The DIY Cyber Security Health Check for Small Business

A practical, jargon-free cyber security checklist you can complete this afternoon to see where your business is exposed - no IT department required.

You don't need a consultant to find many of the most common cyber risks. One structured afternoon can uncover preventable gaps, such as a former employee's active login, a backup that doesn't restore files, or a payment process that trusts email alone.

To complete this checklist, allow around three to four hours. A very small business may finish much sooner, while a business with more users, devices and cloud services may need additional time. You'll need administrator access to Microsoft 365 or Google Workspace, access to your backup system, and a notepad or spreadsheet for recording your findings.

The method matters more than the tools: look at evidence, not memory. “I think only two people have admin access” is an assumption. Opening the admin panel and counting them gives you a fact. Each step below asks you to check an actual setting, process or record.

Write down every issue you find. Unless some findings appear urgent, don’t stop to fix each issue as you go, or you may burn the whole afternoon on the first item. Fixing them comes later, in priority order shown below.

However, act immediately if you find a clear sign of active compromise. This includes an unknown account administrator, an unauthorised payment or an email forwarding rule you did not create.

Step 1: Accounts and access - 60 minutes

Open the Microsoft 365 Admin Centre or Google Workspace Admin Console and check six things:

  • The user list. Read every name. Is anyone no longer with the business but still active? Is there an account you cannot explain? Record former users for removal. Remove unknown users urgently.
  • MFA coverage. Confirm that every user is required to use MFA and has completed registration. In Microsoft 365, don’t rely only on the legacy per-user MFA status: MFA may instead be enforced through Security Defaults or Conditional Access. Check both - the organisation-wide policy and the users who have registered. In Google Workspace, check 2-Step Verification enrolment and enforcement.
  • Who's an administrator? Count the accounts with administrator roles. There should be very few, and you should be able to explain why each person needs that level of access.
  • Guest and external access. Review guest users, contractors, delegated mailbox access and connected third-party applications. Remove access that is no longer required.
  • Email forwarding rules. Check the business owner's and finance mailboxes for rules that forward messages outside the business. Cyber criminals who compromise email accounts may create a hidden forwarding rule. It may remain active after the password is changed. Treat anything you do not recognise as urgent.
  • Account recovery. For owner and administrator accounts, check the recovery email addresses, phone numbers and backup methods. Remove outdated details. Store emergency recovery codes securely and make sure the business - not one employee personally - controls the recovery process.

Other important account checks:

  • Email domain protection. If your business uses its own email domain, ask your email provider or IT administrator to confirm that SPF, DKIM and DMARC are configured correctly. These help other email systems recognise messages that falsely claim to come from your domain.
  • Domain-name protection. Sign in to your domain registrar and confirm that your business controls the account, MFA is turned on, the recovery details are current, and automatic renewal is enabled. Losing control of your domain can affect your website, email, and password resets.
  • Passwords and shared accounts. Check whether staff reuse passwords or share one login. Each person should have their own account. All important accounts should use unique passwords stored in a reputable password manager.

Evidence to keep

Export or screenshot the user list and MFA report. Date it. This is your baseline for next time. Store this user list securely as it contains personal information and details that could help a cyber criminal.

Step 2: Money paths - 30 minutes

Review your actual payment process and recent examples:

  • How do suppliers change their bank details? If the answer is "by email", record it as a finding. Never accept new or changed payment details without confirming the request through a separate, trusted channel. For example, call the supplier using a phone number you already have, not a phone number provided in the email.
  • Can one person create and approve payments alone? Where separation of duties is not practical, use several compensating controls: independent verification of new or changed payment details, bank transaction limits, payment alerts and a regular review of payments by another owner, director or trusted adviser.
  • Does your banking show information about the recipient before you approve a payment? This may include an account-name check, PayID name, or Confirmation of Payee result. Make sure whoever pays invoices understands the message, but does not use it as a substitute for independently confirming changed payment details.

Step 3: Backups and cloud systems - 30 minutes

  • What is actually backed up? Name the systems and information your business could not operate without. Examples may include accounting and payroll records, client files, email, customer databases, contracts, website data, source code, project files, important system settings and more. Confirm that each one is included in the backup, not just "the computer".
  • Is one backup copy protected? A permanently connected drive or a synchronised folder like OneDrive or Google Drive should not be your only backup. Deleted, encrypted, damaged files or ransomware may be synchronised across devices. Check whether your service offers separate version history or recovery features.
  • Restore one real file now. Pick any recent document from your backup, restore it and open it. This may be the highest-value ten minutes of the whole health check. A backup that has never been tested is only an assumption. If the restore fails, you have discovered the problem to fix before a real emergency.
  • Critical cloud systems. List the online services your business relies on. Examples may include accounting, payroll, CRM, website hosting, and document storage. Confirm who owns each account, who has administrator access, and what recovery or export options are available.

Step 4: Devices and updates - 30 minutes

  • Is every work computer and phone supported and automatically updating? Check whether the operating system is still receiving updates, and whether automatic updates are on. Put anything that no longer receives security updates on the replacement list - it cannot be protected to the same standard as a supported device.
  • Are laptops encrypted? Check whether BitLocker on Windows or FileVault on Mac is turned on.
  • Is computer protection working? Check that antivirus or other built-in security protection is turned on and up to date.
  • Do devices lock automatically? Make sure computers and phones lock after a short period of inactivity and require a strong password, passcode, PIN or biometric sign-in.
  • Does each person have their own login? Ensure that staff do not share accounts and do not use an administrator account for everyday work.
  • Lost phones. If a phone with company email went missing today, could you wipe it remotely? If you don't know, the answer is no.

Step 5: People and paper - 30 minutes

  • Offboarding checklist. Is there a written checklist removing a departing employee or contractor’s access to every business system? If not, create one using the user list from Step 1.
  • The two rules for staff. Make sure everyone who works with email or payments knows these rules:
    1 - Never approve an MFA prompt you didn't request. Repeated unexpected prompts may mean that someone already has your password.
    2 - Never change suppliers’ bank details based on an email alone. Confirm the changes by calling a trusted phone number you already have.
  • The incident card. Print one page with your bank's fraud number, the Australian Cyber Security Hotline 1300 CYBER1 (1300 292 371) - it’s available 24/7, and the ReportCyber web address. Also include your cyber insurer and policy number, IT or incident-response provider, legal or privacy adviser, authorised decision-maker, domain registrar and website host. Keep this card somewhere accessible if your systems are unavailable.

If you suspect an active incident, stop the health check and seek professional assistance. Do not delete files, messages or logs that may be evidence. Where safe to do so, disconnect an affected computer from Wi-Fi or the network without wiping or resetting it.

Step 6: Official checks and your findings - 20 minutes

Finish with the Australian government’s free and anonymous Cyber Health Check Tool. It takes about five minutes and provides simple, tailored suggestions that you can compare with your findings.

For a deeper follow-up with your team, use the ACSC's free Exercise in a Box. It provides practical exercises to help you test how your business would respond to a cyber incident.

Turn your notes into an action plan. Use one row for each finding and four columns:

FindingRiskFixWho / by when
2 staff accounts do not have MFAA stolen password could allow someone to access business emailEnforce MFAMe / Friday

That simple table is the beginning of a practical cyber security risk register. Over time, you can add the severity of the risk, status and date reviewed.

For most small businesses, repeating this check every three months is a practical starting point. Run it sooner after an employee departure, major system change or suspected incident.

Prioritise your findings, or what should I fix first after the health check?

Deal immediately with any sign of active compromise. Examples may include an unknown administrator, unexplained email forwarding rule, unfamiliar login, or unauthorised payment.

For other findings, a practical starting order is:

  1. Protect administrator, email and financial accounts with MFA.
  2. Disable former users who still have access.
  3. Confirm that critical information can be restored from backup.
  4. Strengthen payment verification and approval controls.
  5. Update devices and software.
  6. Replace unsupported devices and software.
  7. Address the remaining findings according to their likely business impact.

When DIY isn't enough

This health check can identify common security gaps, but it does not test your systems for technical weaknesses. Seek professional help if there’s a suspected cyber security incident, when important findings remain unfixed, when your business needs technical security testing, or when it holds sensitive or high-risk information such as health records, identity documents, TFNs or financial details.

Most Australian businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but important exceptions apply. For example, some health service providers, businesses that trade in personal information and certain Commonwealth contractors may be covered regardless of turnover.

Check the OAIC’s Small Business Privacy Checklist or obtain legal advice if you are unsure whether the Privacy Act applies to your business.

When engaging a cyber security provider, ask what framework and assessment method they will use. Depending on your systems and risks, an Essential Eight assessment - often beginning with Maturity Level One - may provide a structured and comparable baseline.

Can't spare a whole afternoon?

Do the ten-minute version:

  1. Check that MFA protects the owner's email account.
  2. Explain the payment-verification rule to anyone who pays invoices.
  3. Restore one file from backup.

This article is part of our cyber security for small businesses series - including why hackers target accounting firms.


Sources used

  • ASD’s ACSC, Cyber Health Check Tool
  • ASD’s ACSC, Small Business Cyber Security Guide
  • ASD’s ACSC, Small Business Hub
  • ASD’s ACSC, Preventing Business Email Compromise
  • ASD’s ACSC, Review Your Email Account Security
  • ASD’s ACSC, Exercise in a Box
  • ASD’s ACSC, Essential Eight
  • ASD’s ACSC, Cybercrime - getting help
  • business.gov.au, Cyber Security Checklist
  • OAIC, Small Business and the Privacy Act
  • Microsoft Learn, relevant current MFA administration guidance
  • Google Workspace Admin Help, relevant 2-Step Verification guidance
Share
Share

Frequently Asked Questions

Can a small business complete a cyber security health check without an IT provider?

Yes. A business owner or manager can for check common risks, including inactive accounts, missing MFAs, untested backups, unsupported devices, and unsafe payment processes. Please note that a DIY review does not test networks, applications, or systems for technical vulnerabilities.

Do I need an IT background to run a cyber security health check?

No. You need admin access to your Microsoft 365 or Google Workspace, your backup system login, and a notepad. Follow the cyber security checklist steps and write down your findings to act on them later.

Is OneDrive or Google Drive a backup?

File synchronisation may help recover earlier files, but a synchronised folder should not be your business’ only backup. Deletions, damaged files or ransomware may be synchronised across devices. Keep a separate protected backup and regularly test that you can restore files from it.

How often should a small business run a cyber security health check?

Every three months is a practical starting point. Run the check sooner if there is a major change, such as a staff departure, the introduction of new software, a change of IT provider, or a suspected cyber security incident.

Is there a free government cyber security assessment for small businesses?

Yes. The Cyber Health Check Tool on cyber.gov.au is free and anonymous. It provides tailored suggestions based on your answers. The ACSC's free Exercise in a Box can help your team practice responding to realistic cyber incident scenarios.

When should a business get professional cyber security help?

Seek professional help after a suspected cyber security incident, when important security issues remain unresolved, when a technical testing is required, or when your business holds sensitive or high-risk information, such as health records, identity documents, tax file numbers or financial details. Most Australian small businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but important exceptions apply. Obtain privacy or legal advice if you are unsure whether the Privacy Act applies to your business.

More To Explore

Latitude Financial Data Breach: Lessons for Small Businesses

Latitude Financial Data Breach: Lessons for Small Businesses

The 2023 Latitude Financial breach exposed approximately 14 million records, including information dating back to 2005. Here is what Australian businesses can learn about data retention, third-party access, stolen credentials and breach response.
What The Medibank Breach Teaches Small Businesses

What The Medibank Breach Teaches Small Businesses

The 2022 Medibank data breach made headlines, but the weaknesses that contributed to it are not unique to large companies. Here are the practical lessons small businesses can take from the incident.
Why Hackers Target Accounting Firms and How to Reduce the Risk

Why Hackers Target Accounting Firms and How to Reduce the Risk

Accounting firms hold the keys to their clients' finances - which is exactly why they're such an attractive target for cybercriminals. Here's what makes them vulnerable, and how to close the cyber security gaps.