There's a dangerous myth: 'we're too small to be a target'. The opposite is true. Smaller businesses are attacked more often precisely because attackers know your defences are weaker. Here are the five mistakes I see most often — and what to do about them.
1. No multi-factor authentication on email
Email is the master key to your business. Business email compromise (BEC) attacks cost Australian businesses tens of millions of dollars annually. If someone gets access to your inbox, they can reset passwords for every other system you use.
Fix it: Enable MFA on Microsoft 365 or Google Workspace today. It takes 15 minutes and immediately eliminates 99% of credential attacks. There is no excuse not to have this in 2026.
2. Default or weak router passwords
If your office router still has 'admin/admin' or the default password printed on a sticker, your network is effectively public. Any device on your network is exposed.
Fix it: Change your router's admin password to something strong, disable remote management if you don't need it, and ensure your Wi-Fi uses WPA3 (or at minimum WPA2). Segment guest Wi-Fi from your business network.
3. No offboarding process for ex-staff
When an employee leaves, do you immediately disable their accounts? Revoke their access to cloud tools, shared drives, and internal systems? Most smaller businesses don't — and ex-employees retain access for weeks, sometimes months.
4. Backups that have never been tested
Having a backup is not the same as having a working backup. Many businesses discover their backups are corrupted or misconfigured only when they actually need them — after a ransomware attack or hardware failure.
Fix it: Run a restore test at least quarterly. Make sure backups follow the 3-2-1 rule: 3 copies, 2 different media, 1 offsite (or cloud).
5. Unpatched software and operating systems
Windows Update prompts get dismissed. Software update notifications get ignored. This is how most ransomware gets in — through known vulnerabilities in outdated software that patches already exist for.
Fix it: Enable automatic updates where possible. For critical business systems, schedule monthly maintenance windows to apply patches. This is non-negotiable.
Getting a proper IT audit
If you're not sure where you stand, a basic IT security audit will identify your highest-risk gaps. We offer this as part of our infrastructure onboarding. It usually takes less than half a day and gives you a clear picture of what to fix first.
Want advice for your business?
Twenty minutes, specific to you, no pitch deck.
