smallbusiness.net.au

Board 4 · Devices and accounts

A cyber check-up for the till, the laptop and the phone

The key actions in the Australian Cyber Security Centre’s guides for small businesses are four habits: multi-factor authentication, strong unique passwords kept in a password manager, automatic updates, and regular backups. This board turns that advice into a check-up you can run on the devices your business already uses, and says where to call, at any hour, when something goes wrong.

General information, not technical advice for your systems. The official place to check is the Australian Signals Directorate’s small business hub at cyber.gov.au.

Five minutes

Start with a self-assessment

The Australian Signals Directorate’s Cyber Health Check is a free, anonymous self-assessment of about five minutes, made of simple questions, that gives a small business an action plan with advice suited to it.

For a fuller start, the ACSC’s educational pack for small businesses gathers a checklist to track progress, Exercise in a Box for practising a response, a quiz, a top tips poster, and guides on ransomware, email attacks and securing a mobile phone. The ACSC recommends that small businesses put Maturity Level One of its Essential Eight strategies in place.

The four habits

The key actions, device by device

The ACSC has written step-by-step guides, prepared in consultation with Apple, Google and Microsoft, for small businesses using their devices and accounts. The page sets out the same four key actions. Tick them off for every device and account the business uses:

  • Multi-factor authentication on. Use it wherever it is offered, and where you can, choose a kind that resists phishing, such as passkeys or hardware security keys.
  • Long, unique passwords in a password manager. Where an account still uses a password, the guides ask for one that is long (at least 15 characters, ideally a passphrase of four or more unrelated words), mixing capitals, symbols and numbers, and used on no other account. ASD recommends a standalone password manager, and the Google and Microsoft guides suggest keeping business accounts in a different password manager from personal ones.
  • Automatic updates on. Turn them on for the operating system and for apps, so security fixes arrive early.
  • Regular backups. Back up important business data so you can recover quickly if something goes wrong.

The cyber.gov.au hub also calls keeping software up to date and keeping current backups stored offline the best way to protect a business from a ransomware attack. The guide for each kind of device, with the exact settings to change, is on the ACSC’s how-to guides for small business page.

Older devices

The device that no longer gets updates

A device, program or system reaches end of support when its maker stops sending security updates and technical support. It may keep working, but known weaknesses can stay unpatched, and the ACSC says the risk of an incident is much higher. Its guidance includes the case of an architecture firm locked out of its own files by ransomware after an attacker got in through outdated firmware on its server.

What the ACSC suggests for older devices and software
SituationWhat to do
Still supportedKeep automatic updates on and install updates as soon as they arrive, including on routers and other networked devices.
Support ending soonCheck each product’s end-of-support date on its maker’s website, since each can differ, so you know when to upgrade.
No longer supportedUpgrade to a supported product as soon as possible. If you replace hardware, follow the ACSC’s advice on disposing of a device securely.
Can’t be replaced yetDisconnect it from the internet, Wi-Fi, Bluetooth and other networks where possible; don’t store important data on it or log in to accounts with it; don’t open unknown links and attachments; don’t install apps you don’t need, and remove ones you no longer use; keep it locked.

People

The staff, and the message that feels urgent

The Ombudsman’s cyber checklist for small businesses includes talking to your staff about cyber security and knowing who has access to your data. It also points to Cyber Wardens, free online training funded by the Australian Government for small business owners and their employees.

Scams reach work accounts by email, text, phone call and social media, and the ACSC names the tricks they lean on: pretending to be someone you trust, such as a bank or government; urging you to act fast; playing on fear, excitement or curiosity; offers that seem too good to be true; and real news used to look genuine. Its advice is to check any request for money or sensitive information using contact details you already trust, never the ones in the message.

When it happens

The first hour after something goes wrong

Australian Cyber Security Hotline

1300 CYBER1 (1300 292 371), 24 hours a day, 7 days a week. The hotline can connect you with support services and guide you through reporting to police through ReportCyber; it says it can’t provide technical support for your device or recover lost money.

For a suspicious email, message or call that may have cost money, information or access, the ACSC’s first steps are these:

  • don’t respond to threats or transfer any money, don’t click links, and don’t give anyone remote access to a computer or account;
  • contact your bank to secure the affected accounts or cards;
  • report the cybercrime to police through ReportCyber;
  • report it to the business, service or platform involved, and to whoever looks after your IT if a work device was affected;
  • if a scammer is impersonating an Australian business, contact the fair trading agency in your state or territory;
  • get identity security support from IDCARE.

The cyber.gov.au hub describes IDCARE’s small business cyber resilience service as free, tailored support for building resilience and for recovering after an incident. The ACSC’s help during a cybercrime page has the steps for each kind of incident, including malware, hacking and ransomware.