Small business cyber security handbook
Explore the practical steps small business can take to protect their systems, data, staff and customers from cyber threats.
- Published
-
- Last reviewed
-
Protecting business & customer data
Data breaches affecting Australian businesses are increasing in scale, complexity and impact. As more business activity moves online, organisations have a responsibility to protect the personal information they collect from unauthorised access, disclosure, modification and loss.
To apply effective security measures, businesses must first understand what data they hold and how it is protected. The ASD’s ACSC recommends using the free Exercise in a Box tool to:
- assess current data handling and cyber security practices
- identify strengths, weaknesses and areas for improvement.
Protect your business data
Apply appropriate security measures to protect it from unauthorised access. Some businesses may also have legal obligations to protect certain types of data, so it’s important to be aware of these requirements and meet them.
Getting started
Consolidate your business data. Data stored across numerous devices or services increases the number of systems you have to keep secure and backed up. More systems can also create more opportunities for a cybercriminal to attack.
Where possible, store your business data in a central location that is secure and backed up regularly. Centralising your data can create a bigger breach if your systems are compromised, so ensure this central location is protected with secure configurations and restricted access.
Read the Office of the Australian Information Commissioner’s (OAIC) guide for small businesses to learn more. Consult with a legal professional if you are unsure.
Key data security practices
The following practices will help businesses manage personal data securely and reduce the impact of a data breach.
Create a register of personal data
Businesses should understand:
- what personal data they collect
- where it is stored
- how it is used.
Maintaining a register of personal data, such as databases, systems, and data assets, supports effective protection and oversight. The National Archives of Australia provides guidance on maintaining information asset registers.
Limit personal data collected
Only collect personal data that is required to operate your business. Clearly define why the data is needed and how it will be used. Avoid collecting and holding unnecessary data as this increases risk if a breach occurs.
Delete unused personal data
Set clear policies for how long personal data is kept and when it should be deleted. Retention periods should be based on business needs, legal obligations and the sensitivity of the data. Removing data that is no longer required reduces exposure.
Control access to personal data
Restrict access so staff can only view or modify the personal data they need to perform their role. Strong access controls limit damage if systems are compromised and reduce the risk of misuse by insiders.
Encrypt personal data
Apply full disk encryption to devices such as laptops, servers and mobile phones that store or access personal data. Consider file level encryption for added protection. Check that data is encrypted when transmitted, such as when information is sent over the internet.
Back up personal data
Regular backups allow businesses to recover personal data if it is lost, damaged or encrypted by ransomware. Backups are a key defence against cyber incidents and physical events like fires or floods.
Report a data breach involving personal data
Businesses must understand and meet their reporting obligations if a data breach involves customers’ personal information. All cyber security incidents should be reported through the ReportCyber portal or by calling 1300 CYBER1 (1300 292 371).
Affected customers or users should also be informed if their personal data may have been compromised.
Businesses covered by the Privacy Act 1988 must report eligible data breaches to the Office of the Australian Information Commissioner (OAIC). An eligible data breach occurs when:
- personal information is accessed, disclosed or lost without authorisation
- is likely to result in serious harm to individuals
- cannot be prevented through remedial action.
Further guidance is available on the OAIC’s Notifiable Data Breaches webpage.