Cyber awareness, insurance and protection: Seven tips for small businesses
23 July
Small businesses rely on email, cloud platforms, online banking, customer databases and digital payments. This creates convenience, but also opportunities for criminals.
A cyber incident can interrupt operations, expose confidential information, damage customer trust and create major recovery costs. Cyber protection is not simply an IT issue; it is a business continuity, financial and reputational issue.
Make Cyber Awareness Part of Everyday Business
Technology cannot stop every attack. Staff should be trained to recognise suspicious emails, unexpected payment requests, fake login pages, unusual attachments and urgent messages designed to create panic. Cyber awareness should be discussed regularly, particularly with employees who handle payments, customer data or administration. Encourage people to pause, question and report anything unusual.
Strengthen Passwords and Account Access
Important business accounts should have unique, strong passwords or passphrases. A password manager can help staff create and store secure login details without reusing them. Multi-factor authentication should be activated wherever available, particularly for email, banking, accounting software, cloud storage and administrator accounts. Staff should never approve an unexpected authentication request or share a verification code.
Keep Software and Devices Updated
Outdated software may contain known weaknesses that criminals can exploit. Turn on automatic updates for operating systems, browsers, applications, antivirus tools, routers and connected devices. Remove programs and user accounts that are no longer required. Access should be limited according to each employee’s role, with administrator privileges reserved for those who genuinely need them. The Australian Cyber Security Centre provides practical guidance and free resources specifically designed for small businesses.
Back Up Critical Business Information
Regular backups can help a business recover from ransomware, equipment failure, theft or accidental deletion. Important files may include customer records, financial data, contracts, databases and website content. Backups should be protected and kept separately from the main network. Recovery procedures should also be tested, because a backup has limited value if information cannot be restored when required.
Protect Payments and Supplier Changes
Business email compromise can occur when criminals impersonate an owner, employee, supplier or trusted contact to redirect payments. Any request to change bank details should be verified using a known telephone number, not contact details in the message. Consider dual approval for larger transactions and clear limits on who can authorise payments. Simple checks can stop a convincing email from becoming a costly loss.
Understand Cyber Insurance
Cyber insurance may help with costs such as forensic investigation, data recovery, legal support, customer notification, business interruption and third-party claims, depending on the policy. Policies vary and may contain exclusions, sub-limits and minimum security requirements. Businesses should disclose their systems and controls accurately, review coverage limits, and understand excesses, waiting periods and incident notification rules.
Cyber insurance should complement strong security practices, not replace them. A qualified insurance broker or adviser can help compare policies, identify potential gaps and explain what assistance may be available after an incident.
Prepare an Incident Response Plan
A written plan should explain who takes control, how systems are isolated, which specialists are contacted, how evidence is preserved and how customers, insurers and authorities are informed. Australian privacy obligations may require some organisations to notify affected individuals and the Office of the Australian Information Commissioner when a breach is likely to cause serious harm.
Keep contact details for your IT provider, insurer, broker and legal adviser somewhere accessible if systems are unavailable.
Cyber threats continue to evolve, but small businesses can reduce their exposure through planning and consistent habits. Speak with a qualified cyber security professional about technical controls and with an experienced insurance broker or adviser about suitable cover. Legal and privacy advice may also be needed when collecting personal information or responding to a breach. Good advice can identify gaps before an incident and provide a clearer path to recovery.
If this article has inspired you to think about your unique situation and, more importantly, what you and your family are going through right now, please get in touch with your advice professional.
This information does not consider any person’s objectives, financial situation, or needs. Before making a decision, you should consider whether it is appropriate in light of your particular objectives, financial situation, or needs.