- 43% of cyberattacks target small businesses, yet most owners assume they are too small to be a target
- Phishing accounts for 83% of attacks on small businesses; email is the biggest entry point
- MFA, a password manager, and a tested backup are the three most impactful things you can do today
- The ACSC's free cybersecurity hotline (1300 292 371) is available to Australian businesses right now
- You do not need to be a security expert. You need consistent habits and clear ownership of accounts
Your inbox holds client conversations. Your website brings in enquiries. Your cloud drive stores the work you cannot afford to lose. These everyday tools deserve the same care you put into your business.
We helped a client set up professional Microsoft 365 email after they lost access to a hacked account. It was a frustrating, time-consuming process that disrupted their work for days. Email problems quickly become business problems, especially when clients are waiting on replies and invoices.
You do not need to become a cybersecurity expert to make meaningful improvements. Start with the accounts, devices and information you rely on most, then build habits that keep them protected. Australia's Cyber Security Centre recommends three starting points: multi-factor authentication, software updates and backups. This guide builds on those foundations.
The "I'm too small to be a target" assumption is one of the most dangerous things a small business owner can believe. Automated attacks do not distinguish by business size. They scan for weak passwords, outdated software and unprotected accounts at scale, and they find them.
Source: Verizon Data Breach Investigations Report 2024. Percentages reflect incidents where the method was identified as a contributing factor.
1. Know what you own and who can access it
Before buying another security tool, make a simple register of your essential systems: email, domain registration, website hosting, social media, banking, accounting software and file storage.
For each one, record the account owner, authorised users, recovery contact and the person responsible for maintenance. Record where credentials are managed, rather than placing passwords in the register itself.
Ask yourself: if your laptop stopped working or a contractor became unavailable, could you still get into everything?
Give people their own accounts and only the access their role requires. Keep business ownership under your control, with delegated access for suppliers. Remove access when someone leaves, including connected apps and shared links.
2. Give every account a unique password
Reusing one password creates a shared point of failure across every service that uses it. When one service gets breached and credentials are leaked, attackers try those same details everywhere else. It is called credential stuffing, and it is extremely common.
A password manager makes separate, strong passwords much easier to manage. Bitwarden is one option to consider. Its generator creates random passwords and passphrases, so you do not have to invent memorable variations of the same login.
Use a long, unique master passphrase for the vault and enable its two-step login. Save the recovery code somewhere secure that you can reach without opening the vault. Bitwarden recommends saving it immediately, with a safely stored printed copy as one option. Its two-step recovery code does not replace a forgotten master password.
Prefer individual user access over shared logins. Where sharing is unavoidable, use controlled password-manager sharing rather than email or chat.
3. Turn on MFA, and consider passkeys
Multi-factor authentication (MFA or 2FA) adds another proof of identity when you sign in. Even if someone steals your password, they cannot get in without the second factor. Start with email, your password manager, banking, domain registration and administrator accounts.
Where available, consider passkeys or FIDO2 security keys. Passkeys are tied to the legitimate service, making them resistant to fake-login-page phishing. Protect the device or account storing them, and arrange a backup method before relying on them.
Where passkeys are unavailable, an authenticator app is a useful alternative. Microsoft Authenticator and Google Authenticator are common examples. Never approve a sign-in notification you did not initiate, and never give someone a verification code because they claim to be support.
4. Plan for a lost phone before it happens
Extra security should not leave you permanently locked out. Extra steps at setup save you from a very bad day later.
For each critical account, confirm your recovery details and understand the provider's recovery process. Store backup codes securely, and avoid keeping the only copy inside the account they unlock. For hardware security keys, consider registering a spare and storing it separately.
Here is a useful scenario to test: your phone is lost while travelling. You have a replacement computer, but no access to your usual authenticator app. What happens next? Work through that answer before it becomes urgent. Write down the recovery process without exposing passwords in an ordinary document. Make sure an authorised person knows how to find it.
5. Treat business email as a critical system
Email often connects to password resets, invoices, client conversations and supplier payments. It is the master key to most of your other accounts. It deserves more than a strong password.
Microsoft 365 and Google Workspace are the main options for professional business email. The setup matters as much as the choice: individual accounts, appropriate administrator permissions, MFA and recovery arrangements all need attention from the start.
Ask your provider to review SPF, DKIM and DMARC. These help receiving mail systems assess whether messages using your domain are authorised. They reduce certain kinds of impersonation, but do not prevent every scam or protect a mailbox that has already been compromised.
Include every legitimate sender in your email authentication setup, such as your newsletter platform, booking software and website forms. Test and monitor before tightening DMARC policy, so genuine messages are not accidentally rejected.
6. Make verification part of your payment process
A familiar sender name is not enough to trust a payment request. A criminal can impersonate a business, or use a genuinely compromised account to send a fraudulent invoice from a real email address.
If a supplier changes bank details, call them on a number you already trust from a previous invoice or your own records. Do not use the contact number supplied in the suspicious message. Where practical, require a second person to approve changes to payment details.
Use the same pause-and-check habit for unexpected account warnings. Open the service directly through your app or saved bookmark instead of following an urgent message's login link. For teams, make reporting easy. Someone should feel comfortable saying "I clicked something" immediately, without fear of being blamed.
7. Keep your devices and website maintained
Software updates often fix security weaknesses. Enable automatic updates where practical, and replace systems that no longer receive security support. Include browsers, phones, and business software in your checks. An outdated plugin on your website can be just as risky as an outdated operating system.
Use a strong device passcode, automatic screen locking and device encryption. Store encryption recovery information safely. Keep built-in security protection enabled, and do not disable it to make something more convenient.
For your website, agree with your developer on who maintains the platform, plugins and integrations. Remove unused components and former users. A website launch date should also come with an ongoing maintenance plan.
8. Check that your backups can actually restore your work
Having files in the cloud does not automatically mean you have recovery protection. Sync can copy accidental changes or damaged files between locations, overwriting your only good version. Check version history, retention limits and recovery options rather than assuming everything is recoverable.
Your backup plan should answer four questions: what is covered, how often it runs, how far back you can recover, and who can restore it. Include important email, client files and website data. Keep a protected copy that cannot easily be deleted through the same compromised account.
Then test it. Restore a sample file to a safe location and confirm the process works. Ask your website provider when they last tested a restoration.
9. Use a VPN for the right reasons
NordVPN is one example of a commercial VPN you might consider when working remotely or using networks you do not control. A VPN encrypts traffic between your device and its VPN server and changes the public IP address websites see.
It does not make you anonymous or prevent every attack. It cannot stop you handing your password to a fake website, replace MFA, or make an infected computer safe. HTTPS already encrypts the connection to properly configured websites; a VPN adds protection on the network path and shifts some trust to the VPN provider.
Treat a VPN as an optional layer, not a foundation. Prioritise account security, updates and recovery first. Follow any client or employer requirements for connecting to their systems before choosing a VPN for that purpose.
10. Keep less sensitive information, and share it carefully
Privacy also depends on what you collect and who can see it. The OAIC recommends collecting only the personal information you genuinely need. Every extra copy of client data is another thing to protect.
Review enquiry forms, shared folders and old client exports. Use named-person access instead of public links for private material. Remove unnecessary copies in line with your retention obligations.
Before putting client information into a new AI tool, browser extension or transcription service, check the permissions, storage and data-use settings. Choose tools deliberately rather than granting broad access simply to try a feature.
Your first-week security checklist
Eight things to do this week. Tick them off as you go. Your progress is saved automatically in your browser.
- Turn on MFA or passkeys for your most important accounts
- Replace reused passwords and protect your password manager
- Save recovery codes securely and review recovery contacts
- Remove former staff, suppliers and unnecessary app access
- Install outstanding updates and check device encryption
- Confirm that a backup has completed and test a restoration
- Introduce independent verification for changed bank details
- Assign someone to review these checks regularly
Where to start: a priority matrix
Not everything is equally urgent. This grid shows which actions to tackle first based on effort and impact.
- Turn on MFA for email and banking
- Set up a password manager
- Enable automatic device updates
- Save backup and recovery codes
- Configure SPF, DKIM and DMARC
- Set up a proper backup system
- Migrate to Microsoft 365 or Workspace
- Audit and tighten access across all accounts
- Review shared folder permissions
- Enable screen lock on all devices
- Clear old browser sessions
- Remove unused apps and extensions
- Set up a VPN for remote work
- Enable advanced threat protection
- Formal security policy documents
- Staff security awareness training
What happens in the first 24 hours after an account is hacked
Understanding the typical timeline makes the urgency clearer. This is why responding quickly matters.
A practical toolkit to consider
The right setup depends on your business and how you work. These are options to evaluate, not a list every business needs to buy immediately.
Use a trusted device and contact your provider or IT support promptly. For compromised Microsoft 365 email, remediation can involve temporarily blocking the account, resetting credentials, revoking active sessions and checking for unauthorised MFA methods and forwarding rules. Changing the password alone may not remove every route back in.
If money is at risk, contact your bank immediately through an official channel. Preserve relevant messages and a timeline.
"You do not need to secure everything at once. Pick the three accounts you rely on most, secure them this week, then work outward from there. Small, consistent improvements are far more effective than one big security audit that never gets finished."
Need a hand getting the foundations right?
At Sonder, we help small businesses with professional email setup and migration, including Microsoft 365 and Google Workspace, as well as practical support with websites, domains and account access. If you are unsure where to start, we can help you work through the setup and identify where specialist IT or cybersecurity support might also be needed.
Give the digital side of your business the attention it deserves
We can help with business email setup, domain management and website maintenance. No jargon, no pressure.
Get in touch with Sonder- ASD's ACSC: Small business cybersecurity guidance
- Bitwarden: Username and password generator
- Bitwarden: Recovery code for two-step login
- ASD's ACSC: Turn on multi-factor authentication
- ASD's ACSC: Passkeys
- Google Workspace: Set up DMARC
- ASD's ACSC: Preventing business email compromise
- ASD's ACSC: How to secure your devices
- ASD's ACSC: How to back up your files and devices
- ASD's ACSC: Mitigations for network defence
- NordVPN: Personal VPNs and their limitations
- OAIC: Protecting customers' personal information
- Microsoft: Respond to a compromised email account
- ASD's ACSC: Report a cybercrime or incident
