Ask any incident responder what actually breaches Australian small businesses and the answers are unglamorous: a reused password, an unpatched system, an invoice email that looked close enough to real.
The good news hiding in that list is that most of it is preventable with tools businesses already own.
The checklist that stops most attacks
Turn on multi-factor authentication everywhere. Email, accounting software, cloud storage, remote access — MFA remains the single highest-value control a small business can enable, and it’s usually free.
Patch on a schedule, not a vibe. Enable automatic updates for operating systems and browsers, and put a monthly reminder in the calendar for the stragglers: routers, NAS boxes, point-of-sale devices and that one legacy application everyone forgets.
Back up like you expect to be hit. The 3-2-1 rule still holds — three copies, two different media, one offsite or offline. Critically, test a restore. A backup that has never been restored is a hope, not a plan.
Train the humans. Payment redirection scams — where an attacker impersonates a supplier and quietly changes bank details — are among the most costly attacks on Australian businesses. A simple rule fixes most of them: verify any change of payment details by phone, using a number you already had.
The risk that remains after you’ve done everything right
Here’s the uncomfortable part: a well-run small business can do all of the above and still get hit. Zero-days, compromised suppliers and simple human error don’t respect checklists. When it happens, the costs stack up fast — forensic investigators, legal advice on notification obligations, system rebuilds, and days or weeks of lost trading while systems are restored.
That residual risk is what cyber cover for Australian businesses is designed to absorb. Good policies do more than reimburse losses after the fact — they typically include access to a 24/7 incident response team, which for a small business without an IT department can matter more than the indemnity itself. It’s the difference between improvising through the worst week of your business life and having specialists on the phone within the hour.
Where to start
Do the checklist first — insurers increasingly expect controls like MFA and tested backups as a condition of cover anyway, and businesses with good hygiene pay less for it. Then treat cyber insurance the way you treat the smoke alarms and the fire extinguisher: the layer you invest in precisely because you plan never to need it.

