectual property and privacy breaches

Feeding proprietary code, product designs or unpublished strategy into an external tool can weaken your claim over that IP. More seriously, if the data includes personal information — names, contact details, health or financial records — you are likely engaging the Privacy Act 1988 and the Australian Privacy Principles, which require reasonable steps to protect personal information and to control offshore disclosures. A staff member uploading a customer database to a US-hosted chatbot can put you on the wrong side of those obligations, and a serious breach is reportable to the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.

Inaccurate output, trusted blindly

The risk that gets least attention is the most common in practice. AI tools produce confident, fluent answers that are sometimes wrong — fabricated case citations, invented figures, misremembered policy. When staff paste that output straight into client advice, a board paper or a compliance document without checking it, the error is now yours. The tool does not sign off on the work; your business does.

Why banning it outright fails

The first reaction from a nervous business owner is “block all of it”. It does not work, for three reasons.

First, the tools are too accessible. You can block a domain on the corporate network, but staff will use their phone, home laptop or personal browser profile. You have not removed the risk; you have just lost sight of it.

Second, AI genuinely makes people faster and your competitors are using it. A blanket ban tells your best people the business is behind, and they will route around it.

Third, a ban with no sanctioned alternative guarantees the worst outcome: people still use AI, but only the unmonitored consumer versions, because you gave them nothing else. The goal is not zero AI. It is governed AI — the same logic that underpins sensible cyber security everywhere else.

How to discover what is already in use

You cannot govern what you cannot see, and most businesses have no idea how deep shadow AI already runs. Three practical ways to find out:

  • SaaS and cloud app discovery (CASB) — a Cloud Access Security Broker, or the app-discovery capability in Microsoft Defender for Cloud Apps, inventories which cloud services staff sign into and ranks them by risk. The fastest way to see that thirty people are logging into AI tools you never approved.
  • Network and DNS logs — your firewall and DNS resolver already record outbound connections. Filtering for known AI domains shows traffic volume and which devices generate it, even before you have a CASB in place.
  • Conversations — the most underrated method. Ask teams, without blame, what AI tools they use and why. People are usually happy to tell you, because they do not see it as a security issue. That honesty tells you where to provide a safe option.

A construction firm in Box Hill we work with ran exactly this exercise. A discovery scan plus a few honest conversations turned up four AI transcription tools quietly joining site-coordination meetings, and two project managers pasting subcontractor agreements into a public chatbot to summarise variations. Nobody was acting in bad faith. They simply had no sanctioned tool and no rule telling them where the line sat.

Building a sane AI position

The fix is a short, clear acceptable-use position backed by a real alternative — not a 40-page policy nobody reads.

A short acceptable-use position

Write a one-page AI acceptable-use statement that answers the questions staff actually have: which tools are approved, what data must never go into a public tool (client personal information, financials, contracts, anything under NDA), and that AI output must be checked by a human before it is used in client work. A policy people understand is worth ten they ignore.

Provide a sanctioned, safe option

This is the part most businesses skip, and the part that makes the policy stick. Give staff an enterprise-grade AI tool with proper data protections — most commonly Microsoft 365 Copilot, which operates inside your tenant, respects existing permissions, and does not use your prompts to train public models. When people have a fast, sanctioned tool that works, the pull towards consumer apps drops sharply.

The catch is that Copilot surfaces anything the asking user can already reach, so loose permissions become a liability the moment you switch it on. That is why governance comes first, and why conditional access policies matter for controlling which devices and users can reach these tools at all. The data-governance groundwork sits alongside the rest of your Microsoft 365 setup.

The governance and DLP layer

A policy tells people what to do; technical controls back it up when they forget. This is the AI data governance layer, and for Microsoft 365 businesses it largely lives in Microsoft Purview.

Two Purview capabilities do most of the work:

  • Sensitivity labels — tagging documents as Confidential or Highly Confidential, with encryption on the top tier, so the most sensitive data is marked and protected before any AI tool can touch it.
  • Data Loss Prevention (DLP) — rules that detect sensitive content (Tax File Numbers, Medicare numbers, credit card numbers, client records) and warn or block when someone pastes or uploads it to an unsanctioned destination. Endpoint DLP extends that to the browser and clipboard, which is precisely where shadow AI lives.

Start DLP rules in audit-only mode for a fortnight, tune out the false positives, then move the high-risk ones to block. Turn everything to block on day one and you will have the finance team locked out of legitimate work by Tuesday.

ConcernConsumer AI (free tier)Sanctioned enterprise AI
Data residency / controlUsually offshore, no guaranteesInside your tenant, contractual terms
Used to train public modelsOften, unless opted outNo
Respects existing permissionsNo concept of themYes
AuditableNo visibilityLogged via Purview audit
DLP enforceableNoYes

Staff training closes the loop

Tools and policies fail without the why. A thirty-minute session showing real examples — what happens to a contract pasted into a free chatbot, why the transcription bot in the board meeting is a problem, how to use the sanctioned tool instead — changes behaviour far more than a signed policy ever will. The message is not “AI is dangerous, stop”. It is “AI is useful, here is how we use it safely”. Train people to treat AI output as a draft to verify, never a finished answer.

Frequently asked questions

Is using ChatGPT at work illegal in Australia?

Using it is not illegal. The risk is what you put into it. If staff feed personal information into a public AI tool, you may breach the Australian Privacy Principles, particularly the rules on protecting personal information and disclosing it overseas. A serious breach can trigger reporting obligations to the OAIC. The tool is fine; uncontrolled data going into it is the problem.

Does Microsoft 365 Copilot solve the shadow AI problem?

It removes most of the pull towards consumer tools by giving staff a fast, sanctioned alternative that keeps data inside your tenant. It does not replace governance. You still need sensitivity labels, sensible permissions and DLP, because Copilot surfaces whatever the user can already access. Provide the safe tool and govern the data underneath it.

What is the first thing we should do about shadow AI?

Find out what is actually in use. Run a SaaS discovery scan or check your DNS logs, and have a few honest conversations with staff. You cannot write a sensible policy or pick the right sanctioned tool until you know what problem people are solving and which tools they have reached for.

Where to start

Shadow AI is not a reason to panic, and certainly not a reason to ban a technology your staff find useful. It is a reason to look. Find out what is in use, write a one-page position people will follow, give them a safe enterprise tool, and back it with Purview labelling and DLP. That sequence — discover, sanction, govern, train — turns an invisible risk into a managed one.

TechAssist has run Microsoft 365 and security for Melbourne SMEs since 2008, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. If you would like a hand finding what is in use and putting a sane AI position in place, get in touch with TechAssist. We will tell you plainly what is happening, what to allow, and what to lock down.

The right to disconnect lets employees refuse to monitor, read or respond to work contact outside their working hours unless that refusal is unreasonable. It is Fair Work law, not an IT rule. But the email, Teams and mobile settings your MSP controls are what turn a policy on paper into something that actually holds.

What the right to disconnect actually says

The right to disconnect was added to the Fair Work Act and took effect on 26 August 2024 for medium and larger employers. For small business employers (fewer than 15 employees), it commenced a year later, on 26 August 2025. So as of now, it applies across the board.

The substance is narrow but important. An employee may refuse to monitor, read or respond to contact (or attempted contact) from their employer outside their working hours, unless the refusal is unreasonable. The same applies to contact from a third party — a client, a supplier — if it relates to their work. Whether a refusal is unreasonable depends on factors the legislation spells out: the reason for the contact, how it is made and how disruptive it is, whether the employee is compensated for being available, the employee’s role and level of responsibility, and their personal circumstances including family or caring responsibilities.

Note what it does not say. It is not a ban on after-hours contact. An employer can still send a message at 9pm. What changes is that the employee is generally entitled not to engage with it until they are back on the clock, and they cannot be punished for that. Disputes are meant to be worked out at the workplace first, and if that fails, the Fair Work Commission can deal with them.

This is workplace-relations law, and the genuinely hard questions — what counts as “working hours” for a salaried manager, how an on-call allowance is structured, what your enterprise agreement or award says — are HR and legal questions. Get advice on those. What we deal with as a Melbourne MSP is the layer underneath: the systems that decide whether a notification lands on someone’s phone at all, and whether your roster and monitoring arrangements line up with what you have told staff.

The IT controls that make a policy real

A right to disconnect policy that says “please don’t email after hours” and changes nothing in Microsoft 365 is theatre. Staff still hear the buzz, still feel the pull, and the more conscientious ones still answer. The controls below are the ones that actually shift behaviour, and most of them are already sitting in your tenant waiting to be turned on.

Quiet hours and scheduled send in Outlook and Teams

Microsoft Teams has a built-in quiet hours and quiet days feature in the mobile app, so notifications are silenced outside the hours a user sets. The catch is that it is per-user and opt-in by default — most people never find it. The fix is to make it part of standard onboarding and to actually show people where the setting lives, rather than burying it in a policy PDF.

On the sending side, Outlook’s scheduled send (Delay Delivery) lets a manager who genuinely does their thinking at 10pm queue the email to land at 8am. That one habit removes most of the after-hours pressure without anyone having to ignore anything. We usually pair it with a short signature line on out-of-hours senders — something like “I work flexible hours; I don’t expect a reply outside yours” — which the Fair Work Ombudsman’s own guidance points to as good practice.

If you want notifications properly switched off rather than left to each person, that is configurable through Microsoft 365 administration and device policy. This is part of the day-to-day work in any managed Microsoft 365 environment, and it is the kind of thing worth getting right once across the whole organisation rather than user by user.

Mobile device management and conditional access

The real after-hours leak is the phone. Work email and Teams on a personal mobile means contact follows people into the lounge room. Mobile device management (through Microsoft Intune) and conditional access policies give you proper levers here.

You can enforce app protection so work data stays inside managed apps, and you can use conditional access to shape when and how people connect. For specific roles — not everyone — you can even restrict access to corporate apps to particular hours or locations, so that someone who is genuinely off the roster is not technically able to be pulled back in. Used carefully, this turns a written rule into an enforced boundary. Used clumsily, it locks out the on-call engineer at 2am, so it has to be designed around your actual roster rather than applied with a blunt instrument.

A professional services firm in Hawthorn we work with had the opposite problem to most: their junior staff were answering partner emails at all hours because the Teams app pinged their personal phones and nobody had told them they didn’t have to. The remedy was not a stern memo. It was switching most of the team to managed app access with notifications off outside business hours, leaving a small after-hours group properly resourced, and writing the policy to match what the systems now did.

On-call rosters and the compensation question

The right to disconnect bites hardest where there is no clear on-call arrangement. If you expect certain people to be reachable after hours, that should be a defined roster with an allowance or overtime attached — not a vague cultural expectation that everyone is always on. The legislation explicitly weighs whether the employee is compensated for being available when judging if a refusal is unreasonable.

From the IT side, that means your access controls and notification rules should mirror the roster. The on-call person this week gets the alerts and the access; everyone else doesn’t. We run our own 24/7 NOC out of Tecoma on exactly this model, with a defined roster and the tooling configured so the engineers who are off are genuinely off. The technology and the employment arrangement have to agree with each other, or one of them is lying.

Monitoring, alerts and overtime creep

System monitoring is where this gets subtle. Automated alerts from a server, a backup job or a security tool are not “the employer contacting you” in the Fair Work sense — they are machines. But if a human is expected to act on those alerts after hours, that expectation is exactly what the right to disconnect is about, and it should be rostered and paid like any other on-call duty.

The practical move is to route after-hours monitoring to whoever is actually on call, not to a whole team’s inboxes. Alert fatigue and silent unpaid overtime usually come from the same root cause: everyone gets every alert, so everyone feels vaguely responsible at all hours. Tightening alert routing is both better security operations and a cleaner employment boundary. This is core to how a managed security operations capability should be run regardless of the legislation.

Writing a policy your systems can back up

The order of operations matters. Plenty of businesses write the policy first, then discover their systems don’t support it. Do it the other way around: decide what the systems will enforce, then write a policy that describes that reality.

A workable right to disconnect policy generally covers:

  • Working hours by role — what they are, and who, if anyone, is on a defined after-hours roster.
  • Contact expectations — that staff are not expected to respond outside their hours, and won’t be penalised for not doing so.
  • The genuine exceptions — emergencies, the on-call roster, and how those people are compensated.
  • The tools — quiet hours, scheduled send, managed notifications — and that the business has configured them, not just recommended them.
  • How to raise a concern — the internal process before anything goes near the Fair Work Commission.

The wording and the workplace-relations judgement calls belong with your HR adviser or employment lawyer. The Fair Work Ombudsman publishes plain-English guidance on the right to disconnect that is a sensible starting point for that conversation. Our job is the other half: making sure the tenant settings, device policies and alerting genuinely do what the document claims. When we take on a new client we treat this as part of the broader managed IT baseline, alongside the security and identity controls that touch the same systems.

Frequently asked questions

Does the right to disconnect ban after-hours emails?

No. Employers can still send messages outside working hours. What the law changes is that employees are generally entitled not to monitor or respond to them until they are back at work, and they can’t be disadvantaged for that — unless their refusal is unreasonable in the circumstances. Scheduled send is the easy way to avoid the issue entirely.

Does it apply to my small business?

Yes. The right to disconnect commenced on 26 August 2024 for employers with 15 or more employees and on 26 August 2025 for small business employers under 15 staff. Both dates have now passed, so it applies regardless of size.

Can IT settings actually enforce this?

To a large degree, yes. Quiet hours in Teams, managed-app notifications through Intune, and conditional access policies can stop most after-hours pings reaching staff who aren’t on call. They can’t make legal judgements about what’s reasonable, but they remove the temptation and the pressure that cause the problem in the first place.

What about our on-call engineers and after-hours support?

Genuine on-call work is fine — it just needs to be a defined roster with proper compensation, and your access and alert routing should match it so only the on-call person is pinged. The law specifically considers whether someone is paid for being available when deciding if declining contact is reasonable.

Is this a security or a compliance issue?

It is primarily a workplace-relations issue, so the policy and any disputes are HR and legal territory. But the controls that make it work — identity, device management, conditional access, alert routing — are the same ones that underpin your security posture, which is why it tends to land on the IT plate.

Where TechAssist fits

We’re a Melbourne MSP, founded in 2014, with 13 Australian-employed engineers — no offshore call centre — and we run this kind of configuration work across professional services, construction, manufacturing and healthcare clients every week. The right to disconnect is one of those rules where the legal text is short but the implementation lives entirely in settings most businesses have never opened.

If you want your Microsoft 365 tenant, mobile device policies and after-hours alerting set up so they actually back the policy you’re putting in writing, get in touch. We’ll handle the IT half; pair it with your HR adviser for the rest.

SOC 2 is an independent attestation report, produced under American Institute of Certified Public Accountants (AICPA) standards, that tells your customers an external auditor has examined your security controls. It is not a certification you pass. For Australian SaaS firms selling into the US or to enterprise buyers, it has become the price of entry.

If you build software in Melbourne and your sales pipeline runs through US accounts or large Australian enterprises, you have probably hit a security questionnaire that asks one blunt question: “Do you have a SOC 2 report?” The honest answer for most early-stage Australian SaaS companies is no, and that “no” stalls deals. This post explains what SOC 2 actually is, how it differs from ISO 27001, what the audit involves, and what it realistically costs in time and money.

What SOC 2 actually is

SOC 2 (System and Organization Controls 2) is a reporting framework owned by the AICPA. A licensed CPA firm examines how you manage customer data and issues a report describing your controls and whether they were designed, and in some cases operating, effectively. The deliverable is a report, not a logo or a certificate. You cannot self-certify, and there is no central registry to check against — your customers read the report under NDA.

The report is built around the Trust Services Criteria. There are five of them, and you choose which apply to your business:

  • Security — the only mandatory criterion (often called the “common criteria”). Covers access control, change management, risk assessment, monitoring and incident response.
  • Availability — uptime, performance monitoring, disaster recovery. Relevant if you make uptime commitments in SLAs.
  • Processing Integrity — data is processed completely, accurately and on time. Matters for payments, payroll or anything that transforms data.
  • Confidentiality — protection of information designated as confidential, including encryption and retention controls.
  • Privacy — collection, use, retention and disposal of personal information in line with your privacy notice.

Most SaaS companies scope their first report to Security alone, then add Availability and Confidentiality once customers ask. Privacy is the least commonly included because, for Australian companies, the Privacy Act 1988 and the Australian Privacy Principles already govern that ground — and bolting it onto SOC 2 adds work for limited buyer benefit.

Type I versus Type II

This distinction trips people up, so be clear on it before you commission anything.

AspectSOC 2 Type ISOC 2 Type II
What it testsWhether controls are designed appropriatelyWhether controls operated effectively over time
TimingA single point in timeA monitoring period, typically 3 to 12 months
EvidencePolicies and configurations as they stand on the dateEvidence sampled across the whole window
Buyer confidenceModest — proves intentHigh — proves you actually do it
Typical useA first step to show momentumThe report enterprise buyers actually want

A Type I says “on 30 June, these controls were in place and well designed.” A Type II says “across the six months to 30 June, these controls ran and here is the audit evidence.” Serious buyers want Type II. Many Australian SaaS firms do a Type I first to demonstrate progress to a waiting prospect, then run a Type II over the following six to twelve months. That is a sensible path, but do not expect a Type I alone to clear an enterprise security review.

Why Australian SaaS companies pursue it

The driver is almost always commercial, not regulatory. SOC 2 is not law anywhere — it is a market expectation that crystallised in US procurement and has spread to large Australian buyers running mature vendor risk programmes.

If your product touches a customer’s data and you want to sell to a US fintech, a healthcare platform, or any ASX-listed enterprise, their security team will ask for a SOC 2 Type II report early in the process. Without one you get stuck in a back-and-forth of bespoke questionnaires, and procurement treats you as a higher-risk vendor. The report short-circuits all of that: it answers most of the questionnaire in one document and signals that you take security seriously enough to pay an auditor to check.

A logistics-tech startup in Cremorne we work with hit exactly this wall — a US enterprise prospect wouldn’t progress past security review without a Type II, and the deal was large enough that the audit cost was a rounding error against the contract value. That is the usual shape of it: SOC 2 pays for itself the moment it unlocks one enterprise account.

SOC 2 versus ISO 27001

This is the question every founder asks, and the honest answer is that they overlap heavily but serve different audiences.

SOC 2ISO 27001
OriginAICPA (United States)ISO/IEC (international)
OutputAttestation report from a CPA firmCertificate from an accredited certification body
NatureAuditor’s opinion on your controlsCertification of a management system (ISMS)
Recognised byUS buyers, North American enterpriseEurope, UK, Australia, global enterprise
RenewalReport covers a period; reissued annuallyThree-year cycle with annual surveillance audits
Public proofPrivate report shared under NDAPublic certificate

The control sets behind them are largely the same — access management, change control, risk assessment, vendor management, incident response. The difference is the wrapper. SOC 2 is an auditor describing and testing your controls; ISO 27001 certifies that you run a documented Information Security Management System that continuously improves.

Do you need both?

If your buyers are overwhelmingly North American, SOC 2 alone is usually enough. If you sell into Europe, the UK and Australia, ISO 27001 carries more weight and is the more recognised brand. Plenty of Australian SaaS companies end up doing both because their customer base spans regions — and the marginal effort is smaller than it looks, since one set of controls and one evidence library can support both audits. Build the controls once, attest and certify twice. If you are weighing the options, our cybersecurity services team can map your buyer base to the right framework before you spend a cent on auditors.

The audit process and the role of a security partner

A SOC 2 engagement has two distinct phases, and conflating them is where budgets blow out.

Readiness

Readiness is everything you do before the auditor arrives. You define scope, write or tidy policies, implement the controls, and stand up the tooling that proves they work — multi-factor authentication everywhere, centralised logging, formal access reviews, change management tied to your code pipeline, vendor risk records and an incident response plan you have actually tested. For most Australian SaaS companies this is the real work, and it is where an MSP or security partner earns its fee. The auditor will not help you fix gaps; their job is to observe, not advise.

This is what a security partner does in readiness: run the gap assessment against the Trust Services Criteria, prioritise the controls that matter, deploy the technical guardrails, and set up evidence collection so you are not scrambling at audit time. Much of the Security criterion overlaps with hardening work we already do for clients — the Essential Eight mitigation strategies map cleanly onto SOC 2’s access control, patching and application hardening expectations, so if you are already Essential Eight aligned you are further down the road than you think.

Evidence collection and continuous controls

Type II is won or lost on evidence. The auditor samples across the monitoring period and asks for proof that each control operated every time it should have — access reviews completed each quarter, every code change approved, every alert triaged, every offboarding done within policy. If those records do not exist, the control fails for the period regardless of how good your intentions were.

This is why continuous controls monitoring matters. Compliance automation platforms such as Vanta, Drata or Secureframe connect to your cloud, identity provider and code repositories and collect evidence automatically, flagging drift the moment a control slips. They do not make you compliant — they make the evidence trail survivable. A partner who already runs your SIEM and managed detection stack is well placed to wire these tools into your environment and keep the controls green between audit windows. TechAssist runs a 24/7 NOC out of Tecoma and our engineers are Australian-employed, so the monitoring that underpins your evidence is staffed locally, not handed to an offshore queue.

Realistic timeline and cost

Be wary of anyone promising SOC 2 in a few weeks. Here is the honest shape of it for an Australian SaaS company starting from a reasonable baseline.

  • Readiness: two to four months for an early-stage company with decent foundations; longer if your access controls and logging are immature.
  • Type I report: issued shortly after readiness, reflecting a point in time.
  • Type II monitoring window: three months at minimum, but six to twelve months is what enterprise buyers expect to see.
  • Annual reissue: SOC 2 is not one-and-done. A Type II report covers a stated period, so you run a fresh audit each year to keep a current report on hand.

On cost, the auditor’s fee for a Type II from a reputable CPA firm typically runs into the tens of thousands of dollars (AUD), and that is before tooling and the internal or partner effort to get ready. Compliance automation platforms add an annual subscription. The readiness work — the controls, the policies, the engineering — is usually the larger line item, especially the first time through. Budget for the whole programme, not just the audit invoice, and treat year one as the expensive one.

Frequently asked questions

Is SOC 2 a certification?

No. It is an attestation report issued by a CPA firm under AICPA standards. There is no certificate and no public registry — you receive a report describing your controls and the auditor’s opinion, which you share with customers under NDA. Calling it a “certification” is common shorthand, but technically wrong.

Should an Australian company do SOC 2 or ISO 27001?

It depends on who buys from you. North American buyers expect SOC 2; European, UK and Australian buyers lean on ISO 27001. If your customer base spans both, doing both is common and the underlying controls are largely shared, so the second framework costs far less effort than the first.

Does SOC 2 satisfy Australian privacy law?

Not on its own. The Privacy Act 1988 and the Australian Privacy Principles still apply to your handling of personal information regardless of any SOC 2 report. SOC 2 can include a Privacy criterion, but it is a US framework — it is not a substitute for meeting your obligations under Australian law.

Can an MSP get us SOC 2 ready?

A security partner can run the gap assessment, implement and harden the controls, stand up evidence collection and keep controls monitored continuously between audits. The CPA auditor must remain independent, so the same firm cannot both prepare you and issue the report — but the readiness work is exactly where an MSP adds value.

Where TechAssist fits

We are a Melbourne MSP, founded in 2014, with thirteen Australian-employed engineers. We do not issue SOC 2 reports — that is the auditor’s job, and it has to stay independent — but we do the readiness and the continuous controls work that gets you there and keeps you there. That means hardening your Microsoft 365 and cloud environment, standing up logging and detection, wiring in compliance automation, and making sure the evidence trail your auditor samples actually exists every time. If a SOC 2 report is gating your next enterprise deal, get in touch and we will map the gap before you commit to an audit timeline.

If your business gets hit by a data breach that’s likely to seriously harm the people whose data you hold, the law gives you a tight window: assess it fast, then notify the regulator and the affected individuals as soon as practicable. Get the timing wrong and the penalties now run into the millions.

That’s the short version of the notifiable data breaches scheme, and it catches far more Melbourne SMEs than most directors realise. Here’s what it actually requires, who it covers, and the incident-handling steps you should have ready before anything goes wrong.

What the NDB scheme actually is

The notifiable data breaches scheme sits under Part IIIC of the Privacy Act 1988 (Cth) and has been in force since February 2018. It’s administered by the Office of the Australian Information Commissioner (OAIC). The core obligation is simple to state and harder to live by: if you experience an eligible data breach, you must notify both the OAIC and every affected individual.

It isn’t a “tell us if you feel like it” arrangement. Notification is mandatory once the threshold is met, and the clock starts the moment you have reason to suspect something has gone wrong. The scheme exists so people can take protective steps — change passwords, watch their bank accounts, put a credit ban in place — before stolen data is used against them.

Who the Privacy Act covers

The Act applies to “APP entities” — organisations bound by the Australian Privacy Principles. The headline test is annual turnover. If your business turns over more than $3 million a year, you’re almost certainly covered. Plenty of directors stop reading there and assume they’re exempt. That’s a mistake, because the exceptions sweep in a lot of smaller operators.

You’re covered regardless of turnover if you:

  • Are a health service provider that holds health information — this includes GPs, allied health, dentists, physios, psychologists and pharmacies, no matter how small the practice.
  • Trade in personal information (buying or selling it).
  • Are a credit reporting body or provide credit.
  • Are a contractor delivering services under a Commonwealth contract.
  • Are a tax file number recipient (most employers handle TFNs).

A three-chair dental practice in Camberwell with $1.2 million turnover is covered because it holds health information. A logistics broker handling TFNs and credit checks gets pulled in through those activities. The $3 million line is a floor for ordinary businesses, not a free pass for everyone under it. If you handle health data specifically, our write-up on healthcare IT support and OAIC obligations goes deeper on the sector rules.

What counts as an “eligible data breach”

Not every lost laptop or misdirected email triggers notification. An eligible data breach has three ingredients:

  1. There’s unauthorised access to, or unauthorised disclosure of, personal information you hold — or that information is lost in circumstances where unauthorised access or disclosure is likely.
  2. A reasonable person would conclude the breach is likely to result in serious harm to one or more affected individuals.
  3. You haven’t been able to prevent that likely serious harm through remedial action.

That third point matters. If you act quickly enough that serious harm is no longer likely — say, you remotely wipe a stolen, encrypted laptop before anyone could read it — the breach may not be notifiable at all. Remediation is a genuine off-ramp, but only if it’s fast and effective.

The “serious harm” test

“Likely to result in serious harm” is the pivot the whole scheme turns on, and there’s no fixed checklist. The OAIC asks you to weigh factors including the kind of information involved (health records and financial details rank high; a publicly listed business name does not), its sensitivity, whether it was encrypted or otherwise protected, who is now likely to have it, and what they could do with it.

Serious harm can be physical, psychological, emotional, financial or reputational. A breach exposing identity documents and bank details is far more likely to clear the bar than one exposing a marketing mailing list. The judgement is yours to make, but you have to be able to defend it — the OAIC can and does ask to see your reasoning.

The timeframes you have to hit

This is where SMEs get caught out, so be precise about the two clocks.

The assessment clock. If you only suspect an eligible data breach has occurred — you’re not yet sure it clears the serious-harm threshold — you must carry out a reasonable and expeditious assessment. The word “expeditious” means you start straight away, not when it’s convenient. The Act sets an outer limit of 30 calendar days from when you became aware of the grounds for suspicion. Thirty days is a ceiling, not a target. If you can resolve it in three, do it in three.

The notification clock. Once you’ve decided you have an eligible data breach, you must notify the OAIC and affected individuals as soon as practicable. There’s no fixed day count here — “as soon as practicable” is judged on your circumstances — but it is not weeks of internal deliberation. You prepare a statement, lodge it with the Commissioner through the OAIC’s online form, and notify individuals by whatever method you normally use to contact them.

People often talk about a “72-hour rule” for data breaches. That figure comes from the EU’s GDPR, not the Australian Privacy Act. Australia’s standard is the “as soon as practicable” test, with the 30-day assessment ceiling sitting behind it. Treating 72 hours as your internal working deadline is sensible discipline — just don’t mistake it for the letter of Australian law.

The 2024 reforms and the new penalty regime

The penalties for getting this wrong are no longer trivial. Reforms that began with the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 and continued through the Privacy and Other Legislation Amendment Act 2024 sharpened the OAIC’s teeth considerably.

For serious or repeated interferences with privacy, the maximum penalty for a body corporate is now the greater of $50 million, three times the value of any benefit obtained from the misuse of information, or 30 per cent of the entity’s adjusted turnover for the relevant period. That’s a dramatic jump from the old cap and it’s aimed squarely at organisations that treat privacy as optional.

The 2024 reforms also introduced a statutory tort for serious invasions of privacy, gave the Commissioner new mid-tier and low-tier civil penalty powers for less severe contraventions, and added powers to issue infringement notices. The practical effect for an SME: there is now a graduated enforcement ladder, so even a moderate compliance failure can attract a penalty rather than just a stern letter. Australia’s privacy framework is being progressively tightened, and the direction of travel is more obligations, not fewer.

What an SME should have ready before a breach

The businesses that handle a breach well aren’t the ones that read the Privacy Act after the fact — they’re the ones who decided in advance who does what. A data breach response plan doesn’t need to be a 40-page document. It needs to answer a handful of questions before the pressure is on.

ElementWhat good looks like
Response leadOne named person who owns the assessment and can convene the team within the hour.
DetectionLogging and alerting that actually tells you when data is accessed or exfiltrated — not a customer phoning to ask why their details are on a forum.
Assessment templateA repeatable way to record what was breached, who’s affected, and your serious-harm reasoning, dated and saved.
Containment runbookSteps to isolate systems, revoke credentials and preserve evidence without destroying it.
Notification draftsPre-drafted OAIC statement and individual notice you only have to fill in, not write from scratch at 11pm.
Contact listOAIC, your insurer, your lawyer, your MSP and the ACSC’s ReportCyber — current numbers, not guesswork.

A construction firm in Box Hill we work with discovered a compromised mailbox after a finance staffer’s credentials were phished. Because the logging was already in place, we could see exactly which messages and attachments the attacker had opened, scope the affected individuals within a day, and confirm that the exposed data did clear the serious-harm threshold. The notification went out fast and clean — not because they panicked well, but because the plan already existed. That kind of visibility is exactly what our cybersecurity services and managed detection and response are built to deliver.

Where most breaches actually start

In practice, the overwhelming majority of breaches we see trace back to compromised credentials and email — phishing, business email compromise, reused passwords. The single highest-value control for an SME is strong identity protection: multi-factor authentication everywhere, conditional access on Microsoft 365, and monitoring that flags anomalous sign-ins. Tightening identity is cheaper than any post-breach notification exercise, and it’s the foundation the Essential Eight is built on.

How TechAssist helps

TechAssist is a Melbourne-based MSP, founded in 2014, with 13 Australian-employed engineers — no offshore helpdesk. Our 24/7 NOC operates out of Tecoma in the eastern suburbs, with a second office in the Melbourne CBD at 575 Bourke Street. When a breach is unfolding, response time is everything: we target sub-15-minute response on critical incidents, which is the difference between containing a compromise and explaining it to the OAIC.

The realistic goal isn’t never having an incident — it’s detecting fast, containing faster, and being able to make a defensible serious-harm decision inside your timeframes. If you’re not confident you could do that today, that’s the gap worth closing. Have a look at our broader managed IT services, or get in touch and we’ll pressure-test your breach readiness before something forces the issue.

Frequently asked questions

Does the NDB scheme apply to my business if I turn over under $3 million?

Possibly. The $3 million turnover threshold is the general rule, but exceptions bring in any size of business that provides health services, handles credit information, trades in personal information, or operates under a Commonwealth contract. Most healthcare providers are covered regardless of turnover.

Is there really a 72-hour deadline to report a data breach in Australia?

No — the 72-hour figure is a GDPR (European) rule. Under the Australian Privacy Act you must notify the OAIC and affected individuals “as soon as practicable” after deciding you have an eligible data breach, and you have up to 30 days to assess a suspected breach. Acting within 72 hours is good practice, not the legal test.

What if I fix the breach quickly — do I still have to notify?

Not necessarily. If you take remedial action fast enough that serious harm is no longer likely, the breach may not be “eligible” and notification isn’t required. The catch is that the remediation has to genuinely remove the risk, and you need to document why it did.

Who do I actually notify, and how?

You notify the OAIC by lodging a statement through its online Notifiable Data Breach form, and you notify affected individuals directly using your usual contact method. If you can’t reasonably contact individuals one by one, you publish the statement and take steps to publicise it.

What happens if I don’t comply?

Failing to comply is an interference with privacy and can attract enforcement by the OAIC. Following the 2024 reforms, penalties for serious or repeated breaches reach the greater of $50 million, three times any benefit gained, or 30 per cent of adjusted turnover — alongside new mid- and low-tier penalty powers for lesser failures.

If your business stores, processes or transmits card payment data, PCI DSS compliance applies to you. It’s the security standard the card brands enforce on every merchant that touches cardholder data. The good news for most Australian SMEs: with the right payment setup, your obligations are smaller than you’d think.

What PCI DSS actually is

PCI DSS stands for the Payment Card Industry Data Security Standard. It’s not Australian law or a government regulation. It’s a contractual standard maintained by the PCI Security Standards Council, owned by the major card brands: Visa, Mastercard, American Express, Discover and JCB. When you signed your merchant agreement, you agreed to comply with it.

The current version is PCI DSS 4.0.1, a minor revision of version 4.0. The old v3.2.1 standard was retired in March 2024, and the future-dated v4 requirements that were optional during the transition became mandatory from 31 March 2025. So if you ticked “best practice, not yet required” against those controls at your last assessment, that grace period is over. The v4 requirements push harder on multi-factor authentication for all access into the cardholder environment, tighter password rules, anti-phishing controls and scripts on payment pages.

Who has to comply

The rule is blunt: any business that stores, processes or transmits cardholder data must comply, whether you take ten transactions a year or ten thousand. A florist in Camberwell on an EFTPOS terminal is in scope, just as a national retailer is. The standard scales, but never switches off.

Cardholder data means the primary account number (the long number on the front of the card) plus cardholder name and expiry date. A stricter category, sensitive authentication data, covers the full magnetic stripe, the CVV/CVC code and the PIN. That must never be stored after a transaction is authorised, full stop. A surprising number of Australian SMEs breach this by keeping card details in an email, spreadsheet or CRM note.

The four merchant levels

Merchants are sorted into four levels by annual card transaction volume. The level decides how you validate, from a heavyweight external audit at the top to a self-assessment at the bottom. The Visa and Mastercard tiers below are the ones almost everyone uses.

LevelAnnual transaction volume (per card brand)How you typically validate
Level 1Over 6 million transactionsAnnual on-site audit by a Qualified Security Assessor (QSA), plus quarterly network scans
Level 21 million to 6 millionAnnual Self-Assessment Questionnaire (SAQ), often QSA-reviewed, plus quarterly scans
Level 320,000 to 1 million (e-commerce)Annual SAQ plus quarterly scans
Level 4Under 20,000 e-commerce, or up to 1 million totalAnnual SAQ; scans where applicable

The overwhelming majority of Melbourne SMEs are Level 4: no auditor turns up at your door. You validate by completing the correct Self-Assessment Questionnaire and, depending on your setup, running quarterly external vulnerability scans through an Approved Scanning Vendor.

Self-Assessment Questionnaires in plain English

The SAQ is a checklist you fill in to attest that you meet the relevant controls. There are several types, and using the wrong one means answering hundreds of irrelevant questions or, worse, under-scoping your risk.

  • SAQ A — for merchants who have fully outsourced all cardholder data handling to a compliant third party and never see the card number: the e-commerce shop that redirects customers to Stripe, Square or a hosted payment page. The shortest questionnaire, and where you want to be.
  • SAQ A-EP — for e-commerce merchants whose site doesn’t receive card data directly but controls how the payment page is delivered, for example loading the payment fields via JavaScript from a provider. Your site can affect transaction security, so you carry more responsibility.
  • SAQ B — for merchants using standalone dial-out or IP EFTPOS terminals, or imprint machines, with no electronic card data storage. Common for cafes, trades and small retail.
  • SAQ C — for merchants with an internet-connected payment application, where card data is processed through your own network but not stored. More controls apply because your environment is exposed.
  • SAQ D — the full questionnaire, for everyone who doesn’t fit the simpler categories, including any merchant that stores cardholder data. It covers all applicable requirements and is the most demanding.

The practical goal is to engineer your way down to SAQ A or SAQ B. The further down you sit, the fewer controls you have to build, evidence and maintain.

How compliant providers and tokenisation shrink your scope

“Scope” is the most important word in PCI DSS. It covers every system, person and process that touches cardholder data, or connects to systems that do. So the smartest strategy isn’t building more controls, it’s keeping card data out of your environment entirely.

Two levers do most of the work. The first is a compliant payment provider. If you take payments through a PCI-certified gateway like Stripe, Square, Tyro or Eway, and your systems never see the raw card number, you’ve handed the hardest parts of the standard to a provider built to meet them. That’s the gap between a 20-question SAQ A and a 300-question SAQ D.

The second lever is tokenisation. Instead of storing a customer’s card number for repeat billing, the provider stores it and hands you back a meaningless token. You charge the card by sending the token, never the real number. Because the token is worthless to an attacker, the systems holding it generally fall out of scope. For any business doing subscriptions, retainers or saved-card checkouts, it’s the cleanest way to keep recurring payments running.

Where Australian SMEs trip up

We see the same handful of mistakes again and again across Melbourne, and nearly all are avoidable.

  • Storing card details in email, spreadsheets or CRM notes. A customer phones through a card number and a staff member jots it into an Outlook draft “to process later”. That single act pulls your mail platform and CRM into scope and often breaches the rule against storing the CVV.
  • Assuming the payment provider’s compliance covers you. Stripe being compliant doesn’t make you compliant; you still complete your own SAQ. Outsourcing reduces your obligations; it doesn’t delete them.
  • Treating it as a once-a-year form. PCI DSS 4.0.1 expects controls to operate continuously, not just on assessment day.
  • Conflating it with the Privacy Act. Your obligations to the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme are separate. A card data breach can trigger both; meeting one doesn’t satisfy the other.

A professional services firm in Hawthorn we work with had been emailing client card numbers internally for years to process annual retainer invoices. We moved them to tokenised, saved-card billing through their gateway and wiped the historical card data out of their mail and accounting systems, dropping them from SAQ D to a short SAQ A.

How an MSP handles the technical side

For businesses that can’t fully outsource card handling, real engineering work is involved, and that’s where an MSP earns its keep.

Network segmentation

The fastest way to cut scope where card data does flow is segmentation: isolating the cardholder data environment from the rest of your network with firewalls and VLANs, so a compromise of the office Wi-Fi can’t reach the payment systems. Done correctly, it takes dozens of machines out of scope. Done badly, your entire flat network is in scope. This is core to our cybersecurity services and overlaps with the controls we deploy under our Essential Eight compliance work.

Logging and monitoring

Version 4 is strict about logging. You need to capture access to cardholder systems, retain those logs, and actually review them, not just generate them. For most SMEs that means feeding logs into a SIEM with alerting, which is what our security operations team runs. When a bank or assessor asks for six months of access logs, having them already searchable is the difference between a quick answer and a panic.

The everyday technical controls

The rest is the disciplined IT hygiene that underpins the whole standard: MFA on every account that can reach the cardholder environment, prompt patching, hardened firewall rules, anti-malware, encrypted transmission of card data and tightly controlled access. None of it is glamorous; all of it is the work, and the controls slip the moment no one owns them. As a Melbourne managed IT services provider founded in 2014, with 13 Australian-employed engineers and a 24/7 NOC in Tecoma, TechAssist keeps them running year-round, not just at audit time.

Frequently asked questions

Is PCI DSS a legal requirement in Australia?

Not directly. There’s no Australian statute that says “thou shalt be PCI compliant”. It’s a contractual obligation you accepted in your merchant agreement. Non-compliance can mean fines passed on by your acquirer, higher transaction fees, or in serious cases losing the ability to take card payments. A breach can also trigger separate obligations under the OAIC’s Notifiable Data Breaches scheme.

We only take payments through Square. Are we still in scope?

Yes, but your scope is small. If card data never lands in your own systems, you’ll typically complete the short SAQ A and confirm you don’t store card details anywhere. The risk is staff quietly creating shadow records, a card number in an email or spreadsheet, which drags other systems back into scope.

How often do we have to validate, and what’s the easiest way to stay compliant?

Validation is annual for most merchants: you complete the relevant SAQ each year, plus quarterly external vulnerability scans through an Approved Scanning Vendor if your setup requires them. The underlying controls are expected to operate year-round under PCI DSS 4.0.1. The single biggest thing you can do to make it easier is get card data out of your environment, using a compliant gateway and tokenisation so you never handle the raw card number.

Getting it sorted

For most Melbourne SMEs, PCI DSS compliance is far more achievable than the standard’s bulk suggests, provided you keep card data out of your hands and lock down whatever’s left. If you’re not sure which SAQ applies, or you suspect card numbers are lurking in your email and CRM, that’s worth fixing before an incident forces the issue. Get in touch with our team and we’ll map your scope and the controls you need.

SMB1001 is an Australian-developed cyber security certification standard built specifically for small and medium businesses. It uses five ascending tiers — Bronze, Silver, Gold, Platinum and Diamond — so a business can prove it has sensible controls in place without the cost and overhead of an enterprise framework like ISO 27001.

If you have heard it referred to as “Cyber Certification” or under the Dynamic Standards branding, that is the same lineage. SMB1001 is the named standard that sits behind those schemes. For a Melbourne SME being asked by a larger customer or insurer to “prove your security,” it is increasingly the answer that gets accepted — and it is far more achievable than people assume.

What SMB1001 actually is

SMB1001 is a tiered, multi-level cyber security standard aimed squarely at the businesses that the bigger frameworks were never written for: the 5-person bookkeeping firm, the 30-person fabrication shop, the family logistics operation running three trucks and a back office. These businesses still hold client data, still process payments, still get phished — but they do not have a CISO, a security budget, or the appetite to spend six months and tens of thousands of dollars on an ISO audit.

The standard’s strength is that it is designed to be self-assessed at the lower tiers and independently certified at the higher ones. You do not need to boil the ocean. You pick a tier that matches your size, risk and what your customers are demanding, implement the controls, and certify against it. As your obligations grow, you climb.

It is genuinely useful, and it is genuinely not a silver bullet. A certificate on the wall does not stop a determined attacker, and the lower tiers in particular set a floor, not a ceiling. Treated as a starting point and a discipline rather than a finish line, though, it does real work.

The five tiers, and roughly what each requires

The whole point of the tiered model is that the requirements scale with the business. Bronze is a sensible baseline that almost any micro-business can reach; Diamond approaches the kind of maturity you would expect from an organisation handling sensitive data at scale. Here is the broad shape of it.

TierWho it suitsRoughly what it asks for
BronzeMicro-businesses and sole traders new to cyberFoundational hygiene: multi-factor authentication, backups, patching/updates, basic staff awareness, antivirus. Self-assessed.
SilverSmall businesses wanting to show baseline diligenceEverything in Bronze plus tighter controls — documented processes, account management, a basic incident response approach. Self-assessed.
GoldGrowing SMEs, or those being asked for proof by customersMore formalised governance, access control, logging and a written security policy. Independent certification typically required.
PlatinumEstablished businesses with real compliance exposureStronger technical and procedural controls, risk management, supplier and data handling requirements, independently certified.
DiamondSMEs handling sensitive data or operating in higher-risk supply chainsThe most comprehensive set — closer to a small-scale information security management system, independently certified and reviewed.

The exact control list at each tier is defined by the standard itself and is refreshed periodically, which is part of the “dynamic” idea — the requirements move as the threat picture moves, so a Bronze in 2026 is not the Bronze of several years ago. Treat the table above as the shape, not the letter of the law. When we scope this for a client we work from the current published control set, not memory.

Who SMB1001 suits

The honest answer is most Australian SMEs that have never certified against anything. If you have been muddling along with decent-enough IT, an MSP keeping the lights on, and a vague sense that you “should do something about cyber,” SMB1001 gives you a structured, affordable way to start — and a credential at the end that means something to the people asking.

It fits particularly well for businesses in supply chains. A construction subcontractor in Box Hill bidding for work with a tier-one builder, a manufacturer supplying a listed company, a professional services firm acting for larger corporate clients — all of these are increasingly being asked, in tender documents and vendor onboarding forms, to demonstrate a baseline of security. SMB1001 is built to answer that question proportionately. We see it most across the construction, manufacturing and professional services clients we work with.

How it differs from — and complements — the Essential Eight and ISO 27001

This is where a lot of business owners get confused, so it is worth being precise. The Essential Eight, ISO 27001 and SMB1001 are three different things that overlap rather than compete.

The Essential Eight is a set of eight technical mitigation strategies published by the Australian Cyber Security Centre (ACSC). It is a controls framework, not a certification scheme — there is no certificate you receive at the end, only maturity levels you self-assess or have assessed against. It is excellent at telling you what to harden (application control, patching, MFA, restricting macros and so on) but it does not, by itself, give you a credential to wave at a customer. We cover this in detail in our guide to Essential Eight compliance for Melbourne businesses.

ISO 27001 sits at the other end. It is an international standard for a full information security management system (ISMS) — risk-driven, documentation-heavy, externally audited annually, and respected globally. It is the right answer for businesses that need international credibility or are contractually required to hold it. It is also a serious undertaking in time and cost, which is exactly why it is overkill for a 15-person business that simply needs to prove it is not negligent.

SMB1001 lands in the gap between them. It borrows the practical, control-based spirit of the Essential Eight, packages it into a certifiable, tiered credential like ISO 27001 offers, and scales it down to SME reality. The tiers map sensibly onto the others: the lower tiers cover much of the same ground as the Essential Eight’s foundational maturity, while the upper tiers start to resemble a lightweight ISMS. None of them cancels the others out.

SMB1001Essential EightISO 27001
TypeTiered certification standardTechnical controls frameworkFull ISMS certification
OriginAustralian, SME-focusedAustralian (ACSC)International (ISO/IEC)
Gives you a certificateYes (independently at higher tiers)No — maturity levels onlyYes — externally audited
EffortLow to moderateLow to high by maturityHigh
Best forSMEs needing proof, proportionateAny business hardening its techLarger or globally-facing firms

In practice we often run them together. We will harden a client against the Essential Eight because the controls are sound, then certify the business under SMB1001 because that is the thing a customer or insurer actually recognises. The work overlaps heavily, so doing both is far less than twice the effort.

Why customers and primes are asking for it

Three forces are driving the demand. First, supply-chain security has become a procurement issue — larger organisations have woken up to the fact that their weakest link is often a small supplier with the keys to their data, so they are pushing security requirements down the chain. Second, cyber insurers have tightened underwriting and want evidence of basic controls before they will quote, let alone pay a claim. Third, regulators expect more: under the Privacy Act and the OAIC’s Notifiable Data Breaches scheme, a business that suffers a breach has to be able to show it took reasonable steps, and “we had nothing in place” is not a defensible position.

SMB1001 gives an SME a clean, recognised way to satisfy all three at once. It is a credential a prime contractor’s procurement team will accept, a data point an insurer’s underwriter understands, and evidence of diligence if the worst happens. That is why it is showing up in tender packs and vendor questionnaires far more often than it did two years ago. If cyber insurance is part of your thinking, our cyber insurance guide for Australian SMEs covers how these pieces fit together.

The certification path, effort and cost

The route through SMB1001 is deliberately straightforward. You scope which tier you need — driven by your size, your risk and, frankly, whatever your biggest customer is demanding. You implement the controls for that tier. At Bronze and Silver you self-assess and attest; at Gold and above you engage an authorised assessor for independent certification. Certification is then maintained and renewed periodically rather than being a one-off.

On effort: for a business with reasonable IT already in place, Bronze or Silver can be a matter of tidying up MFA, backups, patching and staff awareness, then documenting it — weeks, not months. Gold and above take longer because the governance and evidence requirements are real, and because independent assessment means you actually have to demonstrate the controls, not just claim them. Where there is groundwork to do — and there usually is — the gap is the controls, not the paperwork.

On cost: SMB1001 is markedly cheaper than ISO 27001, which is the whole point. The certification fees scale with the tier, and the larger expense for most businesses is the remediation work to actually meet the controls rather than the certification itself. As a rough guide, the lower tiers are a modest annual outlay; the upper tiers cost more but remain a fraction of an ISO programme. Figures move, so we scope it per-business rather than quoting a number that ages badly.

A heads-up worth giving plainly: the certificate is the easy bit. The controls are what protect you, and they only protect you if they are maintained — MFA stays enforced, backups keep being tested, patches keep landing, leavers keep getting offboarded. A business that certifies and then lets it all drift has a piece of paper and a false sense of security. That ongoing discipline is exactly what a managed arrangement is for.

How TechAssist approaches it

We are a Melbourne-based MSP, founded in 2014, with 13 Australian-employed engineers — no offshore helpdesk. We are Essential Eight aligned and ISO 27001 capable, which means the controls underneath SMB1001 are bread and butter for us. When a client comes to us holding a tender that demands certification, we scope the right tier, close the control gaps, and get them through assessment — then keep the controls live afterwards under fixed per-user monthly pricing so they do not quietly rot.

A recent example of the pattern: a transport and logistics operator in Dandenong we work with was told by a national client that ongoing work depended on demonstrating a baseline of cyber controls. They had no certification and a tender deadline. We mapped their environment, lifted the gaps — MFA across Microsoft 365, tested backups, patching discipline, basic staff training — and put them in a position to certify at a sensible tier without blowing the budget. The work doubled as genuine risk reduction, not box-ticking. Our cyber security services are built around exactly this kind of proportionate, evidence-backed uplift.

Frequently asked questions

Is SMB1001 mandatory in Australia?

No. SMB1001 is a voluntary certification standard. There is no law requiring you to hold it. The pressure to certify is commercial — customers, primes and insurers asking for proof of security — rather than legal. That said, demonstrating reasonable security steps does help your position under the Privacy Act and the OAIC’s breach-notification obligations.

Which SMB1001 tier should we aim for?

Start from what is driving the decision. If a specific customer or tender names a tier, that is your target. If you are certifying proactively, Bronze or Silver is a sensible entry point for most small businesses, with Gold and above reserved for those handling sensitive data or facing stronger contractual demands. We scope this per-business rather than guessing.

Does SMB1001 replace the Essential Eight or ISO 27001?

No — they complement each other. The Essential Eight tells you which technical controls to harden, SMB1001 gives you a recognised certificate proving you have a sensible baseline, and ISO 27001 is the heavyweight option for businesses needing international-grade assurance. Many SMEs run the Essential Eight controls underneath an SMB1001 certification.

How long does it take to get certified?

For a business with reasonable IT already in place, the lower tiers can be achieved in weeks once the remediation is done. Higher tiers take longer because of the governance and independent assessment involved. The timeline is driven mostly by how much control gap there is to close, not by the certification paperwork.

Where to start

If a customer, prime contractor or insurer has put SMB1001 in front of you — or you simply want a structured, affordable way to prove your business takes security seriously — the first step is an honest look at where your controls actually stand. We will tell you which tier is realistic, what it takes to get there, and whether the bigger frameworks are worth it for you. Get in touch and we will scope it properly.

The SOCI Act directly captures owners and operators of designated critical infrastructure assets across 11 sectors. Most small and mid-sized Melbourne businesses are not caught. But if you supply, manage IT for, or sit in the supply chain of one of these entities, its obligations can land on your desk regardless.

That gap — between “the law doesn’t name me” and “I’m still on the hook” — is where most of the confusion sits. Here is who is actually captured, what they have to do, and how to tell whether any of it touches your business.

What the SOCI Act actually is

The Security of Critical Infrastructure Act 2018 (Cth) is Commonwealth legislation administered by the Department of Home Affairs through the Cyber and Infrastructure Security Centre (CISC). When it first passed it covered four sectors and did little more than require an asset register for electricity, gas, water and ports.

Two rounds of amendments changed that dramatically. The Security Legislation Amendment (Critical Infrastructure) Act 2021 expanded the sectors and introduced mandatory cyber incident reporting and government assistance powers. The 2022 Act, shortened to SLACIP, added the Risk Management Program obligation and enhanced duties for “systems of national significance”.

So the SOCI Act today means the 2018 Act as amended by those packages — the expanded version that now reaches businesses that never thought of themselves as critical infrastructure.

The 11 critical infrastructure sectors

The amended Act defines 11 sectors. If your organisation owns or operates an asset inside one of these, you are potentially in scope.

  • Communications
  • Financial services and markets
  • Data storage or processing
  • Defence industry
  • Higher education and research
  • Energy
  • Food and grocery
  • Health care and medical
  • Space technology
  • Transport
  • Water and sewerage

Being in a sector is not the same as being captured. The Act bites on specific critical infrastructure assets defined by rules and thresholds within each sector. A small clinic in Camberwell sits within “health care and medical”, but the obligations attach to large hospitals and designated systems, not every GP practice. The sector tells you to keep reading; the asset thresholds tell you whether you are actually in.

The three core obligations

For captured entities, the Act imposes a tiered set of duties. Three are worth understanding in plain terms.

The asset register

Responsible entities must provide ownership and operational information about their assets to the Register of Critical Infrastructure Assets, held by the CISC: who controls the asset, who has access, and where interest or control sits offshore. The register is not public. It exists so government has visibility of who runs the country’s important infrastructure.

The Risk Management Program

This is the heart of the SLACIP amendments. Captured entities must adopt, maintain and comply with a Critical Infrastructure Risk Management Program (CIRMP) that identifies and manages hazards across four domains: cyber and information security, personnel, supply chain, and physical and natural hazards. Boards must approve it, and entities submit an annual report confirming the program is current and signed off at board level.

For the cyber domain, the rules point entities towards a recognised framework such as the Essential Eight maturity model or an equivalent standard like ISO 27001. This is where security posture stops being a nice-to-have and becomes a documented, board-signed legal obligation.

Mandatory cyber incident reporting

Captured entities must report cyber security incidents to the Australian Signals Directorate (ASD), in practice through the Australian Cyber Security Centre and coordinated with the CISC. There are two clocks, and the difference matters:

Incident typeReporting deadlineMethod
Critical incident — significant impact on availability of an essential serviceWithin 12 hours of becoming awareVerbal report acceptable, written follow-up
Other incident — relevant impact on the assetWithin 72 hours of becoming awareVerbal or written report

Twelve hours is a brutal window if you have not planned for it. A captured entity needs an incident response process that can detect, triage and report inside half a day — overnight, on a weekend, during a holiday. That is operational maturity, not a policy in a drawer, which is why our managed detection and response work exists.

Be honest: most Melbourne SMEs are not directly captured

This gets glossed over by anyone trying to sell you compliance product. The vast majority of small and mid-sized businesses in Melbourne are not responsible entities under the SOCI Act. A 25-person law firm in the CBD, a manufacturer in Dandenong, a logistics operator in Footscray — these are not critical infrastructure assets, and the asset register, CIRMP and 12-hour reporting clock do not apply to them directly.

The obligations are deliberately aimed at scale and national consequence: major energy networks, large hospitals, designated data centres, financial market operators, telecommunications carriers, significant ports and rail. If a cyber attack on you would disrupt an essential service for a meaningful slice of the population, you are the target of this law. If it would mostly hurt you and your customers, you almost certainly are not directly captured. Anyone telling a 30-person SME it must file a Risk Management Program because of the SOCI Act is either confused or selling something.

Why it still matters to SMEs: the supply chain flow-down

Direct capture is not the only way SOCI obligations reach you. The Risk Management Program explicitly requires captured entities to manage supply chain hazards — a legal duty to assess and control the security risk posed by their vendors, contractors and IT providers.

So the obligation flows downhill through contracts. A captured hospital cannot meet its CIRMP duty unless it can demonstrate its suppliers are secure, so it pushes security requirements into procurement and supplier agreements. If you sell software, provide IT support, host data, supply equipment or deliver professional services to a captured entity, you will increasingly be asked to prove your security posture as a condition of doing business.

We see this constantly. A professional services firm in Hawthorn that works for a captured energy operator suddenly receives a security questionnaire demanding evidence of multi-factor authentication, patching cadence, access controls and an incident response plan — Essential Eight territory. The firm is not captured by the SOCI Act, but its client is, and the client’s obligation has become the firm’s commercial reality.

This is the honest reason SMEs should care. Not because the regulator is coming for you, but because your captured customers are. Losing a contract because you cannot answer a supplier security assessment is a far more immediate risk than any enforcement action. Aligning to the Essential Eight is the most efficient way to be ready, and it is the same framework the captured entities are pointed to.

How do I know if any of this applies to me?

A practical test, in order:

  1. Are you in one of the 11 sectors? If not, the SOCI Act does not directly apply, though you may still face flow-down obligations if you supply someone who is.
  2. Do you own or operate a defined critical infrastructure asset? Each sector has thresholds — capacity, customer numbers, designation by the Minister. Most SMEs fall well under them. The CISC publishes the authoritative guidance on which assets are caught.
  3. Have you been notified? Responsible entities are generally aware they are captured; the framework is not a hidden trap. If no regulator or rule has identified you as one, you very likely are not.
  4. Do your contracts impose security obligations? This is the one that catches SMEs. Read your supplier agreements and any new security schedules from larger clients — that is where SOCI reaches you in practice.

If you are genuinely unsure whether you are captured, that is a legal question worth getting right. Where we add value is the technical side: building the controls and evidence that either satisfy a direct CIRMP obligation or answer the supplier assessments flowing down from your captured clients. Our virtual CIO engagements often start here — turning a vague “our client wants us to be secure” into a concrete, costed plan.

What TechAssist does about it

We are a Melbourne-based MSP, founded in 2014, with 13 Australian-employed engineers and a 24/7 NOC in Tecoma. That on-shore, around-the-clock capability matters here, because the 12-hour reporting clock does not respect business hours. For captured entities, we build the cyber domain of a Risk Management Program: Essential Eight uplift, documented controls, monitoring, and an incident response process that can actually meet a 12-hour deadline. For the far larger group of SMEs facing flow-down pressure, we get your posture to where supplier questionnaires become a formality rather than a fire drill. Either way it is real engineering, not a compliance binder, and it sits inside our standard cybersecurity services.

Frequently asked questions

Does the SOCI Act apply to small businesses?

Almost never directly. The Act captures owners and operators of defined critical infrastructure assets, which are large-scale and nationally significant. A typical Melbourne SME is not a responsible entity. The real exposure is indirect — security obligations flowing down through contracts from captured customers.

What are the SOCI Act reporting timeframes?

Captured entities must report a critical cyber incident with significant impact within 12 hours of becoming aware, and an incident with relevant impact within 72 hours. Reports go to the Australian Signals Directorate via the Australian Cyber Security Centre.

What is a Risk Management Program under the SOCI Act?

The CIRMP, introduced by the 2022 SLACIP amendments, requires captured entities to identify and manage hazards across cyber, personnel, supply chain and physical domains, have the board approve it, and report annually that it is current.

I supply a captured entity. What will they ask me for?

Typically evidence of multi-factor authentication, patching, access controls, backup and recovery, logging, and an incident response plan — broadly the Essential Eight. Getting these in place and documented is the most efficient way to keep those contracts.

The short version

The SOCI Act is real and serious, and mostly not aimed at you if you run a Melbourne SME. What is aimed at you is the security pressure your captured customers are now legally required to push down their supply chains. The smart move is not to panic about direct capture, but to get your security posture to a standard that satisfies both your clients and your own risk. For a straight answer on where you sit, talk to us.

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon — just a clear-eyed look at where you stand and what's possible.