Cyber Security FAQs

Can Mercury IT provide cybersecurity if I already have an MSP?

Yes. Many organisations have an existing MSP handling their general IT operations but need specialist cybersecurity capabilities their MSP cannot provide. Mercury IT works collaboratively with your existing MSP, adding a dedicated security layer including SIEM/SOC monitoring, endpoint detection and response, vulnerability management, and security incident response. We also provide board-level security reporting and assurance that gives executives and directors visibility into your security posture. This collaborative model means you keep your trusted IT partner while gaining enterprise-grade security oversight.

Can Mercury IT provide independent security assurance if we already have an MSSP?

Yes. Some organisations require independent assurance over their existing security provider's work—particularly for board reporting, regulatory compliance, or internal governance requirements. Mercury IT provides independent cybersecurity assurance services, reviewing and validating your current MSSP's controls, reporting, and incident response capabilities. We deliver objective assessments and board-level reporting that gives executives and directors confidence in their security investments. This independent oversight model is increasingly requested by boards seeking assurance that security commitments are being met.

Can you help my business comply with the Notifiable Data Breaches (NDB) scheme?

Yes, at Mercury IT, Cyber Security is a part of everything we do. We offer  a complete range of Cyber Security services, check out our Cyber Security pages for more information here  

Does Mercury IT work with other IT providers?

Yes. Mercury IT works collaboratively with other MSPs and MSSPs. We understand that many businesses have long-standing relationships with IT providers and don't want to disrupt what's working well. Whether you need us to add a security layer on top of your existing IT management, provide independent assurance over your current security provider, or deliver specialist services like Essential Eight assessments and board reporting, we integrate smoothly with your existing arrangements. Our focus is on improving your security outcomes, not replacing trusted relationships.

How do I choose a cybersecurity provider in Australia?

When selecting a cybersecurity provider, evaluate their certifications (look for CISSP, CCIE, ISO 27001, or Microsoft security certifications), their local presence and response capability, whether they offer 24/7 monitoring, and their experience in your industry. Ask about their Essential Eight implementation and assessment experience and whether they can support your compliance requirements. Request references from businesses similar to yours. Mercury IT meets all these criteria as a certified MSSP with proven experience across healthcare, legal, finance, and not-for-profit sectors.

How do I know if my business needs a cybersecurity provider?

You need a cybersecurity provider if your business handles sensitive customer or financial data, relies heavily on IT systems for operations, must meet regulatory or contractual security requirements, or lacks in-house capability to design and maintain strong security controls. The ACSC recorded over 84,700 cybercrime reports in FY2024–25 (around one report every six minutes), showing that cyber risk is a routine business issue, not a rare event. A specialist provider helps you reduce risk, respond faster to incidents, and demonstrate due diligence.

How does cybersecurity protect business data?

Cybersecurity protects data using a defence-in-depth model with multiple layers of protection. This includes technical controls such as encryption (making data unreadable without authorisation), next-generation firewalls (blocking malicious traffic), endpoint detection and response (protecting laptops and servers), access controls (ensuring only authorised users can access sensitive data), and continuous monitoring for signs of a data breach. Mercury IT implements these layered defences aligned to the Essential Eight framework recommended by the Australian Cyber Security Centre.

How much does cybersecurity cost for a small business in Australia?

Cybersecurity costs vary based on your business size, complexity, and compliance requirements. According to the ACSC, Australian businesses should expect cyber incidents to cost an average of $56,600 for small businesses and $97,200 for medium businesses when attacks succeed. Investing in preventative security is significantly more cost-effective than incident recovery. Mercury IT offers scalable security packages starting with essential protection (endpoint security, email filtering, MFA) through to comprehensive managed security with 24/7 monitoring. We provide transparent, fixed-monthly pricing so you can budget with certainty.

How should businesses manage AI cybersecurity risks?

AI introduces new security risks including data leakage through public AI tools like ChatGPT, shadow AI usage by employees without IT oversight, and AI-powered social engineering attacks. The Mimecast State of Human Risk Report found 81% of organisations are concerned about sensitive data leaks via generative AI tools. Businesses need an AI governance policy that defines acceptable AI use, protects sensitive data from being entered into AI systems, and trains staff on AI-specific risks. Mercury IT provides AI governance consulting, helping organisations develop policies and technical controls that enable AI innovation while maintaining security and privacy compliance.

Is cybersecurity worth the investment for small businesses?

According to the ACSC Annual Cyber Threat Report 2024-25, the average cost of a cyber incident for Australian small businesses is $56,600—a 14% increase from the prior year. For medium businesses, costs average $97,200 (up 55%). Cyber insurance claims are increasingly being denied for businesses without adequate controls like multi-factor authentication and endpoint protection. Investing in preventative cybersecurity is significantly cheaper than recovering from an attack. Mercury IT helps businesses implement cost-effective, Essential Eight-aligned security that satisfies insurers and protects your bottom line.

What are the biggest cybersecurity threats currently?

Based on the ACSC Annual Cyber Threat Report 2024–25 and broader industry trends, the biggest cybersecurity threats remain ransomware and extortion, phishing and credential theft, business email compromise, and attacks targeting exposed edge or cloud services. Threat actors are increasingly using automation and AI-assisted techniques to scale social engineering and identify vulnerable systems. Maintaining the Essential Eight, strong identity security (MFA, conditional access, least privilege), and rapid patching are the most practical ways to reduce exposure.

What are the consequences of not having strong cybersecurity in place?

The consequences are severe and increasingly costly. According to the ACSC Annual Cyber Threat Report 2024-25, the average cost of a cyber incident for Australian small businesses is $56,600, rising to $97,200 for medium businesses and $202,700 for large businesses. These costs increased by 14%, 55%, and 219% respectively in just one year. Beyond direct costs, businesses face reputational damage, customer trust erosion, and potential legal penalties under the Privacy Act reaching up to $50 million for serious breaches. Mercury IT helps businesses avoid these consequences through proactive security management.

What are the most common cyber threats facing Australian businesses?

According to the ACSC Annual Cyber Threat Report 2024–25, the most common cyber threats affecting Australian businesses include phishing and other social-engineering scams, ransomware and other forms of malware, business email compromise, and attacks that exploit unpatched or misconfigured internet-facing systems. The Essential Eight and layered security controls are designed to reduce the likelihood and impact of these threats.

What certifications should a cybersecurity provider have?

Look for industry-recognised certifications that demonstrate verified expertise. Key individual certifications include CISSP (Certified Information Systems Security Professional) for strategic security leadership and CCIE (Cisco Certified Internetwork Expert) for network security. Organisation-level certifications like ISO 27001 (information security management) and ISO 9001 (quality management) demonstrate mature, audited processes. For Essential Eight assessments, look for assessors who have completed the official Essential Eight Assessment Course designed by the Australian Signals Directorate's Australian Cyber Security Centre. Mercury IT holds all of these certifications and qualifications.

What is cybersecurity and why is it important for businesses?

Cybersecurity is the practice of protecting your company's networks, devices, and data from digital attacks, data theft, and unauthorised access. Mercury IT is a Gold Coast-headquartered managed security service provider delivering cybersecurity solutions to businesses across Australia, with dedicated focus on South East Queensland, Sydney, Melbourne, and Brisbane. With over 25 years of experience, ISO 27001 and ISO 9001 certifications, and Microsoft Certified Partner status, we help organisations protect customer data, maintain compliance with Australian privacy regulations, and prevent the financial and reputational damage that accompanies a breach.

What is the Notifiable Data Breaches (NDB) scheme?

The Privacy Amendment (Notifiable Data Breaches) Act 2017, also known as Notifiable Data Breach (NDB) legislation is an amendment to the Privacy Act 1988 that came into effect on February 22, 2018. The legislation is regulated by the Office of the Australian Information Commissioner (OAIC).

The NDB scheme requires organisations covered by the Australian Privacy Act 1988 (Privacy Act) to notify any individuals likely to be at risk of serious harm by a data breach.

  • It affects a significant number of businesses including all those who have turned over $3million in revenue since 2001, it captures a number of other businesses regardless of turnover based on a number of different criteria
  • Data breaches that cause serious harm to individuals are reportable
  • In the event of non-compliance, the Office of the Information Commissioner (OAIC) can:
    • Apply for civil penalty orders of up to $420,000 for individuals (such as directors and sole traders) and $2.1million for organisations and;
    • The Commissioner can also make organisations pay compensation for damages and issue a public apology
  • For more information regarding the NDB scheme click here
What is the ROI of cybersecurity investment?

Cybersecurity ROI comes from multiple sources: avoided incident costs (averaging $56,600 for small and $97,200 for medium Australian businesses per the ACSC), reduced cyber insurance premiums with proper controls in place, maintained business continuity avoiding costly downtime, and protected reputation preventing customer loss. Additionally, strong security posture is increasingly required to win contracts with government and enterprise clients—the ACSC reports government tenders now commonly mandate Essential Eight compliance. Mercury IT helps businesses quantify their risk exposure and implement controls that deliver measurable return on security investment.

What's the difference between an MSP and an MSSP?

A Managed Service Provider (MSP) handles general IT operations like helpdesk support, network management, and infrastructure maintenance. A Managed Security Service Provider (MSSP) specialises in cybersecurity—threat monitoring, incident response, vulnerability management, and compliance. Many businesses need both. Mercury IT operates as both MSP and MSSP, providing integrated IT and security services so your technology and protection work as one unified system rather than separate silos with gaps between them.

Why is everyone talking about Cyber Security?

Cyber Security is quite topical for a number of reasons: increased cyber-criminal activity, increased monetisation of stolen data, increased focus on protecting data by governments (such as the Notifiable Data Breach Scheme in Australia and the GPDR in Europe) and large corporations (such as Facebook). Cyber Security is squarely in the spotlight and for good reason, protecting our business and personal information is more important than ever as the consequences for failure are continuing to grow exponentially. Recent studies have shown that 60% of small businesses and 30% of large business never recover from a significant data breach event.