Cyber Security

Small Business Cyber Security: 10 Practical Ways to Protect Your Business

Cyber security is no longer something only large companies need to worry about.

Small businesses hold valuable information, process payments, use cloud services, communicate with suppliers and customers, and often depend heavily on email and online systems to operate.

That makes them attractive targets for cybercriminals.

The good news is that improving cyber security does not necessarily require expensive equipment or a large IT department. A relatively small number of sensible controls can prevent many of the attacks commonly directed at Australian small businesses.

Why are small businesses targeted?

Attackers do not necessarily target a business because it is large or famous. Many cyber attacks are automated and search the internet for vulnerable accounts, websites and systems.

Small businesses can also be attractive because they may have fewer security controls while still having access to money, customer information and other businesses in their supply chain.

Common threats include:

  • Phishing and fake login pages
  • Business email compromise
  • Fraudulent invoices and payment redirection
  • Stolen passwords
  • Ransomware
  • Malware
  • Compromised websites
  • Unauthorised remote access
  • Lost or stolen computers and phones

1. Protect Important Accounts

Turn on multi-factor authentication

Multi-factor authentication, or MFA, is one of the most effective security improvements a small business can make.

MFA requires another form of verification in addition to a password. This makes it significantly harder for an attacker to access an account using a stolen password alone.

Start with your most important accounts, including:

  • Business email
  • Microsoft 365 or Google Workspace
  • Internet banking
  • Accounting systems
  • Cloud storage
  • Domain name and website administration
  • Social media accounts
  • Remote access systems

Where supported, authentication applications, passkeys and security keys can provide stronger protection than relying entirely on SMS codes.

2. Stop Reusing Passwords

Use unique passwords and a password manager

Every important account should have a different password. If the same password is reused, one compromised service can potentially expose several other accounts.

Use a reputable password manager. It can generate and securely store long, random passwords so staff do not have to remember them.

Protect the password manager itself. Use a strong master passphrase and multi-factor authentication.

Avoid passwords in spreadsheets or notebooks. Password lists stored insecurely can defeat otherwise good security.

3. Know Who Has Access

Give each staff member their own account

Shared usernames and passwords may be convenient, but they create significant security problems.

If five employees use the same account, it can be difficult to determine who performed an action or whether someone outside the business has gained access.

Wherever possible, give each person an individual account and only provide access to the systems they actually require.

When an employee leaves, their access should be removed promptly rather than simply relying on them no longer using the account.

4. Limit Administrator Access

Not everyone needs to be an administrator

Administrator accounts have the ability to make significant changes to computers, networks and cloud systems.

Staff should generally have only the access required to perform their jobs. Administrative access should be limited to people who genuinely need it.

This reduces the potential damage if a staff account becomes compromised.

Where practical, people responsible for administration should use a separate administrator account for those tasks rather than using a highly privileged account for everyday email and web browsing.

5. Keep Systems Updated

Install security updates promptly

Software vulnerabilities are regularly discovered in operating systems, applications, routers, network equipment and other devices.

Security updates repair these vulnerabilities.

Enable automatic updates wherever practical and make sure you are updating more than just desktop computers.

Check:

  • Windows and macOS computers
  • Phones and tablets
  • Web browsers
  • Office applications
  • Routers and firewalls
  • NAS devices
  • Servers
  • Website software and plugins
  • Security cameras and other network-connected devices

Equipment that no longer receives security updates should be considered for replacement.

6. Protect Your Email

Teach staff to recognise phishing

Email remains a major attack path. An attacker may impersonate a bank, supplier, manager, Microsoft, courier company or government department.

Be suspicious of unexpected login requests. Instead of clicking the supplied link, open the service directly through its normal website or application.

Be careful with attachments. Unexpected invoices, shared documents and compressed files can be used to deliver malicious software.

Do not rely on spelling mistakes. Modern phishing messages can be professionally written and highly convincing.

Phishing works because it attacks people rather than technology. Staff should feel comfortable questioning unusual requests rather than being pressured into acting quickly.

7. Protect Payments

Independently verify changes to bank details

One of the most damaging scams affecting businesses is payment redirection.

An attacker may compromise the email account of a supplier or customer, monitor existing conversations and then alter bank account details when an invoice is due to be paid.

The email can be completely genuine because it may actually come from the compromised supplier's real account.

Establish a simple business rule:

Any change to bank account details must be independently verified before payment.

Call the supplier using a phone number already known to your business. Do not rely on a telephone number supplied in the email requesting the change.

This simple procedure can prevent a very expensive mistake.

8. Prepare for the Worst

Maintain proper backups

Backups protect against more than cyber attacks. They can also help recover from equipment failure, accidental deletion, theft and human error.

A business backup strategy should answer several questions:

  • What information is being backed up?
  • How often does the backup run?
  • Where is the backup stored?
  • Can ransomware access or modify the backup?
  • How long are previous versions retained?
  • Who checks that backups are actually working?
  • Has the business tested restoring its data?

A backup that has never been tested should not automatically be assumed to work.

Cloud storage can be useful, but synchronisation and backup are not necessarily the same thing. If damaged or encrypted files are automatically synchronised, the damage may also be synchronised.

9. Secure Your Network

Do not forget routers, Wi-Fi and remote access

Business cyber security extends beyond computers.

Routers, Wi-Fi access points, network storage, security systems and remote access services can all create potential paths into a network.

Basic precautions include:

  • Change default administrator passwords
  • Use strong Wi-Fi encryption
  • Keep network equipment updated
  • Separate guest Wi-Fi from important business systems
  • Disable services that are not required
  • Review anything that can be accessed directly from the internet
  • Use MFA for remote access wherever possible

Remote Desktop, VPN systems and other externally accessible services deserve particular attention because a vulnerability or stolen password can potentially provide direct access to the business network.

10. Have a Plan

Know what you will do when something goes wrong

Who do staff contact? Employees should know who to tell if they click a suspicious link, lose a device or notice unusual activity.

Who can disable accounts? Someone needs to know how to quickly suspend compromised email and cloud accounts.

Who controls your domain and website? Keep important provider and account information available.

How will you operate if computers are unavailable? Consider what would happen if key systems were offline for a day or several days.

Keep important contact details offline. An incident plan stored only on the computer that has just been encrypted by ransomware is not particularly useful.

Do not overlook staff mobile phones

Phones now provide access to business email, cloud storage, authentication applications, banking and workplace messaging systems.

A personal phone connected to business systems is therefore part of the organisation's cyber security.

Business owners should consider requirements for screen locks, software updates, multi-factor authentication and the removal of business access when a phone is lost or an employee leaves.

Staff should also avoid approving unexpected authentication requests, even if the notification appears to come from a legitimate business service.

Your website also needs maintaining

Business websites are public-facing systems and therefore constantly exposed to the internet.

Keep your content management system, extensions and other website software updated. Remove extensions and user accounts that are no longer required.

Administrator accounts should use strong unique passwords and multi-factor authentication where supported.

Regular website backups are also important so the site can be restored following a compromise, failed update or other problem.

Have an employee exit procedure

Cyber security should be part of the process whenever an employee or contractor leaves the business.

Review and remove access to:

  • Email accounts
  • Cloud storage
  • Accounting systems
  • CRM systems
  • Remote access
  • Social media
  • Website administration
  • Password managers
  • Security and access control systems

Shared passwords known by the departing person should also be changed.

What about the Essential Eight?

The Australian Signals Directorate recommends the Essential Eight as a baseline set of cyber security mitigation strategies for Australian organisations.

These cover application and operating system patching, multi-factor authentication, restricting administrative privileges, application control, Microsoft Office macro controls, user application hardening and regular backups.

For a small business that has already implemented the basic measures in this article, the Essential Eight provides a useful framework for taking security to the next level.

Small business cyber security checklist

Enable multi-factor authentication on important accounts.

Use unique passwords and a reputable password manager.

Give staff individual accounts rather than sharing logins.

Restrict administrator privileges.

Enable automatic security updates where practical.

Train staff to recognise phishing and suspicious requests.

Independently verify changes to supplier bank details.

Maintain and test regular backups.

Secure Wi-Fi, routers and remote access.

Create a basic cyber security incident response plan.

Cyber security does not need to be complicated

Small businesses do not need to become cyber security experts, but they do need to manage the basics consistently.

Strong account security, reliable backups, current software, sensible access controls and staff who know when to question something unusual can prevent a large proportion of common cyber incidents.

The aim is not to make a business impossible to attack. No system can provide that guarantee.

The goal is to make compromise significantly more difficult, detect problems quickly and ensure the business can recover when something does go wrong.

Further information

The Australian Signals Directorate's Australian Cyber Security Centre provides dedicated cyber security guidance, checklists and resources for Australian small businesses.

Australian Cyber Security Centre: Small Business Cyber Security