No Jargon Edition

Good IT Advice for Australian Businesses

No frameworks. No acronyms. No vendor pitches. Just practical advice we give Australian business owners on the first call.

The six things that actually matter

Everything else is noise. These six items stop most attacks and let you sleep at night.

Turn on MFA everywhere

Multi-factor authentication on email, banking, accounting, everything. Microsoft now enforces MFA on all admin centres from February 2026. Use Microsoft Authenticator or FIDO2 keys, not SMS. ACSC data shows MFA blocks 99.9% of account compromise attempts.

Do this today

Back up properly and test it

Microsoft 365 does not back up your email forever. Get third-party backup (Veeam, AvePoint, or Backupify). Use immutable backups that cannot be encrypted by ransomware. Test restores quarterly. The ACSC says backup is the single most effective ransomware recovery control.

Do this this week

One login per person

No shared accounts. No "office@" login that everyone knows. When someone leaves, you should be able to disable their access in 5 minutes.

Do this this week

Get proper endpoint protection

The free antivirus that came with your laptop is not enough. Get Microsoft Defender for Business (included in M365 Business Premium), Huntress, or SentinelOne. Proper EDR detects behaviour, not just signatures. Essential Eight Maturity Level 2 requires next-gen AV at minimum.

Do this this month

Patch within 14 days

Windows updates, Office updates, browser updates. ACSC guidance: patch critical vulnerabilities within 48 hours, all others within 14 days. Most attacks use bugs that were already fixed months ago. Turn on automatic updates and monitor the ACSC alerts feed.

Do this this month

Phone to verify bank detail changes

Email invoices with changed bank details are the #1 business email compromise. The ACCC reported over $560 million lost to BEC in 2025. Pick up the phone and call on a number you already have. Never trust email-only payment changes.

Do this forever

Stop doing these things

Every one of these has caused a real incident at a real Australian business in the last two years.

Sharing passwords via email or Teams

Do this instead: Use a password manager like 1Password, Keeper or Bitwarden

Letting staff use personal Gmail for work

Do this instead: Everyone gets a proper business email with their name on it

Running Windows Server 2012 or older

Do this instead: Unsupported = vulnerable. Migrate or shut it down

Assuming your nephew "does IT"

Do this instead: Cyber security is not a hobby. Get someone accountable

Waiting until after an incident to get serious

Do this instead: Insurers and customers ask now, not later

What it actually costs

Real numbers. Ex GST. Australian businesses, 2026 pricing.

Basics done properly

$30-80 per user per month

M365 Business Premium, backup, MFA, EDR, patching

Full managed IT

$120-250 per user per month

24/7 monitoring, helpdesk, security operations, documented processes

Cost of doing nothing

$50k-250k per incident

Ransomware recovery, downtime, legal, insurance excess, lost customers

For context: the average ransomware incident at an Australian small business costs $50k to $250k once you add downtime, recovery, legal, insurance excess and lost customers. The cost of doing it properly is genuinely cheaper than the cost of not.

Cyber insurance premiums for a 50-person business typically run $5k to $15k annually. Insurers now require evidence of MFA, EDR, backup testing, and patching before they will pay out. Document everything.

Or get someone else to do it

That is the entire reason businesses use a Managed Service Provider. You stop thinking about MFA enforcement, patching schedules, backup tests and admin reviews. Someone else does the boring, important work.