Cyber security best practices for small businesses in 2026

12 cyber security best practices for small businesses in 2026: MFA, patching, backups, payment verification, monthly training and phishing simulations.

The cyber security best practices that matter most for a small business in 2026 are not exotic: turn on multi-factor authentication everywhere, patch quickly, back up daily, verify every payment change by phone, and train the people who answer the email. Roughly 60% of data breaches involve a human element — an error, a clicked link or a manipulated employee (Verizon, 2025 DBIR) — which is why the practices below start with people before tools.

TL;DR

Cyber security best practices for small businesses

Australia's average self-reported cybercrime cost to a small business is $56,571 per incident, up 14% year on year (ASD, Annual Cyber Threat Report 2024-25). The practices below are ordered by the ratio of protection to effort — start at the top and work down.

1. Enforce multi-factor authentication on everything

Email, accounting, remote access, banking, cloud storage. Microsoft measured that MFA blocks over 99.2% of account-compromise attacks, and stolen credentials remain the simplest way into a small business. An MFA prompt you did not trigger is itself an alarm: deny it and treat it as an incident.

2. Patch operating systems, apps and devices promptly

Most successful attacks exploit vulnerabilities that were fixed weeks or months earlier. Turn on automatic updates everywhere, set a weekly patch review for anything manual, and replace software the vendor no longer supports. Australia's Essential Eight rates patching of internet-facing systems and applications among its top controls for exactly this reason.

3. Back up automatically — and test the restore

Ransomware and accidental deletion are both solved by a backup nobody tests and proven by one somebody has. Follow the 3-2-1 rule: three copies, two media types, one off-site. Run a restore drill quarterly; an untested backup is a hypothesis, not a plan.

4. Verify payment changes by phone

Payment redirection is the most expensive scam a small business faces: an email arrives, apparently from a supplier or an executive, with "updated bank details". The control is one reflex — any change to payment details is verified by phone on a number you already hold, never the number in the email. Write it into your payment procedure and train the people who process invoices.

5. Train the human layer monthly

Before any training, 33.2% of employees are likely to engage with a malicious email; twelve months of continuous training and phishing simulation cuts that to 4.2% (KnowBe4, 2026). Monthly short courses, run through security awareness training, keep the reflexes current against the lures actually circulating. For a small business this is the cheapest control on the list — a few dollars per employee per month against a $56,571 average incident.

6. Run phishing simulations

Training teaches; simulations rehearse. A monthly phishing simulation exercises the spot-and-report habit under pressure, and every click feeds a coaching moment rather than a punishment. Track two numbers: click rate (falling) and report rate (rising).

7. Control who has access to what

Give each person the minimum access their job needs, and remove accounts the day someone leaves. Shared logins make every audit harder and every breach wider; a simple rule of one person, one account pays for itself the first time an incident needs scoping.

8. Secure the mail platform properly

Enable SPF, DKIM and DMARC on your domain so others cannot spoof you, and use the filtering your mail provider already includes. DMARC enforcement also protects your customers from someone impersonating you — a small business's reputation is often the collateral in someone else's scam.

9. Protect the devices

Full-disk encryption on every laptop, screen locks, remote-wipe on phones, and endpoint protection kept current. A laptop in a car park is a breach with a zipper; encryption makes it an asset-replacement problem instead.

10. Write down the incident plan before you need it

One page: who to call, how to disconnect the network, how to reset credentials, who talks to customers. Under pressure nobody reads a policy, but a rehearsed checklist works. Australia's ReportCyber service is the official reporting channel for cybercrime; scam attempts go to Scamwatch.

11. Know where your data lives

Inventory what customer, staff and financial data you hold, where it is stored and who can reach it. You cannot protect what you have not listed, and any response to a breach starts with the answer to "what could have been taken?"

12. Assess the gaps once a year

Run a gap assessment annually against a framework — Essential Eight, NIST CSF or ISO 27001 — and turn the findings into a 90-day plan. The assessment tells you which of the practices above are actually in place, not which ones you believe are.

Why people come before tools

Firewalls and filters did not make the human element shrink out of breach statistics — it has stayed near 60% for years (Verizon 2025 DBIR). The lures are personalised, fluent and arrive through email, Teams, SMS and phone calls. The controls that change outcomes for a small business are the ones that change what a person does at 4:45pm on a Friday: verify the payment change, hover before clicking, report the strange login prompt. That is what a monthly cadence plus human risk reporting measures — and it is the layer every tool on the market assumes someone else is handling.

A 30-day starter plan

When you are choosing tools rather than habits, comparing awareness platforms side by side shows what each layer adds and what is already included in what you pay for.

FAQ

What is the single most important practice? Multi-factor authentication on every account that supports it. It is free on most services and blocks the majority of credential-based attacks outright.

Do we need cyber insurance as well? It can transfer financial risk, but insurers increasingly ask for evidence — training records, MFA, backups — before underwriting or paying a claim. The practices above are what the policy assumes.

How much should a small business spend on training? Industry pricing lands between $10 and $72 per employee per year depending on features — a rounding error against the $56,571 average small-business incident cost.

Which framework should we follow? Start with the Essential Eight if you are Australian and want government-benchmarked guidance; NIST CSF or ISO 27001 if customers or contracts require them.

Is free antivirus enough? It is better than nothing, but it addresses one layer. The breaches small businesses actually suffer arrive through email and payment fraud, where training and process matter more than signatures.

One last thing

Every practice above is auditable, and the audit is the point: the difference between "we have MFA" and "we had MFA until the receptionist's account was phished in March" is a report you can read every month. Practices that nobody measures decay; practices that get reported get kept.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.