ArchZen Insight
7 Cyber Security Basics Every Australian Small Business Should Have in Place
Cyber security does not need to be complicated. Here are seven practical controls Australian small businesses can put in place to reduce common cyber risks and better protect their people, systems and data.
ArchZen
IT. Security.
AI & Automation.
Insight
What you need to know
Cyber security is often treated as something only larger organisations need to worry about. But smaller businesses also rely heavily on email, cloud applications, laptops, mobile devices and online banking.
A single compromised account or device can interrupt operations, expose sensitive information or lead to financial loss.
The good news is that improving security does not always require expensive or complicated technology. A strong starting point is getting the fundamentals right.
1. Use multi-factor authentication
Passwords alone should not be the only protection for important business accounts.
Multi-factor authentication (MFA) adds another verification step when someone signs in. Prioritise email, Microsoft 365 or Google Workspace, accounting platforms, cloud applications and administrator accounts.
2. Keep devices and applications updated
Operating systems, browsers and business applications should receive security updates regularly.
Updates often fix known vulnerabilities that could otherwise be exploited.
3. Protect business devices
Business laptops and desktops should have appropriate endpoint security, firewall protection and secure configurations.
Businesses should also understand which devices are accessing company information, particularly when employees or contractors use personal devices.
4. Back up important business information
A backup is only useful if the information can actually be recovered.
Important files, cloud data and business systems should have appropriate backup arrangements, and recovery should be tested periodically.
5. Control who has access
Employees should generally only have access to the information and systems they need for their role.
Administrator access should be limited and reviewed. When somebody leaves the business, their access should be removed promptly.
6. Train your people
Technology cannot prevent every incident.
Employees should know how to recognise suspicious emails, unexpected login requests, unusual payment instructions and other common warning signs.
A simple process for reporting something suspicious can also make a significant difference.
7. Have a plan for when something goes wrong
Businesses should know what to do if an account is compromised, a device is lost, suspicious activity is detected or important systems become unavailable.
The middle of an incident is not the best time to decide who needs to be contacted and what needs to happen next.
Cyber security is not about eliminating every possible risk. It is about understanding the risks to your business and putting reasonable safeguards in place to reduce them.
Practical Example
Real-World Scenario
Imagine a 15-person professional services business using Microsoft 365.
One employee receives an email that appears to be a Microsoft sign-in notification. They follow the link and enter their password into a fake login page.
If the account is not adequately protected, an attacker may gain access to the employee's mailbox. They could potentially read business communications, impersonate the employee or use the compromised account to target other people.
Now consider the same situation where MFA is enabled, employees receive security awareness training, suspicious sign-ins are monitored and the business has a documented response process.
The phishing attempt can still happen, but the business has multiple layers of protection and is better prepared to respond.