
Cyber security can feel like a problem built for big companies with big budgets, but the reality for Australian small and medium businesses is simpler and more urgent. Attackers rarely target you by name. They scan for the same handful of weaknesses across thousands of businesses at once, and small businesses get caught because the basics are missing. The good news is that the basics are affordable, well documented, and mostly within reach of any business owner. This guide pulls the whole picture together in plain English, and links to step-by-step help for each piece.
Think of it as a map. You do not need to do everything at once. Work through the areas below in roughly the order they appear, and you will close the doors attackers use most.
Why small businesses get targeted
A common myth is that a small business is too small to bother with. The opposite is true. Most attacks are automated and opportunistic: software scans the internet for known weaknesses, unpatched systems, exposed logins, and staff who can be tricked, then strikes wherever it finds an opening. A small business with the basics missing is an easier and more profitable target than a large enterprise with a security team.
Small businesses also feel the damage more sharply. A few days offline, a drained bank account, or a breach of customer data can be existential when there is no spare capacity to absorb it. That is the real reason the basics matter so much: they are cheap to put in place and they remove you from the easy-target list, which is where most of the harm happens.
Start with the ACSC Essential Eight
The Australian Signals Directorate and its Cyber Security Centre publish a baseline of eight controls that stop the most common attacks. If you do nothing else, do these. Our plain-English guide to the Essential Eight explains what each control is and why it matters, and the maturity levels guide helps you work out how far you actually need to go.
Several of the eight are things you can act on this week. Keeping software patched is one of the cheapest and most effective, as we explain in why software updates matter. The rest are about reducing what can run and who can do what: blocking Office macros, hardening web browsers, restricting admin privileges, and application control so only trusted software runs. For catching what slips through, it is worth understanding what EDR is and whether your business needs it.
Lock down logins with passwords and MFA
Stolen and guessed passwords are behind a huge share of business breaches, so this is the highest-value area after patching. The single best upgrade you can make is multi-factor authentication, which blocks the vast majority of account takeovers and costs almost nothing. Pair it with a business password manager so staff can use strong, unique passwords without sticky notes or spreadsheets.
As you grow, single sign-on makes logins both easier and safer by giving your team one secure identity across many apps. And when people leave, closing their access quickly is a step that is often forgotten, which is why offboarding staff securely deserves a proper process.
Make yourself ransomware-resilient with backups
Ransomware is the attack most likely to put a small business out of action, and the thing that saves you is a backup you can actually restore. Start with how ransomware works and how to prevent and recover from it, then build your safety net around the 3-2-1 backup rule.
Two traps catch people out. The first is assuming your cloud suite protects your data for you; it does not, which is why Microsoft 365 is not a backup. The second is never testing restores, so a backup turns out to be a guess when you need it most. Our 30-minute quarterly backup drill fixes that. And if the worst happens, a calm, hour-by-hour plan for your first 24 hours after a ransomware attack makes a real difference to the outcome.
Train your team against phishing and scams
Most breaches start with a person, not a machine. A convincing email is still the most common way in, so teaching your team to spot a phishing email pays off quickly. The costliest version for Australian businesses is business email compromise, where an attacker uses your own inboxes and invoice templates against you.
Watch especially for money-movement scams: payment redirection fraud and fake invoices can drain a payment in seconds, and newer tricks like QR code phishing get around the usual defences. On the technical side, setting up email authentication with SPF, DKIM and DMARC stops scammers spoofing your domain. For the bigger picture, see the top five ways small businesses get hacked.
Meet your privacy and compliance obligations
Security and privacy go hand in hand, and the rules are tightening. Get across the Privacy Act changes for Australian SMBs and know what to do under the Notifiable Data Breaches scheme if personal information is exposed. A big part of reducing risk is simply holding less data, which is what sensible data retention is about.
Your risk also extends to the tools and suppliers you connect to. Run a vendor security review before trusting a supplier with your data, keep an eye on shadow IT, the apps staff adopt without telling anyone, and set clear rules for using AI tools at work so customer information does not leak into a chatbot.
Cover remote work, and use the free help available
If your team works from home or on the move, the office boundary no longer protects you, so securing remote and hybrid work closes gaps that opened when work went flexible. And you do not have to pay for everything: there are excellent free ACSC resources every Australian business should use, from alerts to step-by-step guides.
A simple order to work in
If the list above feels like a lot, this is a sensible sequence for most small businesses:
- Turn on multi-factor authentication everywhere it is offered, starting with email.
- Get automatic updates running for operating systems and key apps.
- Set up backups to the 3-2-1 rule, then test that a restore actually works.
- Give your team a short phishing and scam briefing, and a clear way to report anything suspicious.
- Tighten admin access, review the apps and suppliers you rely on, and write down who does what if something goes wrong.
How to know where to start
Reading a map is one thing; knowing which turn to take first is another. The fastest way to find your own weak spots is to measure them. Our free self assessment asks 27 plain-English questions about how your business handles passwords, backups, devices and data, then gives you a personalised report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2, with clear next steps ranked by what to fix first.
Find out where you stand
You have the map. Now get your bearings. Take the free security assessment, it takes about 5 to 10 minutes and the PDF report is instant, and you will know exactly which of the areas above to tackle first.