If you manage people in an Australian small business, your job description has likely expanded recently. You aren't just handling leave requests, payroll, and disputes anymore. You are now the gatekeeper of sensitive personal data and the first line of defence against identity theft.

Criminals have shifted tactics. They aren't just attacking your firewall; they are attacking your people and your processes. We see this in two main ways: fraudsters applying for jobs using stolen identities to gain access to your systems, and criminals stealing your current employees' identities to redirect wages or commit tax fraud.

For busy office managers and business owners, this adds another layer of responsibility. You need a practical way to check your defences without getting bogged down in technical details. This 10-point audit checklist will help you tighten your security and simplify your security awareness training efforts.

The Pre-Hiring & Onboarding Phase

The moment someone applies for a job, the risk begins. Modern scammers use stolen data to create "synthetic" employees—fake people who exist only on paper to steal equipment, data, or salaries.

1. Implement the "100 Points of ID" Check

We do it for bank accounts; we should do it for employment. Never accept a simple PDF resume as proof of existence. Before issuing an employment contract, require standard Australian identity documents. A driver's licence, passport, or Medicare card should be standard. If a candidate makes excuses about why they can't produce a photo ID, that is a massive red flag.

2. Validate Remote Candidates via Video

Remote work is standard now, but it opens the door for imposters. A growing trend involves "deepfakes" or stand-ins sitting for the interview, only for a different (less qualified or malicious) person to show up for the job. Always conduct at least one live video interview where the candidate must show their face. Ask them to hold up their ID to the camera. It feels awkward for a second, but it prevents a disaster later.

3. Verify References Using Independent Sources

Don't just call the number listed on the resume. If the applicant is a fraudster, that number leads to their accomplice. Look up the previous employer's main switchboard number online. Call that number and ask to be put through to the manager listed as a reference. This simple step filters out fake work histories immediately.

4. Verify TFNs and Super Funds

During onboarding, pay attention to the Tax File Number (TFN) declaration. The Australian Taxation Office (ATO) has specific systems to verify TFNs. If a new starter provides a TFN that fails validation or insists on being paid into a bank account that doesn't match their name, pause the process. Our 2026 compliance priorities increasingly focus on data integrity, so getting this right at the start saves you headaches with the ATO later.

Ongoing Security & Maintenance

Once staff are on the books, the focus shifts to protecting their identity from external threats.

5. Lock Down Payroll Change Requests

One of the most common scams targeting HR right now involves a simple email: "Hi, I've changed banks. Please update my details for the next pay run." It looks like it came from your employee, but it's a scammer. Never update payment details based on an email alone. Mandate a verbal confirmation process—walk to their desk or pick up the phone.

6. Audit User Access Regularly

When an employee leaves, their access must vanish instantly. A "linger list" of former staff who can still log into their email or accounting software is a security hole waiting to be exploited. Add an "Access Revocation" step to your offboarding checklist that triggers the minute the resignation is accepted.

7. Monitor for "Ghost" Indicators

Keep an eye out for strange patterns in your payroll data. Multiple employees sharing the same bank account number or home address (unless they are known partners) requires investigation. Similarly, if you receive notifications from the ATO about duplicate income statements or superannuation discrepancies, investigate immediately. These are often the first signs of identity misuse.

Compliance Reporting and Training

This is where many businesses get stuck. You might have good practices, but can you prove it? Do businesses take compliance systems seriously? The answer is often "no," until a breach happens and the regulators come knocking.

8. Automate Your Compliance Reporting

If you suffer a data breach, the Privacy Act and the Notifiable Data Breaches (NDB) scheme require you to show what steps you took to prevent it. Keeping a spreadsheet of who attended a security seminar three years ago isn't enough. You need automated logs showing that staff receive regular training and that you track their progress. Modern platforms handle this compliance reporting automatically, giving you a paper trail ready for auditors or insurers.

9. Meet Cyber Insurance Training Requirements

Cyber insurance is becoming harder to get and more expensive. Insurers now demand proof that you actively manage human risk. They want to see that you verify identities and, more importantly, that you train your team to spot phishing attacks. A system that tests your staff and generates reports on their performance helps you meet cyber insurance training requirements without creating extra admin work.

10. Train for Tone and Visuals

Technical filters stop a lot of junk, but bad emails still get through. Research into the effect of tone, signature, and visual elements in emails shows that employees are easily swayed by authority cues—like a fake signature from a CEO or a copied logo. Your training needs to expose staff to these specific tricks safely. Simulation tools that mimic real-world brands (like Microsoft 365 or DocuSign) teach your team to look past the logo and check the actual sender address.

Why Automation Wins

Reviewing this checklist might feel overwhelming if you are already stretched thin. The idea of manually sending fake phishing emails or tracking who watched a training video sounds like a full-time job.

It doesn't have to be. Your IT provider keeps your systems running, but they can't stop an employee from clicking a bad link. That's where automated platforms fill the gap. By using a tool that learns your industry and targets your staff with realistic simulations, you build a "human firewall" that gets stronger over time.

You don't need IT skills to set this up. You upload your staff list, choose a frequency, and let the system run. It trains the people who need help and leaves the experts alone. Most importantly, it generates the compliance reporting you need to satisfy the ATO, your insurer, and your own peace of mind.

Take the First Step

Identity security isn't about paranoia; it's about good business hygiene. Start by auditing your current hiring process against the points above. Then, solve the training problem permanently.

Ready to see how your team handles a realistic threat? Sign up for a free trial today and send a sample test to yourself or your team. It takes seconds to set up and costs nothing to start.