Small business cyber security handbook
Explore the practical steps small business can take to protect their systems, data, staff and customers from cyber threats.
- Published
-
- Last reviewed
-
Common cyber threats to small businesses
Cybercriminals target Australian business and organisations for financial gain. They may use ransomware attacks or data theft to conduct fraud or extortion. Cybercriminals are also likely to conduct multiple layers of extortion that disrupt business operations and damage the organization's reputation.
Below are examples of common cyber threats to small businesses.
Scam messages
Scams aim to trick you or your staff into sending money or gift cards, clicking harmful links or attachments, or sharing sensitive information like passwords.
Scam messages can arrive by various methods including email, text message, phone call or social media platforms. Cybercriminals often pretend to be a trusted person or organisation to make their scams seem real.
Phishing attacks
Phishing attacks often include links to fake websites that ask you to log in or enter sensitive information. If successful, cybercriminals can steal passwords, take over business accounts, such as social media, and demand payment.
Common warning signs
Phishing messages can be difficult to detect. Recognise these warning signs:
Suspicious links
Links in phishing messages often lead to fake or harmful websites. Before opening a link, check the full web address and make sure it matches the official website exactly. Be wary of any link that has been sent to you by someone you don’t know, even if it seems legitimate.
Don’t open links if the address looks unusual or doesn’t match the organisation.
QR codes
QR codes can hide the destination of a link. Malicious actors can place fake QR codes on signs, posters or emails to redirect you to a malicious website. If you must scan a QR code, check for signs of tampering such as damage, alterations or placed over another code. After scanning, always check the full web address to make sure it’s official.
Fake websites and advertisements
Be careful of fraudulent websites and advertisements created by hackers that look real. A search result may show as ‘sponsored’ or ‘advertisement’, but this doesn’t mean it is safe. Consider typing official website addresses directly into your browser rather than using a search engine.
Unexpected phone calls
Malicious actors may call and pretend to be from a trusted organisation. Warning signs include:
- caller IDs that look real but may be fake
- a delay before the caller speaks
- requests for personal, financial information, passwords or authentication codes
- pressure to act immediately
- voices that sound unusual or too perfect (possible voice cloning).
If you are unsure, promptly end the call and contact the organisation using a trusted phone number from their official website.
Unexpected messages
Be cautious of unexpected emails, messages or requests, even if they appear to come from someone you know.
Hackers can impersonate trusted contacts or take over legitimate accounts. Always verify unexpected or suspicious requests using contact details from a trusted source. Warning signs include:
- generic greetings like ’Dear customer‘
- poor spelling, grammar, or layout in messages
- strange or misspelled email addresses
- messages that seem too good to be true.
Requests to install software
Hackers may ask you to install software to fix a problem or access your account. This is often remote access software, which gives them control of your device. If installed, they may access your personal information, monitor your activity and intercept or approve authentication requests. This can allow them to gain access to your online accounts, even if MFA is enabled. They may also change account settings, change passwords and lock you out of your accounts.
Only install software if you have confirmed the request is legitimate, for example by looking into where the request came from. Do not allow remote access to your device unless you have verified the request via a trusted channel.
Getting started
If you notice a suspicious email, text or social media message:
- report it using the platform's reporting tools (where available)
- block the sender and delete the message
- run antivirus or security software to scan your device and remove any suspicious programs
- monitor your accounts for suspicious activity.
If you believe your business has lost money or financial information has been compromised:
- contact your bank or financial institution immediately.
- contact services such as myGov or the Australian Taxation Office if relevant
- report the incident to ReportCyber.
Business email compromise
Small businesses are often targeted by email attacks such as business email compromise. In these attacks, cybercriminals impersonate a business, supplier, customer or staff member to trick people into transferring money, sharing sensitive information or changing payment details.
In some cases, cybercriminals gain access to legitimate email accounts and use them to send fraudulent requests. In other cases, they use email addresses or domain names that appear similar to those of trusted organisations.
Business email compromise can result in financial loss, data breaches, reputational damage and disruption to business operations. Small businesses are often targeted because payment approvals and account changes may rely on trust and email communications.
Getting started
- Use multi-factor authentication (MFA) and strong, unique passwords for all your email accounts.
- Make sure to set up recovery options and regularly review your email login activity to identify suspicious access attempts.
- Be cautious of unexpected requests involving payments, bank account changes, sensitive information or urgent action.
- Verify unusual requests using a trusted communication channel, such as a known phone number rather than contact details provided in the email.
- Only share your email address online if necessary. Consider using an alternative or alias email for general use.
- Delete email accounts you no longer use or monitor and consider deleting emails that contain sensitive or personal information. If a cybercriminal gains access to your account, they could find and steal this information.
- Protect your domain names and consider registering similar domain names that could be used to confuse your customers and staff. For example, pypal.com, payppal.com, pay-pal.com
- Teach staff how to identify suspicious emails and establish clear processes for reporting and verifying unusual requests.
Malware
Malware is a blanket term for malicious software designed to cause harm, such as ransomware, viruses, spyware and trojans. Malware can:
- steal or lock the files on your device
- steal your bank or credit card numbers
- steal your usernames and passwords
- take control of or spy on your computer.
Malware can stop your device from working properly, delete or corrupt your files, or allow others to access your personal or business information. If your device is infected with malware, you could be vulnerable to other attacks. The malware could also spread to other devices on your network.
Your device can be infected by malware in a number of ways, including:
- visiting websites that have been infected by malware
- downloading infected files or software from the internet
- opening infected email attachments.
Getting Started
- Keep devices, operating systems and applications up to date.
- Use reputable security software.
- Be cautious when opening emails, attachments, links and files, particularly if they are unexpected or from unknown sources.
- Only download software and applications from trusted websites or official app stores.
- Avoid installing programs that are not required for your business.
- Teach staff how malware is commonly delivered and how to identify and report suspicious activity.
If you suspect a device has been infected, disconnect it from the network and seek assistance from an IT professional as soon as possible.
Ransomware
Ransomware is a common type of malware. It works by locking up or encrypting your files so you can no longer access them. A ransom, usually in the form of cryptocurrency, is demanded to restore access to the files. Additionally, cybercriminals may also steal business information and threaten to publish or sell it online unless a ransom is paid, which is know as data extortion.
A ransomware attack can cause significant disruption to a business, resulting in downtime, financial loss, reputational damage and the loss of important information. Without reliable backups, recovering encrypted files may be difficult or impossible.
Regular backups that are tested and stored separately from your main systems are one of the most effective ways to reduce the impact of a ransomware attack.
Ransomware commonly spreads through:
- phishing emails
- malicious links
- unsafe websites
- compromised accounts
- infected downloads.
While antivirus or security software can help protect you from malware, no software is 100% effective.
Staff should be cautious when opening unexpected emails, attachments and links. Businesses should regularly update devices, enable multi-factor authentication and maintain reliable backups.
Getting started
- Regularly back up important business information.
- Enable multi-factor authentication (MFA).
- Keep devices and software up to date.
- Use security software and restrict administrator access to those who need it.
- Teach staff to be cautious of unexpected emails, attachments, links and file downloads.
If your business is affected by ransomware, do not pay the ransom. Paying does not guarantee that your files will be recovered or that stolen information will not be leaked or sold online. Seek assistance from an IT professional or report the incident through ReportCyber.
Denial-of-service attacks
A denial-of-service attack is designed to disrupt or prevent access to online services such as websites, email services and online portals. This is usually done by overwhelming a service with large amounts of traffic, connections or requests, preventing legitimate users from accessing it. When multiple compromised devices are used to launch an attack, it is known as a distributed denial-of-service attack.
While denial-of-service attacks do not typically result in data being stolen or files being encrypted, they can cause significant disruption to business operations, impact customer access to online services and result in financial or reputational damage. Small businesses that rely on websites, online booking systems, email or internet-facing services may be particularly affected.
Getting started
Small businesses cannot always prevent denial-of-service attacks, but they can reduce their impact.
- Use reputable hosting, cloud and internet service providers that can respond to large volumes of malicious traffic.
- Monitor critical websites and online services for outages.
- Maintain up-to-date contact details for key service providers.
- Make sure your cyber security incident response plan includes procedures for responding to service disruptions.
If your business relies heavily on online services, such as a website, online store, or customer portal, consider discussing denial-of-service protection options with your service provider.