Australian small businesses should start with multi-factor authentication, tested backups, timely updates, invoice verification, access reviews and a written incident plan. Check these six controls first, then prioritise improvements around your business risks.
The useful version is shorter, because the attacks that actually hit Australian small businesses are mostly unglamorous: someone’s password is reused and gets stuffed into a login page, an invoice gets intercepted and the bank account details changed, a laptop walks out of a car, or ransomware arrives and the backups turn out not to work.
These six controls help reduce those risks. Start with the gaps that affect your business.
1. Multi-factor authentication, everywhere it matters
If you do one thing, do this. Password-only accounts are the way most small business compromises start, because credentials leak from unrelated services and get reused.
Turn MFA on for email first — email is the master key, since it resets everything else — then remote access, then banking and accounting, then anything storing customer data.
Two practical notes. App-based codes or hardware keys are meaningfully stronger than SMS, which can be intercepted. And record who holds the recovery methods for each account: MFA that is registered solely to a staff member who has left is a lockout waiting to happen.
2. Backups you have actually restored
Nearly everyone has backups. Considerably fewer have restores.
A backup is only real if you have taken a file out of it, recently, and opened it. Until then it is an assumption with a monthly cost.
Three questions worth answering honestly:
- How far back does it go? Ransomware often sits quietly before triggering. A single recent copy may already be encrypted.
- Is one copy out of reach? Backups reachable from a compromised admin account get encrypted along with everything else. Offline or immutable copies are what survive.
- How long would a full restore take? Not the copy — the restore, including reconfiguring what sits on top of it. That number is your actual worst case.
Test a restore this quarter. Write down what it took.
3. Patching that includes the forgotten things
Servers and laptops usually get updated. What gets missed are the appliances: the firewall, the router, the NAS, the door controller, the CCTV recorder. These are internet-facing, rarely rebooted, and often running firmware from several years ago.
Make a list of everything with an IP address and an administrative login. Check what firmware each is on and whether it is still supported by its vendor. Anything past end-of-life is not going to be patched, and needs a replacement plan rather than a reminder.
4. Locking down the invoice path
Invoice fraud is the attack most likely to cost an Australian small business real money this year, and it is not technically sophisticated. An attacker gets into a mailbox — yours or a supplier’s — watches for an invoice, and sends a near-identical one with different bank details.
Two controls help reduce the risk:
- Verify any change of bank account by voice, on a number you already had, never a number from the email requesting the change.
- Require a second person to approve new payees and account changes above a threshold you set.
This is a process control, not a product. It costs nothing and it is the single highest return on effort in this list.
5. Knowing who has access to what
Access accumulates. People change roles and keep old permissions, contractors keep accounts after projects finish, and shared logins outlive the reason they existed.
Once or twice a year, list every account with administrative rights and every account that can reach customer data, and confirm each one still needs it. Remove the rest.
Pay particular attention to accounts belonging to people who have left, and to any login shared between several staff — shared accounts make it impossible to tell who did what, which matters most on the day you need to find out.
6. A written plan for the bad day
Not a policy document. One page, printed, that answers: who do we ring, in what order, what do we stop doing immediately, and where is the contact list if email is down.
Include your IT support, your bank, your insurer if you hold cyber cover, and the relevant reporting channels. In Australia, use the Australian Cyber Security Centre’s ReportCyber service for cybercrime reporting and Scamwatch for scam reports and guidance. Contact your bank promptly if payments or bank details may be affected.
The reason to write it down is that the day you need it, someone will be panicking and the usual systems may be unavailable.
How to tell whether yours are working
You are in reasonable shape if you can answer these without checking:
- Is MFA on for every email account, including the shared ones?
- When did we last restore a file from backup, and did it open?
- What is the oldest firmware on anything facing the internet?
- What happens when a supplier emails new bank details?
- Who has admin rights, and does each still need them?
- Where is the incident contact list if email is down?
Any you cannot answer is a place to start. That is usually more useful than a full audit, because it produces a short list of specific, fixable things rather than a report.
If you would rather have that assessed properly, Bestcomm’s approach is to review identities, devices, networks, data and recovery controls, then rank what we find by operational impact rather than by severity score. Call +61 3 8080 8914 to arrange it.
If you think you have an incident right now, use the urgent support route rather than a web form, and do not send passwords, one-time codes or incident detail through the website.
This article is general guidance. The right approach for your business depends on your current environment, obligations and risk. Scope and inclusions are confirmed during discovery. Call +61 3 8080 8914 to talk it through.
