For Australian small businesses with up to 20 people

You weren’t hacked
by geniuses.
You were caught by gaps.

The book Shit, I’ve Been Hacked! by Kevin Greely

Gaps that could have been closed in an afternoon. Shit, I’ve Been Hacked! shows you what to fix first, what you can do yourself, what to hand to your IT provider and what to do if something goes wrong.

  • Twelve short chapters and twelve practical action lists
  • Every action tells you how long it takes, what it costs and who does it
  • Free and low-cost protections first, before anybody sells you anything

No payment now. We’ll email you when preorders open.

We’ll only use your email to tell you when the book is out. No list swapping, no drip sequence. Unsubscribe in one click. Privacy.

You are: small enough that cyber is everyone’s job.
Busy enough that it becomes nobody’s.

  1. 01You don’t have a security team, and cyber has never been anybody’s actual job.
  2. 02You might have an IT provider, but you are not certain if they cover everything you need.
  3. 03It stays on the list because nobody can tell you what “enough” looks like.
  4. 04You want your business protected without becoming a cybersecurity expert.

The point of reading it

What you’ll know by the end

  • What to fix first

    The order matters more than the list. A handful of things carry most of the risk.

  • What can wait

    Just as useful. Most of what you have been sold is not urgent for a business your size.

  • What to ask your IT provider

    In words they will act on, and specific enough that you will know when it is done.

  • What it should cost

    Free where it is free, and a real number where it is not, so you can spot a padded quote.

  • What to do in the first hour

    If something does happen. Who to ring, in what order, and what not to touch.

What’s inside

Twelve chapters. Twelve action lists. No homework you can’t finish.

Each one ends with a single page: what to do, roughly how long it takes, what it costs, and whose job it is.

  1. 01Your Digital ID Card
  2. 02The Digital Back Door
  3. 03The Tech Rego
  4. 04Cloud or Chaos
  5. 05The Fire Drill
  6. 06The Human Factor
  7. 07Money Moves & Red Flags
  8. 08Suppliers, MSPs & Hidden Dependencies
  9. 09Governance Without the Corporate Stuff
  10. 10AI: The New Apprentice
  11. 11Getting Help Without Getting Fleeced
  12. 12The Last ~10%

From Chapter 2

“Everything looked normal.”
That is the point.

> Hi mate, just letting you know we’ve changed banks. Please use the attached invoice with updated payment details.

Same supplier you always deal with. Same email chain. Signature correct and ABN valid. Three weeks later the real supplier rings, asking why they haven’t been paid.

$18,420

Invoice fraud works because it targets a process, not a computer. Nobody researched the business nor was anything broken into. Somebody had simply been reading the mail for weeks, waiting for a real payment conversation to answer.

The business in Chapter 1 had antivirus, a firewall, an IT support company and cyber insurance. What it did not have was two-step login on email. That cost it over ninety thousand dollars.

No one broke the locks.
Someone copied the key.

Composite case studies drawn from real incident patterns, as set out in the book. Names and figures are illustrative, not a single identified business.

A look inside

This is what an action list looks like

Every chapter ends with one. Time required, cost, and who does it, straight across the top. Then the steps in order, in plain English, with the reason each one matters.

There are twelve of them. If you read nothing else in a chapter, read that page.

Every template is printed in the book, and there are online copies you can access.

Photocopy them, laminate them, stick them on the wall near the payments desk. Fillable versions live at www.steady-point.com/resources.

A sample action list page from Chapter 1, Lock Down Identity, showing time required, cost, who does it, and five numbered steps
Chapter 1 — Lock Down Identity. Actual page from the book.

DI(m)Y

So who does the work?

You can do most of it, because most of it is a setting somebody changes once and never thinks about again. So, not DIY, but DI(m)Y. The book explains those for a person rather than a technician, and every action on every list carries a mark telling you whose job it is. And before you say it, yes, techs are people too. We know.

  • You do it

    Most of the list

    Turning on two-step login. Setting backups to run daily. Writing the payment rule down where the person who pays the invoices will actually see it. The steps are in the book, written out in full - explained for you to do.

  • Shared

    A handful of jobs

    Some things go quicker with somebody beside you. The book tells you which ones they are and exactly what to ask for, so you are never paying anyone to explain your own business back to you.

  • Your IT person

    Hand the list over

    Already have someone? Give them the chapter’s action list. It is written plainly enough that they will know exactly what you are asking for, and specific enough that you will know when it is done.

DI(mostly)Y™The genuinely fiddly bits, we will do, or your IT person can. Nothing in this book is written to make you need us.

Before the book properly begins

The First Sixty Minutes

Page four is five things. Most people finish them in under an hour, and that hour removes a large slice of the risk that actually affects businesses your size.

  1. 1Two-step login on email
  2. 2A payment change rule
  3. 3Automatic daily backups
  4. 4Automatic updates, everywhere
  5. 5Make it safe for staff to own a mistake

Measured against something real

A standard built for your size, not for a bank

The book works to SMB1001 and the ASD Essential Eight, which are the two standards an Australian insurer or a tender document is most likely to ask for.

You don’t need to understand the tiers to use it. Work through the chapters and the book tells you where you are. Most people finish further up than they expected.

This book is an independent guide. It is not affiliated with, endorsed by, administered by, or associated with the creators or owners of the SMB1001 standard.

Why I wrote it

Kevin GreelyBA (Business & Economics)

More than 20 years of conferences, product launches and each new acronym as it arrived. My interest, while helping to protect clients in high-risk verticals like finance, health and local government, has always been narrower than the industry’s: what actually stops a business being financially or operationally crippled. The answer is rarely the most complicated thing on the stand.

I wrote this because the businesses I like working with kept being sold the wrong end of the problem. Educated at Trinity College Dublin, now in Northern NSW, working with businesses and not-for-profits here and overseas.

Reserve your copy

Format
Ebook first, paperback to follow
Price
[EBOOK $XX.XX] · [PAPERBACK $XX.XX]
Out
[MONTH 2026]

No payment now. We’ll email you when preorders open.

We’ll only use your email to tell you when the book is out. No list swapping, no drip sequence. Unsubscribe in one click. Privacy.

The book Shit, I’ve Been Hacked! by Kevin Greely