Skip to main content

IT Start

Do These 5 This Month: Cyber Security Checklist for 10–50 Staff SMBs

Technician maintaining network appliance

If you do five things this month, make them these: turn on MFA everywhere, build a real device and account inventory, automate patching, back up your data and actually test restoring it, and train your staff to spot scams. Everything else on a cyber security checklist for small business is worth doing eventually. These five are the ones that stop the breaches we see every week. Do MFA and backups this week. Patching and training this month. Everything else can wait until next quarter.


TL;DR:

  • Enforce multi-factor authentication on all accounts, especially email and admin accounts, and use phishing-resistant methods like hardware keys or authenticator apps.
  • Build a comprehensive device and asset inventory, including shadow IT, and rate their risk levels to facilitate prioritized security actions.
  • Automate patching for operating systems, applications, and network devices, and run monitored endpoint protection with regular security updates.
  • Test backup restorations quarterly to ensure data can be recovered effectively within targeted timeframes and document recovery procedures clearly.
  • Assign an accountable person to oversee security, establish clear onboarding and offboarding processes, and develop an incident response plan with predefined roles and external contacts.

IT Start
Close Your Cyber Security Gaps
IT Start helps Brisbane businesses manage cybersecurity, system monitoring, cloud solutions, and IT support with a proactive, transparent approach.
Visit IT Start

Table of Contents

Cyber security checklist for small business: start with an honest posture check

Honestly, most SMBs we onboard have no idea what’s actually connected to their network. Not a criticism, it’s just how it goes when nobody’s job is specifically “manage the IT estate” and everyone’s flat out running the business. You get a mix of laptops bought at different times, an old server nobody wants to touch because “it just works,” a few cloud apps someone signed up for with a personal card, and a printer that’s been on the same firmware since 2019.

That’s the problem. You can’t protect what you haven’t listed. CISA’s guidance for small businesses makes this the starting point for a reason: every other control on this list depends on knowing what you’re actually defending.

Run a proper audit before you buy anything else. The ACSC’s Cyber Health Check is a free, government-backed way to do a first pass, and it’s genuinely useful for a business with 10 to 50 staff that doesn’t have a dedicated security person. It won’t catch everything, but it forces you to answer questions you’ve probably never asked.

Your inventory needs to cover more than laptops and desktops. We see businesses list the obvious stuff and completely miss:

  • Every laptop, desktop, tablet and phone that touches company data, including personal devices used for email
  • Servers, whether on-prem or hosted, and what’s actually running on them
  • Every cloud app in use, not just the ones IT signed off on (marketing’s Canva account, the bookkeeper’s Xero login, that one Dropbox someone set up years ago)
  • Admin accounts across Microsoft 365, your accounting software, your website host and anything else with elevated access
  • Remote access points: VPNs, remote desktop tools, any way someone can get into your network from outside the office
  • Public-facing assets: your website, customer portals, anything with an IP address the internet can see
  • Printers and IoT devices, which almost nobody thinks of as a security risk until one gets used as a foothold

Once you’ve got the list, rate each item roughly high, medium or low risk based on what it touches and who can access it. You don’t need a spreadsheet with forty columns. A basic list with a risk rating and an owner next to each item is enough to work from, and it’s the same document you’d hand an MSP if you brought one in for a risk assessment.

Protect accounts and identity: MFA is not optional anymore

We see this a lot: a business gets breached, and when we ask about MFA, the answer is “we meant to turn that on.” Microsoft’s own data shows that enabling multi-factor authentication blocks the overwhelming majority of account-based attacks. It’s the single highest-return control on this entire checklist, and it costs nothing to switch on in Microsoft 365.

Not all MFA is equal, though. Here’s how to prioritise it:

  1. Turn on MFA for every user, starting with email and admin accounts. If you can only do one thing today, do this.
  2. Use phishing-resistant methods where the app supports them, like authenticator apps or hardware keys, rather than SMS codes. SMS is better than nothing, but it’s the weakest form of MFA and increasingly targeted.
  3. Adopt a password manager business-wide and set a policy for long passphrases on anything MFA doesn’t cover yet.
  4. Strip local admin rights from everyday user accounts. Nobody needs to be a local admin on their own laptop to do their job, and it’s one of the easiest things ransomware exploits.
  5. Create separate admin accounts for IT staff, used only for admin tasks, never for daily email and browsing.
  6. Pull an MFA enrolment report from your Microsoft 365 admin centre monthly and chase down anyone who’s slipped through.

The business.gov.au cyber security checklist lists MFA and password managers as baseline steps for a reason. They’re baseline. Not aspirational, not “nice to have when we get around to it.”

Pro Tip: Don’t assume MFA is fully rolled out just because you set a policy six months ago. We regularly find five or six accounts that were created after the policy went in and never got enrolled. Check the compliance report, don’t trust memory.

Endpoint and network security: patching is the boring fix that works

Verizon’s Data Breach Investigations Report consistently shows unpatched vulnerabilities are one of the leading initial access points for small business breaches. Not sophisticated zero-days. Known vulnerabilities that had a patch available for weeks or months before someone got in.

This is where reality and perception diverge the most. Business owners assume Windows Update handles everything. It doesn’t touch your firewall firmware, your switch software, or that network-attached storage box in the server room. We’ve walked into offices where the firewall hadn’t been updated in three years because nobody owned that job.

What a proper patching regime looks like for a 10 to 50 seat business:

  • Automate OS and application patching on every endpoint. Don’t rely on staff clicking “update later” for the fourth time.
  • Extend patching to network gear: firewalls, switches, Wi-Fi access points and VPN appliances. These get forgotten constantly.
  • Run monitored endpoint protection, not just antivirus that sits there unwatched. Alerts that nobody looks at are the same as no alerts.
  • Enable full-disk encryption (BitLocker on Windows, FileVault on Mac) on every laptop and mobile device. If a laptop gets stolen from a car, encryption is the difference between a minor incident and a reportable data breach.
  • Replace hardware that’s stopped receiving security updates. That old server running an unsupported OS isn’t saving you money, it’s a liability sitting in a cupboard.

The ACSC’s Essential Eight treats patching applications and operating systems as two of its eight core mitigation strategies, and for good reason. It’s unglamorous work, but it closes the door that most attackers are actually walking through. If your team is spread across home offices and the shop floor, our remote work security guide covers the extra patching headaches that come with unmanaged home networks.

Backups and recovery: the checklist item everyone gets wrong

Here’s the gap between what businesses think and what’s actually true: most owners believe they’re backed up. A lot of them aren’t, not in any way that would survive an actual test. We’ve seen backup jobs that failed silently for months, backups stored on the same server they were meant to protect, and one memorable case where the “backup” was a shared drive being manually copied by an employee who’d left the company eight months earlier.

Illustration of separated backups and restore testing

Verizon’s DBIR analysis and practitioner data both point to untested backups as a recurring failure mode in SMB incidents. Having a backup and having a recoverable backup are two different things.

Build your backup plan around these steps:

  1. Define scope clearly: files, full system images, Microsoft 365 mailbox and SharePoint exports, and any website or e-commerce platform data.
  2. Set retention and offsite storage rules. Keep copies away from your main network, and where ransomware risk is a concern, use immutable storage that can’t be altered or deleted by an attacker who gets into your systems.
  3. Test restores quarterly, both full and partial. Document a realistic Recovery Time Objective and Recovery Point Objective so everyone knows how long recovery takes and how much data you could lose.
  4. Write down the restore plan and name an owner. If your IT person is on leave when disaster strikes, someone else needs to know exactly what to do.

Pro Tip: Quarterly restore tests catch more than you’d expect. In our experience, testing a restore reveals missing files or a misconfigured backup job far more often than it confirms everything’s fine. Do at least one full restore exercise a year, not just partial file checks.

Train staff to spot scams before they click

Annual security training is basically theatre. Everyone sits through a video once a year, forgets it within a fortnight, and clicks the next convincing phishing email anyway. Cyber.gov.au’s guidance points to shorter, more frequent training paired with simulated phishing as the combination that actually shifts behaviour, and that lines up with what we see across our client base.

Build a training cadence that fits a busy team without becoming a burden:

  • Run short training sessions every couple of months, not one long session annually
  • Send simulated phishing emails on a regular schedule and track who clicks, then follow up with targeted coaching, not public shaming
  • Set a dead-simple reporting process for suspicious emails: a single button in Outlook, or a forward address everyone knows
  • Review click rates over time so you can show improvement, or catch a team that’s slipping

One area most checklists skip entirely: AI tools. Staff are pasting customer data, contracts and financial information into public AI chatbots without a second thought, and most businesses have no policy covering it at all. Set an approved list of AI tools, and put a simple rule in place: no client data, no financial records, no personal information goes into a tool that isn’t on that list.

Pro Tip: Ask your team, right now, which AI tools they’ve used for work this month. You’ll probably be surprised, and that surprise is exactly why you need a written policy, not an assumption that “people know better.”

Protect customer data and meet your privacy obligations

If you hold customer names, emails, payment details or health information, you’ve got privacy obligations whether you’ve thought about them or not. The starting point is knowing exactly what personal information you’re holding and why.

Work through this in order:

  • Inventory what personal information you collect and store, and delete what you don’t need. Minimal retention means less exposure if something goes wrong.
  • Use TLS (the padlock icon) on every website and customer-facing form, and route payments through a proper payment provider rather than storing card details yourself.
  • Restrict access to customer data on a need-to-know basis. Not everyone in a 30-person business needs access to the full customer database.
  • Publish a clear privacy policy, and understand your notification obligations if a breach occurs. The OAIC’s guidance for organisations covers the Notifiable Data Breaches scheme and when you’re required to report.
  • Keep simple, dated records of what controls you’ve got in place. Insurers and auditors ask for evidence, not promises, and a folder of screenshots beats a verbal assurance every time.

This connects directly back to the account security section above. Restricting access and enforcing MFA on the accounts that touch customer data does double duty: it satisfies both your security posture and your privacy obligations in one move.

What to do when something goes wrong: your incident response plan

An incident response plan doesn’t need to be a fifty-page document nobody reads — see this step-by-step guide for SMBs on how to manage online reputation after incidents occur. It needs to answer four questions fast: who’s in charge, who do we call, how do we stop the bleeding, and how do we tell people what happened.

Build your IRP around these steps:

  1. Assign roles before an incident happens, not during one. Who makes the call to shut down systems? Who talks to customers? Who talks to media if it comes to that?
  2. Keep a current contact list: your MSP, your insurer, legal counsel and, where relevant, the Australian Cyber Security Hotline for reporting and support.
  3. Document containment steps for the scenarios most likely to hit you: ransomware, a compromised email account, a lost laptop.
  4. Run a tabletop exercise every quarter. Walk through a fake scenario with your team and see where the plan breaks down. It always breaks down somewhere the first few times.
  5. Know when to call in external responders and how to preserve evidence rather than wiping a machine the moment you find something wrong.
  6. Review near-misses, not just actual breaches. A staff member who almost clicked a phishing link is a free lesson if you actually discuss it.

For ransomware or a credential compromise specifically, the quick actions are: isolate the affected device from the network immediately, force a password reset and revoke active sessions on the compromised account, and don’t pay anything or make promises before your MSP or a specialist has assessed the scope.

Where governance breaks down in small businesses

The most common mistake we see isn’t technical, it’s structural: security gets handed to “whoever does IT,” often someone doing it as a fraction of a broader role, with no budget, no authority and no time. Then when something goes wrong, everyone’s surprised nobody was watching.

Shared logins are the other classic. One username and password for the whole accounts team, or a generic “info@” inbox that six people know the password to. It feels efficient. It also means you’ve got zero accountability when something happens, and no way to revoke access for one person without breaking it for everyone.

Fix this with structure, not more tools:

  • Appoint someone, even part-time, as the person accountable for security, with actual authority to say no to risky shortcuts
  • Set quarterly, measurable goals: MFA enrolment percentage, patch compliance, restore test completion, not vague intentions
  • Build a simple onboarding and offboarding checklist: what accounts get created on day one, and critically, what gets disabled the day someone leaves
  • Put change control around critical systems, so nobody’s making unilateral changes to the firewall or the accounting server without someone else knowing

CISA’s guidance on treating cybersecurity as an organisational responsibility, not just an IT task, backs this up. Somebody has to own it, or nobody does.

What we actually find when we walk into a new client

Every new client engagement starts the same way: we look under the hood, and it’s rarely pretty. The recurring pattern across almost every SMB we onboard is missing MFA on at least some accounts, backups that haven’t been tested in years (or ever), and a device fleet that nobody’s fully mapped. It’s not that these businesses are careless. It’s that nobody had the time or the mandate to fix it.

The fixes that move the needle fastest, in order:

  • Enforce MFA across every account, prioritising email and anything with admin rights
  • Build the asset inventory properly, including the shadow IT nobody admits to
  • Turn on automated patching for endpoints and network devices
  • Schedule an actual restore test within the first month, not “sometime this year”

If you’re evaluating an MSP, here’s what to ask them and what evidence they should be able to show you, not just tell you:

  • Can they show you an MFA compliance report, not just say it’s “handled”?
  • Can they show you the result of an actual restore test, with dates and outcomes?
  • Do they have a documented patching cadence you can see, including network gear?
  • Do they have a written incident response process, or is it “we’ll figure it out”?

Pro Tip: If an MSP can’t produce evidence for any of these on request, that’s the answer to whether they’re actually managing your security or just billing for it.

What to fix this week, this month, and this quarter

You don’t need to solve everything at once, and trying to will stall you completely. Sequence matters more than perfection.

This week: turn on MFA for email and every admin account, start the device and account inventory, and confirm backups are actually running (not just configured to run).

This month: set up automated patching across endpoints and network gear, roll out a password manager, and run one short staff training session covering phishing basics.

This quarter: complete a full restore test with documented timing, roll out least-privilege access across all systems, and set up logging and monitoring so you’d actually notice if something went wrong. If you don’t have the internal capacity to watch alerts around the clock, that’s the point where bringing in monitored detection or a managed service stops being optional and starts being the sensible call.

— Matt

How IT Start can help you close the gaps

Most of what’s in this checklist is doable in-house if someone owns it and has the time. The honest limit is that MFA enrolment, patch automation and quarterly restore tests all need consistent follow-through, and that’s exactly where busy 10 to 50 person teams fall behind. That’s the gap some MSPs fill for busy businesses: providing ongoing checking, patching, backup testing and monitoring so nothing quietly slips for months while everyone’s focused on running the business.

Our managed IT support covers MFA enforcement and verification, Microsoft 365 management, endpoint patching, and backup and recovery with actual tested restores, not backups you hope work. If part of your setup is still sitting on ageing on-prem hardware, our cloud services team can help you move it somewhere more secure and easier to manage. If you want a straight answer on where your business actually stands, consider getting a free assessment to walk through this checklist against your real setup, no obligation attached.

Sources

These are the tools and templates referenced throughout this checklist, worth keeping handy rather than hunting for later:

FAQ

What should be on a cyber security checklist for small business?

The core items are MFA on every account, a full device and asset inventory, automated patching for endpoints and network gear, tested backups with documented restore times, staff phishing training, an incident response plan, and a basic privacy policy covering customer data.

What are the 5 C’s of cyber security?

There’s no single agreed “5 C’s” framework in official guidance from bodies like the ACSC or CISA, and definitions vary depending on who’s presenting them. Rather than chase an unofficial acronym, small businesses get more value focusing on the proven controls covered in this checklist: MFA, patching, backups, training and incident response.

Can I earn $200,000 a year in cyber security?

Senior cybersecurity roles, particularly specialised or leadership positions, can reach that level in some markets, but salaries vary hugely by country, experience, certification and specialisation. That’s a career question separate from what small businesses need to budget for their own security, which is usually a managed service arrangement rather than an in-house salary at that level.

What are the real cybersecurity needs of a small business?

Most small businesses with 10 to 50 staff need the same foundational controls regardless of industry: MFA, an inventory of devices and accounts, automated patching, tested backups and a basic incident response plan. Industry-specific needs, like extra encryption for health data or payment security for retail, get layered on top of that baseline.

How often should we test our backups?

Run partial restore tests quarterly and at least one full restore exercise annually, and document the time each one takes against your target recovery objectives. Untested backups are one of the most common reasons SMBs discover, too late, that their recovery plan doesn’t actually work.

Related Posts