Most business systems are connected to each other and the internet, including computers, mobile phones, payment systems and smart devices. These connections help businesses operate efficiently and serve customers.
However, increased connectivity also increases exposure to cyber threats. Protecting your devices and networks is essential to keep your business and information secure. Follow these tips to reduce your risk.
Update your software
Software updates fix security weaknesses that cybercriminals can exploit to install malware or gain access to your devices.
New security flaws are discovered regularly, so it’s important not to ignore update prompts. Devices or software that no longer receive updates can leave your business exposed. If a product is no longer supported by the manufacturer, consider upgrading to a newer, supported version to stay secure.
The easiest way to manage this is by enabling automatic updates wherever possible. This “set and forget” approach ensures your systems stay protected without requiring constant attention. You should still regularly check that updates are being applied across all devices used in your business, including computers, phones, and any systems your staff rely on for work.
Getting started
Update all devices, apps, and software through their settings menus. Where possible, turn on automatic updates so security fixes are applied as soon as they are available. If automatic updates are not an option, set reminders to check regularly and schedule updates outside business hours to minimise disruption.
Make sure all devices connected to your business network are also kept up to date, including servers and storage devices.
Back up your information
Regular backups help your business recover data if it is lost, stolen or damaged. Without reliable backups, it may be difficult or impossible to recover information after a cyber incident.
Backups should be done regularly or automatically as part of normal business operations. There are many backup options available, and the best approach depends on your business needs.
Getting started
Create a plan or procedure for backing up your business. This will be different for every business. Your plan should answer the following questions:
- What data is or is not backed up?
- When do backups occur?
- Where are the backups stored?
- Who is responsible for managing the backups?
- How long are the backups kept for?
- How often are the backups tested?
Think about all the places where your important information is stored. Are these locations included in your backup plan? For example, information held in your email or cloud accounts.
Use security software
Security software, such as antivirus and ransomware protection, helps protect your devices from cyber threats. These tools can detect and remove malware by scanning for suspicious files and programs and alert you when a threat is found.
Your device may have built-in antivirus software which most modern Microsoft and Apple computers automatically include. Third-party companies also sell antivirus software which tend to include more features than free software.
Getting started
- To learn more about Windows Security, search for "Windows Security" in your Start Menu. You should also visit Microsoft’s website for more information, including 'how to use controlled folder accesses for protection against ransomware'.
- Set up your security software to automatically do regular scans, for example every week.
- Familiarise yourself with your security software, including what a legitimate alert looks like. This will help you avoid scams that pretend to be your antivirus software.
Secure your network and external services
Networks and connected services are common targets for cybercriminals and can contain weaknesses if not properly secured.
Because networks can be complex, it’s important to identify and address vulnerabilities carefully. Consider discussing security measures and set-up with an IT professional to ensure your network and external services are protected.
Getting started
Secure your servers
If you use servers such as a network attached storage at home or work, take extra steps to protect them. These devices are common targets because they store important data. Keep them updated and protect administrator accounts with strong password and MFA.
Minimise internet-facing services
Review any services exposed to the internet, such as Remote Desktop, file sharing, or remote administration tools. Limit access and secure or disable services that are not needed.
Migrate to cloud services
For many small businesses, reputable cloud services provide stronger security than self-hosted systems. Use trusted cloud providers for services such as email, file storage and collaboration. Enable MFA, review administrator access regularly, and remove unused accounts or third-party integrations.
Improve your router’s security
Secure your router by:
- changing default passwords
- using strong encryption
- keeping firmware updated
- enabling guest Wi‑Fi for visitors and customers.
Understand your cyber supply chain
Businesses should understand what systems, information and accounts external providers can access. Access should be reviewed regularly and removed when it is no longer required. When engaging new providers, consider how they protect customer and business information.
Harden your website
Websites are a common target for cyber attacks and need basic security protections to reduce the risk of being compromised. To protect your website:
- secure login access with MFA or strong passwords
- keep content management systems and plug‑ins up to date
- back up your website regularly so it can be restored after an incident.
Understand the threats
It is important to understand the major threats you may face as a website owner or manager. Understanding these threats can help you be more prepared for a cyber attack.
Website defacement
Defacement is when a cybercriminal changes your website without you knowing. They can change its appearance and content, which may compromise your data and increase the risk of further attacks. They can even infect your website with malware, putting your visitors at risk.
Cybercriminals will use various tactics to access and deface your website. They may be able to gain unauthorised access to the back end, exploit vulnerability or use malware.
Data breach
A data breach happens when a cybercriminal is able to access and export your data for personal gain. This may include sensitive data such as personal and financial details.
Denial-of-service (DoS) attacks
A denial-of-service attack is when a cybercriminal directs large volumes of traffic to your website. It overloads available resources and prevents users from accessing your website. This can lead to significant disruptions to your business.
Choose a secure hosting service
Understanding the security features provided by your web hosting service is crucial. These features may be what stands between your website and any malicious attacks. When looking for a service provider, consider the following.
How do they back up data?
Check if the provider performs data backups, and how often. Storing backups offsite is a more secure method. Make sure you know where and how they store backups.
Do they mitigate against malware?
Check if the provider offers malware detection tools, such as scanning and antivirus software. They should also use preventative technology such as firewalls and encryption.
What are their security standards?
Check if the provider offers integrated security features like MFA and DoS protection. Features such as a login activity panel and password-protected pages are also desirable.
Confirm where they are located and the security and privacy standards they follow. Providers outside Australia may be subject to different legal obligations.
Getting started
Enable auto‑renewal for your website’s domain name to prevent accidental expiry. If your website is managed by an external provider or developer, speak with them about improving security controls and maintenance practices.
Make sure to use Hypertext Transfer Protocol Secure (HTTPS). HTTPS is an encrypted and more secure version of HTTP. It provides security for sensitive information such as passwords and credit card details. It also helps to keep your data private, making it hard for cybercriminals to read if they intercept it.
Limit website admin access to those who need it and only give users the privileges they need for their role. For example, developers can update the site configuration with admin access, while marketing staff can only publish web pages.
Reset your devices before selling, trading or disposing of them
If you do not dispose of your devices securely, cybercriminals could access the information on it. This could include emails, files and other business data.
Remove all information from your business devices before selling, trading or throwing them away. For example, by doing a factory reset. This will wipe any information and restore the device to its original settings.
Getting started
Even if you follow the right steps, it may still be possible for someone to recover your information. If the information on your device is particularly sensitive, you could use a data destruction service or ask an IT professional to help you dispose of it securely.
Keep your devices locked and physically secure
Restrict access to business devices to reduce the risk of unauthorised access, data theft and malicious activity. Store devices securely and do not leave them in locations where unauthorised staff or members of the public can access them.
Apply basic security controls to all devices. At a minimum, protect devices with a password or biometric authentication and set to automatically lock after a short period of inactivity.