There is probably a security job you already know needs doing.
The former contractor's account. The website nobody has updated. The old laptop under the desk because you are not quite sure what is still on it.
It may have survived several meetings in which everyone agreed cybersecurity was important. Agreement was never really the difficulty. Finding someone to do the job, and checking that it was finished, was.
October is a useful excuse to return to it.
Cyber Security Awareness Month takes place every October. ASD's Cyber Action Year 2026 initiative extends that idea into a year of practical work, bringing government, industry and critical infrastructure together around measurable security outcomes. Its recommendations include addressing legacy technology and improving event logging.
That does not mean a five-person business needs to adopt an entire national program. It does mean there is a sensible question to ask before another month of security reminders begins.
What will actually be different when October is over?
Give a Small Job a Proper Finish
I would choose a handful of changes that fit the business, give each one an owner and agree what completion looks like. Three finished jobs are useful. A list of thirty recommendations with nobody responsible is mostly another document to keep somewhere.
“Review MFA” is vague. “Check the business email administrator account, enable the strongest supported sign-in method and test its recovery arrangements” is something a person can complete.
ASD's September 2026 MFA campaign says 42% of industry, government and critical-infrastructure incidents reported to ASD in 2024–25 involved compromised accounts or credentials. That is a figure about reported incidents in those sectors, not a claim that 42% of Australian small businesses were compromised.
It is a good reason to start with the accounts that control everything else. Primary email, the domain registrar, DNS, Microsoft 365 or Google administration, cloud storage and remote IT administration deserve attention. Accounting and banking access belong in the conversation too.
ASD recommends phishing-resistant MFA such as passkeys, with alternatives such as authenticator apps where passkeys are unavailable. Check what the particular service supports. Record who owns the account and how access can be recovered if the usual phone or security key is lost. Strong sign-in protection is less useful if an old recovery address still belongs to someone who left.
For October, the result might be quite modest: the three most important accounts have appropriate MFA, named owners and usable recovery arrangements. That is progress you can show.
Check Who Can Still Get In
Open the administrator list and compare it with the people currently doing the work.
Is the old web developer still there? Does the previous IT supplier retain remote access? Can a former contractor still open shared files? And do current staff need everything their accounts can reach?
The SA Health article on least privilege looked at why a valid login does not settle whether access to a particular record is appropriate. A small business can apply that without buying an elaborate identity platform. Give people the access their work requires, and review it when the work changes.
For a useful October task, choose one sensitive shared folder. Ask its owner who should have access, compare that with the actual permissions and test the corrected result using an ordinary account. Document any access that needs to remain. Simply removing names without checking dependencies can interrupt legitimate work.
Include software connections as well as people. A trial AI assistant or a reporting integration may still have access long after somebody stopped using it. My agentic AI article makes the same request: give the connection an owner, a defined job and a way to end its access.
If the service records access changes or sensitive activity, make sure someone knows how to retrieve those records. Useful logging is much easier to establish before it is urgently needed.
Find the System Everyone Has Forgotten
Ask whoever manages the technology for a list of services reachable from the internet. Then ask what each one does.
An old staging website may still contain an earlier copy of the customer database. A NAS may have remote access enabled from when someone worked away for a week. A hosting panel or VPN may belong to a supplier arrangement that ended years ago.
If nobody can explain why an internet-facing service still exists, that is a good reason to review it.
This was the practical question behind my Exchange and technical-debt article. The difficult system is often the one whose ownership and dependencies have become unclear. Find those dependencies before shutting it down, then either maintain it properly or retire it in a controlled way.
For a simple business website, that review may also reveal features which no longer earn their maintenance cost. The answer depends on what the site actually needs to do. Removing an unused component can be a useful October result without turning the exercise into a complete website rebuild.
Patching a service is a task with a different finish line from checking whether it was compromised. If a serious exposure is discovered, follow the relevant vendor guidance and preserve useful evidence. The Mathspace incident-response article explains why closing the update ticket may leave that second question unanswered.
Keep What You Need, and Check That You Can Recover It
There are two worthwhile conversations here, and they need to happen together.
First, what personal information are you keeping without a current reason? Old customer exports, identity documents, form submissions and abandoned archives can survive long after the work that created them. My data-retention article asks how many years of customer information one stolen system could expose.
Required records still need to be retained. For entities covered by the Australian Privacy Principles, the OAIC's APP 11 guidance requires reasonable steps to destroy or de-identify information no longer needed for a permitted purpose, subject to exceptions including legal retention requirements and Commonwealth records. Check the obligations for the records concerned before deleting them.
Second, can you recover the information you do need?
A green backup indicator is encouraging. A completed restore is better evidence. ASD's backup guidance recommends regularly testing restoration.
Arrange a safe test away from the live data. Establish whether you can retrieve the required files, open them and recover the settings or applications needed to use them. Record the time involved and any missing credentials. A small file restore can reveal a problem, but it does not prove that an entire business system will recover.
An achievable October outcome is a documented recovery test, with its limits stated and someone assigned to fix the gaps. Agree how long backups should remain, too. Deleting an unnecessary live record does not automatically remove its historical copies.
Deal With the Cupboard
Old laptops, desktops, external drives and phones have a way of becoming permanent office furniture. Nobody uses them. Nobody quite wants to be responsible for throwing them away.
Start by identifying the equipment and deciding what information still needs to be recovered or retained. Before retiring a phone, check whether it holds an authenticator or other recovery method you still depend on.
Deleting files or selecting a reset option is not, by itself, a documented disposal process. Some modern encrypted devices have suitable built-in erase procedures; other media require a different approach. SSDs need particular care, and ASD's device-disposal guidance directs users to manufacturer guidance for them. There is no sensible universal instruction to overwrite every device seven times.
The job should end with an appropriate method, a recorded result and a clear destination for the device. If wiping fails or the media cannot be accessed, record that and arrange suitable handling. Do not label it sanitised because somebody tried.
The secure data-wiping service describes the assessment and reporting involved. A cupboard with fewer unresolved devices is a perfectly respectable security improvement.
A Private Household Can Have the Same Loose Ends
Several computers and phones, personal and work email, cloud storage, home networks, smart-home equipment and more than one property can create a substantial technology environment. Add family members, advisers, accountants, assistants and property managers, each with a legitimate task, and access can become difficult to keep track of.
A useful October exercise is to review the people and providers who can administer those systems. Check privileged accounts, recovery details and stale sharing links. Establish who maintains the home network and which old devices still contain private documents or backups.
Solway Web Consulting provides personalised cybersecurity and IT consulting for private clients and high-net-worth individuals in Sydney. The same practical approach applies: understand the environment, agree what needs changing and leave a record that another authorised person can use later.
To mark Cyber Security Awareness Month, I will also offer 50% off the normal quoted service fee for secure data wiping and cybersecurity audits for eligible small-business and private/HNWI clients. The offer opens on 28 September and runs through 31 October 2026. Full terms will be available here when it opens.
You do not need to build an enterprise security program in a month. Pick the jobs you can finish, get the right help where necessary and check the result.
On 31 October, “we removed the former supplier's access, tested recovery and retired four old laptops properly” would be a useful answer. Much more useful than “we circulated the awareness email”.
Tags: security, small-business, private-client, australia