A practical cyber security checklist for small businesses
Most small businesses in Bairnsdale and around East Gippsland don't have an IT person. Security tends to get done in bits, usually after something goes wrong. This checklist turns it into ten things you can tick off. It's practical rather than exhaustive, and most of it costs nothing but a bit of time.
Written by Adam CurtisPublished Last updated
Accounts and sign-ins
1. Turn on multi-factor authentication (MFA)
MFA means signing in needs your password plus a second step, such as a code or a tap in an app on your phone. Turn it on for email first, then banking, accounting software and anything holding customer details. A stolen password on its own then becomes far less useful.
2. Use unique passwords and a password manager
Reusing one password means one breach opens everything. A password manager remembers long, unique passwords so you and your staff don't have to. Where you do need to remember one, a long passphrase of several words is easier to type and harder to guess than a short, complicated password.
3. Keep admin accounts separate
Everyday work shouldn't happen in an account that can install software or change settings for everyone. Give each person their own login, keep admin rights to the people who actually need them, and remove access promptly when someone leaves. Shared logins make it impossible to tell who did what.
Devices and updates
4. Turn on automatic updates
Most attacks use known problems that updates have already fixed. Turn on automatic updates for Windows or macOS, your browser and your main business apps. If a computer or phone no longer receives security updates, plan to replace it.
5. Lock and encrypt every device
Every laptop, desktop and phone should have a screen lock and a PIN or password. Turn on device encryption, called BitLocker or Device Encryption on Windows and FileVault on a Mac, so a lost laptop doesn't mean lost customer data. On Windows, make sure the built-in Microsoft Defender protection is switched on.
6. Check your Wi-Fi and router
Change the router's default admin password if it hasn't been changed. If customers use your Wi-Fi, give them a separate guest network rather than the one your business computers use.
Data and email
7. Back up, and test the restore
Keep at least one copy of important data away from the office, such as a reputable cloud backup. Be aware that cloud sync isn't always a backup: if a file is deleted or encrypted by ransomware, the change can sync everywhere. Every few months, try restoring a file. A backup you've never tested is a hope, not a plan. Cloud and file support can help set this up.
8. Tighten email security
Email is where most small business attacks start. Beyond MFA, check for forwarding rules nobody remembers creating. If you use your own domain, make sure the email authentication records (SPF, DKIM and DMARC) are set up, which helps stop others sending email that pretends to be you. My email support and Microsoft 365 support pages cover what's involved.
People and process
9. Talk to your staff about scams
The most expensive scams I hear about don't involve hacking at all. Someone emails asking to change bank details, or an invoice looks slightly different. Agree a simple rule: any change to payment details is confirmed by phone, on a number you already have. Make it clear it's always fine to stop and ask.
10. Write down what to do if something goes wrong
A single page is enough: who to call, your bank's fraud number, where the backups are, and how to report through ReportCyber (opens in a new tab). When something happens, people panic. A short plan saves time when it matters.
Where to start if this feels like a lot
Start with number 1 and number 7. MFA on email and a tested backup protect you against the two things that hurt small businesses most: account takeover and losing data.
Then work through the rest over a few weeks. None of it needs to happen in one go. The Australian Cyber Security Centre's guidance for small businesses (opens in a new tab) goes into more depth if you want it.
If you'd rather have someone review it with you, the small business security check is a fixed price from $495 for up to 5 people. I look at your accounts, email security, backups and device updates, then give you a plain English report of what to fix first. Details are on my computer security help page, and ongoing help is covered by small business computer support.
Common questions
What's the most important security step for a small business?
For most small businesses, turning on multi-factor authentication for email. Email is where password resets go and where invoice scams start. MFA means a stolen password alone isn't enough to get in.
Is OneDrive, Google Drive or Dropbox a backup?
Not on its own. Sync services copy changes everywhere, including deletions and files damaged by ransomware. Some keep previous versions for a while, which helps, but a separate backup you've tested restoring from is safer.
What does the small business security check cover?
It reviews your accounts, email security, backups and device updates, then gives you a plain English report of what to fix first. It's a fixed price from $495 for up to 5 people and is done remotely.
Do I need to buy expensive security software?
Usually not to start with. Built-in protection, automatic updates, MFA, unique passwords and tested backups cover a lot of ground for a small team. Specialised tools can make sense later, depending on your industry and the data you hold.