Cyber Security for Small Business Australia: 2026 Checklist

Sanjay Singh
By
Sanjay Singh
Writer - Journalist
- Writer - Journalist

Cyber security for small business Australia is mostly habits, not a six-figure security team. Attackers go after accountants, tradies, clinics and shops because the inbox is open and the backup is a USB in a drawer.

This is a working order. Do the first five before you buy software with a logo.

Why small Australian firms get hit

Most jobs start with a fake invoice, a hijacked mailbox, or a password reused from a breach dump. Ransomware still pays when the only copy of MYOB is on the same machine that just got encrypted.

You do not need to be interesting. You need to be reachable and slow to notice.

The ACSC Essential Eight, in plain language

The Australian Signals Directorate’s Essential Eight is still the live baseline in late 2026. A broader “Essentials” series is coming. Consultation closed in July. Nothing has replaced the Eight yet. Aim at Maturity Level One first. Level Two if you handle money, health files or government work.

The eight strategies:

Application control. Stop random programs running.
Patch applications. Browser, Office, accounting tools.
Patch the operating system. Windows and macOS updates are not optional.
Restrict admin rights. The owner should not live in an admin account all day.
Configure Microsoft Office macros. Most shops can turn them off.
User application hardening. Block Flash-era junk and risky ads.
Multi-factor authentication. On email, banking, Xero, Microsoft 365.
Daily backups. Offline or in a separate cloud account the ransomware cannot reach.

You do not need all eight at Level Three next week. MFA, patches and a backup you have actually restored from will stop more pain than a policy binder.

A 10-step checklist you can finish this month

1. Unique passwords, a manager, no sharing. Bitwarden or 1Password is enough. Ban the same password on Gmail and the bank.

2. MFA on everything that holds money or mail. Authenticator app beats SMS. Turn it on for Microsoft 365, Google Workspace, Xero, MYOB, the bank and the domain registrar.

3. One admin account, used rarely. Day-to-day work happens as a standard user.

4. Patch Tuesday is a calendar item. Windows Update. Mac Software Update. Adobe. The accounting app. Uninstall what nobody uses.

5. Backups you have tested. 3-2-1 if you can: three copies, two media, one off-site. Restore a file this week so you know the password still works.

6. Lock the mailbox. Look-alike domains and “new bank details” emails fund most local scams. A 24-hour pause on changed invoice accounts saves more than another firewall.

7. Separate Wi-Fi for guests and the till. Default router passwords go first.

8. Staff get one page, not a seminar. How to spot a fake invoice. Who to call. No USB from a trade show.

9. Vendors sign something short. Where is the data. Is it in Australia. Who gets told if they get hit.

10. Insurance after the basics, not instead of them. Insurers now ask about MFA and backups. Fix those before you pay the premium.

After a breach: the NDB scheme

If personal information is lost or opened without permission, and serious harm is likely, organisations covered by the Privacy Act must tell the OAIC and the people affected. That generally means turnover above $3 million, plus health providers, credit players and TFN holders of any size. Many firms under $3 million are still out. Tranche 2 privacy reforms are expected to drag more small operators in. Do not wait for that bill to write a one-page incident plan.

Practical order if something is wrong:

Pull the suspect machine off the network.
Change the mailbox and bank passwords from a clean device.
Call the bank if money moved.
Preserve logs. Do not wipe the box in a panic.
If customer records walked, get advice on whether you must notify.

The ACSC has a small-business hotline and published playbooks. Use them. This is not legal advice.

What it costs

Free or cheap: password manager, MFA, Windows Update, a second cloud backup account, a written one-pager for staff.

Paid when you outgrow that: a managed Microsoft 365 tenant with Defender, an MSP who patches on a schedule, cyber insurance once MFA is on.

A $30-a-month stack beats a $12,000 clean-up after a locked Xero file.

FAQ: cyber security for small business Australia

Is the Essential Eight compulsory for private companies?
No. Commonwealth agencies are in a different bucket. Clients, insurers and government tenders increasingly expect the same controls.

What is SMB1001?
A separate small-business certification. Useful for tenders. It does not replace patching and MFA.

Do I need an MSP?
If nobody on staff will own patching and backups, yes. A quiet retainer is cheaper than a weekend restore.

Is a firewall enough?
No. Most incidents start in email.

How often do I test backups?
Quarterly at minimum. After any big software change.

Bottom line

Turn on MFA.
Patch what you already own.
Keep a backup the attacker cannot encrypt.
Write down who you call on a Saturday.

Share This Article
Leave a Comment
Share via
Copy link