Good IT Advice for Australian Businesses
No frameworks. No acronyms. No vendor pitches. Just practical advice we give Australian business owners on the first call.
The six things that actually matter
Everything else is noise. These six items stop most attacks and let you sleep at night.
Turn on MFA everywhere
Multi-factor authentication on email, banking, accounting, everything. Microsoft now enforces MFA on all admin centres from February 2026. Use Microsoft Authenticator or FIDO2 keys, not SMS. ACSC data shows MFA blocks 99.9% of account compromise attempts.
Do this today
Back up properly and test it
Microsoft 365 does not back up your email forever. Get third-party backup (Veeam, AvePoint, or Backupify). Use immutable backups that cannot be encrypted by ransomware. Test restores quarterly. The ACSC says backup is the single most effective ransomware recovery control.
Do this this week
One login per person
No shared accounts. No "office@" login that everyone knows. When someone leaves, you should be able to disable their access in 5 minutes.
Do this this week
Get proper endpoint protection
The free antivirus that came with your laptop is not enough. Get Microsoft Defender for Business (included in M365 Business Premium), Huntress, or SentinelOne. Proper EDR detects behaviour, not just signatures. Essential Eight Maturity Level 2 requires next-gen AV at minimum.
Do this this month
Patch within 14 days
Windows updates, Office updates, browser updates. ACSC guidance: patch critical vulnerabilities within 48 hours, all others within 14 days. Most attacks use bugs that were already fixed months ago. Turn on automatic updates and monitor the ACSC alerts feed.
Do this this month
Phone to verify bank detail changes
Email invoices with changed bank details are the #1 business email compromise. The ACCC reported over $560 million lost to BEC in 2025. Pick up the phone and call on a number you already have. Never trust email-only payment changes.
Do this forever
Stop doing these things
Every one of these has caused a real incident at a real Australian business in the last two years.
Sharing passwords via email or Teams
Do this instead: Use a password manager like 1Password, Keeper or Bitwarden
Letting staff use personal Gmail for work
Do this instead: Everyone gets a proper business email with their name on it
Running Windows Server 2012 or older
Do this instead: Unsupported = vulnerable. Migrate or shut it down
Assuming your nephew "does IT"
Do this instead: Cyber security is not a hobby. Get someone accountable
Waiting until after an incident to get serious
Do this instead: Insurers and customers ask now, not later
What it actually costs
Real numbers. Ex GST. Australian businesses, 2026 pricing.
Basics done properly
$30-80 per user per month
M365 Business Premium, backup, MFA, EDR, patching
Full managed IT
$120-250 per user per month
24/7 monitoring, helpdesk, security operations, documented processes
Cost of doing nothing
$50k-250k per incident
Ransomware recovery, downtime, legal, insurance excess, lost customers
For context: the average ransomware incident at an Australian small business costs $50k to $250k once you add downtime, recovery, legal, insurance excess and lost customers. The cost of doing it properly is genuinely cheaper than the cost of not.
Cyber insurance premiums for a 50-person business typically run $5k to $15k annually. Insurers now require evidence of MFA, EDR, backup testing, and patching before they will pay out. Document everything.

Remote Support