You don't need a consultant to find many of the most common cyber risks. One structured afternoon can uncover preventable gaps, such as a former employee's active login, a backup that doesn't restore files, or a payment process that trusts email alone.
To complete this checklist, allow around three to four hours. A very small business may finish much sooner, while a business with more users, devices and cloud services may need additional time. You'll need administrator access to Microsoft 365 or Google Workspace, access to your backup system, and a notepad or spreadsheet for recording your findings.
The method matters more than the tools: look at evidence, not memory. “I think only two people have admin access” is an assumption. Opening the admin panel and counting them gives you a fact. Each step below asks you to check an actual setting, process or record.
Write down every issue you find. Unless some findings appear urgent, don’t stop to fix each issue as you go, or you may burn the whole afternoon on the first item. Fixing them comes later, in priority order shown below.
However, act immediately if you find a clear sign of active compromise. This includes an unknown account administrator, an unauthorised payment or an email forwarding rule you did not create.
Open the Microsoft 365 Admin Centre or Google Workspace Admin Console and check six things:
Other important account checks:
Export or screenshot the user list and MFA report. Date it. This is your baseline for next time. Store this user list securely as it contains personal information and details that could help a cyber criminal.
Review your actual payment process and recent examples:
If you suspect an active incident, stop the health check and seek professional assistance. Do not delete files, messages or logs that may be evidence. Where safe to do so, disconnect an affected computer from Wi-Fi or the network without wiping or resetting it.
Finish with the Australian government’s free and anonymous Cyber Health Check Tool. It takes about five minutes and provides simple, tailored suggestions that you can compare with your findings.
For a deeper follow-up with your team, use the ACSC's free Exercise in a Box. It provides practical exercises to help you test how your business would respond to a cyber incident.
Turn your notes into an action plan. Use one row for each finding and four columns:
| Finding | Risk | Fix | Who / by when |
|---|---|---|---|
| 2 staff accounts do not have MFA | A stolen password could allow someone to access business email | Enforce MFA | Me / Friday |
That simple table is the beginning of a practical cyber security risk register. Over time, you can add the severity of the risk, status and date reviewed.
For most small businesses, repeating this check every three months is a practical starting point. Run it sooner after an employee departure, major system change or suspected incident.
Deal immediately with any sign of active compromise. Examples may include an unknown administrator, unexplained email forwarding rule, unfamiliar login, or unauthorised payment.
For other findings, a practical starting order is:
This health check can identify common security gaps, but it does not test your systems for technical weaknesses. Seek professional help if there’s a suspected cyber security incident, when important findings remain unfixed, when your business needs technical security testing, or when it holds sensitive or high-risk information such as health records, identity documents, TFNs or financial details.
Most Australian businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but important exceptions apply. For example, some health service providers, businesses that trade in personal information and certain Commonwealth contractors may be covered regardless of turnover.
Check the OAIC’s Small Business Privacy Checklist or obtain legal advice if you are unsure whether the Privacy Act applies to your business.
When engaging a cyber security provider, ask what framework and assessment method they will use. Depending on your systems and risks, an Essential Eight assessment - often beginning with Maturity Level One - may provide a structured and comparable baseline.
Do the ten-minute version:
This article is part of our cyber security for small businesses series - including why hackers target accounting firms.
Yes. A business owner or manager can for check common risks, including inactive accounts, missing MFAs, untested backups, unsupported devices, and unsafe payment processes. Please note that a DIY review does not test networks, applications, or systems for technical vulnerabilities.
No. You need admin access to your Microsoft 365 or Google Workspace, your backup system login, and a notepad. Follow the cyber security checklist steps and write down your findings to act on them later.
File synchronisation may help recover earlier files, but a synchronised folder should not be your business’ only backup. Deletions, damaged files or ransomware may be synchronised across devices. Keep a separate protected backup and regularly test that you can restore files from it.
Every three months is a practical starting point. Run the check sooner if there is a major change, such as a staff departure, the introduction of new software, a change of IT provider, or a suspected cyber security incident.
Yes. The Cyber Health Check Tool on cyber.gov.au is free and anonymous. It provides tailored suggestions based on your answers. The ACSC's free Exercise in a Box can help your team practice responding to realistic cyber incident scenarios.
Seek professional help after a suspected cyber security incident, when important security issues remain unresolved, when a technical testing is required, or when your business holds sensitive or high-risk information, such as health records, identity documents, tax file numbers or financial details. Most Australian small businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but important exceptions apply. Obtain privacy or legal advice if you are unsure whether the Privacy Act applies to your business.


