All insights

What should a cyber security audit checklist cover for an Australian small business?

5 min readBy Brendon Whiting, Founder · 16 March 2026

An Australian small business audit checklist has five sections: identities (MFA everywhere, admin rights, leavers), devices and patching (update age, what is allowed to run), data (backups tested, where records live), the human layer (payment verification, phishing reporting), and obligations (Privacy Act readiness, insurer answers). Check evidence, not intentions, and the Essential Eight supplies the standard.

A word on why the checklist should be this one rather than a downloaded template: most templates in circulation are American or British, built around frameworks your insurer and your customers never mention. Australian small business runs on different reference points, the Essential Eight for controls, the Privacy Act for obligations, and an audit is more useful when its items map to the questions you will actually be asked. Everything below does. The five sections are ordered by where incidents actually start, so if the audit gets interrupted, the most important half is already done.

Section one, identities, because most incidents are logins. Every account has multi-factor authentication, verified by export rather than memory, with admin accounts checked first. Administrative rights exist only where the role requires them, and the list of who holds them would survive being read aloud. Every departed staff member's access is gone, checked against the actual leavers list. Shared logins have been eliminated or documented with a reason. Third parties, bookkeeper, after-hours service, former IT provider, appear on the access list deliberately or not at all.

Section two, devices and what runs on them. Every device touching business data is known, managed and encrypted, including the phones. Operating system and application updates are current within a stated window, shown by a patch report, not a feeling. Something controls what software can execute, application control at best, sensible restrictions at least. Office macros are restricted per the Essential Eight's expectations, and browsers are hardened, the two items that are pure configuration and forever forgotten.

Section three, data. You can name where your important records live, all of them, including the spreadsheet empire nobody admits to. Backups cover those locations, run on schedule, keep a copy ransomware on the network cannot reach, and, the item that separates real audits from rituals, a restore has been performed recently and logged. Cloud data is included, because the platform's resilience is not your backup. Retention matches what the Privacy Act and your industry expect, so you are neither losing what you must keep nor hoarding what you should not.

Section four, the human layer, two items long and worth the whole exercise. There is a written, practised rule that any change to bank account details, a supplier's, a customer's, an employee's, is verified by phone to a known number before money moves. And staff know exactly how to report a suspicious email or a mistake, and the last person who did was thanked rather than blamed, because a punished reporter is the last report you get.

Section five, obligations and paper. Your security policy exists, is dated, and describes systems you actually run. There is a one-page incident plan with names and numbers, and the people named know they are named. You could answer an insurer's renewal questionnaire truthfully without wincing, and whatever you told a customer or tender panel about your security is still true. If personal information were breached tomorrow, someone knows the Privacy Act assessment steps begin at once.

Running it: the rule that keeps the exercise honest is evidence per item, an export, a report, a log, a document, never a nod. Mark items green, amber or red, date the result, and keep it, because this quarter's audit is next quarter's comparison and next year's proof to an insurer. Self-auditing has limits, familiarity breeds blind spots, but a self-audit against real evidence is worth ten questionnaires, and it makes any later professional assessment faster and cheaper. An afternoon covers the full pass for most ten-person businesses; the first one runs longest, because it is also an inventory.

The caveat: a checklist verifies; it does not protect. Every red item still needs an owner, a fix and a date, or the audit was a ceremony. If you would rather the whole thing were done for you, against the Essential Eight, with the evidence gathered and the report written, that is the Cyber Security Scorecard, and it is free: 1800 456 567.

Have the checklist run for you

The free Cyber Security Scorecard works through these sections against your actual systems and reports the answers in writing.

Frequently asked questions

A light pass quarterly, a proper one annually, and immediately after significant change: new systems, new premises, a wave of hires or departures. The quarterly version can be an hour against the identity and backup sections alone, because those two drift fastest and hurt most, and an hour four times a year beats a panic once.

Something a stranger could verify: an export showing which accounts have MFA, a patch report with dates, a restore log, the leavers list cross-checked against active accounts, the phone-verification rule in writing. If an item's evidence is somebody's assurance, mark it amber regardless of how confident the somebody sounded.

It overlaps deliberately but is not identical. The Essential Eight is the technical core, and a formal assessment goes deeper on each control's maturity level. This checklist adds the surrounding layers an owner also needs checked, obligations, payment habits, incident readiness, that the framework itself does not cover. Do the checklist yourself; use an assessment for the score.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.