All resources

Cybersecurity Best Practices for Small Businesses

Three controls stop most attacks on a small business: multi-factor authentication, patching the right things first, and staff who know what to report.

3 min readUpdated 29 September 2026
Cybersecurity Best Practises

Small businesses in Australia get attacked because they are easy, not because they are interesting. Almost everything that gets through is opportunistic.

That is good news. Opportunistic attacks are stopped by ordinary measures, and three of them do most of the work.

1. Sort out passwords and accounts

Start with MFA. It is the highest value control you can switch on, and on its own it defeats most stolen password attacks. There is more detail in The Power of Multifactor Authentication.

Then fix how passwords get made and stored.

The old advice was to enforce complexity rules and change every password every 90 days. Both have since been dropped by the ACSC and by NIST, for the same reason. They pushed people towards predictable patterns, and “Spring2026!” is what that looks like in practice.

What works instead:

  • Long passphrases. Four or five unrelated words beat a short string of symbols.
  • A password safe, so nobody has to remember more than one of them. See The Importance of Password Safes.
  • Change a password when there is a reason, such as a breach or a departure. Not on a calendar.
  • Check new passwords against known breached lists. Most password safes and Microsoft 365 will do this for you.

One thing that gets missed. Remove accounts on the day someone leaves. An old account nobody watches is a favourite way in.

2. Patch, and patch the right things first

Outdated software is how most opportunistic attacks land. The attacker has not found a new flaw. They are scanning for an old one you never fixed.

Not every patch is equally urgent, so sort them:

  • Internet facing systems with a flaw being actively exploited. Hours, not weeks. The Essential Eight asks for 48.
  • Operating systems and browsers on staff devices. Within two weeks.
  • Everything else. A monthly cycle is fine.

Turn on automatic updates wherever you can. For a business with 20 or 30 devices, Microsoft Intune or a managed service will handle this properly and tell you when a machine falls behind. A spreadsheet will not.

Do not forget the things that are not computers. The firewall, the wifi access points, the NAS in the cupboard and the printer all run software, and they rarely get looked at.

3. Teach people what to look for

Your staff are the target, not the weak link. Phishing is a well funded industry now and the emails are good.

Run short sessions regularly rather than one long one a year that nobody remembers. Cover three things:

  • What a phishing email looks like today, including one that arrives from a supplier’s real but compromised mailbox.
  • Invoice fraud and changed bank details. Always verify by phone, on a number you already had.
  • MFA prompts nobody triggered. Never approve one, and always report it.

Then make reporting easy. If someone clicks a bad link you want to know within five minutes, not next week. That only happens if the answer to the first report is thanks rather than blame.

Where to go next

The ACSC publishes free, practical guidance for small business at cyber.gov.au. It is genuinely good, and it is written for people who do not work in IT.

If you want the next level up, the Essential Eight is the framework most Australian organisations get measured against. We wrote about what implementing it actually feels like in Essential 8 Lessons.

Element Digital offers IT consulting services in Hobart. If you would like a hand working out where you stand, get in touch.

Read it elsewhereMarkdownOpen in ClaudeOpen in ChatGPT

Read next

Ready to get started?

Let us talk about what you are trying to achieve, no obligation, just a conversation.

Get in touch