Finally sleep at night. Someone accountable for your cyber security.
Managed cyber security for Australian businesses that run their own IT, built around the SMB1001 certification tiers. 24/7 monitored detection and response, Microsoft 365 hardening, dark-web monitoring, staff security training and quarterly reviews. Security only. Your IT stays yours.
Founder video slot
Reserved for the founder video. Remove this block when the embed is added.
What we will not do: take over your IT.
You keep running your systems, your way. We manage one thing for you, your security risk, for a fixed price per person. No bundled IT transformation, no pressure to hand over the keys. That is the whole deal.
What is included, from the entry tier up
- 24/7 managed detection and response across your endpoints and Microsoft 365 identities, backed by a Huntress-powered SOC
- Microsoft 365 security hardening to a defined baseline
- Dark web monitoring for your staff credentials
- Security awareness training for your people
- A quarterly posture review with a person, not an emailed PDF
- SMB1001 certification maintenance at your tier
What we need from you
One project champion. The technical controls we deploy ourselves, but SMB1001 also requires policy and procedure to be genuinely adopted across your organisation. We will tell you exactly what needs to be in place and give you the material to do it, and someone on your side has to carry it internally. That is the single biggest factor in whether certification takes 4 to 6 weeks or drags on.
Five tiers, matched to SMB1001
The offer is built around the SMB1001 certification tiers. Each tier is the security stack and the ongoing management needed to reach and hold that certification level.
Bronze
The security stack and ongoing management needed to reach and hold SMB1001 Bronze.
Silver
Everything in Bronze, plus the additional controls SMB1001 Silver requires.
Gold
Everything in Silver, plus the additional controls SMB1001 Gold requires.
Platinum
Independently audited rather than self attested. The tier where certification starts to carry real weight in tenders.
Diamond
The most rigorous tier in the standard, and the one DJC holds itself. Scoped to your environment, so price on application.
Which tier you need depends on what your customers, insurer or tender panel are asking for. We work that out with you on a scoping call, along with what it costs to get there and to stay there.
Questions people actually ask
Do we have to move our IT to you?
No. That is the whole point of this offer. You keep running your systems exactly as you do now, and we take responsibility for the security layer only. We are not going to use this as a way in to quoting you for managed IT.
What if we already have an IT provider?
That is fine and it is common. We coexist with your existing provider and handle security only. We will work with them where something we detect needs a change on their side, and we do not need to displace them to do our job.
What exactly do you monitor, 24/7?
Your endpoints, the laptops and servers your people work on, and your Microsoft 365 identities, which is where most attacks against Australian businesses now start. Monitoring is backed by a Huntress-powered security operations centre, so there are human analysts reviewing what the tooling flags rather than an alert landing in your inbox at 2am.
What happens when something is detected at 2am?
The SOC investigates it immediately rather than waiting for business hours. Where the right response is containment, isolating a device or disabling a compromised account, that happens straight away to stop the spread. You get told what happened and what was done about it, without needing to have been awake for it.
What is Huntress and why do you use it?
Huntress is a security platform built around human-led threat hunting rather than alerts alone. We use it because the failure mode we see most often is not the absence of security tooling, it is nobody actually watching what the tooling says. Huntress pairs detection with a staffed SOC, which is what turns monitoring into a response.
Does this cover Microsoft 365 account takeover and MFA bypass?
Yes, and it is one of the main reasons this offer exists. Identity attacks against Microsoft 365, where an attacker gets a legitimate login rather than deploying malware, are now the most common way Australian SMBs are breached. We monitor for the signals that indicate a takeover, including MFA bypass techniques and suspicious mailbox rules.
Will this help with our cyber insurance renewal or a customer questionnaire?
Usually, yes. The controls in this offer map to what insurers and customer security questionnaires ask about: managed detection and response, MFA and identity hardening, staff training, and a documented review cycle. Where you are certifying to an SMB1001 tier, you also end up with a certification you can put in front of whoever is asking.
What is SMB1001 and is certification included?
SMB1001 is an Australian tiered cyber security standard for small and medium businesses, running Bronze, Silver, Gold, Platinum and Diamond. This offer is built around it: each tier is the security stack and ongoing management needed to reach and hold that certification level, and maintaining your certification is part of what you pay for. Our SMB1001 page explains the tiers in more detail.
What does the monthly price include, and what is separate?
The monthly per person price is ongoing management: the monitoring, the hardening, the training, the quarterly reviews, and maintaining your certification once you hold it. Getting certified in the first place is separate. That is a one-off program to close whatever gaps you have today, plus the certification fees themselves, and both are scoped on your call once we know your starting position. We say this up front because finding it out at quote stage would be a rotten surprise.
Who actually certifies us, and is it a conflict if you also run our security?
Certification is independent, and deliberately so. The body that issues an SMB1001 certificate is never the party managing security for that customer. We implement and maintain the controls; an independent certifier assesses them. That separation is what makes the certificate worth anything to your customers and your insurer, and it is the same arrangement under which DJC itself is certified at Diamond.
Is there a lock in contract?
Managed SMB1001 runs on a 12 month commitment. Certification is not a one-off exercise: the controls have to be deployed, held and evidenced over time, and a shorter term would mean charging you for the setup work without either of us getting the benefit of it. You will know the term before you sign, not after.
How fast is onboarding and will it disrupt us?
Typically 4 to 6 weeks, depending on how much there is to work through in your environment. Agent deployment and Microsoft 365 hardening are low disruption and largely happen in the background. The part that needs you is policy and procedure: we tell you exactly what has to be adopted, but it has to land inside your organisation, so you will need a project champion on your side to drive it.
What do you not cover?
We do security, not system administration. The clearest line is rebuild work: if you suffer a major breach we will tell your IT person exactly what needs to happen, but we do not re-image machines. Business as usual configuration of your systems stays with whoever supports them today, which in these engagements is you or your existing provider. That is deliberate, and it is what keeps this a fixed price you can rely on.
Keep your IT. Hand over the risk.
A 30 minute scoping call tells you what tier you need and what it costs. If the answer is that you do not need us, we will say so.
Talk to us about managed cyber security