This month’s stories share a common question: who in the business is responsible for the technology it depends on. In several of the cases below, the answer turned out to be nobody in particular.
The ACSC rated a warning critical in July after finding many Australian small and medium businesses already compromised through their own websites. A national network outage then stopped card payments and prevented lawyers from reaching clients before court.
The month also produced genuine good news. Microsoft has expanded the AI and security capabilities across its Microsoft 365 Business plans, and construction has begun in Queensland on a utility-scale quantum computer.
The pattern among businesses handling this well is consistent. They are not those spending the most on technology, but those who can name the person accountable for each system they rely on.
Microsoft 365 pricing and packaging changes, an AI agent that completes whole tasks, and quantum computing construction in Queensland
Microsoft 365 Business plans changed on 1 July: higher prices, more capability
Microsoft 365 Business prices rose on 1 July 2026. Every Business plan gained mailbox storage and expanded Copilot Chat, and two plans gained a new email security control.
Microsoft raised the list price of Microsoft 365 Business Basic and Business Standard on 1 July 2026, and Business Premium remained unchanged. On Microsoft’s global price list, Business Standard moved from US$12.50 to US$14 per user per month.
Australian pricing varies by agreement, and existing customers remain on current pricing until renewal. The capability added alongside the increase is more significant than the amount.
All three Business plans gained 50GB of additional mailbox storage and expanded Copilot Chat with inbox and calendar awareness. Business Basic and Business Standard also gained URL time-of-click protection.
That control checks a link at the moment a user clicks it rather than when the email arrived. It is a genuine security improvement, included at no additional cost.
The Copilot Chat included in these plans is not broadly grounded in your organisation’s files by default. The separately licensed Microsoft 365 Copilot is, so permissions are worth settling before that product is added.
What to do next
Confirm which Microsoft 365 plan each staff member holds.
Ask your IT provider for the date of your next renewal.
Confirm which Copilot product your business is licensed for.
Review folder permissions in SharePoint and OneDrive.
Confirm URL time-of-click protection has been activated.
OpenAI has released an AI agent that completes whole tasks
ChatGPT Work, released on 9 July 2026, works across connected files and applications to produce finished documents. A free training program for small businesses followed on 21 July.
OpenAI released ChatGPT Work on 9 July 2026. It accepts a goal, divides that goal into steps, and works across connected files and applications until the task is complete.
An agent in this context is software that carries out a sequence of steps on a user’s behalf. The output is a completed spreadsheet, document or presentation rather than a conversation.
OpenAI followed on 21 July with a small business program of free webinars covering bookkeeping, marketing and similar functions. OpenAI reports that 42% of participants at equivalent sessions last year saved more than five hours each week.
The in-person events are held in the United States, so the webinars are the practical option for Australian businesses. The question to settle before adoption is which client information may be processed on an external platform.
What to do next
Identify one repetitive task suitable for testing an agent.
Register for one of the free webinars.
Define which staff may connect business files to an AI tool.
Document the client information that must never be entered into an external platform.
Australia has begun building a utility-scale quantum computer in Queensland
PsiQuantum broke ground at Moreton Bay in Queensland on 18 June 2026. The company describes the site as the first utility-scale, fault-tolerant quantum computer.
PsiQuantum broke ground at Moreton Bay Central on 18 June 2026. The site will house tens of thousands of light-based computing chips, linked by optical fibre and cooled to close to absolute zero.
The company opened a test and validation laboratory at Griffith University in May 2026. A TAFE Centre of Excellence and a university campus sit adjacent to the main site.
Computers of this class are the reason parts of today’s encryption carry a deadline. The concern is public-key cryptography, which secures website connections, VPNs and digital signatures.
ASD recommends organisations complete the move to quantum-resistant alternatives by the end of 2030. Symmetric encryption, used to protect stored data, is expected to remain viable longer.
What to do next
Read the announcement for the technical detail.
Ask your IT provider which systems depend on encryption you do not control.
Ask your major software vendors about their post-quantum transition plans.
Technology and running your business
A national outage with inexpensive lessons, a scam that depends on a phone call, slow offboarding, and a critical ACSC alert
The July Telstra outage: what it revealed about business continuity
A network timing fault disrupted mobile, data and card payment services across Australia on 8 July. Businesses that continued trading had a second connection method already in place.
Telstra’s mobile network began failing early on 8 July 2026, after maintenance on a network timing server. The server restarted with the wrong date, and as that error spread, voice and data services started to drop.
Telstra later told a Senate inquiry that approximately 45% of calls and data sessions were affected at the peak. Most services were working again by 10am, and the original fault was addressed by 4pm.
The likely cause was a design change to the equipment that had never been documented, combined with a software update that had not been applied. Telstra has commissioned an external investigation.
Customers of Boost, Belong, ALDI Mobile and Tangerine were affected as well, as those providers use the Telstra network. Payment provider Tyro advised merchants to move card terminals from 4G onto ethernet or Wi-Fi.
V/Line suspended regional train services in Victoria. ABC News reported that two court matters were stood down because lawyers could not reach their clients.
That final consequence is the one most relevant to professional services firms, and none of the preventive measures are expensive. Telstra is offering compensation to affected small businesses, though claims must be lodged with evidence.
What to do next
Enable Wi-Fi calling on all staff mobile devices.
Ask your payment provider how to switch terminals to a fixed connection.
Nominate one person to divert the main business phone line.
Confirm that person knows the process.
Lodge a compensation claim with Telstra if the outage affected trade.
Fake purchase callback scams rely on the recipient making the call
Scamwatch issued an alert on 14 July 2026 about fake purchase receipts containing a phone number to dispute the charge. Calling that number is the attack.
Scamwatch published an alert on 14 July 2026 about fake purchase callback scams. A receipt arrives claiming a charge of between $300 and $2,000, often containing the recipient’s correct name, phone number or address.
Scamwatch has recorded the scam arriving as PayPal invoices, Microsoft subscription renewals, delivery receipts and calendar invitations. The message contains no link to click.
It provides a telephone number instead, which is why the scam bypasses most staff awareness training. Callers are asked for card details to process a refund, or are guided through installing remote access software.
In a law or accounting practice, this message typically arrives in a shared accounts inbox. A staff member acting in good faith places the call, and the attack succeeds without any technical compromise.
What to do next
Instruct staff never to call a number printed in an unexpected invoice.
Verify any disputed charge inside the official account or application.
Source the organisation’s telephone number from its own website.
Removing a departing employee’s access takes longer than most firms assume
Most firms can name the person responsible for removing access when staff leave. Fewer can state when that process is actually complete.
When an employee resigns, the mailbox is usually disabled the same day. Subscriptions purchased on a company card, and logins configured on personal devices, frequently remain active for months.
Research from identity and security vendors has repeatedly found the same pattern. Former employees can retain access after leaving, in some cases for days or considerably longer.
For a firm holding client files, this is a confidentiality exposure before it is a technical one. The cause is rarely deliberate, and the gap is rarely noticed.
It is also among the least expensive gaps to close. The practical control is a single written list of every system a new starter is granted, reused as the checklist on their final day.
What to do next
Document every system a new starter is granted access to.
Use that document as the checklist on a departing employee’s final day.
Ask your IT provider how long complete removal currently takes.
Cancel subscriptions still billed in the name of former staff.
ACSC issues critical alert: Australian business websites are being compromised at scale
The ACSC rated an alert critical on 9 July 2026 after finding many Australian small and medium businesses already compromised through their websites. Every vulnerability named already had a patch available.
The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) published a critical alert on 9 July 2026. It covers a global campaign targeting website content management systems, and confirms that many Australian small and medium businesses are already affected.
Attackers scan websites for known vulnerabilities in content management software and plugins, then install a webshell. A webshell is a small piece of code that gives an attacker remote control of the web server.
From there, an attacker can harvest credentials and move into connected systems. WordPress plugins are the primary route, alongside several smaller website platforms.
Every vulnerability named in the alert already had a patch available at the time of publication. The alert is addressed to website owners and managers.
In many firms no individual formally holds that responsibility. The website consequently sits outside the routine patching schedule applied to computers and servers.
What to do next
Confirm who is responsible for maintaining your business website.
Ask that person or provider to apply all outstanding updates to the site and its plugins.
Request written confirmation that the site has been checked for compromise.
Sender ID registration, a complaint pathway opening in 2027, and record patch volumes
Unregistered branded sender IDs are now labelled Unverified
Since 1 July 2026, an unregistered branded sender ID displays as Unverified. Those messages are grouped with scam messages on the recipient’s phone.
The Australian Communications and Media Authority (ACMA) now requires businesses to register any branded sender ID used on their text messages. A branded sender ID is a business name appearing in place of a phone number.
Unregistered names are replaced with the word Unverified, and those messages group into a single thread alongside other unverified senders. Businesses sending from an ordinary phone number are not affected.
What this means for your business
This applies to any practice sending appointment reminders, settlement notifications or payment confirmations under its own name. Many firms have not realised it applies to them, because a booking system or client management platform sends on their behalf.
Ask whoever sends those messages to confirm the sender name is registered. Late registration remains possible, so the ACMA’s guidance for businesses is worth reviewing if messages currently display as Unverified.
Scams Prevention Framework: small businesses gain a complaint pathway from March 2027
The framework is being introduced in stages. Regulated entities must join the AFCA scheme from 1 September 2026, and most obligations start on 31 March 2027.
The Scams Prevention Framework will require banks, telecommunications providers and designated digital platforms to prevent, detect, disrupt, report and respond to scams. Introduction is staged, and most obligations apply from 31 March 2027.
Entities providing a regulated service must be members of the Australian Financial Complaints Authority (AFCA) scheme from 1 September 2026. AFCA will handle eligible scam complaints from 31 March 2027.
What this means for your business
Most professional services firms are not regulated by this framework, and most stand to benefit from it. Banks and telecommunications providers will carry defined obligations to prevent, detect and respond to scams.
The date to record is 31 March 2027, and AFCA can only consider matters occurring on or after it. Maintaining records of any scam attempt from now on is worthwhile, and the ACCC summary lists the sectors covered.
Record patch volumes: Oracle released 1,449 security fixes in a single update
Oracle’s July 2026 update contained 1,449 security patches, the largest release in the company’s history. Oracle has added monthly patch releases alongside its existing quarterly cycle.
Oracle’s July 2026 Critical Patch Update contained 1,449 new security patches. The company has also introduced monthly Critical Security Patch Updates, which supplement rather than replace the quarterly releases.
AI-assisted tools are identifying software vulnerabilities considerably faster than manual research did. On 22 June 2026 the Five Eyes cyber security agencies, including the ACSC, published a joint statement on the consequence.
The interval between a vulnerability becoming public and attackers exploiting it is narrowing. That statement described cyber security as a core business risk and a leadership responsibility.
What this means for your business
No decision is required from your business this month, and a single practice addresses the underlying issue. Updates need to be applied on a schedule that somebody owns, rather than when a device prompts an individual user.
Ask your IT provider how quickly critical updates reach every machine in your environment. Ask the same question about equipment not usually treated as a computer, including the firewall, the printer and the website.
What Jam Cyber is up to
Single sign-on: the business case for one company login
Most people encounter single sign-on as a convenience. Signing in with a Microsoft account removes the need to create and remember another password.
Implemented across a whole business, the same arrangement delivers considerably more than convenience. The Microsoft account becomes the single point of control for every platform that supports it.
One credential to protect
Fewer passwords in circulation means fewer opportunities for a stolen credential to be reused.
Access ends with employment
Where applications support single sign-on and automated provisioning, disabling the company account removes access from one central point.
Verification applied consistently
Multi-factor authentication is configured once at the point of sign-in rather than application by application.
A record that can be produced
Sign-in activity is recorded in one place, which is what insurers and client security questionnaires request.
The final point is the one business owners most often raise with us. When a client sends a security questionnaire, the response comes from a single system rather than several.
It also addresses the offboarding gap described earlier in this edition. Where an application supports automated provisioning, closing the company account withdraws access from one place.
We implement this for Australian professional services firms using the Microsoft licences they already hold. Businesses paying for Business Premium generally have most of the required capability available already.
The stories in this edition returned repeatedly to the same question, and it is not primarily a technical one. Responsibility for the website, the subscriptions, the phone line and the access list has to sit with a named person.
Businesses that handle a month like July well are rarely those spending the most on technology. They are those who can identify who is accountable for each system, and who review that list rather than assume it remains current.
If you would like an objective view of where your business stands, get in touch with the Jam Cyber team.
Ready to take the next step?
Let’s talk about where your business stands
No jargon, no hard sell. Just a clear, honest picture of your cyber security and IT, and what to do about it.
More than 20 years protecting Australian businesses
Not a single fully protected client has been breached since 2017
Jam Cyber Brief
August 2026 Edition
This month’s stories share a common question: who in the business is responsible for the technology it depends on. In several of the cases below, the answer turned out to be nobody in particular.
The ACSC rated a warning critical in July after finding many Australian small and medium businesses already compromised through their own websites. A national network outage then stopped card payments and prevented lawyers from reaching clients before court.
The month also produced genuine good news. Microsoft has expanded the AI and security capabilities across its Microsoft 365 Business plans, and construction has begun in Queensland on a utility-scale quantum computer.
The pattern among businesses handling this well is consistent. They are not those spending the most on technology, but those who can name the person accountable for each system they rely on.
In this edition
New and worth knowing
Microsoft 365 pricing and packaging changes, an AI agent that completes whole tasks, and quantum computing construction in Queensland
Microsoft 365 Business plans changed on 1 July: higher prices, more capability
Microsoft raised the list price of Microsoft 365 Business Basic and Business Standard on 1 July 2026, and Business Premium remained unchanged. On Microsoft’s global price list, Business Standard moved from US$12.50 to US$14 per user per month.
Australian pricing varies by agreement, and existing customers remain on current pricing until renewal. The capability added alongside the increase is more significant than the amount.
All three Business plans gained 50GB of additional mailbox storage and expanded Copilot Chat with inbox and calendar awareness. Business Basic and Business Standard also gained URL time-of-click protection.
That control checks a link at the moment a user clicks it rather than when the email arrived. It is a genuine security improvement, included at no additional cost.
The Copilot Chat included in these plans is not broadly grounded in your organisation’s files by default. The separately licensed Microsoft 365 Copilot is, so permissions are worth settling before that product is added.
What to do next
OpenAI has released an AI agent that completes whole tasks
OpenAI released ChatGPT Work on 9 July 2026. It accepts a goal, divides that goal into steps, and works across connected files and applications until the task is complete.
An agent in this context is software that carries out a sequence of steps on a user’s behalf. The output is a completed spreadsheet, document or presentation rather than a conversation.
OpenAI followed on 21 July with a small business program of free webinars covering bookkeeping, marketing and similar functions. OpenAI reports that 42% of participants at equivalent sessions last year saved more than five hours each week.
The in-person events are held in the United States, so the webinars are the practical option for Australian businesses. The question to settle before adoption is which client information may be processed on an external platform.
What to do next
Australia has begun building a utility-scale quantum computer in Queensland
PsiQuantum broke ground at Moreton Bay Central on 18 June 2026. The site will house tens of thousands of light-based computing chips, linked by optical fibre and cooled to close to absolute zero.
The company opened a test and validation laboratory at Griffith University in May 2026. A TAFE Centre of Excellence and a university campus sit adjacent to the main site.
Computers of this class are the reason parts of today’s encryption carry a deadline. The concern is public-key cryptography, which secures website connections, VPNs and digital signatures.
ASD recommends organisations complete the move to quantum-resistant alternatives by the end of 2030. Symmetric encryption, used to protect stored data, is expected to remain viable longer.
What to do next
Technology and running your business
A national outage with inexpensive lessons, a scam that depends on a phone call, slow offboarding, and a critical ACSC alert
The July Telstra outage: what it revealed about business continuity
Telstra’s mobile network began failing early on 8 July 2026, after maintenance on a network timing server. The server restarted with the wrong date, and as that error spread, voice and data services started to drop.
Telstra later told a Senate inquiry that approximately 45% of calls and data sessions were affected at the peak. Most services were working again by 10am, and the original fault was addressed by 4pm.
The likely cause was a design change to the equipment that had never been documented, combined with a software update that had not been applied. Telstra has commissioned an external investigation.
Customers of Boost, Belong, ALDI Mobile and Tangerine were affected as well, as those providers use the Telstra network. Payment provider Tyro advised merchants to move card terminals from 4G onto ethernet or Wi-Fi.
V/Line suspended regional train services in Victoria. ABC News reported that two court matters were stood down because lawyers could not reach their clients.
That final consequence is the one most relevant to professional services firms, and none of the preventive measures are expensive. Telstra is offering compensation to affected small businesses, though claims must be lodged with evidence.
What to do next
Fake purchase callback scams rely on the recipient making the call
Scamwatch published an alert on 14 July 2026 about fake purchase callback scams. A receipt arrives claiming a charge of between $300 and $2,000, often containing the recipient’s correct name, phone number or address.
Scamwatch has recorded the scam arriving as PayPal invoices, Microsoft subscription renewals, delivery receipts and calendar invitations. The message contains no link to click.
It provides a telephone number instead, which is why the scam bypasses most staff awareness training. Callers are asked for card details to process a refund, or are guided through installing remote access software.
In a law or accounting practice, this message typically arrives in a shared accounts inbox. A staff member acting in good faith places the call, and the attack succeeds without any technical compromise.
What to do next
Removing a departing employee’s access takes longer than most firms assume
When an employee resigns, the mailbox is usually disabled the same day. Subscriptions purchased on a company card, and logins configured on personal devices, frequently remain active for months.
Research from identity and security vendors has repeatedly found the same pattern. Former employees can retain access after leaving, in some cases for days or considerably longer.
For a firm holding client files, this is a confidentiality exposure before it is a technical one. The cause is rarely deliberate, and the gap is rarely noticed.
It is also among the least expensive gaps to close. The practical control is a single written list of every system a new starter is granted, reused as the checklist on their final day.
What to do next
ACSC issues critical alert: Australian business websites are being compromised at scale
The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) published a critical alert on 9 July 2026. It covers a global campaign targeting website content management systems, and confirms that many Australian small and medium businesses are already affected.
Attackers scan websites for known vulnerabilities in content management software and plugins, then install a webshell. A webshell is a small piece of code that gives an attacker remote control of the web server.
From there, an attacker can harvest credentials and move into connected systems. WordPress plugins are the primary route, alongside several smaller website platforms.
Every vulnerability named in the alert already had a patch available at the time of publication. The alert is addressed to website owners and managers.
In many firms no individual formally holds that responsibility. The website consequently sits outside the routine patching schedule applied to computers and servers.
What to do next
Keep on the radar
Sender ID registration, a complaint pathway opening in 2027, and record patch volumes
Unregistered branded sender IDs are now labelled Unverified
The Australian Communications and Media Authority (ACMA) now requires businesses to register any branded sender ID used on their text messages. A branded sender ID is a business name appearing in place of a phone number.
Unregistered names are replaced with the word Unverified, and those messages group into a single thread alongside other unverified senders. Businesses sending from an ordinary phone number are not affected.
What this means for your business
This applies to any practice sending appointment reminders, settlement notifications or payment confirmations under its own name. Many firms have not realised it applies to them, because a booking system or client management platform sends on their behalf.
Ask whoever sends those messages to confirm the sender name is registered. Late registration remains possible, so the ACMA’s guidance for businesses is worth reviewing if messages currently display as Unverified.
Scams Prevention Framework: small businesses gain a complaint pathway from March 2027
The Scams Prevention Framework will require banks, telecommunications providers and designated digital platforms to prevent, detect, disrupt, report and respond to scams. Introduction is staged, and most obligations apply from 31 March 2027.
Entities providing a regulated service must be members of the Australian Financial Complaints Authority (AFCA) scheme from 1 September 2026. AFCA will handle eligible scam complaints from 31 March 2027.
What this means for your business
Most professional services firms are not regulated by this framework, and most stand to benefit from it. Banks and telecommunications providers will carry defined obligations to prevent, detect and respond to scams.
The date to record is 31 March 2027, and AFCA can only consider matters occurring on or after it. Maintaining records of any scam attempt from now on is worthwhile, and the ACCC summary lists the sectors covered.
Record patch volumes: Oracle released 1,449 security fixes in a single update
Oracle’s July 2026 Critical Patch Update contained 1,449 new security patches. The company has also introduced monthly Critical Security Patch Updates, which supplement rather than replace the quarterly releases.
AI-assisted tools are identifying software vulnerabilities considerably faster than manual research did. On 22 June 2026 the Five Eyes cyber security agencies, including the ACSC, published a joint statement on the consequence.
The interval between a vulnerability becoming public and attackers exploiting it is narrowing. That statement described cyber security as a core business risk and a leadership responsibility.
What this means for your business
No decision is required from your business this month, and a single practice addresses the underlying issue. Updates need to be applied on a schedule that somebody owns, rather than when a device prompts an individual user.
Ask your IT provider how quickly critical updates reach every machine in your environment. Ask the same question about equipment not usually treated as a computer, including the firewall, the printer and the website.
What Jam Cyber is up to
Single sign-on: the business case for one company login
Most people encounter single sign-on as a convenience. Signing in with a Microsoft account removes the need to create and remember another password.
Implemented across a whole business, the same arrangement delivers considerably more than convenience. The Microsoft account becomes the single point of control for every platform that supports it.
One credential to protect
Fewer passwords in circulation means fewer opportunities for a stolen credential to be reused.
Access ends with employment
Where applications support single sign-on and automated provisioning, disabling the company account removes access from one central point.
Verification applied consistently
Multi-factor authentication is configured once at the point of sign-in rather than application by application.
A record that can be produced
Sign-in activity is recorded in one place, which is what insurers and client security questionnaires request.
The final point is the one business owners most often raise with us. When a client sends a security questionnaire, the response comes from a single system rather than several.
It also addresses the offboarding gap described earlier in this edition. Where an application supports automated provisioning, closing the company account withdraws access from one place.
We implement this for Australian professional services firms using the Microsoft licences they already hold. Businesses paying for Business Premium generally have most of the required capability available already.
Talk to the Jam Cyber team →
Final thoughts
The stories in this edition returned repeatedly to the same question, and it is not primarily a technical one. Responsibility for the website, the subscriptions, the phone line and the access list has to sit with a named person.
Businesses that handle a month like July well are rarely those spending the most on technology. They are those who can identify who is accountable for each system, and who review that list rather than assume it remains current.
If you would like an objective view of where your business stands, get in touch with the Jam Cyber team.
Ready to take the next step?
Let’s talk about where your business stands
No jargon, no hard sell. Just a clear, honest picture of your cyber security and IT, and what to do about it.
Recent Posts
Categories