All Guides
No Jargon Edition

Just tell me what to actually do to protect my business

No frameworks. No acronyms. No vendor pitches. Just a plain English checklist for an Australian business owner who is sick of being told to read 200 page documents. Here is what to do this week, this month, and this quarter.

Last reviewed September 20268 min read

The honest truth

Most cyber attacks on Australian businesses are not sophisticated. They are someone clicking a dodgy link, an old password being reused, an account without MFA, or a backup that nobody tested. The attackers are not James Bond. They are running automated tools at scale, looking for whoever is easiest.

Your job is not to be unhackable. Your job is to be slightly harder to hack than the next business on the list, and to be able to recover quickly if something does happen. That is genuinely it.

Everything below is what we actually tell Australian business owners on the first call, before we sell anything. It is the same advice whether you have 3 staff or 300. Bigger businesses just need more of each item.

Before anything else

Back up your data. Properly. Today.

If you do nothing else on this page, do this. A working, tested backup is the single thing that decides whether a ransomware attack, a deleted folder, a quitting staff member, or a fried server is a bad afternoon or the end of your business.

Use the 3-2-1 rule

Three copies of your data, on two different types of storage, with at least one copy off-site or in the cloud.

Microsoft 365 is not a backup

Microsoft and Google do not back up your email, OneDrive, SharePoint or Teams data forever. You need a separate third-party backup.

Test it every quarter

A backup you have never restored from is a guess, not a backup. Pick a random file or mailbox and actually restore it.

The two questions you should be able to answer right now

  • 1.If every server, laptop and Microsoft 365 mailbox was wiped tomorrow morning, where is the copy and how long would it take to get back to working?
  • 2.When was the last time someone actually restored a file from that backup and confirmed it worked?

If you cannot answer both clearly, you do not have a backup strategy. You have a hope.

Do these five things this week

If you do nothing else, do these. They take a few hours and stop most automated attacks dead.

Week 1Quick wins
01

Turn on multi-factor authentication (MFA) for every email account. Especially the boss, the bookkeeper and anyone who handles invoices. Use the Microsoft Authenticator or Google Authenticator app, not SMS.

02

Make sure every laptop and computer has a password to log in, and that the screen locks when you walk away. No shared passwords. No sticky notes.

03

Check that your work email (Microsoft 365 or Google Workspace) is actually being backed up somewhere separate. The default does NOT keep emails forever if someone deletes them or gets hacked.

04

Tell every staff member: if a payment, bank detail or supplier email looks even slightly weird, pick up the phone and call the supplier on a number you already have. Never reply to the suspicious email.

05

Write down a list of who has admin access to your systems (email, accounting, banking, website). If you cannot list them in 5 minutes, that is the problem.

Do these six things this month

These take a bit more effort. They are the difference between a business that gets back up in 24 hours and one that closes for two weeks.

Month 1Build the foundations
01

Get every staff member off their personal Gmail/Outlook for work and onto a proper business email account with their name on it.

02

Turn on automatic updates (patches) for Windows, Mac, phones and major apps. Most attacks use bugs that were already fixed months ago.

03

Install proper endpoint protection (the modern version of antivirus) on every computer. Microsoft Defender for Business, Huntress or SentinelOne are all fine. The free stuff that came with the laptop is not.

04

Set up a password manager for the whole team (1Password, Keeper or Bitwarden). Stop the spreadsheet of passwords. Stop reusing the same password everywhere.

05

Make sure your data is backed up to somewhere the attackers cannot reach, and actually test that you can restore it. A backup that has never been tested is a wish.

06

Document who does what when something breaks. Even one A4 page that says "if X happens, call Y" is better than nothing.

Do these six things this quarter

These are the "grown up" items. Insurers, customers and prime contractors will start asking about them. Better to have answers ready.

Quarter 1Grown-up items
01

Run a 30-minute security awareness session with every staff member. Phishing, dodgy invoices, fake supplier emails, password hygiene. Keep it short and human.

02

Review who has access to what. Anyone who has left the business in the last 12 months should be removed from every system. Yes, every one.

03

Lock down admin access. The day-to-day account you use for email should NOT be the same account that can change settings or add new users.

04

Talk to your insurance broker about cyber insurance. Premiums and questions have got serious. Knowing what they will ask is half the battle.

05

Decide whether to certify against SMB1001 (Australian, designed for businesses your size) so you can prove to insurers, customers and primes that you actually do the basics.

06

Pick someone (internal or external) who is accountable for IT and cyber. Not "everyone is sort of responsible". One name.

Free stuff you can do right now to be better

No vendor pitches. No credit card. Every item below is genuinely free, takes less than 30 minutes, and uses a tool either built into what you already pay for, or run by the Australian government and reputable security orgs. Click any card to open the tool. Pick three and do them this afternoon.

Free nowNo cost, just time
01

Monitor your domain on Have I Been Pwned

Get an email the moment any account on your business domain shows up in a new data breach. Takes 5 minutes to set up and runs forever, for free.

haveibeenpwned.com/DomainSearch

02

Turn on Microsoft 365 Security Defaults

If you do not have Conditional Access licensed, Security Defaults enforce MFA on every account and block legacy authentication. Free, included in every M365 tenant.

learn.microsoft.com (Security Defaults)

03

Check your Microsoft Secure Score

Score your M365 tenant out of 100 and get the exact list of settings to flip to improve. No extra licence required, just open the admin centre.

security.microsoft.com/securescore

04

Audit your email auth (SPF, DKIM, DMARC)

Misconfigured email is the most common reason Australian businesses get impersonated. MXToolbox tells you what is missing in 30 seconds.

mxtoolbox.com

05

Subscribe to ASD ACSC alerts

Plain English alerts about active threats targeting Australian businesses, straight from the Australian Signals Directorate. Free, official, no spam.

cyber.gov.au/alerts-and-advisories

06

Run the Essential Eight Self-Assessment

The official ACSC tool that tells you exactly where you sit against the national baseline every Australian business is measured against. No login, no cost.

cyber.gov.au (Essential Eight)

07

Turn on login alerts everywhere

Banking, Xero, MYOB, payroll. The bookkeeper getting an email at 2am when someone logs in from overseas has saved more than one Australian business. Free in every system.

Xero MFA setup guide

08

Alert on mailbox forwarding rules

A new forwarding rule is the #1 sign of a compromised mailbox in business email compromise attacks. Free audit log alerts in M365 and Google Workspace.

Microsoft Purview alert policies

09

Switch your office DNS to Quad9

Block known malicious websites for free by changing your router DNS to Quad9 (9.9.9.9) or Cloudflare (1.1.1.2). Five minutes, blocks a huge chunk of phishing and malware.

quad9.net

10

Sign up for Scamwatch alerts

Plain English warnings from the ACCC about scams and fraud campaigns targeting Australians right now. Helps the whole team spot what is doing the rounds.

scamwatch.gov.au

11

Test your business website with SSL Labs

If it scores below an A, customers may already be seeing browser warnings that kill trust and conversions. Free, takes 90 seconds.

ssllabs.com/ssltest

12

Report incidents to ReportCyber

Bookmark the official Australian government cybercrime reporting portal now, before something happens. It is the right first call for fraud, ransomware, and BEC.

cyber.gov.au/report

Stop doing these things. Right now.

Every one of these is on the list because we have personally seen it cause a real incident at a real Australian business in the last two years.

Sharing logins between staff

One login per person. Always. If you are sharing the "office@" inbox login, that is a problem.

Using SMS for two-factor codes if you can avoid it

SIM swap fraud is real. Use the Microsoft Authenticator or Google Authenticator app instead. Hardware keys are even better for the boss.

Letting staff use personal Dropbox / Google Drive for work files

When they leave, your files leave with them. Use proper business storage with central control.

Running an old server in the back room because "it still works"

Windows Server 2012 and earlier are unsupported. Same for old Synology and QNAP NAS units. They are how ransomware gets in.

Paying invoices when bank details have changed without phoning the supplier

Business email compromise (BEC) costs Australian businesses hundreds of millions a year. One phone call fixes it.

Assuming Microsoft 365 backs up your email forever

It does not. If someone gets hacked or quits and you delete their account, that mail is gone within 30 to 90 days unless you bought separate backup.

Letting the same person be admin of everything for 10 years with no review

When that person leaves, retires or gets phished, the entire business is exposed. Spread it out, document it, review it.

If something bad actually happens

Print this section. Stick it on the wall in the office, or save it as the first thing in your IT folder. The first hour of a cyber incident is the most important hour. People who panic make it worse.

1. Do not panic, but move fast

The first hour matters. Stay calm. Get the right people in the room (or on a call).

2. Disconnect, do not turn off

If a computer is acting strange, unplug the network cable and turn off Wi-Fi. Do not shut it down. The forensic evidence is in memory.

3. Stop money moving

If invoices, bank details or payments are involved, call your bank straight away. Some fraud can be reversed in the first few hours, almost none after that.

4. Change the boss, finance and IT admin passwords first

In that order. From a clean device. Not from the laptop you suspect is compromised.

5. Call your IT provider or call us

Do not try to "have a poke around" yourself. You will overwrite the evidence and make recovery harder.

6. Tell the right people

Australian businesses have legal obligations under the Privacy Act 1988 if personal information is involved. The OAIC Notifiable Data Breaches scheme has a 30 day clock. Your insurer also wants to know early, not late.

If you have no idea what to do, call us.

Even if you are not a client. We would rather take a 5 minute call from a panicked business owner than read about another preventable disaster on the news.

07 3114 2808

What about all those framework names?

Essential Eight, SMB1001, ISO 27001, NIST, CIS, CMMC, ISM, SOCI Act, Privacy Act. Every consultant uses different ones. Here is the honest version of what each is, and whether a small or medium Australian business actually needs to care.

Essential Eight

Care: Yes

The Australian government baseline for cyber security. Eight practical things every business should do: MFA, patching, backups, restricting admin access, and so on. Insurers and bigger customers will ask if you are doing it. ASD is evolving it into a new Essentials series over the next two years, but the eight strategies stay the same and it remains current guidance. Start here.

SMB1001

Care: Yes (if you want a certificate)

An Australian cyber security certificate built specifically for small and medium businesses. Five tiers from Bronze to Diamond. Gold is the sweet spot for most SMEs. It is the easiest way to prove to insurers, customers and primes that you actually do the basics.

Privacy Act / Notifiable Data Breaches

Care: Yes (it is the law)

Australian law. If personal information leaks and people could be seriously harmed, you must notify the OAIC and the people affected. Applies to most businesses turning over $3M+ and plenty of smaller ones (health, childcare, contractors handling personal data). Not optional.

ISO 27001

Care: Only if a customer demands it

International information security standard. Heavy on documentation and expensive to certify (think tens of thousands of dollars). Worth it if a multinational customer or large tender requires it. For most SMEs, SMB1001 Gold covers the same ground for a fraction of the cost.

ISM (Information Security Manual)

Care: Probably not

The full Australian government cyber security rulebook (hundreds of pages). Mostly relevant if you sell to government, work in Defence supply chain, or run critical infrastructure. Almost no SMEs need to read this cover to cover.

NIST CSF / CIS Controls

Care: Probably not

American cyber security frameworks. Sometimes used as a shared language with US-based customers or parent companies. If you are doing the Essential Eight properly, you are already covering most of what NIST and CIS ask for. Do not chase them just because someone mentioned them.

CMMC

Care: Almost certainly not

A US Department of Defense requirement. Only matters if you supply into the American defence industry. If that is not you, ignore it completely.

SOCI Act

Care: Only if you are critical infrastructure

Australian critical infrastructure law. Covers energy, water, telco, transport, food, healthcare, education and designated mining assets. If this applies, your obligations are far beyond the SMB baseline and you need specialist help, not a checklist.

The honest summary for most Australian SMEs: do the Essential Eight properly, get certified to SMB1001 at Gold tier, and understand your Privacy Act obligations. That answers about 90% of what insurers, customers, and regulators will ever ask. Ignore the rest until someone specifically requires it of you.

What does it actually cost?

Real numbers, ex GST. Australian businesses, 2026 pricing. No "request a quote" nonsense.

The basics, done properly

$30 to $80 per user per month

Microsoft 365 Business Premium with proper backup, MFA, EDR, monitored patching and a real human to call. This is the floor for an Australian business that takes itself seriously.

Full managed IT and security

$120 to $250 per user per month

Everything above plus 24/7 monitoring (SOC), incident response, identity hardening, security awareness training, documented policies and quarterly reviews.

Co-managed with your internal IT

Varies

You keep your IT person or team. We bring the security operations centre, after-hours cover, vCISO advisory and the parts no SMB can hire for.

For context: the average ransomware incident at an Australian small business costs $50k to $250k once you add downtime, recovery, legal, insurance excess and lost customers. Cyber insurance premiums alone for a 50 person business are usually $5k to $15k a year. The cost of doing it properly is genuinely cheaper than the cost of not.

Or get someone else to do it for you

That is the entire reason businesses use a Managed Service Provider (MSP). You stop thinking about MFA enforcement, patching schedules, backup tests and admin reviews. Someone else does the boring, important work, and you get a phone number to call when something is wrong.

Quick answers to the questions everyone asks

Is this enough to be "secure"?

Nothing makes a business 100% secure. Doing the items in this guide puts you ahead of roughly 80% of Australian small and mid-sized businesses, defends against most automated attacks, and gives you a real chance of recovering when something does happen. That is what good looks like for an SMB.

Can we just do this ourselves?

You can do most of it yourself if you have the time, the discipline, and at least one technical person who actually owns it. Where most businesses come unstuck is the day-to-day: someone has to keep MFA enforced when staff change, test backups, review admin access, run patching, and respond to alerts at 11pm. That is what an MSP does.

We are 5 people. Do we really need all this?

Yes, but the version sized for 5 people is much smaller and cheaper than the version sized for 50. MFA, business email, backup, patching, EDR and a password manager are non-negotiable at any size. Everything else scales with headcount and risk.

My nephew/cousin/mate "does IT". Is that fine?

For setting up a printer, yes. For protecting the business from ransomware, business email compromise and notifiable data breaches under the Privacy Act, no. Cyber security in 2026 is not a part-time job. If something goes wrong, you need a documented chain of accountability, an insurer who will pay out, and someone you can sue if needed.

One last thing

The biggest mistake Australian business owners make is not the technical stuff. It is waiting until after a problem to take cyber seriously. Insurers know this. Attackers know this. Your customers will eventually figure it out too.

Doing the items on this page over the next 90 days puts you ahead of most businesses on your street. That is genuinely the goal.

Want someone else to just deal with all of this?

That is literally our job. We are an Australian MSP and MSSP. We do the boring, important security work for Australian businesses every day so the boss can get back to running the business.