All T3 Blog posts

The Ultimate SMB Cyber Security Checklist

Eleven things a small business can put in place to become a much harder target, in roughly the order most people should do them.

7 minute read security

In 2015 more than a hundred financial institutions around the world were robbed by a single criminal group, in what became known as the Carbanak campaign. The attackers got in using spear phishing emails, installed remote access tools, and then moved money out quietly through transfers and cash machines. Estimates of the total run to around a billion dollars.

Your business does not have a billion dollars in it. That is less reassuring than it sounds, because the way in, an email somebody opened, is the same way in that gets used against everybody else, and it costs an attacker almost nothing to try it on you as well.

What cyber security risks do small businesses face?

If you run a small or medium business you may think you are not big enough to be worth attacking. It tends to be the other way round. Smaller businesses invest less in security and training, which makes them the easier target.

Consider these figures:

  • A cyberattack occurs every 39 seconds.
  • 43% of them target small businesses.
  • 60% of small businesses that suffer a cyber attack go out of business within six months.
  • Nearly half, 47%, of small and medium businesses have suffered an attack in the last 12 months.
  • The average cost of an attack on a business is $200,000 USD, which is daunting for any company without a plan for it.

Almost none of this is aimed at anybody personally. It is automated, it sweeps for whatever is reachable and out of date, and a smaller business is simply the one least likely to notice. The useful part of that is the same as the frightening part: because it is not personal, ordinary measures genuinely work.

The checklist

Cyber security has a great many aspects to it. This is condensed to eleven, in roughly the order they are worth doing.

  1. Prepare for a crisis
  2. Do a risk assessment
  3. Use more than one layer of protection
  4. Protect and back up your data
  5. Patch and update
  6. Keep a strong password policy
  7. Limit who can reach what
  8. Restrict what arrives by email
  9. Secure your wifi
  10. Train your staff
  11. Revisit the policies

1. Prepare for a crisis

Something will happen eventually. Deciding who rings who, who can authorise what, and what gets restored first is far easier on a quiet Tuesday than at 6am in the middle of it. A plan does not have to be long. It has to exist, and somebody other than you has to know where it is.

2. Do a risk assessment

A risk assessment tells you what you actually have and what would hurt to lose. It should turn up four things.

  • Your most valuable assets: servers, databases, client records, trade secrets, contracts, the website, and anything covered by privacy obligations.
  • The threats that matter to you: hardware failure, ransomware, an accident by somebody in the building, and deliberate misuse.
  • The gaps that let them in: kit out of warranty, software out of support, unpatched systems, and staff nobody has ever trained.
  • What to do about it, in an order somebody can work through.

3. Use more than one layer of protection

Layered security means that when one thing fails, and one thing eventually fails, something else is still standing between the attacker and your data.

  • Keep browsers, operating systems and security patches current.
  • Run managed endpoint protection, and check it is reporting rather than just installed.
  • Put a firewall in front of the network and keep its firmware current.
  • Use a VPN for staff reaching the office network from outside it.
  • Watch for behaviour that does not fit, so something odd raises an alert instead of going unnoticed for a month.

4. Protect and back up your data

Backups are the difference between a bad week and the end of the business.

  • Know which third parties hold your data and what they hold.
  • Stop sharing whatever does not need sharing.
  • Back up daily, and keep a copy somewhere separate from the live data. A backup reachable from the machine that gets encrypted is not a backup.
  • Test a restore. A backup nobody has restored is a guess, not a safety net.

5. Patch and update

Most successful attacks use a hole that was fixed months ago by somebody who published the fix.

  • Update operating systems and software on a schedule rather than when somebody remembers.
  • Remove old software you no longer use. It cannot be exploited if it is gone.
  • Set up the ability to wipe a device remotely, so a laptop left in a taxi is an inconvenience rather than a data breach.

6. Keep a strong password policy

  • Turn on multi factor authentication. If you do only one thing on this list, do this one.
  • Use a password manager so people can have long, unique passwords without having to remember them.
  • A different password for every account, and never a shared login.
  • Change passwords when a breach is known, rather than every ninety days for the sake of it. Forced rotation mostly produces Summer2026 followed three months later by Autumn2026, which is not the improvement it looks like.

7. Limit who can reach what

A Harvard Business Review study found that 60% of cyber attacks were carried out by insiders. Three quarters of those were deliberate and a quarter were accidental. Either way the fix is the same.

  • People get access to what their job needs, and not to everything else.
  • Set up proper security groups for file access rather than sharing folders one at a time.
  • No installing software without an administrator, which also stops a lot of malware installing itself.

8. Restrict what arrives by email

Email is still the front door. Business email compromise is the most reported business cybercrime in the country.

  • Filter mail before it reaches the mailbox.
  • Set SPF, DKIM and DMARC correctly so nobody can send mail that looks like it came from you.
  • Train people on what a convincing fake invoice looks like, because some of it will always get through.

9. Secure your wifi

  • Change the router’s default admin login. This is still the way in more often than it should be.
  • Keep the guest network separate from the one your business runs on.
  • Review firewall rules rather than inheriting them from whoever set it up.

10. Train your staff

Training only counts if it changes what people do.

  • Test afterwards, so you know whether any of it landed.
  • Make it normal to check something suspicious, and make it safe to be wrong. Somebody who fears being blamed will not report the click they should not have made, and that delay is where the damage happens.

11. Revisit the policies

  • Keep up with what is actually being used against businesses this year, not the year the policy was written.
  • Run awareness training more than once. People forget, and staff change.

Where to start

Do the multi factor authentication, then the backups, then the patching. Those three cover a large share of what actually happens, and none of them needs a budget approval.

If there is nobody in-house to put the rest in place, that is the job a managed provider does. We build the security into every agreement at the published price rather than selling it afterwards, on the reasoning that the business that cannot justify a security add on is precisely the one that ends up needing it.

If you want to know where you stand before talking to anybody, the free two minute risk check scores your setup and tells you which gaps to deal with first. Or have a look at what we cover on the security side, and get in touch if you would rather just ask somebody.

Keep reading

More Tech Tip Tuesdays.

  1. 4 min

    What's Changing in Your Microsoft 365 This July

    Microsoft is lifting prices on most 365 plans from 1 July 2026. Business Premium is not one of them, and Cloud PCs just got cheaper. What it means for your bill.

  2. 3 min

    5 Signs Your Business IT Is a Ticking Time Bomb

    Five things that quietly make a small business an easy target, and the three you can fix this afternoon without spending anything.

  3. 2 min

    Pros and Cons of VoIP for your Business

    What VoIP genuinely gives a business, and the three things that go wrong with it, including the one most providers would rather not own.

Tech Tip Tuesdays

Get it in your inbox

One email a month with the new Tech Tip Tuesdays piece in it. No sequences, no sales emails, and one click to stop.

One email a month. Unsubscribe any time.

Want this looked at properly?

Thirty minutes, no obligation. We will go through what you are running and tell you straight what is worth doing something about and what is fine as it is.

Or ring us

1300 025 110 (07) 5638 1255

Monday to Friday, 9am to 5pm

Or send us a message

We get back to you within one business hour, Mon to Fri

Call now Book a call