Blog

A Practical Cyber Security Checklist for Sydney Small Businesses

May 23, 2026

Small business cyber security does not need to start with a complex framework. The first step is to reduce the most obvious risks around accounts, email, websites, backups and old devices.

The checklist

  1. Turn on MFA for email, banking, accounting, cloud storage, website admin and domain registrar accounts.
  2. Remove old staff, contractor and supplier accounts.
  3. Check that backups exist, are current and can be restored.
  4. Keep operating systems, browsers, WordPress, plugins and business software patched.
  5. Review SPF, DKIM and DMARC for your domain.
  6. Check that the domain registrar account is controlled by the business and protected with MFA.
  7. Avoid shared administrator accounts where possible.
  8. Record who has access to website hosting, DNS, email admin and business systems.
  9. Securely wipe or destroy retired laptops, drives and storage devices.
  10. Keep a short written record of important settings and recovery steps.

Essential Eight-style thinking

The Australian Cyber Security Centre's Essential Eight is aimed at improving practical resilience. Small businesses do not need to turn that into bureaucracy, but the same thinking is useful: patch systems, control admin rights, protect accounts, back up data and reduce common attack paths.

Get a practical review

Solway Web Consulting provides a small business cyber security review in Sydney covering website, email, DNS, backups, admin access and priority fixes.

Book a Sydney business security review

Share on LinkedIn