Good cyber security is less about buying more products and more about closing the ordinary gaps that attackers rely on. The incidents we help with rarely involve anything clever. They tend to trace back to a small number of habits that are common in busy small and medium businesses, and every one of them is fixable without turning the place upside down. Here are the five we still see most often, why each matters, and what we would do instead.
1. No multi-factor authentication on email and key logins
Passwords get reused, guessed, and phished. Once someone has a working password, very little stands between them and your mailbox, your files, or your finance system. This is still the most common way we see a business get compromised, and it is also the easiest to prevent.
Turn on multi-factor authentication (MFA) for Microsoft 365 first, then for anything else that holds business data or money: your accounting package, your bank, your remote access, your line-of-business apps. Where you can, use an authenticator app or a passkey rather than SMS codes, which are weaker. In Microsoft 365 you can go further and use Conditional Access to require MFA in a way that suits how your team actually works. If you are not sure what is switched on today, our free Cyber Health Check will tell you.
2. Shadow IT with no guidance on what is allowed
Shadow IT is the everyday reality of staff reaching for whatever app gets the job done: a free file-sharing site, a personal cloud drive, an AI tool they have pasted a client list into. Usually it is well-intentioned, but it means business data ends up in places no one is managing, backing up, or able to shut off when someone leaves.
You do not fix this by banning everything. Give people a short, plain acceptable-use guide that spells out which tools are approved for work data and where to go if they need something new. Standardise on Microsoft 365 for email, files, and collaboration so there is an obvious sanctioned option, and make it easy to ask. When staff know the approved path, most shadow IT quietly disappears.
3. Treating antivirus on its own as enough
Antivirus still has a job to do, but on its own it is a single lock on one door. Plenty of modern attacks never drop a file it would recognise. A stolen password, a convincing phishing email, or a malicious link does not look like a virus at all.
What works is layered defence, where no single failure is fatal. In practice that means securing identity with MFA and Conditional Access, filtering email and links before they reach the inbox, running proper endpoint detection rather than basic antivirus, keeping operating systems and applications patched, and holding tested backups you could actually restore from. This layered approach is the basis of the Australian Signals Directorate's Essential Eight, and it is what our AgileSECURE service is built around. A few of the quick wins live inside settings you already own, which we cover in 5 Microsoft 365 settings worth checking.
4. No device or endpoint management
If you cannot see the laptops and phones that connect to your business data, you cannot secure them. Unmanaged devices miss updates, go without encryption, and stay logged in long after someone has left the business or misplaced the device. That is a lot of risk sitting outside your control.
Bring devices under management with a tool like Microsoft Intune. It lets you push updates, enforce disk encryption, set a screen lock, and require that only healthy, known devices reach your data. If a device is lost or someone leaves, you can remove access remotely. It is one of the highest-value steps a growing business can take, and it quietly closes several of the gaps above at once.
5. A one-off induction instead of ongoing awareness
Your team is the layer that meets every phishing email and dodgy phone call first. A single security talk on someone's first day does not stick, and the tactics change constantly, so a once-a-year tick-box does not keep pace either.
Make awareness a light, regular habit: short refreshers through the year, the occasional simulated phishing email so people can practise spotting one, and a simple, blame-free way to report anything suspicious. The aim is not to catch people out. It is to build the reflex to pause before clicking. Frameworks like SMB1001 recognise this and expect training to be ongoing rather than a one-off, which we unpack in our guide to the SMB1001 framework.
Where to start
You do not have to do all five at once. If you tackle them in order, MFA and layered defence give you the most protection for the least effort, and device management and ongoing training build on that foundation. If you would like a clear picture of where you stand today, start with the Cyber Health Check and we will walk through the gaps with you.
Common questions
Is multi-factor authentication really necessary if we already use strong passwords?
Yes. Strong passwords still get phished or reused, and MFA blocks most attempts to use a stolen password, which is why we turn it on for Microsoft 365 and any system holding data or money.
Isn't a good antivirus enough to keep us safe?
No. Antivirus is one useful layer, but many attacks never involve a file it would detect, so you also need secured identity, email filtering, endpoint detection, patching, and tested backups.
Where should a small business start with cyber security?
Start with MFA and a layered defence, then add device management and ongoing awareness training. A Cyber Health Check will show you which gaps to close first.