If a staff member received a convincing phishing email this afternoon, what would they do? Would they report it straight away, or delete it and move on?
For most Australian small businesses, the honest answer is "I'm not sure." This uncertainty is a real risk, no matter what security tools you use. Phishing simulation programs and employee cyber training can help, but knowing where you stand right now takes just five minutes with the right questions.
This checklist draws on what works at businesses that contain incidents before they become breaches. Print it, share it with your team, or use it as a quick audit before your next staff meeting.
Part 1: The Reporting Culture Check
Your team's willingness to speak up early determines whether a clicked link becomes a contained incident or a notifiable data breach. These three questions reveal how safe your staff feel about reporting.
- Does everyone know who to contact? Ask three staff members right now: if you received a suspicious email, who would you call? If the answers vary, you have a gap.
- Is calling encouraged before certainty? The most protected businesses train staff to call before they're sure something is wrong. If staff wait to be sure, a small mistake can turn into a costly breach.
- Have you removed blame from the equation? Staff who fear getting in trouble will delete suspicious emails rather than report them. That silence costs more than any false alarm.
Score yourself: Three yes answers means your reporting culture is solid. One or two? You've found your first priority.
Part 2: The Verification Habit Check
AI-generated phishing now uses your business's language, your clients' names, and real transaction details. Research into phishing behaviour confirms that even well-trained people click when attacks are personalised and urgent. Verification habits catch what awareness misses.
- Is there a written rule for payment changes? Any request to update bank details or process an unusual payment should require phone verification before action. Not "when it looks suspicious" but always.
- Do staff verify using a known number? Calling back on a number from the suspicious email defeats the purpose. Staff need to use saved contacts or official websites.
- Are access requests treated the same way? Password resets, new login locations, and access change requests deserve the same verification as money movements.
Score yourself: Written policies that staff actually follow? You're ahead of most. Informal expectations? Time to document them.
Part 3: The Security Awareness Training Check
A single annual training video creates the illusion of protection without the reality. Staff need regular practice recognising current attack methods, not just old examples.
- When did staff last see a simulated phishing email? Security awareness training works best when it's ongoing. Monthly or quarterly phishing simulation tests keep recognition skills fresh.
- Does training match real attack patterns? Attackers time campaigns around tax season, lodgement deadlines, and busy periods. Your training should too.
- Do people who click get immediate feedback? People learn best right after they click, not weeks later in a meeting.
If you haven't tested your team recently, you can start a free trial and send yourself a test phishing email to see what your staff would face.
Part 4: The Technical Controls Check
Security awareness training alone won't stop every mistake. Technical controls limit the damage when someone inevitably clicks.
- Is multi-factor authentication enabled everywhere? Stolen passwords shouldn't be enough to get into your systems. MFA on email, accounting software, and cloud storage is the minimum.
- Does everyone have access to everything? Role-based access means a compromised account can only reach what that person needs for their job. Check who can see what.
- What happens when someone leaves? Offboarding should remove all access the same day. A former employee's active login is an open door.
Building a human firewall on a budget means combining people habits with these technical basics. Neither layer works alone.
Part 5: The Documentation Check
Under the Privacy Act and the Notifiable Data Breaches scheme, many Australian businesses need to demonstrate adequate security controls. These obligations apply mainly to entities with over $3 million in turnover or those in specific categories such as health, credit reporting, or AML-designated services. Smaller businesses should still check whether they fall into one of these categories. "We take security seriously" isn't evidence. Documentation is.
- Do you have a written policy for handling sensitive data? Staff should be onboarded into documented expectations, not just informal practice.
- Could you show an insurer what training staff completed? Records of employee cyber training help with insurance applications and claims.
- Is there a data breach response plan? Knowing who does what during an incident prevents panic decisions that make things worse.
Score yourself: Written, current, and accessible? You're prepared. Somewhere on a shared drive from 2019? Add "update policies" to your list.
Your Quick Reference Checklist
Print this and tick off each item:
Reporting Culture
- ☐ Staff know exactly who to contact about suspicious emails
- ☐ Calling before certainty is encouraged
- ☐ No blame for reporting false alarms
Verification Habits
- ☐ Written rule for payment and bank detail changes
- ☐ Staff verify using known numbers, not email-provided ones
- ☐ Access requests get the same treatment
Training
- ☐ Regular phishing simulation tests (monthly or quarterly)
- ☐ Training covers current attack patterns
- ☐ Immediate feedback when someone clicks
Technical Controls
- ☐ Multi-factor authentication on all business systems
- ☐ Role-based access (people only see what they need)
- ☐ Same-day access removal when staff leave
Documentation
- ☐ Written policy for handling sensitive data
- ☐ Training records you could show an insurer
- ☐ Data breach response plan
What to Do With Your Results
Count your ticks. Twelve or more out of fifteen means your human firewall is well built. Eight to eleven? You have the foundations but gaps to close. Under eight? Start with the reporting culture questions. They cost nothing to fix and make the biggest difference.
The goal isn't perfection. It's building an environment where a human mistake doesn't become a breach. Start with one gap this week.
Ready to see how your team would respond to a real phishing test? Sign up for a free trial and send yourself a test email to experience what your staff face every day.