October is Cyber Security Awareness Month in Australia, and this year the national framing has shifted in a way that's actually worth noting: the emphasis is moving from awareness to sustained action — the recognition that knowing about threats does nothing on its own. A poster in the break room doesn't stop an attack. A habit does.
So instead of a list of scary statistics, here's the honest, practitioner's version: the five things that, done properly, stop the large majority of real attacks that actually hit small Australian businesses. None of them are exotic. Most are free or nearly so. All of them matter more than whatever product a vendor is selling this month.
1. Multi-factor authentication on everything — email first
If you do only one thing, do this. The single most common way a small business gets breached is a password — reused, guessed, phished, or bought from a previous leak. Multi-factor authentication means a stolen password alone isn't enough to get in.
Start with email, because email is the master key: whoever controls your inbox can reset the password on nearly everything else. Then extend it to banking, your domain registrar, your hosting, and any system holding customer data. And where you can, use phishing-resistant MFA — passkeys — because ordinary SMS and push-approval MFA can still be phished, while passkeys can't. This one control closes off the majority of account-takeover attacks by itself.
2. Keep everything patched
A large share of breaches start with a known vulnerability in software that had a fix available — sometimes for months. Attackers scan the internet constantly for unpatched systems, because it's the easiest way in that exists.
- Turn on automatic updates for operating systems and applications wherever you can.
- Pay special attention to anything internet-facing — your website, its plugins, any remote-access tools — because those are what gets scanned and hit first.
- Retire software that's no longer getting security updates. Unsupported software is a permanent open door that never gets fixed.
3. Real, tested backups
Backups are what turn a ransomware attack or a catastrophic mistake from a business-ending event into a bad day. But the key words are real and tested — a backup you've never restored from is a guess, and a backup an attacker can reach and delete is no backup at all.
The modern standard adds an immutable or offline copy specifically so ransomware can't destroy your recovery path, plus regular verification that you can actually restore. Our backup guide walks through exactly what that looks like for a small business. If you're not certain you could restore right now, that uncertainty is the thing to fix.
4. Restrict who has the keys
Not everyone needs to be an administrator, and every account with elevated access is a bigger prize — and a bigger risk — if it's compromised. The principle is simple: people should have the access their job needs, and no more.
- Use standard (non-admin) accounts for day-to-day work, reserving admin access for when it's genuinely needed.
- Review who has access to what periodically, and remove access promptly when someone leaves or changes roles.
- Protect the highest-value accounts hardest — domain registrar, hosting, banking, and whatever holds customer data.
5. Make your people threat-aware — about the real threats
Most attacks involve a human being doing something a well-crafted message convinced them to do. No technical control fully closes that gap, which is why awareness of the actual threats matters — not generic "be careful online," but the specific patterns that target businesses.
Top of that list is business email compromise — the invoice-redirection and impersonation fraud that costs Australian businesses more than almost anything else, and that no antivirus can catch because there's no malware involved. A team that knows to verify any change of payment details through a separate channel, and to treat urgency as a reason to slow down, is protected against the thing most likely to actually cost them money.
The through-line: notice that all five of these are the same controls that anchor formal frameworks like the Essential Eight — because they're what actually works, stripped of the compliance packaging. You don't need a certification or a consultant to start. You need to pick the weakest of these five in your business and fix it this month, then the next. That's what turning awareness into action actually means.
Frequently asked questions
When is Cyber Security Awareness Month in Australia?
Every October. It's a national campaign to encourage individuals and businesses to improve their cyber security, with the current emphasis on turning awareness into sustained, year-round action rather than one-off gestures.
What's the single most important thing a small business can do for cyber security?
Enable multi-factor authentication everywhere, starting with email — ideally phishing-resistant MFA like passkeys. A stolen password alone is the most common way in, and MFA closes off the majority of account-takeover attacks by itself.
Do I need to spend a lot of money to be reasonably secure?
No. The five highest-impact controls — MFA, patching, tested backups, restricted admin access, and staff awareness — are mostly free or low-cost. They matter far more than most paid security products for a typical small business.
Is antivirus enough to protect my business?
No. Many of the most costly attacks on small businesses — particularly business email compromise and invoice fraud — involve no malware at all, so antivirus has nothing to detect. Process and authentication controls matter as much as, or more than, endpoint software.
Want a straight, no-sales-pitch read on where your business actually stands? Get in touch.
Get in touch →