Skip to content
Operations HubIT & Cybersecurity

Cybersecurity Basics Every Small Business Needs to Get Right

If you're running a small or medium business in Australia, there's a good chance technology and security isn't the part of your day you look forward to.

By Andrew Northcott·18 March 2026·5 min read·Last reviewed 8 July 2026

The short answer

The cybersecurity basics most Australian small businesses need are straightforward: turn on multi-factor authentication everywhere, keep software and devices patched, use strong unique passwords with a manager, back up your data and test that backups restore, and train staff to spot phishing. Restrict administrative access and know your obligations under the Privacy Act and Notifiable Data Breaches scheme. The ACSC Essential Eight offers a practical framework to build on. None of it requires becoming an IT expert.

Cybersecurity for a small business isn't about buying the most expensive tool or turning your office into a fortress. It's about closing the handful of doors that attackers actually walk through, and doing so in a way your team will actually stick to. Most breaches in businesses your size aren't clever hacks; they're a reused password, an unpatched laptop, or someone clicking a convincing invoice.

Start with the ASD Essential Eight

The Australian Signals Directorate publishes a set of eight mitigation strategies known as the Essential Eight, and it's the most useful free framework an Australian SME can anchor to. You don't need to implement all eight to a high maturity overnight; the value is in having a checklist that experts agree matters. The eight are: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.

Read them as a priority order for attention, not a shopping list. If you only had a fortnight, you'd get multi-factor authentication on, make sure patching is happening automatically, and confirm your backups actually restore. Those three alone remove a large share of your real-world risk.

Turn on multi-factor authentication everywhere

Passwords get reused, phished, and leaked in breaches you'll never hear about. Multi-factor authentication (MFA) means that even a correct password isn't enough on its own. Turn it on for email first, because email is the master key that resets every other account. Then your accounting software, your banking, your payroll, and any admin logins.

Prefer an authenticator app over SMS codes where you have the choice, since SMS can be intercepted or diverted through a SIM swap. Make MFA a condition of joining the business, not an optional extra people can defer.

Patch, and let it happen automatically

Unpatched software is the equivalent of a known-broken lock that the manufacturer has already published the fix for. Attackers scan for exactly these gaps. Set operating systems, browsers, and business applications to update automatically, and don't leave old, unused software installed — it's an open door nobody's watching. This includes the router and any network hardware, which people routinely forget for years.

Get backups right — and test the restore

Ransomware is the threat backups defend against, and the detail that catches people out is that a backup only counts if you can actually restore from it. Keep at least one copy offline or otherwise isolated, so that if malware encrypts your live systems it can't reach the backup too. Then, at a sensible interval, do a real test restore of a file or two. An untested backup is a hope, not a plan.

Train the humans — they're the real perimeter

The most common way money leaves a small business isn't a technical breach at all. It's business email compromise: someone impersonates a supplier or a director and asks for a payment or a change of bank details. The defence is a simple, non-negotiable rule that any change to payment details is verified by phoning a known number — never the number in the email. Teach your team to slow down when a message creates urgency, and make it safe to say "that looked odd, I checked."

Alongside that, cover phishing basics, the danger of reused passwords (a password manager solves this cheaply), and what to do the moment someone thinks they've clicked something they shouldn't have. Speed of reporting is often what limits the damage.

Know your obligations and have a plan for the bad day

If you handle personal information, you may have obligations under Australia's Notifiable Data Breaches scheme to report certain breaches to the Office of the Australian Information Commissioner and to affected people. Write down, in advance, who you call and what you do if you suspect a breach — the middle of an incident is the worst time to be inventing a process. Keep the plan short enough that someone will actually follow it.

Cybersecurity sits squarely in your operations function, and it's one of those areas where a small amount of consistent discipline beats a large one-off spend. Get MFA, patching, backups, and staff awareness right, and you've addressed most of what actually goes wrong. This is general information and not a substitute for advice specific to your systems and risk profile.

About the author

Andrew Northcott

Founder & Chairman, Valont

Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.

LinkedIn →

Want to know where your business stands?

Take our free Business Health Check — it takes 5 minutes and gives you a clear picture across finance, people, operations, and growth.