Cyber Security Audit Checklist for Australian SMBs
Cyber attacks on small and medium businesses are no longer rare, opportunistic events — they’re routine. Attackers increasingly target SMBs precisely because they tend to have weaker defences than large enterprises, while still holding valuable data and cash flow. A cyber security audit is the fastest way to find out where your business is exposed before someone else does.
This checklist walks through the areas a proper cyber security audit should cover, so you can assess your own business or brief a provider on what you need.
Why SMBs need regular cyber security audits
Many small and medium businesses assume they’re “too small to be a target.” In practice, the opposite is often true — cyber criminals use automated tools to scan for vulnerabilities at scale, and a business with fewer defences and less monitoring is an easier payoff than a well-resourced enterprise. Add to that the fact that many SMBs hold sensitive client data, financial records, and access to larger supply-chain partners, and the incentive for attackers is clear.
A cyber security audit isn’t a one-off box-ticking exercise. Threats evolve, staff change, new software gets added, and configurations drift over time — which is why an annual (at minimum) audit, with lighter reviews in between, is the standard most Australian MSPs recommend.
Account and access security
Start with who can get into your systems, and how.
Multi-factor authentication (MFA). Check whether MFA is enforced across email, cloud services, remote access tools, and any admin accounts — not just optionally available.
User access reviews. Confirm that staff only have access to the systems and data they actually need for their role, and that access is revoked promptly when someone leaves the business.
Password policies. Look for weak, reused, or shared passwords, and confirm whether a password manager is in use across the business.
Privileged accounts. Identify who holds administrator-level access, and whether that number is kept as small as possible.
Email and phishing defences
Email remains the single most common entry point for cyber incidents.
Spam and phishing filtering. Confirm your email platform has modern filtering enabled, including protection against look-alike domains and malicious attachments.
Email authentication records. Check that SPF, DKIM and DMARC records are correctly configured on your domain to prevent your business being spoofed.
Staff awareness. Assess whether staff have had any phishing awareness training, and consider a simulated phishing test to see how the business actually responds.
Device and endpoint security
Every laptop, desktop, and mobile device connected to your business is a potential entry point.
Endpoint protection. Confirm all devices run up-to-date antivirus or endpoint detection and response (EDR) software, not just Windows Defender left on default settings.
Patching and updates. Check whether operating systems and applications are patched promptly, and whether unsupported software (like end-of-life Windows versions) is still in use.
Device encryption. Confirm laptops and mobile devices have disk encryption enabled, so a lost or stolen device doesn’t expose data.
Mobile device management. If staff use personal or mobile devices for work email and files, check whether there’s any policy or management tooling in place.
Network security
Firewall configuration. Review firewall rules for anything overly permissive, and confirm remote access points (like VPNs) are properly secured.
Wi-Fi security. Check that guest and staff Wi-Fi networks are segregated, and that Wi-Fi access uses strong, unique credentials.
Network monitoring. Assess whether there’s any visibility into unusual network activity, or whether incidents would only be discovered after the fact.
Backup and disaster recovery
A cyber security audit should always include backup, because ransomware makes backup and security inseparable.
Backup coverage. Confirm what’s actually being backed up — not just servers, but cloud email, files, and line-of-business application data.
Backup testing. Check whether backups are regularly tested by actually restoring data, not just assumed to be working because a job completed.
Recovery time expectations. Understand how long it would realistically take to restore operations after a serious incident, and whether that meets the business’s tolerance for downtime.
Compliance and policy gaps
Even strong technical controls can fall short without the right policies behind them.
Documented policies. Check whether the business has basic policies covering acceptable use, data handling, and incident response — and whether staff have actually seen them.
Industry-specific obligations. Businesses in regulated sectors (financial services, healthcare, legal) should confirm their controls meet relevant compliance requirements, not just general best practice.
Cyber insurance alignment. If the business holds cyber insurance, check whether current practices would actually satisfy the insurer’s requirements in the event of a claim.
Getting a proper audit done
A genuinely useful cyber security audit goes beyond a checklist — it should result in a clear, prioritised list of gaps and a practical plan to close them, not just a report that sits in a drawer.
At SSDL, we run cyber security audits for Australian businesses that combine technical assessment with practical, prioritised recommendations your team can actually act on. If you’d like a clear picture of where your business stands, book a free consultation and we’ll talk through what an audit would involve for your environment.