Sector focus

Cyber security by industry

The technical controls are broadly consistent. What changes is the order you apply them in, what downtime costs, and who is asking you for evidence. Here is how we approach the sectors we work in most.

Manufacturing & Industrial

Plants running 24 hours with a flat network, legacy control systems, and no tolerance for unplanned downtime.

What makes it different

Manufacturing sites tend to carry decades of accumulated infrastructure. Control systems, HMIs and older Windows hosts often sit on the same flat network as the office file share, because that is how the line was commissioned and it has worked ever since. Patch windows are scarce, and the people who understand the equipment are frequently the vendor rather than your IT team.

Where the risk concentrates

Ransomware that reaches the production network stops the line, and the cost is measured in shifts rather than tickets. Flat networks mean a single compromised office laptop can reach the equipment. Remote vendor access for maintenance is often permanent, shared, and unmonitored. Backups exist for the ERP but rarely for the machines that matter.

What we usually do first

Segmentation between corporate IT and production, so an office compromise cannot reach the line. Documented, time-boxed vendor access to replace standing VPN accounts. Backup validation for the systems that would actually halt production. Then Microsoft 365 and endpoint baselines for the corporate side.

Food & Beverage

Cold chain, batch records and traceability systems where an IT outage becomes a food safety and compliance event.

What makes it different

In food and beverage, IT failure has consequences beyond productivity. Temperature monitoring, batch records and traceability data underpin your HACCP obligations and your ability to execute a recall. Major retail customers increasingly audit their suppliers' cyber posture as part of standard supplier assurance.

Where the risk concentrates

Loss of batch and traceability records during an incident can force product disposal or block a recall. Cold chain monitoring often depends on systems nobody has patched. Supplier questionnaires from large retailers ask questions most SMB manufacturers cannot currently answer with evidence.

What we usually do first

Identify the systems that hold traceability and monitoring data, and confirm they are genuinely backed up and restorable. Segment them from general office IT. Then build the evidence pack that answers customer supplier-assurance questionnaires without a scramble each time one arrives.

Transport & Logistics

Many small sites, high staff turnover, and enough invoice volume to make business email compromise genuinely profitable for an attacker.

What makes it different

Logistics operations are geographically distributed by nature: depots, yards, cross-docks and third-party sites, often with minimal on-site IT. Staff turnover is high, shift work is the norm, and a large volume of legitimate invoices and remittance advice moves by email every day.

Where the risk concentrates

Business email compromise is the dominant threat. High invoice volume means a fraudulent payment-detail change can pass unnoticed. Distributed depots frequently run inconsistent firewall configurations and forgotten remote access. High turnover means dormant accounts accumulate faster than they are removed.

What we usually do first

Microsoft 365 identity and mail hardening, because that is where the money actually leaves. Conditional Access, phishing-resistant MFA for finance and approvers, and mail flow rules that catch external senders impersonating internal staff. Then a joiner-mover-leaver process that actually disables accounts.

Local Government & Councils

Public records obligations, constrained budgets, and a service catalogue far broader than the IT team's headcount.

What makes it different

Councils deliver an unusually wide range of services from a small IT function: rates, planning, libraries, waste, community facilities, sometimes water. Each brings its own system. Records obligations and public accountability mean an incident carries reputational and regulatory weight beyond the technical impact.

Where the risk concentrates

Wide, heterogeneous system estates are difficult to patch consistently. Public-facing services expand the attack surface. Residents' personal information creates notifiable data breach exposure. Budget cycles make sustained security investment harder than one-off capital spend.

What we usually do first

An Essential Eight maturity assessment that produces a defensible, costed roadmap suitable for a council report. Then the controls with the widest coverage per dollar: MFA, admin privilege reduction, patching cadence and validated backups.

Professional Services

Client data held under NDA, supply-chain security questionnaires, and cyber insurance renewals that get harder every year.

What makes it different

Professional services firms hold concentrated, sensitive client data with a small internal IT footprint. Your clients' procurement teams increasingly treat your security posture as their supply chain risk, and they ask for evidence before renewal.

Where the risk concentrates

Business email compromise and account takeover, because client trust and payment instructions travel by email. Data sprawl across cloud file shares nobody has audited. Client questionnaires and insurer renewal forms that require documented controls you may not have formalised.

What we usually do first

Microsoft 365 hardening and a documented control set mapped to the questionnaires you actually receive. The aim is that the next client security review or insurance renewal is a document retrieval exercise, not a project.

Not on this list?

The underlying pattern is remarkably consistent across Australian SMBs: Microsoft 365 for identity and email, Windows endpoints, a firewall configured during a project years ago, and backups nobody has restored from. If that sounds familiar, sector labels matter less than you would expect.

Get in touch and we will tell you honestly whether we are a good fit for your environment.

Let's find your weakest link before someone else does

A 30-minute scoping call is usually enough to tell you where the real risk sits and what a sensible first engagement looks like. No obligation, no sales theatre.

Book a consult