Cyber security basics every Australian small business can do this week
Cyber attacks are rising, but you don't need a big budget to fight back. Here is your plain-English guide to securing your small business this week.
By ECTD Editorial · Published 2026-06-11 · Updated 2026-06-11
It is 6:00 PM on a Friday. You lock the shop door, check the alarm, and head home. But did you lock the digital back door? For many Australian small businesses, the greatest theft risk is not a broken window; it is a compromised email account. Cybercriminals do not just target big corporations anymore; they target the local plumber, the marketing agency, and the corner store because they know small operations often lack the time or budget for complex IT security. The good news is that the most effective protections are often the cheapest and easiest to implement.
Your Email Account is the Keys to the Kingdom
If a criminal gains access to your business email inbox, they effectively own your business. This is not just about reading your private messages; it is about the authority your email address carries. Your email is likely linked to your banking, your super fund, your Australian Taxation Office (ATO) portals, and your client relationships. Once inside, a hacker can reset passwords for other services, impersonate you to suppliers, and send fraudulent invoices to your customers.
The most common way attackers get in is through brute-force attacks, where they guess simple passwords, or phishing, where they trick you into handing over your credentials. Once they have control, they often set up forwarding rules so they can monitor your correspondence without you noticing. They might wait weeks for the perfect moment—like a large invoice payment—to strike. Securing this single point of access is the most critical step you can take.
Watch out for 'logged in elsewhere': Most email providers (like Gmail, Outlook, or Hosted Exchange) allow you to view 'active sessions'. If you see a login from a country you have never visited or a device you do not own, change your password immediately and log that session out.
Turn on Multi-Factor Authentication (But Not Just SMS)
Multi-factor authentication (MFA), often called two-factor authentication (2FA), adds a second layer of security. It means you need your password plus a code sent to your phone or generated by an app to log in. According to the Australian Cyber Security Centre (ACSC), MFA is one of the most effective measures to stop cyber attacks. Even if a hacker has your password, they cannot get in without the second factor.
However, not all MFA is created equal. The weakest form is SMS-based verification. While better than nothing, SMS codes can be intercepted by sophisticated attackers exploiting vulnerabilities in the mobile phone network (SIM swapping). A stronger, and often free, alternative is using an <strong>Authenticator App</strong> (like Microsoft Authenticator, Google Authenticator, or Authy). These apps generate codes that change every 30 seconds and are not sent over the network.
- Go to the security settings of your email, banking, and cloud storage.
- Enable 2FA/MFA.
- Choose 'Authenticator App' over 'SMS' if the option is available.
- Cost: Free.
Password Managers: Stop Writing Them on Sticky Notes
The average Australian has dozens of online accounts. The natural temptation is to reuse the same password or to write them down on a note stuck to the monitor. Both are security disasters. If one site gets breached and you reuse that password, hackers will try it on your bank, your email, and your accounting software.
A password manager solves this by generating long, complex, unique passwords for every site you use. You only need to remember one single, very strong 'master password' to unlock the vault. Many password managers also allow you to share passwords securely with staff without ever revealing the characters to them.
For a small business, the cost is negligible. <strong>Bitwarden</strong> offers a strong free tier for personal use and very affordable plans for business teams (around $6 AUD per user per month). <strong>1Password</strong> and <strong>LastPass</strong> are other popular alternatives. The small monthly fee is a fraction of the cost of a data breach.
Passphrases are better than passwords: If you struggle to remember passwords, use a passphrase. 'Horse-Battery-Staple-Correct' is much harder for a computer to crack than 'Tr0ub4dor&3' and easier for you to remember.
Spotting Invoice Fraud and Business Email Compromise
Business Email Compromise (BEC) is a scam where a criminal impersonates a business executive or a supplier. A common scenario involves a hacker compromising a builder's email account. They watch the inbox for an upcoming invoice from a timber supplier. Just before the real invoice arrives, the hacker sends a fake email to the builder saying, 'Sorry, our bank details have changed, please pay the attached invoice to this new account.'
The builder, trusting the email comes from their supplier, transfers $30,000 to the fraudulent account. By the time the real supplier calls asking for payment, the money is usually gone, transferred overseas and unrecoverable. This pattern is rampant in Australia, targeting real estate agents, accountants, and tradespeople.
- Always verify a change of bank details using a <strong>different communication channel</strong>. If the request comes via email, call the supplier on a phone number you have used before (not the one in the suspicious email).
- Check the email address carefully. Scammers often use slight misspellings, like 'mycompany@qantas.com' instead of 'qantas.com.au'.
- Implement a internal policy: No payments to new accounts without verbal confirmation from a senior manager.
The 3-2-1 Backup Strategy Explained
Ransomware is a type of malware that locks your files and demands payment to unlock them. If you do not have backups, you lose your data. The 3-2-1 strategy is the gold standard recommended by experts globally to protect against this.
The rule is simple: keep <strong>3</strong> copies of your data, on <strong>2</strong> different types of media, with <strong>1</strong> copy stored offsite (usually in the cloud). For example, you might have your work files on your computer (1), backed up to an external hard drive in your office (2), and also synced to a cloud service like Google Drive or Dropbox (3).
Crucially, if you use a cloud backup, ensure it supports 'versioning'. This means if a file gets encrypted by ransomware, the cloud service keeps a copy of the file from before the attack so you can restore it. Cloud storage is incredibly affordable now; you can get 200GB of storage from Google One or Microsoft OneDrive for around $3 AUD per month.
Software Updates: The Digital Maintenance
We have all seen the prompt to 'Update and Restart' on our computers or phones. It is tempting to click 'Remind me tomorrow', but delaying updates is a security risk. Software updates are not just about adding new features or changing the interface; they often contain critical security patches that fix holes hackers could use to get in.
This applies to your operating system (Windows or macOS), your web browser (Chrome, Edge, Safari), and your applications like accounting software (MYOB, Xero). Attackers actively scan the internet for computers running outdated software because they know exactly which vulnerabilities to exploit.
- Turn on 'Automatic Updates' for your operating system and browser.
- Update your smartphone apps regularly.
- If you are still using Windows 7, 8.1, or 10, you are at high risk. Microsoft ended support for Windows 7 and 8.1 in 2023, and Windows 10 reaches end of life in October 2025. Upgrade to Windows 11 immediately.
Training Staff to Spot Phishing
Your staff are your first line of defence, but they can also be your weakest link. Phishing emails have become sophisticated. They no longer just feature poor grammar and a prince asking for money. They look like legitimate delivery notifications from Australia Post, urgent requests from the ATO, or internal HR documents.
Training does not have to be expensive or formal. It starts with a conversation. Teach your team to be sceptical. Tell them to look at the sender's email address, not just the display name. Encourage them to hover their mouse over links before clicking to see the actual destination URL. If an email creates a sense of urgency—'Pay this now or you will be arrested'—that is a major red flag.
The 'Hover' trick: Without clicking, hover your mouse cursor over a link in an email. A small box will appear showing the actual web address. If it says 'anz.com' in the text but points to 'anz-secure-login.xyz', it is a scam.
The ACSC Essential Eight in Plain English
The Australian Signals Directorate (ASD), part of the ACSC, publishes the 'Essential Eight' mitigation strategies. These are eight technical strategies designed to stop cyber attacks. While the full technical implementation can be complex for a small business, the core principles are straightforward.
In plain English, the Essential Eight asks you to: use applications that are supported by vendors (so you get updates); patch your software (security updates); restrict the use of Microsoft Office macros (a common way malware spreads); restrict admin privileges (don't let everyone install whatever they want); use MFA (discussed above); perform daily backups; and restrict web access to only necessary sites.
You do not need to implement all eight perfectly tomorrow. However, understanding this framework helps you prioritise. If you are doing nothing, start with MFA, patching, and backups. Those three cover the majority of risks for a small business.
Where to Get Help: cyber.gov.au and IDCARE
You are not alone in this. The Australian Government provides free resources specifically for businesses. The <strong>ACSC's cyber.gov.au</strong> website has a 'Small Business Cyber Security Guide' that is worth downloading. It offers checklists and templates you can use right now.
If the worst happens and you or your business falls victim to a scam or identity theft, <strong>IDCARE</strong> is Australia's national identity and cyber support service. They can help you formulate a response plan to limit the damage. It is a free service for individuals and small businesses.
What to do this week
Improving your cyber security does not require an IT consultant or a massive budget. It requires action. Here is a simple 7-day checklist to get your house in order.
- <strong>Day 1:</strong> Change your email password to a 12-character passphrase and turn on an Authenticator App for MFA.
- <strong>Day 2:</strong> Install a password manager and move your most critical passwords (banking, email) into it.
- <strong>Day 3:</strong> Check your computer and phone for software updates and install them immediately.
- <strong>Day 4:</strong> Set up an automatic cloud backup for your key business documents (e.g., Desktop and Documents folders).
- <strong>Day 5:</strong> Talk to your staff (or family) about phishing. Show them how to hover over links to check them.
- <strong>Day 6:</strong> Review your bank's procedures for paying new suppliers. Add a rule to call and verify details.
- <strong>Day 7:</strong> Visit cyber.gov.au and download the Small Business Cyber Security Guide to see what you missed.
<em>This information is general in nature and does not take into account your personal or business situation. For specific technical advice, consult a qualified IT professional.</em>
General information only — not personal financial, tax, legal or medical advice. Consider your own situation and consult a licensed professional before acting. Figures are current as at the date shown above.