Why a checklist, and why now
The ACSC receives a cybercrime report roughly every six minutes, and small business is the most reported category. The pattern behind most incidents is not sophisticated — it is a known gap that nobody had written down. A checklist turns “we think we’re covered” into a scored, evidence-based answer you can hand to your accountant, your insurer or your board.
What the checklist covers
- Identity and access — MFA, shared accounts, offboarding and privilege control.
- Devices and software — patching, encryption, unsupported systems and device inventory.
- Email and phishing — domain spoofing protection, payment verification and staff reporting culture.
- Data and backups — isolated backups, tested restoration and Privacy Act data awareness.
- Incident readiness — a written plan, named contacts, NDB obligations and tabletop practice.
How to score yourself
Mark each item as in place and evidenced, partially in place, or not in place. Any domain where fewer than half the checks pass is where your next security dollar should go. If you would like a second set of eyes, bring your completed checklist to us and we will prioritise it with you — straight answers, no sales sequence.