Cyber criminals don’t care how big your business is. They care whether they can get in, and whether there’s anything worth taking once they’re inside.

For most small and mid-sized businesses, the answer to both is yes. The Australian Cyber Security Centre reports that small businesses are now the most common target of cyber attacks in the country. The average cost of a cyber incident to an Australian small business now sits in the tens of thousands of dollars, and many businesses that suffer a serious breach don’t recover.

The good news is that the steps to dramatically improve your security are well known and well within reach. You don’t need an enterprise budget. You need a clear plan and the discipline to follow it.

Understand what you’re actually protecting against

The threats that target small businesses most often aren’t the dramatic, high-profile attacks you see in the news. They’re far more mundane and far more common.

  • Phishing — Emails that trick staff into clicking a malicious link or entering credentials on a fake login page. The single most common way businesses get compromised.
  • Business email compromise (BEC) — Criminals gain access to a business email account and use it to impersonate a director or supplier, often to redirect a payment.
  • Ransomware — Malicious software that encrypts your files and demands payment for the key.
  • Credential theft — Staff passwords leaked in a breach somewhere else and reused on your business systems.
  • Insider mistakes — Accidental data loss, incorrect access permissions, or files shared with the wrong people.

Almost every successful attack on a small business uses one of these methods. All of them can be prevented with a sensible set of controls.

1. Turn on multi-factor authentication everywhere

If you only do one thing on this list, do this.

Multi-factor authentication (MFA) requires a second piece of evidence in addition to a password, usually a code from an app on your phone, before granting access to an account. It is the single most effective defence against credential theft and account takeover.

Microsoft has reported that MFA blocks more than 99% of automated attacks on accounts.

Turn it on for:

  • Microsoft 365 or Google Workspace
  • Online banking
  • Accounting software
  • Cloud storage
  • Any system that stores customer data

If your provider doesn’t support MFA in 2026, find a different provider.

2. Use a password manager and stop reusing passwords

Most data breaches happen because the same password was used across multiple services. When one gets breached, the password ends up on the dark web, and attackers try it on every other system.

A password manager generates a unique, strong password for every account, stores them securely, and fills them in automatically. Staff don’t need to remember anything except one master password.

Recommended business password managers include 1Password and Bitwarden, both of which offer affordable business plans.

3. Keep software up to date, automatically

Most successful attacks exploit known vulnerabilities in software that should have been patched months or even years earlier.

This includes:

  • Operating systems (Windows, macOS, iOS, Android)
  • Web browsers
  • Microsoft 365 and other applications
  • Antivirus and security tools like Bitdefender
  • Network equipment and firewalls

Automate updates wherever possible, and use a patch management tool to ensure nothing gets missed. A managed IT provider will handle this as part of their core service.

4. Back up your data, and test the backups

Backups are your insurance policy against ransomware, accidental deletion, hardware failure, and almost every other disaster. But a backup is only useful if it’s actually working.

A good backup strategy follows the 3-2-1 principle:

  • Three copies of your data
  • On two different types of media or platforms
  • With at least one copy stored off-site or in the cloud

If you can’t restore a file from your backup, you don’t have a backup.

Test your backups regularly. Restore a file from last week, last month, and last year, and make sure each one comes back cleanly. Tools like Veeam make this process automated and verifiable, with local copies stored on a Synology NAS and offsite copies sent to Wasabi cloud storage.

A note on Microsoft 365 and Google Workspace: these platforms do not back up your data the way most people assume. They protect against their own infrastructure failing, not against accidental deletion or ransomware. A separate cloud backup tool is essential.

5. Train your staff to recognise threats

Technology can stop a lot of attacks, but it can’t stop a staff member from clicking a convincing phishing email and entering their password into a fake login page.

Run regular cyber security training. Cover what phishing looks like, how to verify suspicious emails, what to do if you make a mistake, and how to report concerns. Repeat the training every six months. Test staff with simulated phishing exercises so they can practise spotting attacks in a safe environment.

Staff who feel comfortable reporting mistakes catch problems faster. Punish silence, not honesty.

6. Lock down email with proper filtering

Most attacks arrive by email. A properly configured email filter blocks the vast majority of phishing, malware, and spam before it ever reaches a staff member’s inbox.

The basic email security in Microsoft 365 and Google Workspace is reasonable, but every business should also enable:

  • SPF, DKIM, and DMARC records on their domain to prevent email spoofing
  • Advanced threat protection to catch malicious links and attachments
  • External sender warnings to flag emails from outside the organisation
  • Anti-impersonation rules to detect attempts to spoof your CEO or finance team

7. Limit who has admin access

The fewer people who have administrator access to your systems, the smaller the damage when an account is compromised.

Review who has admin access in Microsoft 365, your network, your accounting system, and any other critical platform. Reduce the list to the smallest possible number of people who genuinely need it. Use separate admin accounts for administrative work, kept apart from day-to-day email and browsing.

8. Have a plan for when something goes wrong

Even with good controls in place, no business is 100% secure. The difference between a minor incident and a business-ending disaster usually comes down to how prepared you were to respond.

A simple incident response plan covers:

  • Who to call when something is suspected
  • How to contain the damage
  • How to communicate with staff, clients, and stakeholders
  • How to recover from backups and rebuild

It doesn’t need to be complicated. It just needs to exist before you need it.

9. Get an outside review

Every business has blind spots. An external security review looks at your systems with fresh eyes and identifies the highest-priority risks.

A good review will check your accounts, your devices, your backups, your email security, and your staff awareness, and produce a clear list of what to fix first. It’s the fastest way to know where you stand. See how we approached this for Camden Haven Medical, where a full security and infrastructure overhaul was delivered without a single day of downtime.

Where to start

If your business hasn’t done any of this, the list can feel overwhelming. Start with the highest-impact actions first:

  1. Turn on multi-factor authentication on every account.
  2. Set up a password manager.
  3. Make sure backups are running and tested.
  4. Run a phishing awareness session with your team.
  5. Get an external security review to identify the rest.

Steps 1 to 4 can be done in a single week. Step 5 will tell you what to focus on next.

Cyber security is not a project you finish. It is a discipline you maintain. The businesses that take it seriously now will be the ones still standing in five years. If you are not sure where your business stands, a security review is the fastest way to find out.

Need a hand putting these protections in place? We set up and manage cyber security for businesses through our IT support in Armidale and IT support in Tamworth.