Skip to content
Free, no account required

Tools built to be used, not admired.

Three tools, each answering a question you can act on today — where to review your readiness, which patterns deserve attention, and what the ten controls to review actually are.

Tool 02 · Interactive

Password Pattern Check

Try a disposable password pattern and see local feedback on length and common patterns. Nothing you type is transmitted or stored — this is not a breach-database lookup.

Nothing typed here is transmitted or stored — the check runs entirely in this browser tab. Use disposable examples only; never type an actual password.

Start typing above to see an instant, illustrative read on that pattern’s local characteristics.

Get the password hardening checklist

The checklist covers long unique credentials, recovery protection, and enforced MFA — practical steps that reduce avoidable credential risk.

Run the full password checklist →
Tool 03 · Download

The Security Essentials Checklist

A practical checklist of ten foundational controls for Australian small businesses — MFA, backups, patching, and more, with space to assign an owner and review date.

  • Practical controls with an owner and review date for each item
  • Written for a business owner, not a security team
  • Covers MFA, credentials, updates, access, email, backups, response, and review

Security Essentials Checklist

0 / 10 reviewed0%

Turn on multi-factor authentication

Enable MFA for email, administrator, remote-access and other high-value accounts. Prefer stronger methods where the service supports them.

Use unique passwords and passphrases

Use a password manager to create unique credentials. Protect the manager with MFA and a long, unique passphrase.

Keep software supported and updated

Turn on automatic updates where appropriate and maintain an inventory of operating systems, applications, network devices and plugins.

Limit access and administrator rights

Give people only the access they need. Use separate administrator accounts, review access regularly and remove access when roles change.

Control applications and risky content

Use application control where practical, restrict internet-sourced Office macros and harden browsers, PDF readers and Office applications.

Protect email and domains

Use provider security controls, protect domain administration with MFA and give staff a clear way to report suspicious messages.

Back up important information

Define what is backed up, where it is stored, who owns it and how often restores are tested. Keep a protected or offline copy where appropriate.

Monitor important activity

Keep useful security logs and alerts for identity, endpoint, email and backup systems. Decide who reviews alerts and when.

Prepare an incident response plan

Keep current contacts, containment steps, decision rights and reporting pathways. Practise the plan so the first response is deliberate.

Review progress

Set a review date, record exceptions and prioritise the controls that protect your most important accounts, information and services.

Complete each control to see your prioritised plan before submitting.

Request a prepared action plan

Share business details so GMAN IT can prepare a useful follow-up by email and with the team.

Optional business context

Your submitted details and checklist answers are shared with GMAN IT to prepare the plan and follow up. Read our Privacy Policy. If a delivery link is generated, it expires after 7 days.

Tools tell you where to look. An assessment tells you what to fix.

The Cyber Readiness Assessment turns everything above into a written, prioritised plan for your business.