All Guides
Security Basics

What Good Cyber Hygiene Actually Looks Like

Plain English, no jargon. What good identity, device, email, backup, and patching look like across an Australian SMB, and what bad looks like.

Last reviewed August 2026

Overview

Most breaches exploit basics, not advanced techniques. Missing MFA, un-patched servers, weak backups, and oversharing are how attackers still get in. Cyber hygiene is the set of everyday habits that make a business genuinely hard to breach.

Identity

Good looks like

  • MFA on every account
  • Phishing-resistant MFA on admins
  • Separate admin accounts
  • Password manager for all staff
  • Break-glass accounts in a safe

Bad looks like

  • SMS MFA on admin accounts
  • Shared logins to SaaS tools
  • Spreadsheets of passwords
  • No MFA on VPN
  • 10+ Global Admins

Devices

Good looks like

  • EDR on every endpoint
  • Disk encryption enforced
  • Automated patching
  • Intune-managed compliance
  • Secure Boot and TPM enabled

Bad looks like

  • AV-only protection
  • Unencrypted laptops travelling
  • Unpatched OS or apps for months
  • Windows 7 or Server 2012 still running
  • Local admin rights for everyone

Email

Good looks like

  • DMARC at p=reject
  • Defender for Office 365 or equivalent
  • Safe Links and attachment sandboxing
  • External sender banners
  • Anti-phishing and impersonation protection

Bad looks like

  • No DMARC, no SPF hardening
  • Default M365 only, no Defender
  • External mail looks identical to internal
  • No user training or simulation
  • Legacy auth still enabled

Backup

Good looks like

  • Daily automated, immutable, offsite
  • Microsoft 365 backed up separately
  • Monthly file restores, quarterly VM restores
  • Documented recovery runbooks
  • Retention aligned to compliance

Bad looks like

  • Local-only backup
  • Never tested
  • Backups on the domain
  • Short retention windows
  • M365 data unprotected

Patching

Good looks like

  • Automated OS and app patching
  • Critical CVEs patched in days
  • Monthly reporting against SLA
  • Inventory maintained in RMM
  • Unsupported software retired

Bad looks like

  • Manual patching that slips
  • Deferred reboots for months
  • Servers unpatched because of fear
  • No visibility of coverage
  • Third-party apps ignored

Good vs Bad: Quick Test

If you can answer yes to all of these, you are in the top 20% of Australian SMBs on cyber hygiene:

MFA on every account, phishing-resistant on admins
EDR on every laptop, desktop, and server
Immutable backups tested quarterly
Microsoft 365 backed up separately from the tenant
DMARC at p=reject
Critical CVEs patched within 48 hours
Intune or equivalent MDM deployed
Offboarding completed within 24 hours of exit
Incident response plan tested annually
Essential Eight Maturity Level 1 or above

Common Mistakes

Chasing advanced tools while basics are broken

AI-powered everything does not help if MFA is missing.

Measuring activity, not outcomes

Deployed tools means nothing if they are not configured correctly.

No ownership

Without a named owner (internal lead or MSP), hygiene drifts.

Annual reviews, monthly threats

Controls need continuous attention, not annual dusting off.

Start With the Basics

We run cyber hygiene assessments and remediations that close the common gaps most businesses overlook. Measurable uplift in weeks.