Resource
Cybersecurity standards are mostly written for organisations with a security team. SMB1001 is not. It gives a small business five defined levels and a route through them.
Cybersecurity standards are mostly written for organisations that already have a security team. Everyone else is left to work out what good looks like on their own.
SMB1001 is built for those organisations. It sets out five progressive certification levels, each with a defined set of controls, and it is reviewed annually so it keeps pace with how attacks actually change.
Layer3 builds SMB1001 into every managed service plan. That gives your organisation something to measure against, a clear view of the gaps, and an agreed order for closing them.
It walks through the first three levels.
If you want help placing your organisation against the levels, talk to us. That assessment is where a vCIO engagement usually starts.
Next step
A completed template tells you where you stand today. Keeping it true to your organisation, quarter after quarter, is the work our vCIO service exists to do.

Layer3 is a managed IT provider operating an ISO/IEC 27001-certified ISMS, with offices across New Zealand.
Contact
0508 LAYER3 Book a discovery call Service status Notices
Level 2, CBD Towers
84-90 Main Street
Upper Hutt, Wellington 5018
Layer3
Book a discovery call - 30 minutes, no obligation