Your inbox holds client conversations. Your website brings in enquiries. Your cloud drive stores the work you cannot afford to lose. These everyday tools deserve the same care you put into your business.

We helped a client set up professional Microsoft 365 email after they lost access to a hacked account. It was a frustrating, time-consuming process that disrupted their work for days. Email problems quickly become business problems, especially when clients are waiting on replies and invoices.

You do not need to become a cybersecurity expert to make meaningful improvements. Start with the accounts, devices and information you rely on most, then build habits that keep them protected. Australia's Cyber Security Centre recommends three starting points: multi-factor authentication, software updates and backups. This guide builds on those foundations.

43% of cyberattacks target small businesses Verizon DBIR 2024
60% of small businesses close within 6 months of a major cyberattack National Cyber Security Alliance
$39K average cost of a data breach for Australian SMBs IBM Cost of a Data Breach 2024

The "I'm too small to be a target" assumption is one of the most dangerous things a small business owner can believe. Automated attacks do not distinguish by business size. They scan for weak passwords, outdated software and unprotected accounts at scale, and they find them.

Most common attack vectors targeting small businesses % of small business incidents involving each method
Phishing
83%
Stolen credentials
49%
Ransomware
24%
Business email compromise
19%
Insider threat
9%

Source: Verizon Data Breach Investigations Report 2024. Percentages reflect incidents where the method was identified as a contributing factor.

1. Know what you own and who can access it

Before buying another security tool, make a simple register of your essential systems: email, domain registration, website hosting, social media, banking, accounting software and file storage.

For each one, record the account owner, authorised users, recovery contact and the person responsible for maintenance. Record where credentials are managed, rather than placing passwords in the register itself.

Ask yourself: if your laptop stopped working or a contractor became unavailable, could you still get into everything?

Give people their own accounts and only the access their role requires. Keep business ownership under your control, with delegated access for suppliers. Remove access when someone leaves, including connected apps and shared links.

Your next step: Check who currently has administrator access to your website, email and social accounts. Does every person still need it?

2. Give every account a unique password

Reusing one password creates a shared point of failure across every service that uses it. When one service gets breached and credentials are leaked, attackers try those same details everywhere else. It is called credential stuffing, and it is extremely common.

A password manager makes separate, strong passwords much easier to manage. Bitwarden is one option to consider. Its generator creates random passwords and passphrases, so you do not have to invent memorable variations of the same login.

Use a long, unique master passphrase for the vault and enable its two-step login. Save the recovery code somewhere secure that you can reach without opening the vault. Bitwarden recommends saving it immediately, with a safely stored printed copy as one option. Its two-step recovery code does not replace a forgotten master password.

Prefer individual user access over shared logins. Where sharing is unavoidable, use controlled password-manager sharing rather than email or chat.

Your next step: Replace reused passwords on your email, domain registrar and financial accounts first. Those three are the highest-risk.

3. Turn on MFA, and consider passkeys

Multi-factor authentication (MFA or 2FA) adds another proof of identity when you sign in. Even if someone steals your password, they cannot get in without the second factor. Start with email, your password manager, banking, domain registration and administrator accounts.

Where available, consider passkeys or FIDO2 security keys. Passkeys are tied to the legitimate service, making them resistant to fake-login-page phishing. Protect the device or account storing them, and arrange a backup method before relying on them.

Where passkeys are unavailable, an authenticator app is a useful alternative. Microsoft Authenticator and Google Authenticator are common examples. Never approve a sign-in notification you did not initiate, and never give someone a verification code because they claim to be support.

Your next step: Secure your main email account today, then work through the accounts that depend on it for password resets.

4. Plan for a lost phone before it happens

Extra security should not leave you permanently locked out. Extra steps at setup save you from a very bad day later.

For each critical account, confirm your recovery details and understand the provider's recovery process. Store backup codes securely, and avoid keeping the only copy inside the account they unlock. For hardware security keys, consider registering a spare and storing it separately.

Here is a useful scenario to test: your phone is lost while travelling. You have a replacement computer, but no access to your usual authenticator app. What happens next? Work through that answer before it becomes urgent. Write down the recovery process without exposing passwords in an ordinary document. Make sure an authorised person knows how to find it.

5. Treat business email as a critical system

Email often connects to password resets, invoices, client conversations and supplier payments. It is the master key to most of your other accounts. It deserves more than a strong password.

Microsoft 365 and Google Workspace are the main options for professional business email. The setup matters as much as the choice: individual accounts, appropriate administrator permissions, MFA and recovery arrangements all need attention from the start.

Ask your provider to review SPF, DKIM and DMARC. These help receiving mail systems assess whether messages using your domain are authorised. They reduce certain kinds of impersonation, but do not prevent every scam or protect a mailbox that has already been compromised.

Include every legitimate sender in your email authentication setup, such as your newsletter platform, booking software and website forms. Test and monitor before tightening DMARC policy, so genuine messages are not accidentally rejected.

Your next step: Ask who manages your domain's email authentication and when it was last checked. If nobody knows, that is the answer.

6. Make verification part of your payment process

A familiar sender name is not enough to trust a payment request. A criminal can impersonate a business, or use a genuinely compromised account to send a fraudulent invoice from a real email address.

If a supplier changes bank details, call them on a number you already trust from a previous invoice or your own records. Do not use the contact number supplied in the suspicious message. Where practical, require a second person to approve changes to payment details.

Use the same pause-and-check habit for unexpected account warnings. Open the service directly through your app or saved bookmark instead of following an urgent message's login link. For teams, make reporting easy. Someone should feel comfortable saying "I clicked something" immediately, without fear of being blamed.

Your next step: Agree on a simple rule with your team: changed payment details always get independently verified by phone before a transfer is processed.

7. Keep your devices and website maintained

Software updates often fix security weaknesses. Enable automatic updates where practical, and replace systems that no longer receive security support. Include browsers, phones, and business software in your checks. An outdated plugin on your website can be just as risky as an outdated operating system.

Use a strong device passcode, automatic screen locking and device encryption. Store encryption recovery information safely. Keep built-in security protection enabled, and do not disable it to make something more convenient.

For your website, agree with your developer on who maintains the platform, plugins and integrations. Remove unused components and former users. A website launch date should also come with an ongoing maintenance plan.

Your next step: Check for pending updates on the device you use for banking and business administration. Do it now, before you close this tab.

8. Check that your backups can actually restore your work

Having files in the cloud does not automatically mean you have recovery protection. Sync can copy accidental changes or damaged files between locations, overwriting your only good version. Check version history, retention limits and recovery options rather than assuming everything is recoverable.

Your backup plan should answer four questions: what is covered, how often it runs, how far back you can recover, and who can restore it. Include important email, client files and website data. Keep a protected copy that cannot easily be deleted through the same compromised account.

Then test it. Restore a sample file to a safe location and confirm the process works. Ask your website provider when they last tested a restoration.

Your next step: Choose one important document and check whether you can recover an earlier version. The test itself reveals whether your backup is working.

9. Use a VPN for the right reasons

NordVPN is one example of a commercial VPN you might consider when working remotely or using networks you do not control. A VPN encrypts traffic between your device and its VPN server and changes the public IP address websites see.

It does not make you anonymous or prevent every attack. It cannot stop you handing your password to a fake website, replace MFA, or make an infected computer safe. HTTPS already encrypts the connection to properly configured websites; a VPN adds protection on the network path and shifts some trust to the VPN provider.

Treat a VPN as an optional layer, not a foundation. Prioritise account security, updates and recovery first. Follow any client or employer requirements for connecting to their systems before choosing a VPN for that purpose.

10. Keep less sensitive information, and share it carefully

Privacy also depends on what you collect and who can see it. The OAIC recommends collecting only the personal information you genuinely need. Every extra copy of client data is another thing to protect.

Review enquiry forms, shared folders and old client exports. Use named-person access instead of public links for private material. Remove unnecessary copies in line with your retention obligations.

Before putting client information into a new AI tool, browser extension or transcription service, check the permissions, storage and data-use settings. Choose tools deliberately rather than granting broad access simply to try a feature.

Your next step: Review one shared client folder. Can anyone outside the intended team still open it? A quick permissions check takes two minutes.

Your first-week security checklist

Eight things to do this week. Tick them off as you go. Your progress is saved automatically in your browser.

First-week checklist 0 of 8 complete
  • Turn on MFA or passkeys for your most important accounts
  • Replace reused passwords and protect your password manager
  • Save recovery codes securely and review recovery contacts
  • Remove former staff, suppliers and unnecessary app access
  • Install outstanding updates and check device encryption
  • Confirm that a backup has completed and test a restoration
  • Introduce independent verification for changed bank details
  • Assign someone to review these checks regularly

Where to start: a priority matrix

Not everything is equally urgent. This grid shows which actions to tackle first based on effort and impact.

Easy + High Impact
Do first
  • Turn on MFA for email and banking
  • Set up a password manager
  • Enable automatic device updates
  • Save backup and recovery codes
Hard + High Impact
Plan it
  • Configure SPF, DKIM and DMARC
  • Set up a proper backup system
  • Migrate to Microsoft 365 or Workspace
  • Audit and tighten access across all accounts
Easy + Lower Impact
Fill time
  • Review shared folder permissions
  • Enable screen lock on all devices
  • Clear old browser sessions
  • Remove unused apps and extensions
Hard + Lower Impact
Consider
  • Set up a VPN for remote work
  • Enable advanced threat protection
  • Formal security policy documents
  • Staff security awareness training

What happens in the first 24 hours after an account is hacked

Understanding the typical timeline makes the urgency clearer. This is why responding quickly matters.

0 to 10 minutes
Credentials tested
Stolen login details are tried on your email, banking and social accounts using automated tools. Reused passwords multiply the risk immediately.
10 to 60 minutes
Email accessed and searched
The attacker searches for invoices, supplier names, bank details and password reset emails. Forwarding rules are often added to hide ongoing access.
1 to 4 hours
Password resets triggered
The attacker uses your email to reset passwords on connected accounts: cloud storage, accounting software, payment platforms and social media.
4 to 12 hours
Fraudulent messages sent
Your clients and suppliers receive invoices or payment requests from your address, often with changed bank details. The requests look completely legitimate.
12 to 24 hours
Discovery and damage assessment
You notice something is wrong. By now, multiple systems may be compromised, clients may have transferred funds, and evidence may already be deleted. Recovery is slow and expensive.

A practical toolkit to consider

The right setup depends on your business and how you work. These are options to evaluate, not a list every business needs to buy immediately.

Need Tool or approach What to check
Passwords Unique passwords for every account
Bitwarden
Protect the vault and store recovery information safely. Enable two-step login.
Sign-ins Stronger sign-in verification
Passkeys, security keys, Microsoft Authenticator or Google Authenticator
Choose supported methods and plan a recovery path for each account.
Email Professional business email
Microsoft 365 or Google Workspace
Configure permissions, MFA, recovery and domain authentication (SPF, DKIM, DMARC).
Network Network privacy for remote work
NordVPN
Understand its limits. A VPN does not replace MFA or strong passwords.
Backup Recoverable files and data
A backup service suited to your files and cloud systems
Check coverage, retention limits, access controls and whether you have actually tested a restore.
Think an account has been compromised?

Use a trusted device and contact your provider or IT support promptly. For compromised Microsoft 365 email, remediation can involve temporarily blocking the account, resetting credentials, revoking active sessions and checking for unauthorised MFA methods and forwarding rules. Changing the password alone may not remove every route back in.

If money is at risk, contact your bank immediately through an official channel. Preserve relevant messages and a timeline.

Australian Cyber Security Hotline 1300 292 371 Free. Available to Australian businesses. Report incidents at ReportCyber.

"You do not need to secure everything at once. Pick the three accounts you rely on most, secure them this week, then work outward from there. Small, consistent improvements are far more effective than one big security audit that never gets finished."

Need a hand getting the foundations right?

At Sonder, we help small businesses with professional email setup and migration, including Microsoft 365 and Google Workspace, as well as practical support with websites, domains and account access. If you are unsure where to start, we can help you work through the setup and identify where specialist IT or cybersecurity support might also be needed.