
Earlier this month, vCISO.One published a press release highlighting a serious issue that I see every week in my consulting work: far too many small-to-medium businesses (SMBs), local councils, and not-for-profits (NFPs) are operating without a formal cybersecurity roadmap.
That release generated strong interest, and I wanted to expand on the topic here with some reflections from my own experience. This blog goes deeper than the news announcement — sharing why this problem persists, what it really looks like on the ground, and what practical steps organisations can take to move from reactive to ready.
Why So Many Organisations Lack a Roadmap
In my work across Australia, I often meet leaders who care about cybersecurity but feel overwhelmed by the complexity. Many assume that having antivirus software, a firewall, or even passing an IT audit means they’re safe. Unfortunately, it doesn’t.
Without a structured roadmap, security spending becomes reactive:
A new tool is purchased after a breach scare.
A policy is written quickly to pass an audit.
A consultant is brought in to plug a specific gap.
The problem? These efforts rarely line up with the organisation’s biggest risks. What you’re left with is a patchwork of tools and policies that might look reassuring on paper, but in reality leave dangerous gaps.
I’ve learned that it’s not a lack of effort — it’s a lack of structure and planning. And that’s exactly what a roadmap is designed to fix.
A Costly Example from Queensland
In the press release, I mentioned a Queensland not-for-profit that became a victim of invoice fraud. Their case is a perfect example of what happens when an organisation grows without a cyber strategy.
They moved rapidly to cloud services during the pandemic, but never developed a long-term plan. When an employee clicked a phishing link, attackers accessed sensitive data and tricked the finance team into paying $78,000 in fraudulent invoices.
Afterwards, it became clear that:
Multi-Factor Authentication (MFA) was only partially rolled out.
No risk register existed.
The board had never been briefed on cyber risk.
In my experience, this story is far from unique. I’ve seen organisations spend hundreds of thousands on technology — yet skip simple governance steps that would have prevented an attack.
What the Standards Tell Us
The reality is, Australia’s own security frameworks all agree on one thing: you need a plan.
The ACSC Essential Eight outlines a maturity model for uplift, and you can’t progress without a roadmap.
The ISM (Information Security Manual) requires organisations to align risks to governance and decision-making.
ISO/IEC 27001 demands an information security management system — a fancy way of saying “documented strategy and controls.”
But here’s the point I stress to clients: a roadmap doesn’t have to be complicated. For smaller organisations, even a simple, one-page plan that identifies risks, sets priorities, and assigns accountability can make a world of difference.
The Benefits Go Beyond Security
When I speak with boards and executives, I try to reframe the discussion away from fear. Cybersecurity is not just about avoiding breaches — it’s also about creating business value.
A clear roadmap delivers:
Budget efficiency – Resources are directed at the risks that matter most.
Insurance alignment – Cyber insurers increasingly want proof of governance.
Regulatory trust – Councils, in particular, face growing scrutiny over community data.
Customer and donor confidence – Stakeholders want to know their data is protected.
Cultural change – Cyber becomes part of decision-making, not just an IT problem.
From Reactive to Ready: My Advice
So how can an organisation actually begin? Based on my own consulting work with councils, SMBs, and NFPs, I recommend five first steps:
Start with a risk assessment – Identify your most critical assets (“crown jewels”) and their vulnerabilities.
Create a basic risk register – Track risks, impacts, and owners in a simple format, even a spreadsheet.
Set a 12–18 month plan – Focus on a handful of initiatives that deliver the most impact.
Engage leadership – Cyber risk needs to be visible at board level.
Review regularly – Adjust as new threats and priorities emerge.
I’ve seen organisations turn things around remarkably quickly by following this structured but simple approach.
Free Resource: “Secure Smarter, Not Harder”
To help organisations take the first step, I created a free whitepaper: “Secure Smarter, Not Harder.”
It outlines 25 of the most common challenges I see in SMBs, councils, and NFPs — from shadow IT and board-level blind spots to confusion around cloud security. For each, it provides practical, plain-language guidance on how to address it and build a tailored roadmap.
This is the same resource referenced in the press release, and I’ve already had feedback from leaders who used it to kickstart discussions at their board meetings.
You can download it here.
Final Thoughts
Cybersecurity can feel daunting, especially for organisations without big budgets or internal expertise. But from what I’ve seen first-hand, the biggest gains don’t come from buying more tools — they come from having a plan.
As I said in the press release:
“Failing to plan is planning to fail — and in cybersecurity, the consequences can be catastrophic.”
By taking the time to build a roadmap, organisations move from chasing threats endlessly to building resilience deliberately. That shift is where real security begins.
About vCISO.One
vCISO.One is the consultancy I founded to help SMBs, councils, and NFPs access the same strategic security leadership as large enterprises — but in a flexible, affordable way. Our services include:
Virtual CISO (vCISO) services
Cybersecurity program management
Risk and compliance consulting
Managed security solutions
With decades of international experience, I focus on bringing practical, results-driven approaches to help clients reduce risk and build long-term resilience.
Learn more at www.vciso.one.
Ready to take action?
Book your free cyber readiness consultation at vCISO.One and take the first step toward better protection today.





