IT Security Audit Checklist for Australian Small Businesses
Why Every Small Business Should Audit Its Security
Most small businesses have never formally reviewed their IT security. Setup happened quickly, tools were added as needed, and nobody has looked at the whole picture. A security audit is simply a structured review of what you have in place against what you should have.
This checklist covers the areas that matter most for Australian small businesses. Work through it section by section. Any item with a cross (✗) is a gap worth addressing.
Identity and Access
- [ ] MFA enabled on Microsoft 365 or Google Workspace for all users
- [ ] MFA enabled on accounting software (Xero, MYOB, QuickBooks)
- [ ] No shared login credentials — each staff member has their own account
- [ ] Former staff accounts have been disabled promptly after departure
- [ ] Admin accounts are separate from daily-use accounts (i.e., you do not use a global admin account for email)
- [ ] Password manager in use — passwords are not reused across services
Devices and Endpoints
- [ ] All computers running a supported operating system (Windows 11 or macOS Ventura or later)
- [ ] Windows 10 devices identified and scheduled for upgrade or replacement (end-of-support October 2025)
- [ ] Endpoint Detection and Response (EDR) software installed on all devices — not just basic antivirus
- [ ] Automatic screen lock after 5–10 minutes of inactivity on all devices
- [ ] Hard drive encryption enabled (BitLocker on Windows, FileVault on Mac)
- [ ] Mobile Device Management (MDM) in place for company-owned mobile devices
Email Security
- [ ] SPF record configured for your email domain
- [ ] DKIM configured and active
- [ ] DMARC policy published and enforced (at minimum p=quarantine; p=reject is preferred)
- [ ] Email filtering / spam protection enabled
- [ ] Staff aware of phishing — training conducted in the last 12 months
Network Security
- [ ] Business-grade router/firewall in place — not the consumer-grade device provided by your ISP
- [ ] Firewall firmware current and on a supported model
- [ ] Guest Wi-Fi network separated from the business network
- [ ] Default router admin credentials changed
- [ ] Remote access (VPN or similar) secured with MFA
Backup and Recovery
- [ ] Automated daily backup of all critical business data
- [ ] Backup stored offsite or in cloud (not only on the same machine being backed up)
- [ ] Backup tested — a restore has been verified in the last 3 months
- [ ] Recovery time objective documented — you know how long recovery would take
- [ ] Microsoft 365 / Google Workspace data backed up separately (cloud platforms are not a backup)
Scoring Your Audit
Count the items checked:
- 35–40 checkedStrong posture — focus on maintaining and reviewing regularly
- 25–34 checkedGood foundation with identifiable gaps — prioritise unchecked items
- Below 25 checkedSignificant gaps — consider a managed IT assessment to prioritise remediation
Beyond the Checklist: Understanding Why Each Item Matters
A checklist is a starting point — understanding the risk behind each item helps prioritise remediation effectively.
MFA on Microsoft 365 / Google Workspace. Without MFA, a stolen password gives an attacker full access to email, files, contacts, and connected applications. The majority of business account compromises that Netluma IT responds to involve accounts without MFA. This is the single highest-impact item on the checklist.
EDR on all devices. Traditional antivirus compares files to a database of known malware signatures. Modern ransomware and custom malware is specifically designed to evade signature detection. EDR monitors behaviour — what processes are doing — and can stop an attack mid-execution based on suspicious activity, even for malware that has never been seen before.
Backup tested within 3 months. The backup job completing successfully is not the same as the backup being usable for recovery. Files can be corrupt, the restore process can fail, or the backup scope may not include the files you actually need. A test restore — actually recovering a file from the backup to confirm the process works — is the only way to know your backup will work when you need it.
DMARC at p=reject. Without DMARC, any email server in the world can send email claiming to be from your domain. This enables invoice fraud, impersonation of your business to your clients, and phishing attacks on your suppliers. DMARC at p=reject prevents these spoofed emails from being delivered.
No Windows 10 devices past end-of-support. Since October 2025, Windows 10 receives no security patches. Every vulnerability discovered is permanently unaddressed. Attackers scan for and target known unpatched vulnerabilities. Each month past end-of-support the risk increases.
After the Audit: Running a Remediation Sprint
For businesses that complete this checklist and find significant gaps, a structured remediation sprint — rather than addressing items ad hoc — is more effective.
A remediation sprint:
Using the Australian Signals Directorate ACSC cyber security guidelines
The Australian Signals Directorate (ASD) publishes the ACSC cyber security guidelines — a prioritised list of mitigation strategies that significantly reduce the risk of cyber incidents. The ACSC cyber security guidelines is Australia's equivalent of the global CIS Controls and is the security baseline recommended by the ACSC for Australian organisations.
The ACSC cyber security guidelines: 1. Patch applications — keep software current 2. Patch operating systems — keep operating systems current 3. Multi-factor authentication — MFA on all accounts 4. Restrict administrative privileges — limit admin access to those who need it 5. Application control — only approved applications run 6. Restrict Microsoft Office macros — block macros from the internet 7. User application hardening — configure browsers and applications securely 8. Regular backups — and test them
The ACSC cyber security guidelines is rated at three maturity levels. For most small businesses, achieving Maturity Level 1 — applying the basics of each strategy — provides significant protection at proportionate cost and complexity.
Netluma IT aligns managed IT services for SE Queensland businesses with the ACSC cyber security guidelines. Call 1300 521 162 to discuss your current cyber security maturity and what it would take to improve it.
Netluma IT provides free security assessments for SE Queensland small businesses. Call 1300 521 162 to book yours.
Worried About Your Business Security?
Get 24/7 threat detection and response, managed endpoint security, business backup and recovery, and dark web monitoring in Netluma Business Shield — $89 per device per month, ex GST. One flat-price module that bolts onto any managed IT plan.
Related Services