Small Business Cyber Security Checklist for 2026 With 25 Essential Steps
A small business cyber security checklist is a prioritised list of controls, starting with multi-factor authentication, updates and tested backups, that lowers the chance of a costly breach. In New Zealand, 53% of small and medium businesses reported a cyber threat in the past six months, up from 36% the year before. Most attacks succeed through basic oversights, not clever hacking. The 25 steps below are ordered by priority. Do the first eight this week, the next nine this month, and keep the last eight running through the year.
Why Does a Small Business Cyber Security Checklist Matter in 2026?
The National Cyber Security Centre’s research on small and medium businesses shows the trend is rising. Across 2024/25, the NCSC logged 5,995 incident reports and $26.9 million in direct financial losses, up from $21.6 million the year before.
Australia looks similar. ASD found the average self-reported cost of cybercrime for a small business rose 14% to $56,600 per report, in Australian dollars.
How attackers get in is also shifting. Verizon’s 2026 Data Breach Investigations Report found vulnerability exploitation as the way in for 31% of breaches, ahead of credential abuse at 13%. Only 26% of critical known-exploited vulnerabilities were fully fixed. Small business cyber security now means patching as seriously as you protect passwords, and the cybersecurity best practices for small businesses below are ordered with that in mind.
Small Business Cyber Security Checklist Steps to Complete This Week
ASD recommends starting with three measures, multi-factor authentication, software updates and backups, before working towards Essential Eight Maturity Level One, as set out in its small business cyber security guide. The first eight steps start there.
1. Turn on multi-factor authentication everywhere
Switch it on for email, banking, payroll, accounting and cloud apps first. Use an authenticator app, passkey, or security key instead of SMS codes when you can. A stolen password alone should never open the door.
2. Use a password manager and unique passphrases
Give every account a long, unique passphrase and store it in a business password manager. Ban shared logins so you can see who accessed what.
3. Switch on automatic updates
Turn on automatic updates for operating systems, browsers, apps and router firmware, then check that they actually install. Unpatched software is now the most common way in, so a missed update is an open door.
4. Set up backups and test a restore
Follow the 3-2-1 rule with three copies, on two types of storage, with one kept offsite or offline. Test a restore, because an untested backup is only a hope. Proper backup and disaster recovery let you recover from ransomware without paying.
5. Remove access the day someone leaves
Disable their accounts, revoke shared logins and change any keys or passwords they knew on their last day. Former staff with live access are a risk even when they leave on good terms.
6. Filter email and set up SPF, DKIM and DMARC
Email is still the main route for phishing. Add spam and attachment filtering, then set up SPF, DKIM and DMARC so criminals cannot easily send mail that looks like yours. Keep MFA on every mailbox.
7. Put managed protection on every device
Antivirus alone misses attacks that use legitimate tools. Endpoint detection and response watches device behaviour and can isolate a compromised laptop. Our endpoint security checklist covers the device-level controls in detail.
8. List every device, app and cloud account
Keep a simple inventory of devices, software and cloud accounts, with an owner for each. You cannot patch what you do not know exists. Retire anything that no longer receives security updates.
Cyber Security Checklist Steps for Small Business to Finish This Month
These steps need a little more planning, so book time for them now.
9. Run a cyber security risk assessment
List the data that would hurt most if lost, the systems you cannot run without, and where your gaps are. A cyber security risk assessment turns that list into a ranked plan, so you know where the next dollar goes.
10. Write a short cyber security policy
Three to five pages is enough. Cover acceptable use, passwords, how data is handled and how to report something suspicious. Staff will read a short policy and ignore a long one.
11. Classify and encrypt sensitive data
Sort data into public, internal and confidential. Encrypt customer, financial and staff records at rest and in transit, and limit access to people who need it. This is the core of data security for small businesses.
12. Limit admin rights and apply least privilege
Give each person only the access their role needs. Keep admin accounts few and separate from daily-use logins. Fewer powerful accounts means a stolen password does less damage.
13. Secure Wi-Fi, router and firewall
Change default router passwords, use WPA3 (or WPA2 if that is all your equipment supports) and put guests on a separate network. Keep the firewall and firmware updated, and replace equipment the vendor no longer supports.
14. Train staff on phishing and voice or video fakes
Short security awareness training should cover phishing, QR-code scams and cloned voices asking for urgent payments. Tell staff they will never be blamed for reporting something suspicious.
15. Add a payment verification rule
Confirm any change of bank details by calling a number you already hold, and require two people to approve larger payments. In the first quarter of 2025, around $5 million of New Zealand losses came from unauthorised transfers and business email compromise.
16. Review vendor and supplier access
List which suppliers can access your systems or data, and remove access they don’t need. Third-party risk management stops a compromised supplier from becoming your breach.
17. Secure remote work and personal devices
Require MFA and disk encryption on work laptops and phones, enable remote wipe, and never leave remote desktop exposed to the internet. If staff use their own devices, set clear BYOD rules.
Ongoing Cyber Security Checklist Tasks for Small Businesses
These tasks prepare you for an incident and keep the rest of the checklist current as your business changes.
18. Document an incident response plan
Write down who decides, who to call and what to do in the first hour. A cybersecurity incident response plan should name your insurer, your IT provider and where to report, which is the NCSC in New Zealand and the Australian Cyber Security Centre in Australia.
19. Turn on logging and 24/7 monitoring
Watch for repeated failed logins, new admin accounts and security tools switched off. Most small businesses cannot staff that overnight, which is where managed detection and response fits.
20. Scan for vulnerabilities and consider a penetration test
Run regular vulnerability scans to find known weaknesses. Consider a penetration test once a year, or after major changes, to see how far an attacker could get.
21. Set rules for AI tools and browser extensions
Decide which AI tools staff may use and ban customer or financial data in unapproved ones. Review browser extensions too, since they can read what staff see.
22. Review user access every quarter
Check for leavers, role changes and accounts with more access than they need. Quarterly reviews catch what offboarding missed.
23. Run phishing simulations and refreshers
Send realistic test emails and follow up with short refreshers. Coach staff who click rather than punishing them, so people keep reporting.
24. Check compliance duties and cyber insurance conditions
Keep evidence that your controls run, because regulators and insurers ask for it. Underwriters commonly ask about MFA, backups, patching and training, and policies can carry exclusions, so read yours closely. Our compliance readiness checklist covers audit evidence.
25. Review the checklist every quarter
Re-run the whole list every quarter and after any incident, new system or staff change. Add a short tabletop drill of your response plan. Treat it as a cyber hygiene checklist you repeat, not a project you finish.
Cyber Security Requirements for Small Business in NZ and Australia
In New Zealand, the NZ Privacy Act 2020 requires you to notify the Privacy Commissioner and affected people of a breach likely to cause serious harm. The Commissioner expects notice within 72 hours of learning a breach is notifiable, though that is a guide rather than a legal deadline.
In Australia, the Notifiable Data Breaches scheme sets reporting duties for businesses covered by the Privacy Act 1988. Businesses over the A$3 million turnover threshold must also report a ransomware or extortion payment to ASD within 72 hours, a duty in force since 30 May 2025. Keep this section as your cyber security compliance checklist.
Small Business Cyber Security Checklist FAQs
What are the most common cyber threats facing small businesses?
Phishing and business email compromise, ransomware, stolen credentials, unpatched software and compromised suppliers. Most succeed through basic gaps such as missing MFA or delayed updates.
What is the best cybersecurity solution for small businesses?
No single product covers it. Layer identity controls, backups, endpoint protection and staff training, and put the most effort into your biggest gap.
What are the 5 C’s of cyber security?
Change, Compliance, Cost, Continuity and Coverage. It is a widely used industry framework, not an official standard.
What is the 80/20 rule in cyber security?
It is an informal Pareto principle that a small set of basics delivers most of the risk reduction. It is not a formal standard and has no fixed percentage.
What are the 5 steps of cyber security?
Identify, Protect, Detect, Respond and Recover, the original five NIST functions. NIST added a sixth, Govern, in Cybersecurity Framework 2.0.
What is the difference between a cyber security checklist and a cyber security audit?
A checklist is a self-check of whether key controls are in place. An audit is an independent review that tests those controls against a standard and records the evidence.
Which Cyber Security Checklist Steps Should a Small Business Start With?
Start with steps 1 to 4. Multi-factor authentication, a password manager, automatic updates and tested backups cost little and close the gaps attackers use most. Work through the monthly block next, then add the ongoing tasks to your calendar. If you have no in-house IT and cannot cover monitoring or device protection yourself, managed security services for small business can carry that load. You can book a security assessment to see where your business stands against this checklist.
Need help reducing your business security risk?
Contact us