Most people picture a large enterprise with a dedicated security team when they think about data protection. Not a plumbing and facilities maintenance business working across Australia’s east coast.
That’s exactly the image Joanne Tonks, General Manager of Watertight Group, set out to challenge in our recent webinar with GuardWare CEO and Co-Founder Rizwan Mahmood. Watertight works B2B across some of the country’s most sensitive sectors, defence, government, education, health, utilities, and critical infrastructure. Those clients don’t just want a plumber who turns up on time. Increasingly, they want proof that the businesses in their supply chain won’t become the weak link that lets a breach through.
The Breach That Changed Joanne’s Thinking
For Joanne, the wake-up call came years before it was ever asked of her directly. In 2013, Target in the US was breached through an HVAC contractor, exposing around 100 million customer records through a supplier that was never meant to be a way in. That story stuck with her. “I do not want to be that company,” she said. “We do not want to be a backdoor for our customers’ systems.” From that point on, she started treating cyber security as a risk management investment rather than a cost to minimise.
Why the First Quotes Nearly Scared Her Off
Like a lot of business owners, Joanne didn’t start with a clear roadmap. She began with the free resources available through cyber.gov.au, worked through the Essential Eight, and watched ISO 27001 shift from a nice to have into something her clients increasingly expected. When she went looking for a vendor, the first quotes she received were, in her words, “pretty scary,” some upwards of $50,000 before she’d even started. What eventually worked was a referral from a defence client into GuardWare, a solution she describes as simple enough for a business her size to take on, and one that could scale as Watertight grew.
Turn It All On, Then Learn Fast
Rather than switching features on gradually, Joanne turned the whole system on from day one and let the data tell her what mattered. That approach surfaced things she didn’t expect, including how differently her own team members were each handling day to day processes. It led to real changes, like banning USB use once she could see exactly how and when it was being used. It also led to a principle she now recommends to every business owner watching: build a no fault culture. “You’ve got to bite your tongue and have a no fault policy,” she said. “You want people to come to you if something happens.”
Hand on Heart: Proving It, Not Just Saying It
The theme that ties Joanne’s whole approach together is evidence. Her insurer now sends detailed questionnaires before renewing cover, and instead of treating that as a compliance chore, she uses it as a yearly check on how mature her posture really is. When her auditors review the business, the system does much of that work automatically.
Joanne put it simply: “I don’t think I’m ever going to be 1,000% confident, and nor should we be, we always have to be vigilant.” The goal isn’t certainty. It’s being able to say, hand on heart, that you’ve done and are doing everything you possibly can.
Hear It From Joanne Herself
There’s a lot more in the full session that we couldn’t fit into this recap, including how Joanne got her team genuinely engaged rather than just compliant, what she’d tell a business owner still on the fence about where to start, and how a stronger security posture changed the conversation with her insurer.
A sincere thank you to Joanne and the Watertight Group team for being so open about a journey that’s still very much ongoing.
Watch the full webinar here:
To talk to GuardWare about a data discovery exercise or the GuardWare Assessor offer,
Related Blogs
Eight Agents, Four Days: AI Runs a Government Intrusion in Taiwan
Closer to Home: Origin Energy’s Breach Traced to a Manila Call Centre
284 Million Rows in Four Days: McKesson’s Cloud Warehouses Emptied
How an SME Built a Security Posture That Enterprise Clients Trust
What If Your Data Could Protect Itself? A Data-First Security Playbook
Payment Security Summit & Gala – Australia 2026
Do you know where your sensitive data is?
Stop your IP and Design files from being stolen?


