Getting Started

Cyber Security Checklist for Australian SMEs (2026)

HB
HMC Bot
7 min read

Why Every Australian SME Needs a Cyber Security Checklist

Cyber attacks do not discriminate by company size. The Australian Cyber Security Centre (ACSC) reports that small businesses account for over 43% of all cybercrime reports, with average losses around $46,000 per incident. Yet many SME owners still treat cyber security as something only big corporations need to worry about.

The truth is simpler and more encouraging: most attacks against small businesses exploit basic weaknesses. A structured checklist can close these gaps without requiring a dedicated IT security team or a six-figure budget.

This checklist draws on the ASD Essential Eight framework, Australian Privacy Act obligations, and real-world lessons from breach investigations. Print it, pin it up, and work through it over the next quarter.

The 15-Point Cyber Security Checklist

1. Enforce Strong, Unique Passwords

Every account used for business — email, cloud storage, accounting software, banking — should have a unique password of at least 14 characters. Use a password manager (such as 1Password or Bitwarden) so staff do not need to remember them all. Ban password reuse across services.

2. Enable Multi-Factor Authentication (MFA) Everywhere

MFA is the single most effective control against account compromise. Enable it on email, Microsoft 365 or Google Workspace, accounting platforms, banking, social media and any system that holds customer data. Prefer authenticator apps over SMS where possible. See our MFA setup guide for step-by-step instructions.

3. Keep Software and Operating Systems Updated

Enable automatic updates for operating systems, web browsers, and business applications. Replace any software that has reached end-of-life and no longer receives security patches. Critical patches should be applied within 48 hours of release.

4. Back Up Your Data Using the 3-2-1 Rule

Maintain three copies of important data, on two different media types, with one copy stored offsite or in the cloud. At least one backup should be immutable or offline so it cannot be encrypted by ransomware. Test your restores quarterly — a backup you cannot restore is not a backup.

5. Set Up Email Authentication (SPF, DKIM, DMARC)

Email remains the number one attack vector for Australian businesses. Configuring SPF, DKIM and DMARC on your domain prevents attackers from sending convincing emails that appear to come from your business. If you have not set these up, you are leaving your brand and your customers exposed.

6. Train Your Staff on Phishing and Social Engineering

Human error is involved in the majority of successful breaches. Run brief, regular awareness sessions — even 15 minutes each quarter makes a measurable difference. Cover how to spot phishing emails, suspicious links, invoice fraud and phone-based social engineering.

7. Restrict Administrative Privileges

Only give admin access to staff who genuinely need it for their role. Everyone else should use standard user accounts. Admin accounts should never be used for everyday tasks like email or web browsing.

8. Secure Your Wi-Fi Network

Use WPA3 (or at minimum WPA2) encryption. Change default router passwords and admin credentials. Create a separate guest network for visitors and personal devices. Hide your business SSID if practical.

9. Install and Maintain Endpoint Protection

Every device that connects to your business network — desktops, laptops, phones — needs up-to-date antivirus and endpoint protection. Windows Defender (included with Windows 10/11) is a capable baseline. Ensure it is enabled and not overridden.

10. Create a Cyber Incident Response Plan

Know what you will do before something goes wrong. Document who to call, how to isolate affected systems, how to notify customers and regulators, and how to restore from backups. Keep a printed copy — you may not have access to digital files during an incident. Our incident response planning guide walks you through the process.

11. Review and Manage Third-Party Access

Audit which suppliers, contractors and SaaS platforms have access to your data. Remove access for anyone who no longer needs it. Ensure critical vendors have their own cyber security measures in place.

12. Encrypt Sensitive Data

Enable full-disk encryption on all laptops (BitLocker on Windows, FileVault on macOS). Use TLS/HTTPS for all web-based services. Encrypt sensitive files before emailing them externally.

13. Review Your Cyber Insurance Policy

Cyber insurance is not a substitute for good security, but it provides a financial safety net. Review your policy annually to ensure it covers business interruption, data breach notification costs, ransomware (if applicable) and third-party liability. Many insurers now require MFA and backups as policy conditions.

14. Understand Your Privacy Act Obligations

If your business has annual turnover above $3 million (or handles health records, or trades in personal information), you are covered by the Australian Privacy Act 1988. The Notifiable Data Breaches (NDB) scheme requires you to report eligible breaches to the OAIC and affected individuals. Even businesses below the threshold should follow best practice.

15. Schedule Quarterly Security Reviews

Cyber security is not a set-and-forget exercise. Set a calendar reminder to review this checklist every quarter. Check for new patches, review user access, test backups, and update your incident response plan as your business evolves.

Tracking Your Progress

A checklist is only useful if you track what you have done and what remains. Consider a simple spreadsheet with three columns: Item, Status (Not Started / In Progress / Done), and Date Completed. Assign an owner for each item so accountability is clear.

If the number of items feels overwhelming, the IDIA framework can help you make sense of it all. IDIA organises every cybersecurity control into four pillars — Identity (items 1, 2, 7 above), Data (items 4, 12, 14), Infrastructure (items 3, 5, 8, 9) and Assurance (items 6, 10, 11, 13, 15). Grouping your checklist this way makes it easier to assign ownership and spot which pillar needs the most attention. Because IDIA maps to ISO 27001, NIST CSF, the Essential Eight and SMB1001, any progress you make here translates directly into broader compliance readiness.

“You do not need to do everything at once. Start with MFA, backups and patching — those three alone will put you ahead of most Australian small businesses.”

How Do You Score?

If you have ticked off fewer than half the items on this list, you are not alone — but you are at elevated risk. Platforms like How’s My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard. Start with the free CYBER9 assessment to benchmark your business across nine critical security domains in under 10 minutes. No technical jargon, no sales pitch — just a clear picture of where you stand and a prioritised action plan you can work through at your own pace.

Share

How secure is your business?

Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.

Try CYBER9 Free