Cyber Security for Business Owners: Where to Start
You Don’t Need to Be Technical
If you run a small or medium business in Australia, you have probably heard that cyber security is important. You may have read the headlines about data breaches at Optus, Medibank or Latitude Financial and wondered: “Could that happen to me?” The short answer is yes — but the good news is that protecting your business is far more achievable than you might think.
According to the ASD’s Annual Cyber Threat Report 2023–2024, over 87,400 cybercrime reports were filed in the financial year, with small businesses reporting average losses of approximately $46,000 per incident. You do not need a computer science degree to reduce that risk dramatically. You just need to know where to start.
Step 1: Understand Your Risk Profile
Before you spend a dollar on security tools, take stock of what you actually need to protect. Ask yourself:
- What data do we hold? Customer names, emails, payment details, health records, employee files?
- Where does that data live? Cloud apps (Xero, MYOB, Microsoft 365), local computers, shared drives, paper files?
- What would happen if we lost access for a week? Could the business survive? Would customers be affected?
- Who has access? Staff, contractors, former employees who never had their access revoked?
This is not a formal risk assessment — it is a 30-minute conversation with yourself (or your team) that gives you clarity on what matters most. Write the answers down. That simple document becomes the foundation of every security decision you make.
Step 2: Identify Your Critical Assets
Not everything needs the same level of protection. Focus your effort on the assets that would cause the most damage if compromised:
- Email accounts — the single most common entry point for attackers. Business email compromise cost Australian businesses over $79 million in 2022–23 according to the ACCC.
- Financial systems — banking portals, accounting software, payment processing.
- Customer databases — any system holding personal information covered by the Australian Privacy Act 1988.
- Backups — your safety net if everything else fails. If backups are compromised, recovery becomes extremely difficult.
Step 3: Start With the Basics
The Australian Signals Directorate (ASD) found that implementing just the top four of their Essential Eight strategies can prevent the vast majority of commodity cyber attacks. Here are the four things every business owner should do first:
Use Strong, Unique Passwords
Every account should have a different password, and each password should be long (at least 14 characters) and impossible to guess. Use a password manager to make this practical — you only need to remember one master password. Our free tools guide recommends several excellent options that cost nothing.
Turn On Multi-Factor Authentication (MFA)
MFA adds a second layer of verification — typically a code from a phone app — so a stolen password alone is not enough for an attacker to get in. Start with email, banking and cloud services. Our step-by-step MFA guide walks you through the process for common business tools.
Keep Everything Updated
Software updates (patches) fix known security holes. Enable automatic updates on operating systems, web browsers, Microsoft Office and any other software you use. When a vendor releases an update, install it as soon as possible — ideally within 48 hours for critical patches.
Back Up Your Data
Follow the 3-2-1 rule: three copies of important data, on two different media, with one stored offsite or in the cloud. Test your backups regularly — a backup you have never restored is a backup you cannot trust. Make sure at least one copy is offline or immutable so ransomware cannot encrypt it.
Step 4: Build Good Habits
Cyber security is not a one-time project — it is an ongoing practice, much like workplace safety or financial management. A useful way to think about it is through four pillars: Identity (who can access your systems), Data (how your information is protected and backed up), Infrastructure (your devices, networks and software) and Assurance (your governance, reviews and continuous improvement). This is the basis of the IDIA framework — a simple operating model that works alongside any standard and helps non-technical owners see exactly where their security habits fit.
Build these habits into your business rhythm:
- Monthly: Review who has access to your systems. Remove access for anyone who no longer needs it.
- Quarterly: Check that backups are working by performing a test restore.
- Annually: Review your overall security posture and update your approach as the business grows.
- Ongoing: Talk to your team about phishing emails and suspicious requests. A one-minute conversation can prevent a major incident.
Use our cyber security checklist for Australian SMEs to track your progress and ensure nothing falls through the cracks.
Step 5: Know When to Get Help
You do not need to do everything yourself. Consider engaging external help when:
- You hold sensitive customer data (health, financial, personal information) and have obligations under the Privacy Act.
- You are growing and your IT environment is becoming more complex.
- A client or government contract requires you to demonstrate a specific security standard.
- You have experienced a security incident and need professional response support.
A managed IT service provider or cyber security consultant does not need to be expensive. Even a few hours of expert guidance can save you thousands in the long run.
Free Resources to Get You Started
The Australian Government provides excellent free guidance for small businesses:
- ACSC Small Business Guide — the Australian Cyber Security Centre’s step-by-step guide tailored for businesses with fewer than 20 employees.
- Stay Smart Online — alerts about current threats and practical advice for individuals and small businesses.
- ReportCyber (cyber.gov.au) — report cybercrime incidents and get guidance on next steps.
- ASD Essential Eight — the eight mitigation strategies that form the backbone of Australian cyber security best practice. Read our detailed guide for a plain-English breakdown.
“Cyber security does not have to be complicated or expensive. The basics — done consistently — will protect your business from the vast majority of threats.”
Find Out Where You Stand Today
The hardest part of any journey is knowing where you are right now. Platforms like How’s My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard — so you never have to wonder which framework to follow. Start with the free CYBER9 assessment to benchmark your business across nine critical domains in under 10 minutes. No technical knowledge required — just honest answers about how your business operates. You will receive a maturity score and a prioritised action plan so you know exactly what to tackle first.
How secure is your business?
Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.
Try CYBER9 Free