Free checklist · PDF download

The Cyber Security Checklist for Australian Small & Mid-Sized Businesses

Most SMB breaches come down to the same handful of gaps: a reused password, an unpatched laptop, a convincing invoice email, a backup that was never tested. This free 30-point checklist covers the five domains where Australian small businesses are actually breached — so you can score yourself honestly in under an hour and know exactly where to spend first.

Aligned to ACSC guidance and the Essential Eight Covers Privacy Act and NDB obligations

Why a checklist, and why now

The ACSC receives a cybercrime report roughly every six minutes, and small business is the most reported category. The pattern behind most incidents is not sophisticated — it is a known gap that nobody had written down. A checklist turns “we think we’re covered” into a scored, evidence-based answer you can hand to your accountant, your insurer or your board.

What the checklist covers

  • Identity and access — MFA, shared accounts, offboarding and privilege control.
  • Devices and software — patching, encryption, unsupported systems and device inventory.
  • Email and phishing — domain spoofing protection, payment verification and staff reporting culture.
  • Data and backups — isolated backups, tested restoration and Privacy Act data awareness.
  • Incident readiness — a written plan, named contacts, NDB obligations and tabletop practice.

How to score yourself

Mark each item as in place and evidenced, partially in place, or not in place. Any domain where fewer than half the checks pass is where your next security dollar should go. If you would like a second set of eyes, bring your completed checklist to us and we will prioritise it with you — straight answers, no sales sequence.

FREE RESOURCE

The Cyber Security Checklist for Australian SMBs

Thirty practical checks across the five domains where small and mid-sized Australian businesses are actually breached — identity, devices, email, data and incident readiness — ordered so you can score yourself in under an hour.

01

Identity and access — lock the front door

Compromised credentials cause most SMB breaches. These checks confirm the right people have the right access — and nobody else does.

  • MFA is enforced on every email account, cloud service and remote access path — no exceptions for owners or executives
  • Every person has their own account; no shared logins for email, accounting or line-of-business systems
  • Admin rights are limited to a small named group and never used for day-to-day email or browsing

+3 further checks in the download

02

Devices and software — close the known holes

Attackers scan for unpatched, unsupported systems within hours of a vulnerability being published. These checks keep the estate current.

  • Automatic updates are on for every operating system, browser and business application
  • No device runs an unsupported operating system (anything out of vendor support is replaced or isolated)
  • Every laptop and desktop has full-disk encryption enabled and verified

+3 further checks in the download

03

Email and phishing — defend the inbox

Email is the number one delivery method for attacks on Australian SMBs. These checks reduce both delivery and impact.

  • SPF, DKIM and DMARC are configured on the business domain so attackers cannot spoof your email address
  • Staff are trained to verify payment and bank-detail changes by phone on a known number — never by reply email
  • Invoice and bank-detail change requests require a second person to approve before payment

+3 further checks in the download

04

Data and backups — survive the worst day

Ransomware is survivable when backups are clean, isolated and tested. These checks make recovery a plan, not a hope.

  • Critical business data is backed up automatically on a documented schedule
  • At least one backup copy is isolated from the main network (offline or immutable cloud storage)
  • A restoration has been tested in the last 90 days — timed, and the result written down

+3 further checks in the download

05

Incident readiness and people — be ready before it happens

The difference between a bad week and a business-ending event is preparation. These checks cover the human and planning side.

  • A written incident response plan exists and names who makes decisions, who calls customers, and who calls the ACSC
  • Key contacts are documented: IT provider, cyber insurer, lawyer, and the ACSC hotline (1300 CYBER1)
  • You know your reporting obligations — the Notifiable Data Breaches scheme requires notifying the OAIC and affected individuals

+3 further checks in the download

Get the checklist

PDF · No cost

Native secure submission. Your details are never sold or shared.

A senior advisor responds within one business day — no sales sequence.

Get the SMB cyber checklist

Free PDF · reply within one business day

Get it