Bold-ICT

Bold-ICT Bold-ICT was founded on the belief that all businesses can take advantage of technology to do busine

04/09/2026

Free, easy, and completely necessary. πŸ›‘πŸ”’

Three quick security fixes every business should implement this week before it's too late. πŸ’»πŸ‘‡

31/08/2026

Most break-ins don't look like the movies. No hoodie, no dark room.

It's a link that looked fine. One click and they're through the door, sitting on your couch, having a look around at what's worth taking on the way out.

Worth asking your team: would they spot it?

31/08/2026

Quick one for anyone with a business website: when's the last time you actually checked on it?

Most of us set the site up once and never think about it again, but a website is software, and software left alone is exactly what hackers go looking for. You don't need to be technical to catch the basics. Check you've got the padlock (HTTPS) next to your web address, keep the software behind the site updated (outdated plugins are the number one way these things get hacked), lock down the admin login with a strong password and multi-factor authentication, and make sure any contact or signup forms are secure.

If a web designer built your site years ago and you haven't heard from them since, it's worth getting someone to take a quick look. A hacked website can start serving malware to your own customers without you ever knowing, and that's a much worse conversation to have later.

28/08/2026

Meet one of the IT engineers at Bold ICT, whose childhood dreams of working in tech turned into the real deal πŸ’». When he's not at the desk, usually after pulling off the motorbike helmet and jacket to check a calendar, you'll find him wrenching under a Nissan Skyline on a Saturday night πŸš— or making music (vocals, drums, and a bit of guitar) 🎸.

Bonus hidden talent: he can rattle off the entire alphabet backwards without skipping a beat.

28/08/2026

If you can't remember the last time your network gear got a security update, there's a good chance it stopped getting them a while ago.

Every switch, firewall and access point has a cut-off date built in. Past that point, the manufacturer stops shipping security patches, and new vulnerabilities just sit there unfixed. It's easy to miss because nothing changes on the surface. The gear keeps working right up until it's the reason someone gets in.

Get your IT provider to give you a full list of what you're running and whether it's still supported, and don't just think about the firewall - old switches, access points and that ancient backup router all count. And next time you're buying gear, look at the support timeline as closely as the price tag, because the cheaper option sometimes runs out of updates years sooner.

26/08/2026

There's a good chance your business is holding customer data it has no reason to still have.

It's rarely deliberate. A spreadsheet of card numbers from an old payment run, client files from people who left years ago, a one-off export someone pulled for a report and forgot. Nobody chose to keep it, but nobody chose to delete it either, and every one of those files is something a hacker can walk off with if they get in. Under Australian privacy rules you're actually meant to get rid of personal information once you no longer need it, so it isn't just a security thing.

Start with payment details, because those hurt the most. Ask your accountant or solicitor how long you're legally required to hold different records, set a limit for each type, and stick to it. And chase down the copies - the version someone saved to their desktop is just as easy to steal as the one in your main system.

They can't steal what you don't have.

If you have customers in Europe, the EU's new AI labelling rules apply to you, even though your business sits here in Au...
24/08/2026

If you have customers in Europe, the EU's new AI labelling rules apply to you, even though your business sits here in Australia.

They came into force on 2 August. The short version is that when AI generates content the public sees, people are meant to be able to tell. In practice the duty is narrower than the headlines make out - it lands mainly on deepfakes and on AI-written material about public interest topics that goes out with nobody reviewing it. The marketing copy you drafted with AI and then edited yourself is mostly fine.

So it's worth actually checking rather than assuming, in either direction. Have a look at where AI already sits in your customer-facing material, make sure your website chat says it's a bot if it is one, and put anything unclear to whoever handles your legal side.

You don't need a European office. You only need one European customer.

This code of practice supports compliance with the AI Act transparency obligations related to marking and labelling of AI-generated content.

21/08/2026

Bad spelling used to be how you spotted a scam. Not any more.

Google has taken legal action against a cybercrime group it alleges used its own Gemini AI to churn out scam texts and fake websites over several months, impersonating banks, government offices and well-known retailers. A crew of a few people can now produce fakes that look better than the real thing.

So stop judging the message by how it looks, and start judging it by what it wants. Anything rushing you to click a link, log in or move money is worth a pause, no matter how clean the logo is.

Don't tap the link. Open the company's app or type the address yourself and check there.

The typos were never the actual warning. They were just the easy one, and now the easy one is gone.

19/08/2026

That "Airport Free WiFi" your team just joined might not belong to the airport.

Anyone can set up a hotspot, name it whatever they like, and route every connection through their own machine. Networks with a password stuck on the wall aren't much better. If everyone has the password, everyone is already inside.

Two things fix most of this. Put a VPN on any device that leaves the office, so a snooper sees gibberish instead of your data. And turn off auto-connect to open networks, so phones and laptops stop joining random hotspots on their own.

Even better, use your phone's hotspot for anything sensitive. A mobile connection is far harder to tamper with.

Most websites encrypt their own traffic these days, so this is less risky than it used to be. But that only covers the browser, not everything else running on the device.

Set it up before the next trip, not during it.

18/08/2026

Your annual security training is mostly forgotten by the time it matters.

One 60 minute session a year doesn't stick, and the scams change faster than the slideshow does. Five minutes a month works far better, especially when it uses what businesses are seeing right now, like the fake "paste this command" prompt, or the AI voice call that sounds like the boss asking for an urgent transfer.

The other half is reporting. If someone clicks and thinks they'll be in trouble, they say nothing, and that silence is how a small problem becomes a breach. Tell your team plainly to report it straight away, no blame.

Ask your IT provider what ongoing awareness training they include, and whether it covers short monthly refreshers and simulated phishing tests.

One slideshow a year teaches your team one thing. How to sit through a slideshow.

Address

70 Breen Street
Bendigo, VIC
3550

Opening Hours

Monday 8:30am - 5pm
Tuesday 8:30am - 5pm
Wednesday 8:30am - 5pm
Thursday 8:30am - 5pm
Friday 8:30am - 5pm

Alerts

Be the first to know and let us send you an email when Bold-ICT posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Bold-ICT:

Shortcuts

Share