Skip to main content

IT Start

Four MSP Tested Cyber Security Awareness Tips for Australian SMEs

White employee reporting suspicious message

Turn on multi-factor authentication, patch your critical software, confirm your backups actually restore, and pause before you click anything unexpected. Those four habits, done consistently, stop the vast majority of the incidents we get called about. The ACSC’s small business guide names the same three starting points for good reason: they’re cheap, fast, and they close the doors attackers walk through most often.


TL;DR:

  • Turning on multi-factor authentication everywhere reduces the risk of compromise, especially on critical accounts like email, banking, and remote access.
  • Regularly testing backup restores with real data recovery, not just checks of backup completion, ensures data integrity and readiness for ransomware events.
  • Implementing two-person approval for bank detail changes and verifying such requests by phone prevents most business email compromise scams.
  • Keeping software patched and devices updated minimizes vulnerabilities that attackers exploit for initial access.
  • Educating staff to recognize phishing signs and report suspicious activity promptly is crucial for quick containment and recovery.

IT Start
itstart.com.au
Strengthen Your Business Cybersecurity
IT Start helps Brisbane businesses manage cybersecurity risks with tailored support, cloud solutions, and proactive managed IT services.
Explore IT Start

Table of Contents

Cyber security awareness tips for daily habits at work

Honestly, most breaches we clean up don’t come from some sophisticated nation-state attack. They come from an employee clicking a dodgy link on a Friday afternoon, or an admin account that’s been sitting there with no MFA since 2019. Here are the tips we actually give clients, in order of what matters most.

  1. Think before you click. If an email creates urgency (invoice overdue, account suspended, CEO needs this now), slow down. Attackers rely on you not stopping to check.
  2. Turn on MFA everywhere it’s offered. Email, banking, accounting software, remote access. We still find businesses with MFA on email but not on their accounting platform, which is exactly where the money moves.
  3. Use a password manager, not your memory. Unique passphrases for every login beat “Password123!” reused six times. We roll these out for clients constantly and it’s one of the cheapest wins available.
  4. Patch your software on a schedule, not “when we get to it.” Unpatched software is still one of the most common entry points we see in the field.
  5. Test your backups, don’t just assume they exist. We see this constantly: a client thinks they’re backed up because Microsoft 365 keeps deleted files for 30 days. That’s retention, not a backup.
  6. Verify any payment or bank detail change by phone. Call a known number, not the one in the email. This one habit alone prevents most business email compromise losses.
  7. Lock your screen every time you step away. Windows key plus L takes two seconds. We’ve seen unlocked machines in open-plan offices cause real damage.
  8. Avoid public Wi-Fi for anything sensitive, or use a VPN if you have no choice. Coffee shop Wi-Fi is not the place to log into your accounting system.
  9. Only give people the access they need. Admin rights should be rare, not default. Least privilege sounds like jargon but it’s just common sense applied properly.
  10. Report anything odd immediately, even if you think you might be wrong. The fastest recoveries we’ve been part of all started with someone speaking up within minutes, not days.
  11. Keep devices updated, including phones. Old operating systems on personal devices connecting to work email are a bigger risk than most people realise.
  12. Handle sensitive data like it’s a liability, not a convenience. Don’t email spreadsheets full of customer details around because it’s quicker than using the proper system.

Pro Tip: The biggest trap we see is confusing retention with backup. If your “backup” lives inside the same Microsoft 365 tenant an attacker could compromise, it’s not a real backup. A genuine backup is a separate, tested copy that survives even if your main environment doesn’t, and choosing from the top backup plugins for BigCommerce can help ensure your e-commerce data is secure.

How to spot and report phishing and business email compromise

Warning signs worth training your team to notice:

  • Urgency or secrecy (“don’t tell anyone, just process this today”)
  • A request to change bank details for a supplier or payroll
  • An unexpected attachment from someone who doesn’t normally send one
  • An MFA prompt you didn’t trigger yourself
  • A sender address that’s almost right but not quite (one letter off, wrong domain)

If any of these show up, verify before you act. Call the supplier or colleague on a known number, never the one in the suspicious email. Require two-person approval for any bank detail change, no exceptions, even for the CEO. If you’re unsure, escalate rather than guess. The ACSC’s guidance on business email compromise backs this exact process.

Report fast and without blame. Fast reporting means faster containment, and a no-blame culture means people actually tell you when something’s gone wrong instead of hiding it for a week.

Phishing report moving into containment

MFA, passkeys, and password manager basics that hold up

Not all MFA is equal. Security keys and passkeys are the strongest option, authenticator apps come next, and SMS or email codes are the weakest because they can be intercepted or socially engineered. The ACSC’s multi-factor authentication guide puts authenticator apps, hardware tokens and passkeys well ahead of SMS or email for this reason.

  • Set up your password manager with a long, unique master passphrase, and protect the vault itself with MFA.
  • Never approve an MFA prompt you didn’t trigger. That prompt at 11pm you didn’t ask for? Decline it and change your password immediately.
  • If you use a physical security key, keep a backup passkey or backup key registered somewhere safe, in case you lose the primary one.
  • Moving to a new phone? Set up your authenticator app on the new device before wiping the old one, so you don’t lock yourself out.

We’ve had clients ignore an unexpected MFA prompt as “just a glitch” more than once. It’s not a glitch. It’s usually someone trying to get in with a stolen password.

Backups and restore testing: the check most businesses skip

A backup that’s never been restored is a guess, not a plan. The difference between “retention” (deleted files sitting in a recycle bin for a few weeks) and an actual independent backup is the difference between recovering from ransomware and losing everything.

  1. Ask who at your business can actually restore data, and whether that’s separate from your everyday admin account.
  2. Confirm you have an offsite or immutable copy that ransomware can’t touch, even if it gets into your main systems.
  3. Check how often backups run, daily is the minimum for most SMEs.
  4. Run an actual restore test, not just a “backup completed successfully” email. The ACSC’s guidance for business leaders is blunt about this: test the restore of representative files and critical systems, don’t assume.

If your provider can’t show you evidence of a recent restore test, that’s a conversation worth having this week.

MSP perspective: what most businesses get wrong and how we fix it

We see the same three mistakes across almost every new client, regardless of industry. Admin accounts with no MFA, because “we trust our team” (that’s not the risk, a compromised password is). Microsoft 365 retention mistaken for backup, until someone needs to recover from a ransomware hit and finds out the hard way. And zero payment-verification process, so one convincing email can move real money out the door.

The fixes aren’t complicated:

  • Lock every admin account behind MFA, no exceptions, ever.
  • Set up delegated access instead of handing out full admin rights by default.
  • Require two-person approval for any payment or bank detail change.
  • Run a real restore test every quarter, and get it in writing.

Pro Tip: If you’re a 10 to 50 staff business trying to figure out what to fix first, start with admin account MFA and a real restore test. Those two fixes address the highest-impact gaps we find during audits, before you spend money on anything fancier.

Three things to do this week, and when to call for help

This week: turn on MFA everywhere, confirm someone has actually restored a file from your backup recently, and set a rule that no bank detail changes happen without a phone call first. Call an IT provider when you can’t answer those three questions confidently, and have your current backup and access setup details ready when you do. If any of this sounds unfamiliar, IT Start’s cyber security services are built around exactly these gaps.

— Matt

Where this advice comes from

This guide draws on the ACSC small business cyber security guide, the OAIC’s notifiable data breach statistics, the Essential Eight maturity model, and ACSC’s business email compromise recovery guidance. For a broader look at building awareness across a whole team, see IT Start’s guide to improving cyber security awareness for SMEs or the password manager rollout guide.

Sources

FAQ

What are the 5 C’s of cyber security?

Definitions vary depending on the source, but a common version covers Change, Compliance, Cost, Continuity, and Coverage, the pillars businesses weigh when building a security program. It’s not an official government framework in Australia, so treat it as a useful mental model rather than a strict standard.

What are the top 5 tips for cyber security?

Enable multi-factor authentication, keep software patched, back up your data and test the restore, verify payment requests by phone, and think before clicking links or attachments. These are the same starting points the ACSC recommends for small business, and they stop most incidents we see.

Beyond MFA, patching, and backups, add password managers, screen locks, least-privilege access, safe Wi-Fi habits, fast incident reporting, careful handling of removable media, and staff training on business email compromise. Each one covers a gap the others don’t, which is why layering them matters more than relying on any single control.

What should businesses focus on during Cybersecurity Awareness Month?

Use it as a reminder to revisit MFA coverage, run a genuine backup restore test, and refresh staff on phishing and payment-verification steps rather than a one-off slideshow. The OAIC’s breach data shows human error still drives a large share of breaches, so repeated, practical reminders matter more than an annual tick-box session.

How do I know if my backup is actually working?

You know a backup works when someone has restored real files or systems from it recently and confirmed the data comes back intact, not just when a backup job reports “success.” Ask your IT provider for evidence of a completed restore test, as ACSC guidance for business leaders recommends, rather than taking a green tick at face value.

Related Posts