
5th January 2026
Turning security into proof you can show.
If you run a small or mid‑sized business, you’ve probably heard of SMB1001. Here’s the straight talk: you don’t need another abstract diagram. You need a certifiable path that fits real‑world constraints and leaves you with evidence you can hand to clients, insurers, and your board.
SMB1001 is that path. It’s tiered (Bronze → Diamond), practical, and recognises that most teams don’t have a spare compliance department.

Why SMB1001 (and not yet another theory)
We help clients who don’t want a rip‑and‑replace or a 200‑page manual. SMB1001 borrows the best of the ACSC Essential Eight, then adds governance, training, and certification—so you’re not just ‘secure-ish’, you’re demonstrably secure.
Three things we see all the time
- MFA everywhere—except two execs. That’s where attackers got in. Close the gaps; inconvenience is cheaper than incident response.
- Backups that never rehearse. A restore drill would have saved days. If you haven’t restored it, you don’t have it.
- Local admin kept ‘temporarily’. Malware rode in on a handy in‑app update. Use least privilege with approved elevation and move on.
The tiered journey in plain English
Bronze / Silver — foundation you can explain:
- MFA for everyone (including service and exec accounts)
- Immutable, off‑site backups + one successful restore rehearsal
- No shared admin logins; least‑privilege by default
- Short, readable policies (passwords, access, incident steps)
- Self‑assessment may be available at these tiers
Gold — managed and measured:
- Centralised logging with alerts that matter (impossible travel, mass mailbox rules)
- Quarterly access reviews; tabletop exercises for incidents
- Email domain hygiene: SPF, DKIM, DMARC aligned
Platinum / Diamond — audit‑ready:
- External audit for higher assurance
- Zero‑trust guardrails (conditional access + device compliance gates)
- A living evidence pack that proves outcomes, not intentions
Our non‑negotiables (we don’t bend these)
- No MFA exceptions
- No untested backups
- No permanent local admin
- No mystery SaaS outside SSO/conditional access
- No shelf‑ware policies—train people, keep it short
Build the evidence pack (and keep it tidy)
Keep artefacts in a dated folder (Q1/Q2/Q3/Q4) with a simple index. Make screenshots legible for non‑technical reviewers.
- MFA coverage screenshots + exception log
- Restore drill notes with RTO/RPO and actions
- Access review records (admins, service accounts, high‑risk SaaS)
- DMARC alignment report (SPF and DKIM working; enforcement policy applied)
- Incident playbook + tabletop debriefs
- Policy register with version history and staff acknowledgements
A 30‑60‑90 that doesn’t derail your week
Days 0–30 — stabilise fast:
- Turn on MFA for everyone; retire shared admin
- Encrypt devices; set sensible lock and browser defaults
- Establish immutable backups and do one restore rehearsal
- Publish the two‑page incident playbook
Days 31–60 — standardise without drama:
- Remove local admin; add approved elevation
- Centralise patching (OS + common apps)
- Align SPF/DKIM/DMARC
- Build a simple asset inventory
Days 61–90 — validate and show your work:
- Run a tabletop exercise and capture lessons
- Do an access review and fix high‑risk gaps
- Repeat a restore to a realistic RTO/RPO
- Set a few alerts that actually help
SMB1001 ↔ Essential Eight (how they fit together)
Think of Essential Eight as the technical spine. SMB1001 adds governance, training, and certification—that’s the muscle and documentation that makes your posture defensible in front of insurers, auditors, and customers.
How iQtec delivers (outcomes over logos)
Week 1: clarity and quick wins
- Map identities, admin accounts, backups
- Enforce MFA; retire shared admin
- Run restore test; fix brittleness
- Publish the two‑page incident playbook
Weeks 2–6: least privilege & allowlisting
- Remove local admin; enable approved elevation
- Apply allowlisting to risky workflows
- Centralise patching and measure it
Quarterly cadence: keep evidence current
- Access reviews; restore drills; concise refreshers
- Save evidence packs for tenders and insurance
- Adjust controls as the business changes
Book a consult
Want a 12‑month, low‑disruption plan to go from ‘we think we’re fine’ to defensible and audit‑ready under SMB1001? Book a consult with iQtec. We’ll start with quick wins and leave you with proof you can show.
