Overview
Most breaches exploit basics, not advanced techniques. Missing MFA, un-patched servers, weak backups, and oversharing are how attackers still get in. Cyber hygiene is the set of everyday habits that make a business genuinely hard to breach.
Identity
Good looks like
- MFA on every account
- Phishing-resistant MFA on admins
- Separate admin accounts
- Password manager for all staff
- Break-glass accounts in a safe
Bad looks like
- SMS MFA on admin accounts
- Shared logins to SaaS tools
- Spreadsheets of passwords
- No MFA on VPN
- 10+ Global Admins
Devices
Good looks like
- EDR on every endpoint
- Disk encryption enforced
- Automated patching
- Intune-managed compliance
- Secure Boot and TPM enabled
Bad looks like
- AV-only protection
- Unencrypted laptops travelling
- Unpatched OS or apps for months
- Windows 7 or Server 2012 still running
- Local admin rights for everyone
Good looks like
- DMARC at p=reject
- Defender for Office 365 or equivalent
- Safe Links and attachment sandboxing
- External sender banners
- Anti-phishing and impersonation protection
Bad looks like
- No DMARC, no SPF hardening
- Default M365 only, no Defender
- External mail looks identical to internal
- No user training or simulation
- Legacy auth still enabled
Backup
Good looks like
- Daily automated, immutable, offsite
- Microsoft 365 backed up separately
- Monthly file restores, quarterly VM restores
- Documented recovery runbooks
- Retention aligned to compliance
Bad looks like
- Local-only backup
- Never tested
- Backups on the domain
- Short retention windows
- M365 data unprotected
Patching
Good looks like
- Automated OS and app patching
- Critical CVEs patched in days
- Monthly reporting against SLA
- Inventory maintained in RMM
- Unsupported software retired
Bad looks like
- Manual patching that slips
- Deferred reboots for months
- Servers unpatched because of fear
- No visibility of coverage
- Third-party apps ignored
Good vs Bad: Quick Test
If you can answer yes to all of these, you are in the top 20% of Australian SMBs on cyber hygiene:
Common Mistakes
Chasing advanced tools while basics are broken
AI-powered everything does not help if MFA is missing.
Measuring activity, not outcomes
Deployed tools means nothing if they are not configured correctly.
No ownership
Without a named owner (internal lead or MSP), hygiene drifts.
Annual reviews, monthly threats
Controls need continuous attention, not annual dusting off.
Start With the Basics
We run cyber hygiene assessments and remediations that close the common gaps most businesses overlook. Measurable uplift in weeks.

Remote Support