Cyber attackers aren't always the technical geniuses we see in movies. Most of the time, they're looking for the easy way in: an old employee account that was never disabled, a personal laptop connecting to your network, or staff who haven't learned how to train staff on phishing emails properly.

A recent analysis of thousands of security incidents found that unmanaged devices appeared in every single case studied. Not some cases. Every one. The attackers didn't need clever exploits. They just walked through doors that were left open.

For Australian small businesses without dedicated IT teams, this is actually good news. You don't need expensive security tools or technical expertise to close most of these gaps. You need a simple audit process and about an hour of your time.

Step 1: Hunt Down Your Unmanaged Devices

Start with a device inventory. This sounds boring, but it's where attackers find their easiest wins.

Walk through your office (or check your remote work policies) and list every device that connects to your business systems:

  • Company computers and laptops
  • Personal phones checking work email
  • Tablets used for presentations or client meetings
  • That old laptop in the storeroom that "someone might need"
  • Smart devices like printers, security cameras, or even smart TVs

Any device not covered by your antivirus, not receiving updates, or not monitored by your IT systems is a potential entry point. The fix doesn't have to be complicated. For personal devices, set minimum requirements (passcodes, current operating systems). For old equipment, disconnect it or dispose of it properly.

Step 2: Audit Your User Accounts (The Boring Work That Matters)

Old accounts are gold for attackers. When someone leaves your business, their login credentials often stick around for months. Sometimes years.

Log into your Microsoft 365, Google Workspace, or whatever systems you use and check:

  • Are there accounts for people who no longer work here?
  • Do any accounts have admin privileges that shouldn't?
  • When did each account last log in?

Security researchers have identified thousands of suspicious Microsoft 365 login alerts in a single year of monitoring. Many of these were compromised accounts that had been sitting dormant. Disable or delete accounts for anyone who's left. Right now, before you finish reading this article.

Step 3: Check for "Impossible Travel" Signs

This one's quick but telling. Most business platforms can show you where logins are coming from. Look for anything strange.

If your Melbourne-based bookkeeper's account logged in from Sydney at 9am and then from London at 9:15am, that's not a fast flight. That's a compromised account.

In Microsoft 365, check the sign-in logs under Microsoft's identity platform (Microsoft Entra ID). In Google Workspace, look at the security dashboard. You're looking for:

  • Logins from countries where you have no staff or clients
  • Multiple locations within impossible timeframes
  • Logins at unusual hours (3am on a Sunday, for instance)

If you find anything odd, force a password reset immediately and enable multi-factor authentication if you haven't already.

Step 4: Review Your Security Controls (Are They Actually On?)

This happens more often than you'd think: security features get switched off during troubleshooting and never turned back on. A quick settings review can catch these gaps.

Check that these basics are active:

  • Multi-factor authentication on all accounts (not just some)
  • Automatic security updates enabled on all devices
  • Email filtering and spam protection active
  • Backup systems running and actually completing

Many cyber insurance policies now require these controls to be in place. This audit aligns with the Essential Eight, a set of security strategies recommended by the Australian Cyber Security Centre (ACSC) to help businesses stay secure. If you need to meet cyber insurance training requirements, documenting this audit gives you evidence of due diligence.

Step 5: Test Your Human Defences

Here's where most businesses fall down. You can have perfect technical controls, but if your staff click on a phishing email, attackers get in anyway.

The data on this is clear. Research shows that 96 per cent of incidents where hackers move between computers (often how they spread through your network after getting in) end in ransomware attacks. The initial entry point? Often a single clicked link or entered password on a fake login page.

Testing your team doesn't require technical skills. You can run a simple phishing simulation to see who might fall for a real attack. The results often surprise business owners. It's rarely the people you'd expect.

A study on phishing training programs found that targeted remedial training for staff who fail simulations produces measurable improvements. The trick is making the training specific to what they missed, not generic security lectures that put everyone to sleep.

Making This Audit a Regular Habit

Running through these five steps once is useful. Running through them quarterly is better. Attackers are constantly probing for new gaps, and your business changes over time. New staff join, old ones leave, new devices appear, and security settings drift.

Set a calendar reminder for the first Monday of each quarter. The whole audit takes about an hour once you've done it the first time.

For the human testing component, automation makes this easier. Platforms that run regular phishing simulations and automatically assign remedial training to anyone who fails take this task off your plate entirely. You get reports showing improvement over time without having to manage the process yourself.

What to Do With Your Audit Results

Document everything. Write down what you checked, what you found, and what you fixed. This documentation serves multiple purposes:

  • Evidence for cyber insurance claims or renewals
  • Compliance records if you handle sensitive client data
  • A baseline to measure improvement against
  • Protection if something does go wrong (you can show you took reasonable steps)

The Privacy Act and Notifiable Data Breaches scheme mean Australian businesses face real consequences for security failures. A documented audit process shows regulators and insurers that you're taking reasonable precautions.

Start With the Easiest Win

If you only do one thing from this list today, test your team's phishing awareness. Phishing Training Australia provides tools that take five minutes to set up and tell you immediately where your biggest human risk sits.

Start free and send yourself a test phishing email first. See how realistic it looks. Then run a simulation across your team and find out who needs a bit of extra training before a real attacker finds out for you.

The gaps attackers target aren't complicated. Neither are the fixes. A simple audit, done regularly, closes most of the doors that hackers are actually trying to walk through.