Cybersecurity for Small Business: 8 Things That Stop Attacks
Eight habits stop the overwhelming majority of attacks on a small business: multi-factor authentication, a password manager, automatic updates, tested backups, recognising the invoice scam, not working from an administrator account, encrypted devices, and cutting off access the day someone leaves. None of that needs an IT department, and most of it is free or costs a few dollars a month. Here's how to do all eight, in the order that buys you the most protection for the least effort.
Why small businesses get hit
Not because you're interesting. Because you're reachable, you pay invoices, and nobody in your business has "security" in their job description.
The numbers back that up. The Australian Signals Directorate received over 84,700 cybercrime reports in 2024-25 — one every six minutes — and the average self-reported cost per report for a small business rose 14% to $56,600 (Annual Cyber Threat Report 2024-25). On the scam side, Scamwatch logged 65,361 phishing reports in the 2025 calendar year, roughly 179 a day, and payment redirection scams alone cost Australians $166.8 million, second only to investment scams (ACCC National Anti-Scam Centre, published March 2026).
Almost none of that is sophisticated. It's a stolen password, an unpatched laptop, or an email that looked like it came from your supplier.
1. Turn on MFA — starting with email
Multi-factor authentication means a password plus a second check: a code from an app, a prompt on your phone, or a passkey. It's the single highest-value thing on this list, because a stolen password on its own stops being useful.
Do it in this order:
- Email. Whoever controls your email can reset the password on everything else. This is the master key.
- Accounting software — Xero, MYOB, QuickBooks. Payroll and bank feeds live here.
- Business banking, including any secondary card or payment platform.
- myID, which is how you sign in to ATO Online services for business. Set it to Strong identity strength if you can.
- Domain name registrar and website host. Losing your domain is a bad week.
- Social accounts and your Google Business Profile.
Use an authenticator app or passkeys rather than SMS codes where you can — SIM swapping is real. And enrol a backup method, or your first lost phone locks you out of your own business.
2. Put every password in a password manager
The shared spreadsheet of logins, the sticky note under the till and "Business2024!" reused across nine sites are all the same problem: one leak compromises everything.
A password manager generates a different long password for every account, fills them in for you, and lets you share a login with a staff member without telling them the password. Business plans typically cost a few dollars per user per month; the free tiers are genuinely fine for a sole trader.
The practical win isn't the encryption — it's that when someone leaves, you rotate one shared vault instead of chasing forty accounts. Worth a line in your software stack.
3. Switch on automatic updates and leave them on
Patching applications and operating systems are two of the eight strategies in the ASD's Essential Eight, and they are the two easiest to automate. Attackers use published vulnerabilities in software people haven't updated — the fix already exists, it just isn't installed.
Turn automatic updates on for: laptops and desktops, phones and tablets, browsers, your accounting and POS software, your website's platform and plugins, and your router. Routers are the forgotten one: if yours no longer gets firmware updates, replace it.
Schedule restarts for a time you're closed. The update that never applies because the machine is never restarted isn't an update.
4. Back up 3-2-1 — and test a restore
The 3-2-1 rule: three copies of your data, on two different types of storage, with one kept off-site or offline.
Cloud sync isn't a backup. If ransomware encrypts your files or someone deletes a folder, OneDrive, Dropbox and Google Drive will faithfully sync the damage. What you want is versioned backup you can roll back, plus something disconnected — an external drive that lives at home and stays unplugged.
Then test it. Once a quarter, restore a file and a folder. A backup you've never restored from is a hope, not a plan.
5. Learn the invoice redirection scam
This is the one that empties bank accounts. Someone gets into an email account — often a supplier's, not yours — watches the conversation, then sends a real-looking invoice with changed bank details. Or emails "the boss" asking a bookkeeper to pay something urgently while they're in a meeting.
The rule that stops all of them: verify any change of bank details by phone, on a number you already had, before you pay. Not the number on the invoice. Write it down, tell everyone who can move money, and make sure nobody gets in trouble for delaying a payment to check. The other scams aimed at businesses — fake ATO and ASIC notices, false billing, overpayment refunds — and what to do in the first hour if you've already paid are covered in our guide to scams targeting small businesses.
Worked example. A three-person cabinet maker pays an $18,400 supplier invoice into a scammer's account. A password manager and MFA across the team, budgeting $5 per user per month, costs 3 × $5 × 12 = $180 a year. That single loss is worth more than a century of subscription fees — $18,400 ÷ $180 = 102 years. And unlike a late invoice, there's no escalation ladder to climb: the payment left the account with your own authorisation, so recovery depends entirely on how fast the bank can recall it.
6. Stop working from an administrator account
On a Windows or Mac laptop, the account you use all day should be a standard user, with a separate administrator account you switch to only when installing something. It's a five-minute change that stops a lot of malware cold.
The same logic applies inside your business apps. Not everyone needs adviser-level access in Xero, admin rights on the POS, or the ability to change bank details in payroll. Give people the least access that lets them do their job, and review it when roles change.
7. Encrypt devices and lock screens
For most small businesses, the likeliest "data breach" isn't a hacker — it's a laptop stolen from a ute or a phone left in a cafe.
- Turn on BitLocker (Windows Pro) or FileVault (Mac). Both are built in and free.
- Set a passcode plus biometrics on every phone, and auto-lock after a minute or two.
- Enable Find My Device so you can wipe remotely.
- Don't leave customer data on USB sticks.
An encrypted, wiped device is a lost asset. An unencrypted one is a privacy problem, and possibly a notification obligation — see your privacy policy obligations.
8. Offboard people the day they leave
Build a leaving checklist that mirrors your onboarding checklist and run it on the last day, not next month:
- Disable the email account (don't delete it — forward or archive it first)
- Remove them from accounting, payroll, POS and the CRM
- Rotate every shared password in the vault
- Remove them as an admin from social accounts and the Google Business Profile
- Collect devices, keys and fobs; deauthorise their phone from work apps
- Check the mailbox for forwarding rules — attackers and departing staff both leave them behind
The eight at a glance
| Step | Time to set up | Cost |
|---|---|---|
| MFA on key accounts | 1 hour | Free |
| Password manager | 1-2 hours | Free to a few dollars per user a month |
| Automatic updates | 30 minutes | Free |
| 3-2-1 backups | 2 hours, then quarterly tests | Drive plus cloud subscription |
| Invoice-scam rule | 15 minutes | Free |
| Standard user accounts | 30 minutes | Free |
| Device encryption | 20 minutes per device | Free |
| Offboarding checklist | 30 minutes to write | Free |
Free help that's actually worth using
The ASD's Australian Cyber Security Centre publishes a Small Business Cyber Security Guide and a set of small business cloud security guides at cyber.gov.au, written for people without IT staff. Cyber Wardens, a government-funded program run by the Council of Small Business Organisations Australia, offers free courses in 10 to 45 minute chunks, aimed at staff as much as owners.
The Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371) is staffed 24 hours a day and answered more than 42,500 calls in 2024-25 — about 116 a day.
Is cyber insurance worth it?
Quote it if a breach would stop you trading, or if you hold customer payment details or health information. The valuable part usually isn't the payout — it's access to an incident response team who have done this before, plus cover for forensics, data restoration and business interruption.
Read the conditions: policies increasingly require MFA, current software and working backups, and an insurer can decline a claim where those weren't in place. It sits alongside, not instead of, your business insurance.
What to do in the first hour
- Call your bank if money has moved. Recovery chances drop by the hour.
- Change passwords from a device you trust, starting with email, and sign out all active sessions.
- Check mailbox rules for auto-forwarding or filters you didn't create.
- Report it through ReportCyber at cyber.gov.au, and to Scamwatch if it was a scam.
- Call 1300 CYBER1 for advice on containing it.
- Work out whether you have to notify. The Notifiable Data Breaches scheme gives covered entities 30 days to assess a suspected breach. Most businesses under $3 million turnover are exempt, but not if you hold health information, trade in personal information, or are a credit provider or TFN recipient (as at September 2026).
- Tell affected customers promptly and plainly, even where you're not legally required to.
Key takeaways
- MFA on email is the highest-value security step you can take, and it's free — do it before anything else on this list.
- Small business cybercrime reports averaged $56,600 each in 2024-25, and payment redirection scams cost Australians $166.8 million in 2025.
- Cloud sync isn't a backup; you need versioned copies plus something offline, and a restore you've actually tested.
- Verify every change of bank details by phone on a number you already had — that one rule stops the most expensive attack small businesses face.
- Run an offboarding checklist on someone's last day, including rotating shared passwords and checking for mailbox forwarding rules.
- Cyber insurance is worth quoting, but most policies now require MFA and patching before they'll pay.
Where to get help
- cyber.gov.au — the ASD's Small Business Cyber Security Guide, the cloud security guides, the Essential Eight, and ReportCyber for reporting incidents.
- Australian Cyber Security Hotline — 1300 CYBER1 (1300 292 371), 24 hours a day.
- Scamwatch (scamwatch.gov.au) — report scams and subscribe to alerts about current ones.
- Cyber Wardens (cyberwardens.com.au) — free short cyber security courses for small business owners and staff.
- OAIC (oaic.gov.au) — guidance on the Notifiable Data Breaches scheme and whether it covers you.
- Your bank — for a suspected fraudulent payment, and for the fraud controls they offer on business accounts.
- Your accountant or bookkeeper — for payment approval processes, and your IT provider or an insurance broker for anything beyond the basics above.
Frequently asked questions
What are the most important cyber security steps for a small business?
Turn on multi-factor authentication for your email account first, then your accounting software and business banking. Email is the master key to everything else, and MFA blocks the single most common way small businesses get compromised. After that: a password manager, automatic updates, and a backup you've actually tested.
How much does a cyber attack cost an Australian small business?
The average self-reported cost of cybercrime per report for a small business was $56,600 in 2024-25, up 14% on the year before, according to the Australian Signals Directorate's Annual Cyber Threat Report 2024-25. That's a self-reported average, so plenty of incidents cost far less and some cost far more.
What is the Essential Eight and does a small business need all of it?
The Essential Eight is the Australian Signals Directorate's list of the eight mitigation strategies that stop the most attacks: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. A two-person business won't implement all eight properly, and that's fine — start with MFA, patching and backups, which cover most of the real-world risk.
Do I need cyber insurance for my small business?
It's worth quoting if a breach would stop you trading or if you hold customer payment or health data, because the useful part is the incident response team, not the payout. Read the conditions before you buy — many policies require MFA and up-to-date software, and will decline a claim if you didn't have them.
Who do I report a cyber attack or scam to in Australia?
Report cybercrime through ReportCyber at cyber.gov.au, and report scams to Scamwatch at scamwatch.gov.au. If money has moved, call your bank first — right now, before you report anything — because the only real chance of recovery is in the first few hours. The Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371) is staffed 24 hours a day.
General information only. This guide doesn't take your personal or business circumstances into account and isn't financial, legal or tax advice. Rates and thresholds change — check the official sources linked in this guide and get qualified advice where your circumstances require it.