CyberSelf-Rescue
- Owen Flynn
- 5 days ago
- 2 min read
Updated: 2 days ago

Today's Business Challenge
Small and Medium Business (SMB) leaders are finding themselves increasingly overwhelmed by the current volume and complexity of data breaches, hacking, and cybercrime. Unable to access the large funding and dedicated security staff of larger enterprise, SMB Leaders are having to become increasingly self-sufficient and almost 'self-rescue' to meet this enormous challenge to the operations and profitability of their business. In light of these challenges, the need for a solid foundation to enable any cyber security capability is vital. To assist SMB leaders in establishing and growing their cyber resilience, ZenITIL has gathered a number of foundational steps into three core domains (below). Additional information sources are also listed overleaf.
Operations
Enable Multi Factor Authentication (MFA)
Enforce appropriate password complexity and length
Restrict access to 'administrator' level or privileged accounts
Keep operating systems and applications current and secure with regular patching and updates
Keep anti-virus and malware protection up to date
Allow only trusted applications to be installed or run
Disable or block untrusted macros in the MS Office suite
Configure software and systems for increased security
Protect your data by enabling encryption on computing devices
Limit phishing by enabling DMARC (or SPF at the least)
Training & Policy
Train staff to recognise suspicious emails, links, and attachments
Generate and maintain a strong staff culture on cyber awareness
Create a Data Governance Policy and Cyber Incident Response Plan
Business Resilience
Ensure data and systems are backed up appropriately (daily)
Confirm backup integrity with a regime of regular test restores
Ensure IT Disaster Recovery and Business Continuity Plans are in place, current, and tested regularly
Invest in standalone cyber insurance (check policy pre-requisites, qualifications, and exclusions)
Australian Cyber Snapshot
43% of data breaches involve small businesses
The average cost of a single cyber attack is $276,000
60% of businesses that experienced a significant breach were out of business within 6 months
Regulators increasingly view Cyber as a part of every director's duties, yet 80% of boards have no experience in this area
Only 20% of smaller businesses have standalone cyber insurance
Future
With the basics established SMBs should look to grow their cyber maturity. We recommend looking at services received from your Managed Service Providers and taking steps to confirm the effectiveness of their internal processes and controls.
Further Resources
Small Business Cyber Security Guide
Australian Cyber Security Centre
Cyber Security Tips for Small Business
Australian Tax Office
Cyber Resilience
Australian Securities & Investments Commission
Cyber Security Playbook
Chartered Accountants (ANZ)
Business Cyber Security Hub
National Australia Bank
Cyber Security Governance Principles
Australian Institute of Company Directors
Notifiable Data Breaches
Office of the Australian Information Commissioner




Comments