Startup.help
Risk & Security

Cyber Security and Privacy for Australian Small Business: A Practical Guide

Published
24 Aug 2026
Reading time
12 min
Type
OPERATIONS GUIDE

Small businesses are rarely targeted because someone chose them. They are targeted because attacks are automated and cheap to run at scale. A credential-stuffing script does not know whether it is hitting a national retailer or a two-person landscaping business; it works through passwords leaked from unrelated breaches and tries them everywhere. Invoice fraud runs on whatever inbox happens to be accessible. You are in the blast radius whether or not anyone picked you out.

That changes what you should do about it. If you imagine a determined adversary studying your business, the response feels like expensive tools and expert advice. If you accept that the realistic threat is opportunistic, the response is to be a harder target than the automated baseline — which, unglamorously, means multi-factor authentication, backups that work, software that updates itself, and staff who pause before clicking. None of that is interesting. All of it works.

This guide is for an Australian owner with no IT department and no appetite for reading a security framework. It draws on the Australian Cyber Security Centre (ACSC) at cyber.gov.au, Scamwatch, the Office of the Australian Information Commissioner (OAIC), and the cyber security checklist on business.gov.au.

The short version

If you do nothing else, do the top three rows. They are ordered by loss prevented per hour of effort.

#ControlEffortWhat it prevents
1MFA on business email and bankingAn hour, onceAccount takeover from stolen or reused passwords — the entry point for most incidents
2Verify bank detail changes by phone, on a number you already hadA policy, two minutes per changeInvoice fraud, typically the largest single loss
3Backups you have actually restored fromHours to set up, an hour twice a year to testRansomware, hardware failure, deletion
4Automatic updates on systems, browsers and appsHalf an hour to switch onExploitation of known, already-patched flaws
5A password manager for the teamAn afternoonPassword reuse, shared logins in spreadsheets
6Staff who recognise phishingAn hour at induction, ten minutes a quarterThe click that starts almost everything else
7Access removal when someone leaves20 minutes per departureLingering access to email, files and banking
8A one-page written incident planTwo hours, oncePanic, delay and destroyed evidence

Nothing below this table beats doing the things in it.

Multi-factor authentication

Multi-factor authentication (MFA) means a password alone is not enough — a second factor is required, usually a code from an app or a physical security key. It defeats the most common attack outright. Passwords leak constantly from services with no connection to you, and attackers try the same combinations everywhere because people reuse them. With MFA on, a correct password gets an attacker nowhere.

Where to turn it on first

  1. Business email. The master key. Whoever controls it can reset the password on nearly every other service you use, read your invoice history and impersonate you convincingly.
  2. Online banking and payment platforms. Confirm every authorised user has it, not just the owner.
  3. Accounting software. Xero, MYOB, QuickBooks and similar hold bank feeds, payroll, supplier details and customer data.
  4. Your domain registrar and DNS. Rarely thought about, catastrophic if lost — control of your domain means control of your email. If you cannot remember who your registrar is, find out today.
  5. Cloud file storage, website admin and social accounts.

App-based versus SMS

An authenticator app is meaningfully safer than SMS, because SMS can be defeated by SIM swap fraud, where an attacker convinces a telco to move your number to their device. Hardware keys are stronger again and worth it for the owner's email and banking. That said, SMS MFA is dramatically better than nothing — if a service offers only SMS, turn it on rather than leaving the account with no second factor.

Passwords and the manager problem

A password manager — 1Password, Bitwarden, Keeper and others have small business tiers at a few dollars per user per month — solves three problems at once. It generates long unique passwords so one breach does not cascade. It lets you share a login without emailing it around or keeping it in a spreadsheet called logins.xlsx. And when someone leaves you revoke their vault, rather than trying to remember what they knew. For the few passwords you must remember yourself, follow the ACSC's passphrase advice: long, unpredictable, never reused.

Invoice and payment fraud

This is the pattern that costs Australian small businesses the most money. It is usually called business email compromise, and Scamwatch reports it under payment redirection scams.

The mechanics are unremarkable, which is why it works. An attacker gains access to an email account — yours, your supplier's, or your customer's — usually through phishing or a reused password, then reads quietly for days or weeks, learning who pays whom and how invoices are worded. Then they wait for a real invoice, or produce one that looks exactly like a real one, and change the bank account details.

Nobody is asked to do anything unusual. Someone in accounts pays an invoice that looks entirely legitimate, from a supplier they know, for work that genuinely happened. The money is gone within hours.

How it reads

Hi Sarah,

Please find attached invoice #4471 for the March works, as discussed.

Note that we've recently changed banks — our new account details are on the invoice. Apologies for the inconvenience, our old account is now closed so payments to it will bounce back.

Could you confirm once processed? We're closing out the quarter this week.

Thanks, Dave

Nothing there is alarming. The banking change reads as routine, the mild time pressure is the kind every business exerts at quarter end, and the sender may genuinely be Dave's compromised account — so the address, signature and thread history are all real. This is why "look for spelling mistakes" is useless advice against this attack.

The rule that stops it

Any change to bank details is verified by phone, on a number you already had, before payment. Not the number on the invoice, in the signature, or in the reply — a number from your own records, a previous contract, or the supplier's website that you navigated to yourself. Attackers anticipate the callback and put their own number on the altered invoice. The whole control rests on the number being one you already had.

Supporting practices:

  • Write the rule down and apply it to everyone, including the owner. Fraudsters routinely impersonate the boss requesting an urgent transfer.
  • Require two people for payments above a threshold you choose. Even in a small team, "whoever enters it does not release it" removes an entire class of loss.
  • Add a line to your own invoices: "Our bank details never change. If you receive notice that they have, phone us on the number on our website before paying."
  • Apply the same rule to payroll bank detail changes — redirecting an employee's salary is the same scam at smaller scale.

If you have already paid a fraudulent invoice, contact your bank immediately. Funds can sometimes be recalled or frozen while still in the receiving account, and every hour reduces the chance. Report to Scamwatch and ReportCyber afterwards, but call the bank first.

Backups that actually work

Backups turn a catastrophe into a bad week. They are also the control most likely to be quietly broken when you need it.

The shorthand is 3-2-1: keep three copies of anything you cannot afford to lose, on two kinds of storage, with one kept somewhere else entirely and not permanently connected to the machine it protects.

That last part is what ransomware turns on. It deliberately seeks out connected backup drives and mapped network shares, so a USB drive permanently plugged into the office computer is not a backup — it is a second victim. Either rotate physical drives and store one offsite, or use a cloud backup with versioning so you can restore to a point before the encryption started.

What cloud software does and does not do for you

There is a widespread and expensive assumption that cloud software means backups are handled. Reputable vendors — Microsoft 365, Google Workspace, Xero, Dropbox — maintain infrastructure redundancy better than you would. What they generally do not protect you against is you: a staff member deleting a folder, a compromised account destroying data deliberately, or a mailbox purged and emptied. Most platforms keep deleted data recoverable for a limited window, then remove it permanently.

That usually means adding a third-party backup for email and cloud file storage, and separately exporting anything from your accounting system you would want in a hurry.

The restore test nobody does

A backup that has never been restored is a hypothesis. Twice a year, restore a real file and a real system, and note what you needed and did not have — a password, a licence key, an admin account. This is also the moment to answer the question that determines your survival: how long can you operate without your systems, and how much data can you afford to lose? If the answer is "half a day" and your backup runs weekly to a drive in the same building, you have found your gap.

The rest of the Essential Eight, translated

The ACSC publishes the Essential Eight, a set of mitigation strategies with maturity levels. It was designed with larger organisations in mind, and not all of it is proportionate for a five-person business.

Essential Eight strategyWhat it means for youPriority with no IT team
Patch applicationsAutomatic updates for browsers, Office, PDF readers, business appsHigh
Patch operating systemsWindows, macOS, iOS, Android updated promptly; retire unsupported devicesHigh
Multi-factor authenticationCovered aboveHighest
Restrict admin privilegesDaily work on a standard account; admin used only when neededMedium
Application controlOnly approved software can runLow — usually disproportionate without IT support
Restrict Office macrosBlock macros from the internet; most small businesses never need themMedium — easy win
User application hardeningDisable unneeded plug-ins, block web content that runs codeMedium — a current browser and ad blocker gets most of it
Regular backupsCovered aboveHighest

Do not be discouraged by maturity levels. "Patching happens automatically and MFA is on everywhere" is a genuinely strong position, and more than many larger organisations achieve. The cyber security checklist on business.gov.au is a shorter starting point.

The human and device layer

Staff and phishing

Training does not need to be a course. It needs to produce one behaviour: when an email creates urgency and asks you to click, log in, or pay something, slow down and verify through a separate channel. That single reflex covers phishing, invoice fraud and most impersonation. Use examples from your own inbox, and make it explicitly safe to report a suspected click — the worst outcome is someone who clicked, felt embarrassed and said nothing for three days.

Your business email account specifically

  • MFA on every mailbox, not just the owner's.
  • Check for mail forwarding rules you did not create. Attackers commonly add a hidden rule copying incoming invoices to an external address, and it survives a password reset.
  • Review which third-party apps can access the mailbox and revoke anything unrecognised.
  • Ask whoever manages your domain to configure SPF, DKIM and DMARC records, which make it materially harder to spoof email from your domain. It takes an IT provider under an hour.

Devices, and when one goes missing

Assume a phone or laptop will eventually be lost or stolen. What makes that a nuisance rather than a breach is set up beforehand: a PIN or biometric lock, full-disk encryption (BitLocker, FileVault, default on modern phones), and remote wipe enabled.

When it happens, wipe or lock the device remotely, change passwords for accounts signed in on it, sign out all sessions, and record what data was on it — that determines whether it is a notifiable breach. An encrypted, locked laptop is a very different situation from an unencrypted one holding a customer spreadsheet.

When someone leaves

Keep a written offboarding checklist, because departure is when you are least likely to think clearly. Cover: disabling the email account (forward rather than delete), removing access to accounting, file storage, the website, social accounts and the password vault, removing them as an authorised banking user, collecting devices and keys, and changing shared passwords that cannot be individually revoked. The same applies to contractors and your bookkeeper.

Suppliers and cloud software

Every system you connect is part of your attack surface. Before adopting something that will hold customer data, ask three questions: where is the data stored, what happens to it if we leave, and do they support MFA and per-user accounts? A vendor who cannot answer quickly is telling you something. Review connected apps annually — most businesses accumulate integrations they no longer use, each still holding access to their files.

Your privacy obligations

Security and privacy overlap but are not the same. Security is about keeping data safe; privacy law is about what you are permitted and obliged to do with it, and it carries legal consequences.

What counts as personal information

Personal information is information about an identified individual, or one who is reasonably identifiable. That is broader than most owners assume: customer names and contact details, but also delivery addresses, appointment histories, photographs, employee records, and data that identifies someone when combined with other information you hold. Sensitive information, including health information, is a subcategory with stronger protections.

Who the Privacy Act covers

Two routes bring a business under the Privacy Act 1988 and the Australian Privacy Principles.

The first is size: most businesses with an annual turnover above the small business turnover threshold are covered. There is a threshold figure, it changes, and it has specific rules about how it is calculated — so confirm your position with the OAIC rather than working from what someone told you.

The second route catches businesses regardless of turnover, and this is the part that surprises people. It includes businesses that provide a health service and hold health information — which sweeps in allied health practices, NDIS providers, natural therapists and aged care providers even when they are very small — along with businesses that buy or sell personal information, credit providers, and contracted service providers under a Commonwealth contract.

If you handle health information in any form, assume you are covered and verify with the OAIC. Privacy law has also been under active reform, so check rather than relying on advice from a few years ago.

The Notifiable Data Breaches scheme

Organisations covered by the Privacy Act must notify both the OAIC and the affected individuals about an eligible data breach: unauthorised access to, unauthorised disclosure of, or loss of personal information you hold, which is likely to result in serious harm to any of the individuals concerned, and where you have not been able to prevent that likely harm through remedial action.

Serious harm is assessed on circumstances, not a fixed list. In practice it means asking what could realistically be done to this person with this information. Identity theft from a leaked driver licence and Medicare number is serious harm; so is financial loss from exposed banking details, and so is significant psychological or reputational harm — a leaked client list from a mental health practice can cause real damage without a cent moving. Whether the data was encrypted and how quickly you recovered it also bear on the assessment.

If you suspect an eligible breach but are not certain, you are expected to assess expeditiously; the scheme sets an outer limit of 30 days, a maximum rather than a target. Penalties for serious or repeated interference with privacy are substantial, and the OAIC is authoritative on both the scheme and the consequences of non-compliance. Notification is not merely a formality either — telling affected people promptly, with specific advice on what to do, is also what most reduces the harm.

If it happens

Print this. Put it somewhere that does not require a working computer to read.

  1. Contain it. Reset passwords on affected accounts, sign out all sessions, disable compromised accounts and remove unauthorised mail forwarding rules. Disconnect a compromised device from the network, but do not switch it off if you can avoid it.
  2. Call your bank immediately if money is involved. This outranks everything else once funds have moved. Recall is sometimes possible in the first hours and rarely later. Ask them to attempt a recall and flag the receiving account.
  3. Preserve evidence. Do not wipe or rebuild devices before someone competent has examined them. Screenshot the suspicious emails, keep the full headers, and log times and actions — you will need it for insurers, the bank and the OAIC.
  4. Work out what was affected. Which accounts, which devices, whose data. This determines everything that follows.
  5. Assess whether it is notifiable. Apply the eligible data breach test above. If you are covered by the Privacy Act and unsure, get advice quickly.
  6. Notify if required. Prepare a statement for the OAIC and notify affected individuals — what happened, what information was involved, and what they should do about it.
  7. Report it. Lodge a report through ReportCyber at cyber.gov.au, and report scams and payment redirection to Scamwatch. Reporting rarely recovers money, but it feeds the intelligence that shuts these operations down.
  8. Tell the people who need to know. Your insurer, since most policies require prompt notification and many include response support you have already paid for; your accountant if financial systems are involved; and anyone your compromised email may have been used to defraud.
  9. Review, then fix the gap. A week later, write half a page: what happened, how it got in, what you changed. Then change it.

Write the plan before you need it

Your incident plan can be one page: who decides, who to call (bank, insurer, IT support, accountant, lawyer), where the backups are and who can restore them, where account recovery details are held, and what you tell customers. Keep a copy offline — a plan stored only in the email account you have just lost is not a plan. The emergency management and risk analysis templates on business.gov.au are a reasonable structure if you would rather not start from blank.

Government tools and templates referenced are © Commonwealth of Australia, licensed under CC BY 3.0 AU.

Cyber insurance

Cyber insurance is worth pricing for most businesses that hold customer data or take payments, but buy it with clear eyes about what it does.

In general terms, policies typically respond to the cost of the incident rather than only the loss itself: forensic investigation, legal advice, notifying affected individuals, data restoration, and business interruption while you are down. Many also cover third-party liability if someone sues you over their data. For a small business the most valuable component is often the incident response panel — a phone number that gets you forensic and legal help at the moment you have no idea who to call.

What policies exclude matters just as much. Losses from social engineering and funds transfer fraud — the invoice scam above — are frequently excluded from base cover, or offered as an extension with a much lower sub-limit than the headline figure. Insurers may also decline where you failed to maintain basic controls you told them you had, so answer the application questions about MFA and backups honestly.

Read the Product Disclosure Statement rather than the brochure. Check the sub-limits, not just the total, and specifically ask how the policy responds to a fraudulently altered invoice. If you do not have a broker, the adviser finder on business.gov.au can point you to accredited advisers.

Frequently asked questions

Does the Privacy Act apply to my small business? It depends on your turnover and what information you handle. Most businesses above the small business turnover threshold are covered, and some are covered regardless of turnover — including those holding health information, which captures many allied health practices and NDIS providers even when very small. Confirm your position with the OAIC.

What do I do first if we have been breached? Contain before you investigate: reset passwords, revoke sessions, disconnect infected devices, and if money has moved, call your bank immediately. Do not wipe devices before someone has examined them. Then assess whether it is an eligible data breach, report through ReportCyber, and notify affected people if required.

Is cyber insurance worth it? For most businesses holding customer data or taking payments, it is worth pricing. The real value is incident response support at the moment you least want to be shopping for forensic investigators. It typically will not make you whole for money you transferred to a fraudster. Read the Product Disclosure Statement.

Is SMS two-factor authentication good enough? Much better than nothing — if it is the only option, turn it on today. But SMS can be intercepted through SIM swap fraud, so use an authenticator app or hardware key where available, especially for email, banking and your domain registrar.

How often should I test that backups restore? Twice a year, and after any significant change. Testing means restoring a file or system to working order, not checking that the job reported success. Discovering a corrupt backup mid-incident is why this advice keeps being repeated.

Do I need to worry if I only use cloud software? Yes — the risk shifts rather than disappears. Vendors handle infrastructure security; they do not handle your accounts, and most platforms permanently delete data after a limited retention window. Your job is account security, access control, and an independent backup.


This article is general information only, current as at the date of publication. It is not legal, financial, insurance or compliance advice, and it is not a statement of your obligations. Cyber threats, government guidance and privacy law all change; verify current guidance directly with the source. For cyber security guidance and to report an incident, refer to the Australian Cyber Security Centre at cyber.gov.au and ReportCyber. For scams and payment redirection fraud, refer to Scamwatch. For privacy obligations, whether the Privacy Act applies to your business, and the Notifiable Data Breaches scheme, the Office of the Australian Information Commissioner is authoritative. For advice specific to your circumstances, consult a qualified legal practitioner, your insurance broker, or an accredited business adviser. Startup Help is not affiliated with or endorsed by any government agency or product mentioned.

Disclaimer

General information only — not financial, legal or tax advice. Confirm anything here with a registered tax agent or advisor before acting on it.