Our Honest Journey to SMB1001 Platinum certification – Why Discipline Matters More Than Badges
by Glen Sawtell, Technical Director
Let me start with the obvious question. Why would we chase SMB1001 Platinum certification in a cyber security framework that most of our clients have never heard of?
Before I answer that, three quick notes for context.
First, we’re publishing this because we think transparency matters. If we’re going to ask and expect businesses to take cyber security seriously, we have to be willing to talk honestly about what we found when we held ourselves to a higher standard, what we changed, and what we learned.
Second, we’re deliberately vague on a few technical specifics. That’s on purpose. The goal here is to share the journey and the lessons, not give malicious actors a roadmap.
Lastly, we were audited and awarded SMB1001:2025 Platinum in mid December 2025, the first IT firm in Australia to reach the Platinum tier.
Also, just for your reassurance, every gap mentioned below was fixed before certification was granted, and it’s fixed today.
The honest reason we did it
This isn’t a badge story. It’s a “we looked under the hood and didn’t like everything we saw” story.
We’re an MSP. We spend our days helping other organisations reduce risk, tighten controls, and build better habits. When we started looking at SMB1001 Platinum in mid 2025, I expected we’d be largely aligned already.
We weren’t quite as close as I’d hoped.
Not in the sense that we were reckless or running insecure systems. The bigger issue was that some of our security maturity lived in habits and technical implementation, but our governance maturity hadn’t caught up. When you’re trying to build repeatable discipline, that gap matters.
Why SMB1001 instead of ISO 27001 or Essential Eight
For most SMBs, ISO 27001 isn’t actually needed. Not because it isn’t a good standard, but because it’s management‑heavy.
ISO makes sense when governance is part of the product — security vendors, SaaS platforms, government suppliers, regulated environments. In those cases, the overhead is justified. For many everyday businesses, it isn’t.
A retail shop doesn’t need an ISMS program that consumes months of effort just to be meaningfully secure. Most professional services firms don’t either, unless there’s specific contractual or regulatory pressure.
At the other end sits Essential Eight.
Essential Eight is a solid, practical baseline. We like it and we use it. But it’s primarily a technical maturity model. It focuses on controls, not always on ownership, evidence, or whether good habits hold up over time. Most organisations are also effectively self‑assessing unless they bring in an independent reviewer.
SMB1001 sat neatly in the middle.
It’s structured without being oppressive, achievable without being superficial, and it forced us to prove, with evidence, that we actually do what we say we do. That external validation was the point, even if the framework itself isn’t yet widely recognised.
If you want the plain‑language view of how we approach it and why it matters for SMBs, it’s here: SMB1001 certification overview
What we found, and why it mattered
When we started the process, the gaps were mostly in the “boring but important” category.
Policies. Registers. Ownership. Evidence.
We didn’t have our core policies and response playbooks documented to the standard we expect of ourselves. We had patterns and practices, but not enough of it was written down in a way that was easy to audit, easy to maintain, and easy to keep consistent as a team grows.
We also didn’t have clean, current registers for everything we use and depend on. We had innternal systems that tracked assets and platforms, but parts of that information drifted over time. In our case, it wasn’t a lack of tooling, it was a lack of consistency.
That sounds small until you look at why organisations get caught out.
Trend Micro research reported that 73% of security leaders said they’d experienced an incident due to unknown or unmanaged assets.
The underlying Trend Micro release makes the same point, and it’s blunt about the visibility problem.
The lesson is simple. You can’t protect what you don’t know you have.
The “how did we miss that” moment
The part that really snapped everything into focus for us was identity and authentication coverage, specifically where MFA and SSO were enforced, where they weren’t, and how we were tracking that.
At the time, we found a legacy access pattern that shouldn’t have existed. It involved a privileged internal platform. The kind of tool you absolutely want locked down, because if it’s compromised the blast radius is ugly.
It was one of those moments where you stop and think, “how did this linger”.
We fixed it immediately. Shared access was removed, MFA was enforced, and we tightened how privileged systems are tracked and reviewed. We also put in place a clearer way to make sure this kind of gap doesn’t quietly reappear months later.
This is where broader industry data is still worth mentioning, because it reinforces that this is not a theoretical risk.
Verizon’s 2025 DBIR shows credential abuse remains one of the top initial access vectors, sitting around the low‑20% range and close to vulnerability exploitation.
A summary deck drawn from the same report makes the initial access vector comparison very clear.
And for MSPs specifically, the stakes are higher because of the supply chain angle. CyberSmart’s 2025 MSP survey reported that 69% of MSP leaders were breached two or more times in the previous 12 months.
That doesn’t mean every MSP is careless. It means MSPs are targeted, repeatedly, because the leverage is high.
The register that changed how we operate
One of the most practical outcomes of this work was the Digital Asset Register, a core requirement of SMB1001 Gold and above, that made gaps visible.
It’s not glamorous, but it’s powerful. With the right register in place, we can see at a glance what platforms exist, what they do, who owns them, and whether key controls like MFA and SSO are in place.
Before that, some of this information effectively lived across credential management, admin habit, and tribal knowledge. It wasn’t “hidden”, but it wasn’t easy to review systematically. That difference matters.
This is the kind of work frameworks are good at forcing. Not because people don’t care, but because busy teams can let small inconsistencies accumulate.
We fixed gaps because they mattered. The audit simply removed the option to procrastinate.
The recognition problem, and why we still did it
SMB1001 isn’t as widely recognised as ISO 27001, and it doesn’t have the same public profile as frameworks like Essential Eight. Big enterprise frameworks are often mandated or regulated, and small and medium business typically doesn’t face as much scrutiny. Not as many people are talking about it – yet.
But the value wasn’t the public recognition. It was the discipline and accountability.
An external auditor reviewed our environment and evidence, and we had to stand behind it. That’s a different level of confidence than “we think we’re good”.
And importantly, it gave us a practical, structured path to improve without pretending every organisation needs the governance overhead of ISO 27001.
What this means for peers, and for buyers doing diligence
If you’re a curious IT manager, this is the part that matters.
A framework doesn’t magically make you secure. What it can do is force you to confront the boring gaps that become painful later. The register that drifts. The access pattern that lingers. The policy that exists as habit but isn’t documented.
If you’re a high-intent buyer assessing an MSP or considering SMB1001 for your own organisation, this story is also the point.
The question you should be asking isn’t “what badge do you have”. It’s “do you have disciplined habits, do you verify them, and do you catch drift before it becomes an incident”.
If you’re an MSP peer reading this, I’ll be blunt. We all have blind spots. The uncomfortable gaps are usually the ones we assume are already fine, because they’ve never bitten us yet. If you’re wrestling with the same questions, we’re always happy to compare notes.
SMB1001 forced us to stop assuming and start checking. It gave us structure, and it gave us accountability.
Is it perfect? No. But it made us better, and it made us more confident that we’re practising what we preach.
That’s why we pursued the SMB1001 Platinum certification, even if it is not as widely known as other standards.
Notice to readers: this blog article was created with assistance from our custom AI Content Marketing agent; we’re IT experts, not content authors or editors.


