Cyber Security Brisbane

Cyber Security Checklist
for Brisbane Small Business

Twenty-three practical controls Brisbane SMEs can roll out across MFA, email, backups and staff training. Built around ACSC guidance and the Privacy Act.

April 2026
9 min read
Brisbane, QLD
ACSC Aligned
ACL Compliant
ASD Trained

Cyber attacks against Australian small businesses doubled between 2022 and 2025. The average ransomware ransom demanded in Australia now exceeds $1M. Yet the attackers behind those numbers are not elite — they exploit basic mistakes any Brisbane SME can fix in a weekend.

This 23-control checklist is the practical floor we recommend every Brisbane SME implement. It maps to the ACSC Essential Eight and the Privacy Act 1988 (NDB scheme). Tick what is done, plan what is not, and book a conversation if you are stuck.

Why this checklist exists

Most SME breaches we see in Brisbane do not involve sophisticated attacks — they involve a missed MFA setup, a reused password, an unpatched browser, or a backup that was never tested. This checklist closes those gaps.

Why This Checklist, Right Now

Three things happened in 2024-25 that changed the risk equation for Brisbane SMEs:

  • Privacy Act fines went up to $50M for serious or repeated breaches
  • Cyber insurers tightened underwriting — they now refuse cover without MFA, EDR and offline backups
  • AI-powered phishing made dodgy emails sound like your accountant

Treat this checklist like an annual roadworthy for your business — same logic, same value, same regulatory pressure.

Identity & Access (5 Controls)

  1. 1. Multi-factor authentication on every cloud account
    Microsoft 365, Xero, MYOB, Dropbox, banking. Microsoft Authenticator with number-matching, not SMS.
  2. 2. Strong unique passwords (password manager)
    1Password, Bitwarden or Keeper. No reused passwords. No spreadsheets of credentials.
  3. 3. Block legacy authentication
    Old IMAP/POP/SMTP auth bypasses MFA. Block it in Microsoft Entra Conditional Access.
  4. 4. Separate admin accounts from daily-use accounts
    Admin work uses a dedicated account with hardware MFA, no email, no browsing.
  5. 5. Off-board promptly when staff leave
    Disable accounts within an hour, not a week. Documented checklist.

Email & Phishing (4 Controls)

  1. 6. SPF, DKIM, DMARC configured for your domain
    Stops spoofing of your own brand. Free with M365 — just needs DNS records set correctly.
  2. 7. Anti-phishing & safe-links policies enabled
    Microsoft Defender for Office 365 (included in Business Premium). Real-time URL detonation.
  3. 8. External email banner
    Visual warning on every external email helps staff spot impersonation attempts.
  4. 9. Annual phishing simulation
    Run a controlled test, train anyone who clicks. Do not punish — coach.

Devices & Endpoints (4 Controls)

  1. 10. Modern EDR on every device
    Microsoft Defender for Endpoint, SentinelOne, CrowdStrike. Not just free antivirus.
  2. 11. Disk encryption (BitLocker / FileVault)
    Mandatory for any laptop with company data. One stolen laptop without it = a breach.
  3. 12. Auto-patching for OS & apps
    Intune Autopatch, Action1, NinjaOne. Not 'sometime when staff click yes'.
  4. 13. Remote wipe capability
    Lost or stolen device — wipe instantly. Intune does this for Windows, iOS and Android.

Data & Backups (4 Controls)

  1. 14. M365 cloud-to-cloud backup
    Microsoft does not back up your M365 data the way you think. Datto, Spanning, Veeam.
  2. 15. Immutable backup copy
    Ransomware cannot encrypt what it cannot change. Datto, Veeam Hardened Repository, S3 Object Lock.
  3. 16. Quarterly restore tests
    An untested backup is not a backup. Pull a random folder, restore it, document the test.
  4. 17. Data classification & retention policy
    Know where personal information lives. Privacy Act expects it. M365 sensitivity labels help.

Network & Wi-Fi (3 Controls)

  1. 18. Separate guest Wi-Fi from staff Wi-Fi
    Visitors and personal phones never on the network with your file server.
  2. 19. Modern firewall on the office NBN
    Ubiquiti, Meraki, Fortinet. Not the ISP-supplied router on its own.
  3. 20. WPA3 (or WPA2-AES at minimum)
    WEP and WPA are broken. Update old access points.

People & Training (3 Controls)

  1. 21. Annual staff cyber training
    30-minute video + quiz. KnowBe4, Hoxhunt, M365 Attack Simulation Training.
  2. 22. Documented incident response plan
    Who calls who when something goes wrong, in what order. Print and stick on the wall.
  3. 23. Annual review & cyber insurance check
    Renew controls every 12 months. Confirm insurance still meets your risk.

Suggested Schedule

Week 1-2

MFA, password manager, SPF/DKIM/DMARC, M365 cloud backup, EDR.

Week 3-4

Disk encryption, Intune, anti-phishing policies, guest Wi-Fi split, firewall.

Month 2

Restore test, phishing simulation, staff training, incident response doc.

Quarterly

Restore drills, off-board audit, patch compliance review, insurance check.

Costs in Brisbane

ItemEffortCost
Initial security audit1-2hrFrom $410
MFA rollout (10-25 users)3-5hr$410-$615
SPF/DKIM/DMARC setup2hr remote$250
M365 cloud-to-cloud backup2hr setup + license$250 + $5/user/mo
Phishing simulation campaign1-2 daysFrom $410
Managed security planOngoingFrom $99/user/month
Onsite hourly$205/hr
Remote hourly$125/hr

Pro tip: If you only have one weekend, knock off Identity (1-5) and Email (6-9). Those nine controls block over 80% of real-world Brisbane SME compromises.

Cyber insurance gotcha: Most policies now require 'enterprise-grade EDR' (not free Defender), MFA on email and remote access, and offline/immutable backups. If any of these are missing, your claim may be denied.

Want Us to Run This Checklist For You?

Half-day Brisbane onsite, full report, prioritised plan and pricing.

Book a Cyber Audit — From $410
What our Brisbane audit covers

We walk every line of this checklist with you, score current state, and produce a prioritised plan with costs. Half-day from $820, includes M365 tenant review, device inventory, and a written report.

Brisbane SMEs Trust Us

4.9 stars across 100+ Google reviews

★★★★★

"We're a 12-person creative agency. After our accountant got a fake invoice email, we asked Geeks Brisbane to run their cyber checklist. They got us through 18 of the 23 controls in one weekend. Honest pricing and no IT jargon."

SK
Sarah K. New Farm
★★★★★

"Found out the hard way our M365 'backup' was just the recycle bin. Geeks Brisbane set up proper Datto cloud backup, immutable copy, the lot. Six months later we did a real restore drill — worked first time. Brilliant."

AP
Andrew P. Indooroopilly
★★★★★

"Sole trader bookkeeper here. I thought cyber security meant antivirus. The Geeks team walked me through everything in 90 minutes — MFA, password manager, M365 backup. Cost less than a tank of fuel and now I sleep better."

LM
Lucy M. Springfield Lakes

How It Works

From booking to a documented cyber posture in under 30 days

1

Audit

23-control review of your IT environment, M365, devices.

2

Plan

Prioritised, costed action plan with timeline.

3

Implement

Hands-on rollout — MFA, backups, EDR, training.

4

Monitor

Quarterly reviews or full managed security plan.

Frequently Asked Questions

Common questions from Brisbane SMEs

MFA on every cloud account, a password manager, M365 cloud-to-cloud backup, and modern EDR on every device. Those four controls — done in a weekend — block the majority of real-world SME attacks. Then work the rest of the checklist over 60 days.
If you turn over more than $3 million annually, yes. If you handle health information, you are covered regardless of turnover. Many SMEs that contract to bigger firms also have Privacy Act obligations baked into their service agreements.
For very small businesses (1-3 people) — it is fine as a baseline, but only if combined with MFA, patching and backups. For 5+ staff and any regulated data, step up to Defender for Endpoint, SentinelOne or similar EDR.
Industry rule-of-thumb: 5-10% of IT spend. For a 10-person Brisbane firm, that is roughly $300-700 per month managed, or $5,000-15,000 for an initial uplift. Cheap compared to a single ransomware incident.
Most controls — yes. M365 hardening, MFA, anti-phishing, backups, training — all remote at $125/hr. Onsite needed for firewall installs, network segmentation, or device imaging.
For a 10-30 staff Brisbane SME, 30-60 days of part-time effort with a managed IT partner. Standalone DIY effort: 80-120 hours of admin time.
Notify the OAIC within 30 days if personal information is involved. Call your cyber insurer. Geeks Brisbane offers emergency response from $410 for the first response and triage.

Related: Digital Security Check | MFA Setup | Internet Security

Lock Down Your Cyber Risk Today

23-point checklist run as a half-day Brisbane audit. From $820. Same-day onsite booking across SEQ.

ACSC Aligned
Same Week Available
Privacy Act Mapped
4.9★ Google Rating

Main Menu

Contact Us