October is Cyber Security Awareness Month. Five practical checks you can run this week, explained in plain language for busy business owners.
October is Cyber Security Awareness Month in Australia, which is as good a reason as any to spend an hour on the boring jobs. None of the five checks below need a technician, and all of them are things we see cause real trouble.
1. Turn on multi-factor authentication for email and banking
Multi-factor authentication, usually shortened to MFA, means logging in needs two things: something you know, like your password, and something you have, like a code from an app on your phone. If someone steals your password, it is not enough on its own.
Email is the one that matters most, because email is the key to everything else. Password resets for your bank, your accounting software and your supplier portals all land in your inbox. If someone else is reading it, they can quietly take over the lot.
Use an authenticator app rather than text messages where you can. Text messages are better than nothing, but phone numbers can be hijacked. And make sure MFA is on for every staff member, not just the boss – attackers go for whichever door is unlocked.
2. Work out who still has access
Have a look at the list of accounts in your email system, your accounting package and your industry software. We regularly find working logins for people who left two or three years ago.
It is rarely malice. It is usually just that nobody had a checklist for a staff member finishing up. But a forgotten account with an old password and no MFA is exactly what an attacker is hoping to find, and nobody is going to notice it being used.
- List every system your staff log in to, including the ones you pay for by credit card.
- Remove or disable accounts for anyone who has left.
- Check who has administrator rights and reduce it to the smallest sensible number.
- Look for shared logins where several people use one account, and plan to split them up.
- Write a one-page offboarding checklist so this does not build up again.
3. Check whether anything is still on Windows 10
Microsoft ended free support for Windows 10 on 14 October 2025. Computers still running it will keep switching on, but they no longer receive the regular security updates that fix newly discovered holes.
That matters more than people expect. Attackers pay close attention to unsupported systems precisely because the holes stay open. The risk is not on day one, it grows quietly month by month.
Some computers will upgrade to Windows 11 without any fuss. Others are too old and will need replacing, which is a hardware conversation and gets quoted separately. Either way, the first job is knowing which machines you actually have. Reception desks, back offices, the laptop in the storeroom and the machine that only runs the label printer are the ones that get forgotten.
4. Prove your backups can actually be restored
Most businesses have a backup of some sort. Far fewer have ever tested restoring from it. A backup that has been silently failing for eight months looks exactly the same as a working one until the day you need it.
Pick one important file, ask for it to be restored from last month, and see how long it takes and whether it works. Then ask the bigger question: if the whole system were unavailable tomorrow morning, how long would it take to get trading again, and what would we lose in the meantime?
Two other things worth confirming. Your backup should include your cloud services, not only the computer in the corner – Microsoft 365 is not backed up for you the way people assume. And at least one copy should be somewhere separate, so a fire, a flood or ransomware cannot take the original and the backup together.
5. Ask whether your staff could spot a dodgy invoice email
Phishing is a message designed to trick someone into handing over a password or clicking something harmful. It usually looks like a normal email from a service you use, and the modern ones are well written with correct logos.
Business email compromise is the more expensive cousin. An attacker gets into a real email account – yours, or one belonging to a supplier – watches the conversation for a while, then sends a genuine-looking invoice with their own bank details. Nothing looks wrong, because nothing is fake except the account number. Scamwatch has been warning about this pattern for years, and it remains one of the costliest for Australian businesses.
The defence is a rule, not a technology: any change to bank details gets verified by ringing the supplier on a number you already had, never the number in the email. Make it a standing rule so no staff member has to make a judgement call under pressure.
How to run a 10-minute phishing chat at your next team meeting
Pull up two real emails from your own inbox, one genuine and one dodgy, and ask the team which is which and why. Then agree three things out loud: nobody is ever in trouble for reporting a suspicious email, changes to bank details are always confirmed by phone on a known number, and anything urgent from the boss asking for payment or gift cards gets checked in person. Ten minutes, no slides, and people remember it.
Where to start if all five feel like a lot
Do MFA on email first. It is the single change that stops the most harm for the least effort, and you can usually get it done in an afternoon. Then work down the list at whatever pace suits.
If you would like a straight answer on where your business currently stands, we have a free Cyber Security Scorecard on this site. It is fifteen plain questions and takes a few minutes, and you get a percentage score and a report telling you what to fix first. No technical knowledge needed, and no obligation to talk to us afterwards.
The Australian Signals Directorate publishes an Annual Cyber Threat Report each year, and the pattern it describes rarely changes: most incidents affecting small businesses are not clever, they are opportunistic. Locked doors do most of the work.
Want someone to walk through these five with you?
Book a free cyber security assessment- cyber security
- mfa
- phishing
- backups
- small business
