Who this is for and what it fixes
We provide cyber security services for small business owners who hold things worth protecting, such as customer records, banking access, payroll and email, and who have nobody whose job it is to protect them. You need the basics done properly, written down and kept up.
Typical starting points:
- A professional services firm where staff share the same handful of passwords.
- A retailer whose backups run to a drive beside the server and have never been restored as a test.
- A trades business where former employees can still sign in to email and the job system.
- A recruitment or migration agency holding identity documents in a shared mailbox.
- A wholesaler asked by a larger customer or an insurer to describe its security controls.
We start with a review that tells you plainly where you stand, then fix the gaps in order of risk. No provider can honestly promise that you will never have an incident. Good security makes one less likely, smaller when it happens and quicker to recover from. Where an ageing office server is the main risk, the fix may be a move to cloud hosting.
The problems it solves
- One password shared by several people, with no record of who used it
- Email protected by a password alone, all a fraudster needs to send a fake invoice from a real mailbox
- Backups that are assumed to work and have never been restored
- Updates put off again and again because nobody owns the job
- A security questionnaire from a customer or insurer that nobody can answer
What is included
- Security review: accounts, devices, email, cloud services, backups and your website checked against a written list, with findings ranked by risk
- Multi-factor authentication (MFA) rolled out across email, accounting, cloud and administrator accounts
- Single sign-on (SSO) and a password manager, so shared passwords are retired and access is removed in one place
- Backups designed, protected from tampering and restored as a test
- Patching of operating systems, applications and network devices, with unsupported software listed for replacement
- Administrator rights reduced to the people and tasks that need them
- Email checked: sender authentication records (SPF, DKIM and DMARC), forwarding rules and who can open each mailbox
- Application control, Microsoft Office macro settings and web browser hardening reviewed
- Encryption turned on for laptops, phones and stored data
- Staff awareness sessions on phishing, invoice fraud and reporting something suspicious
- A short incident response plan: who to call and what to switch off
What you hold at the end
- A security review report in plain English, with findings ranked by risk
- A remediation record: what was fixed, what remains and who owns each open item
- A gap summary set out against the Essential Eight strategies, for your own planning (not a formal assessment)
- A register of accounts, administrators and devices
- A list of unsupported software and devices, in suggested order of replacement
- Backup design and restore test records
- An incident response plan and a written security policy for staff
- Administrator credentials held by you, in a password manager you control
Technology we use and why
We first switch on the protections already included in the subscriptions you pay for, then suggest anything new.
Password manager
A shared vault that creates and stores a different password for every service. Access can be given and withdrawn without anyone seeing the password itself.
Multi-factor authentication (MFA)
A second proof of identity at sign-in, such as an authenticator app or a security key, so a stolen password alone is not enough.
Single sign-on (SSO)
One work identity, usually your Microsoft or Google account, for your other systems. Fewer passwords, and one switch to remove access.
Encryption
Scrambles data so it cannot be read without the key. We turn it on for devices and storage and check that connections are encrypted.
Identity and access management (IAM)
The controls in Google Cloud, AWS and Azure that decide who can do what, set so each person has only the access their job needs.
Cloud backups
Copies of your data held away from the office and from everyday user accounts, so a problem on one laptop cannot reach them.
How we deliver it
| Stage | What happens |
|---|---|
| 1. Discovery call | A free conversation about what you hold, how your staff work and what worries you. |
| 2. Plan and quote | A written scope and fixed quote for the review. Fixes are quoted separately once you have read the findings. |
| 3. Build and test | Fixes are applied in stages, highest risk first, and each is demonstrated to you, such as a backup restored while you watch. |
| 4. Launch and train | New sign-in methods go live for everyone, staff attend an awareness session, and you receive the security policy and incident response plan. |
| 5. Ongoing support | On a monthly plan we keep patching, check backups, review accounts and repeat the review on an agreed cycle. |
Engagement options
| Option | Suits | How it works |
|---|---|---|
| Fixed quote | A security review, or one defined fix such as rolling out MFA | Scope and price are agreed in writing first. The findings report is yours whether or not we carry out the fixes. |
| Staged pricing | Remediation across many accounts, devices and systems | Fixes are grouped into stages by risk, each quoted and approved separately. |
| Monthly plan | Ongoing patching, backup checks, account reviews and staff refreshers | A written list of recurring security tasks for a monthly fee. |
How we handle your data and our access
A review means letting an outsider look closely at your systems, so we follow the rules we recommend.
- Least access. Read-only access where that is enough, and administrator rights only for fixes you have approved, through a separate named account and never a shared login.
- Your vault. Passwords and recovery codes go into your password manager, not ours, and our access is removed when the work ends.
- The report. Findings describe your weak points, so the report goes only to the people you name.
- Your records. We examine settings and do not copy customer or staff records out of your systems. The OAIC's Guide to securing personal information says to provide access on a ‘need to know’ basis, and we apply that to ourselves.
Support after the fixes are in
Security settings drift as staff arrive, devices are replaced and vendors release urgent patches. A monthly plan keeps the routine going and gives you a short record of what was patched, which backup was restored as a test and which accounts changed.
If something looks suspicious, email hello@comingwave.com.au or phone the number on our contact page. We reply within one business day, so your incident response plan also lists who to call outside business hours.
Industries it suits
Professional services
Client files, tax records and banking access make email and document security the priority for accounting, legal and advisory firms.
Recruitment
Resumes, identity documents and visa details arrive by email daily and need a controlled home and a deletion date.
Retail and e-commerce
Online stores, payment terminals and customer accounts, where a hijacked administrator login does the damage.
Education and training
Student records and a changing list of trainers and contractors, so accounts are opened and closed on time.
The Essential Eight and the Notifiable Data Breaches scheme
The Essential Eight. The Essential Eight is a framework developed by the Australian Signals Directorate (ASD) to help organisations protect themselves against cyber threats. ASD lists the eight mitigation strategies as: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups.
The Essential Eight maturity model defines four maturity levels, Maturity Level Zero through to Maturity Level Three:
- Maturity Level Zero signifies that there are weaknesses in an organisation's overall cyber security posture.
- Maturity Level One focuses on malicious actors who are content to use widely available commodity tradecraft, generally looking for any victim rather than a specific victim.
- Maturity Level Two focuses on malicious actors operating with a modest step-up in capability, willing to invest more time in a target and in the effectiveness of their tools.
- Maturity Level Three focuses on malicious actors who are more adaptive and much less reliant on public tools and techniques.
ASD advises organisations to identify a target maturity level suitable for their environment, and to achieve the same maturity level across all eight strategies before moving to a higher one. It states that there is no requirement to have an implementation certified by an independent party, although an independent assessment may be required by a government directive or policy, a regulatory authority or a contract. We help you choose a target and work towards it. We do not issue certification.
The Notifiable Data Breaches scheme. Under the Notifiable Data Breaches (NDB) scheme, any organisation or agency the Privacy Act 1988 covers must notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm to an individual whose personal information is involved. The OAIC says an eligible data breach occurs when there is unauthorised access to, unauthorised disclosure of, or loss of personal information; this is likely to result in serious harm to one or more individuals; and the organisation has not been able to prevent the likely risk of serious harm with remedial action. An organisation that suspects one must quickly assess the incident, and OAIC guidance says all reasonable steps must be taken to complete that assessment within 30 calendar days.
Whether the Privacy Act covers a business with an annual turnover of $3 million or less depends on what the business does, and the OAIC's small business page lists the cases. Deciding whether to notify is a legal question for you and your lawyer, guided by the OAIC.
Cyber security questions
Is a business our size really a target?
Size offers little protection, because common attacks are opportunistic. ASD's Maturity Level One describes attackers looking for any victim rather than a specific one.
Can you get us to an Essential Eight maturity level?
We can help you choose a target maturity level and work towards it, strategy by strategy. Whether you have reached a level is established by an assessment, and some contracts require an independent one. We will not describe you as having reached a level that has not been assessed.
Will multi-factor authentication slow our staff down?
It adds a few seconds when someone signs in on a new device, and trusted devices are remembered. We set it up with each person and arrange a fallback for a lost or replaced phone.
We use Microsoft 365 or Google Workspace. Is that not secure already?
The platforms are well protected, but how your accounts are set up is your responsibility: who is an administrator, whether multi-factor authentication is enforced, what is shared outside the business and where mail is forwarded. A review checks those settings before it recommends any new product.
Is your security review a penetration test?
No. Our review examines how your accounts, devices, backups and cloud services are configured and used. A penetration test is a simulated attack by specialists. If a customer or insurer requires one, we help you scope it and act on its findings.
What happens if we have an incident while working with you?
Contact us and we will help you contain it: disabling accounts, isolating devices and restoring from backup. We reply within one business day and do not run an emergency line around the clock, so your plan lists the other calls to make, such as your bank and insurer. For routine care, see managed IT support, or ask us for a review.


