Menu

Small business cyber security handbook from ASD: where to start this month

Comingwave team · 7 minute read · published

A cafe owner reviews a tablet at the counter before opening while a staff member sets up the register behind.

A Small business cyber security handbook has been published by the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) on cyber.gov.au, with a publication date of 7 October 2026. It is written for small business owners, managers and employees, and it opens with three measures to start on: turn on multi-factor authentication, keep your software up to date, and regularly back up your data. This article sets out what the handbook covers and a realistic plan for the first week.

What ASD's ACSC published

The Small business cyber security handbook is an online guide. Its introduction says that for a small business even a minor cyber security incident can have devastating impacts, and it describes its contents as basic security measures against common threats.

It arrives during Cyber Security Action Month. In its announcement of the month on 1 October, the agency set the 2026 theme as "Take a second. Stay secure." and urged individuals and organisations to turn awareness into action.

The handbook is candid about its limits. It says some measures may not be relevant to every business, that others will have more complex needs, and that small businesses vary in the technical skills and resources they can call on. Its advice for anyone unsure is to speak to an IT professional or a trusted advisor.

What the handbook covers

The handbook is split into short chapters, so a manager can read the part that matches the problem in front of them.

ChapterWhat it asks a business to do
Implement fundamental cyber security controlsSet up multi-factor authentication, use passkeys, use unique and strong passwords, and apply security patches promptly.
Educate staff on good cyber security practicesRun regular awareness training and teach staff to recognise phishing and business email compromise.
Restrict and monitor accessGive staff only the access their job needs, separate administrator accounts, and review access logs.
Use Secure by Design products and servicesChoose vendors with a sound security record and ongoing updates, change default passwords and turn off features you do not need.
Implement and test cyber security incident response plansWrite down how to detect, contain, respond and recover, define who does what, and run simple drills.
Protecting devices, systems and networksUpdate software, back up information and use security software.
Protecting business and customer dataKeep a register of personal data, collect less, delete what is no longer needed, control access and encrypt.
Remote working securitySecure home Wi-Fi and routers and avoid public Wi-Fi for work.

Further chapters describe common threats to small businesses, staff training and incident readiness, using AI tools securely, event logging, and an introduction to post-quantum cryptography.

The three starting measures

Turn on multi-factor authentication

Multi-factor authentication (MFA) means proving who you are in two or more ways before logging in. The chapter on securing accounts and identities says to turn it on wherever it is available, starting with high-risk accounts such as email, banking, cloud storage, accounting software and social media.

The handbook lists the options: passkeys, physical tokens, security keys, biometrics, authenticator apps, and codes sent by SMS or email. It calls SMS and email codes the least secure option, because those accounts are themselves easy to compromise, and it describes passkeys as a more secure way to log in than a password.

Where passkeys are not available, the handbook asks for a unique password for every account, stored in a password manager. Where MFA cannot be used at all, it says passwords should be at least 15 characters long. It also discourages shared accounts: create individual logins for staff wherever possible, and change login details when people leave or change roles.

Keep software up to date

Updates fix security weaknesses that criminals use to install malware or get into devices. The chapter on protecting devices, systems and networks recommends automatic updates as a "set and forget" approach, followed by regular checks that updates are being applied on every device, including servers and storage devices. Where automatic updates are not possible, it suggests reminders and scheduling updates outside business hours. Devices and software that no longer receive security updates should be removed or replaced.

Back up your data

The handbook asks each business to write a backup plan that answers six questions:

  • What data is, and is not, backed up?
  • When do backups occur?
  • Where are the backups stored?
  • Who is responsible for managing them?
  • How long are they kept?
  • How often are they tested?

It also prompts owners to think about information held in email and cloud accounts, which is often left out of the plan.

Beyond the basics

Several chapters go beyond the three starting measures, and they are worth a look once those are in place.

  • Payment fraud. The staff education chapter describes business email compromise, where criminals impersonate executives or suppliers, for example with a fake invoice. Its instruction is to always verify payment recipients before sending money.
  • Customer data. Only collect the personal data the business needs, set retention periods, and apply full disk encryption to laptops, servers and phones that store or access personal data.
  • An emergency plan. The plan should say how staff report incidents, who to contact (such as IT providers or your bank), how you will communicate, and how the business keeps operating. Keep a copy offline.
  • Event logging. Focus on high-value events such as logins, administrator changes and remote access, and retain logs for several months or longer where possible.
  • AI tools. Avoid sharing sensitive business or customer information with AI tools, check where data is stored, and verify outputs.
  • Post-quantum cryptography. The handbook says MFA, updates, backups and access controls remain the first priority for most small businesses, and asks them to be aware of this emerging area.

Who should act, and how soon

Every business that uses email, online banking or cloud software is in scope, whether it is a cafe group with a few point-of-sale tablets, a builder running jobs from a phone, or a clinic's front desk. The handbook does not set deadlines. Its three starting measures are the ones to finish first because they deal with the most common ways in: stolen passwords, unpatched software and data that cannot be recovered.

A plan for the first week

  1. Day one: list your accounts. Email, banking, accounting, cloud storage, social media, website administration. Note who has access to each.
  2. Turn on MFA for email and banking first, then work down the list. Prefer passkeys, security keys or an authenticator app over SMS where the service offers them.
  3. Set up a password manager and replace reused passwords, starting with the most important accounts.
  4. Switch on automatic updates on every computer, phone, tablet and router, and note any device that can no longer be updated.
  5. Answer the six backup questions in writing, then restore one file to prove the backup works.
  6. Agree a payment rule with staff: any new or changed bank details are verified by phone using a number you already hold.
  7. Write a one-page emergency plan with key contacts and print it.

The handbook's own suggestion for anyone who gets stuck is to ask an IT professional. Comingwave is a technology company that provides cyber security, managed IT support and cloud migration and hosting to small and medium businesses, covering access control, encryption, backups, monitoring and updates. To work through the handbook with us, request a free first consultation or a written quote.

Key takeaways

  • ASD's ACSC has published a Small business cyber security handbook on cyber.gov.au, dated 7 October 2026.
  • It recommends three starting measures: multi-factor authentication, software updates and regular backups.
  • It ranks SMS and email codes as the least secure MFA option and favours passkeys.
  • Later chapters cover access control, staff training, customer data, incident plans, logging and safe use of AI tools.
  • The handbook advises speaking to an IT professional or trusted advisor when the advice is hard to apply.

Frequently asked questions

Who publishes the Small business cyber security handbook?

The Australian Signals Directorate's Australian Cyber Security Centre publishes it on cyber.gov.au. The handbook page shows a publication date of 7 October 2026 and lists small and medium business as its audience.

What are the first three things the handbook recommends?

Turn on multi-factor authentication, keep your software up to date, and regularly back up your data. The handbook presents these as the starting point before its other measures.

Is a code sent by SMS good enough for multi-factor authentication?

The handbook lists SMS and email codes as the least secure option. It says to turn MFA on wherever it is available, so use a stronger method such as a passkey, security key or authenticator app when a service offers one.

How long should a business password be?

Where MFA cannot be used, the handbook says passwords should be at least 15 characters long. It also asks for a unique password for every account and recommends a password manager to create and store them.

Does a small business need to act on post-quantum cryptography now?

The handbook says MFA, software updates, backups and access controls are the first priority for most small businesses. It asks businesses to be aware of post-quantum cryptography and to start planning, since the change will take time.

Need help with your business technology?

Tell us what you need. We reply within one business day.

Get a free quote