bcom ICT provides cybersecurity services to small and medium businesses across the Gold Coast and Australia-wide — endpoint protection, email security, multi-factor authentication, ransomware defence, firewall hardening and staff awareness training. bcom ICT works to the ASD Essential Eight, Australia's baseline security framework. Call 07 3041 8993.
Four things that go wrong at Gold Coast businesses
Not hypotheticals. These are what we get called about, and none of them require anyone to be specifically targeting you.
Invoice and payment scams
Someone watches your mailbox, waits for a real invoice, then sends a near-identical one with different bank details. This is the single most common way Australian small businesses lose money, and it needs no technical skill at all.
Account takeover
A staff password gets reused somewhere it shouldn't be, and someone logs into your Microsoft 365 as them. Multi-factor authentication stops nearly all of it, and plenty of businesses still don't have it switched on everywhere.
Ransomware
Files encrypted, a demand for payment, and a business that can't trade. Whether it's a bad week or a fatal one comes down entirely to whether your backups are separate and actually tested.
Unpatched systems
Known holes in software that were fixed months ago but never installed. Unglamorous, boring, and one of the most reliable ways in.
The controls that stop most of it
There is no single product that makes a business secure. There is a short list of unexciting things that, done properly, stop the overwhelming majority of what small businesses get hit by.
Multi-factor authentication
Turned on properly across email, remote access and admin accounts — not just for the people who volunteered.
Endpoint protection
Business-grade protection on every machine, centrally monitored, so we see a problem on one device before it becomes a problem on all of them.
Email security
Filtering ahead of your mailbox, plus the SPF, DKIM and DMARC records that stop somebody sending email pretending to be you.
Backup that's separated
Backups a ransomware infection can't reach from inside your network, with restores tested on a schedule rather than assumed.
Firewall and network hardening
Guest WiFi kept away from your business systems, remote access locked down, and the default passwords nobody ever changed sorted out.
Staff awareness
Short, practical sessions on what a real scam looks like. Your people are the control that catches what the technology misses.
Start with a health check
Most businesses have no clear picture of where they actually stand, which makes it impossible to know what's worth spending money on. The health check fixes that first.
It's a fixed fee, agreed up front. We review your email, identity and accounts, endpoints, backups and network, then give you a plain-English report with a prioritised list — what would hurt most, what's quick to close, and what can reasonably wait.
- A written report you can hand to your board, accountant or insurer
- Findings ranked by what they'd actually cost you, not by severity score
- Where you sit against the Essential Eight, and what the next level takes
- No obligation to have us do the remediation work
For businesses that need continuous cover rather than a point-in-time review, our 24/7 security operations centre monitors endpoints, identities and cloud tenancies around the clock.

If you're in a regulated industry
Some Gold Coast businesses have obligations beyond good practice. Financial planners, mortgage brokers, accountants and insurance brokers operating under an AFS licence carry cyber resilience obligations that ASIC has been increasingly willing to enforce — we cover that on our ASIC compliance page. Healthcare and allied health clients typically need to demonstrate Essential Eight alignment and understand their obligations under the Notifiable Data Breaches scheme.
We state what we are aligned to and what we are not. bcom ICT operates to the ASD Essential Eight and aligns with ISO/IEC 27001:2022, but is not certified to it. The trust centre sets out the frameworks, the credentials our people hold, and who issued them.
The security calls we actually take
Not hypotheticals. These are what Gold Coast businesses ring about, and what is usually behind them.
“We got an invoice with different bank details”
Usually either a spoofed sender, or a genuinely compromised mailbox somewhere in the chain — yours, your client’s, or your supplier’s.
What we do Establish which immediately, because a compromised mailbox is still being read. Check for forwarding rules, review sign-in activity, reset credentials from a clean device, then close the gap with MFA and email authentication records.
“Someone clicked a link and entered their password”
Usually a credential harvesting page. The password is gone; the question is whether anything has been done with it yet.
What we do Reset the password and revoke all active sessions immediately — a password change alone leaves existing tokens working. Check for mailbox rules created since, then review what that account could reach.
“Our emails are going to clients’ junk folders”
Usually missing or misconfigured SPF, DKIM and DMARC records — the same records that let anyone send email pretending to be you.
What we do Publish and align all three properly. It fixes deliverability and closes a spoofing route at the same time, which is why it is worth doing even when deliverability is the only complaint.
“The antivirus says it cleaned something”
Usually a detection, not necessarily a resolution. The question nobody asks is how it arrived and what it did before detection.
What we do Establish the entry point and check for persistence — accounts, scheduled tasks, mailbox rules. Cleaning without closing the route is why businesses get hit twice in a month.
“We can’t answer our insurer’s renewal questions”
Usually no documented position on MFA coverage, patching, backup testing or endpoint protection — not necessarily an absence of controls.
What we do Assess against the ASD Essential Eight, produce a written report you can attach to the form, and close the gaps that matter most first.
“A staff member’s account was logging in from overseas”
Usually credential compromise, usually a reused password on an account without multi-factor authentication.
What we do Disable the session, reset from a clean device, audit what was accessed while the attacker had it, and check whether data left. Then enforce MFA on every account rather than most of them.
What this looks like in practice
Representative engagements, drawn from real work with identifying detail removed — we don’t name clients without written permission.
A near-miss on a settlement payment
The situation
A Gold Coast professional services firm received an email, apparently from a long-standing supplier, advising changed bank details ahead of a scheduled payment. The email was in an existing thread and read entirely normally.
What we found
The supplier’s mailbox had been compromised weeks earlier. A forwarding rule was quietly copying correspondence out and deleting the evidence. Our client had no MFA on two mailboxes and no verbal verification process for bank detail changes.
What we did
Confirmed the compromise, advised the client to verify by phone on a number already held — which stopped the payment. Then rolled MFA across every account, published SPF, DKIM and DMARC, and put a written verification rule in place for any change of payment details.
The outcome
The payment was not made. The firm now treats bank detail changes as a phone call rather than an email, which is the control that would have caught it regardless of the technology.
An insurance renewal that could not be answered
The situation
A Gold Coast business received a cyber insurance renewal questionnaire noticeably harder than the previous year’s — asking specifically about MFA coverage, patch cadence, backup testing and endpoint protection.
What we found
Multi-factor authentication was on for the directors but not for eight other staff. Patching was happening on some machines and not others. Backups ran but had never been restored. None of it was documented, so even the parts that were fine could not be evidenced.
What we did
Ran a fixed-fee health check against the Essential Eight, closed the MFA gap, standardised patching, tested a restore in front of them, and produced a written report they could attach to the renewal.
The outcome
The questionnaire was answered honestly rather than optimistically, and the business now has a document it can reuse when a client asks the same questions during procurement.
Questions Gold Coast businesses ask us
Who provides cybersecurity services on the Gold Coast?
bcom ICT provides cybersecurity services to small and medium businesses across the Gold Coast and Australia-wide, covering endpoint protection, email security, multi-factor authentication, ransomware defence and staff training. bcom ICT works to the ASD Essential Eight, the Australian government's baseline security framework. Call 07 3041 8993.
What is the Essential Eight, and does my business need it?
The Essential Eight is the Australian Signals Directorate's set of eight baseline mitigation strategies, with maturity levels from zero to three. It's the framework Australian auditors, insurers and boards actually ask about — not the American ones you'll see on most security websites. Most small businesses don't need to be certified against it, but knowing where you sit is increasingly what an insurer or a larger client wants to hear.
How much does a cybersecurity assessment cost?
The health check is a fixed fee agreed before we start, so there's no open-ended bill. You get a plain-English report covering your email, identity, endpoints, backups and network, with a prioritised list of what to fix first. What you do with it is up to you — there's no obligation to have us do the remediation.
We're small. Are we really a target?
You're not being singled out, and that's the point. Almost all of this is automated and indiscriminate — it finds whoever is reachable, and small businesses are reachable because they're less likely to have the basics in place. Being small makes you easier, not less interesting.
Do you help with cyber insurance requirements?
Yes. Insurers increasingly ask specific questions about MFA, backups, patching and endpoint protection before they'll quote or pay out. We can tell you where you currently stand against those questions and close the gaps so your answers are honest ones.
What happens if we've already been breached?
Call 07 3041 8993 and don't switch anything off or delete anything — that often destroys the evidence needed to work out what happened. bcom ICT provides incident response covering containment, investigation, recovery and the reporting your insurer and regulators need.
Is bcom ICT certified to ISO 27001?
No, and we won't imply otherwise. bcom ICT aligns its practices with ISO/IEC 27001:2022 and operates to the ASD Essential Eight, but the company is not certified by an accredited certification body. Individually, Ollie holds ISO/IEC 42001:2023 Lead Implementer certification issued by BSI. Our trust centre sets out exactly what we're aligned to and what we're not.
Find out where you actually stand
A fixed-fee health check across your email, accounts, devices, backups and network — with a plain-English report you can act on or hand to your insurer.
