Cyber security for small business

Cyber Security for Small Business in Australia

Last updated: July 2026

Small businesses are attacked for a simple reason: attackers assume the doors are easier. The same scams that hit big companies, invoice redirection, phished passwords, ransomware, hit small businesses harder, because there is no security team to catch them and no spare cash to absorb them.

Vintaris is a mid-market security consultancy, and our small business stream brings the same enterprise-grade methodology to smaller teams, right-sized: mostly self-service, priced flat, and honest about what you can safely do yourself.

2min
to a first exposure result
17
plain-English questions
10
core controls scored
$479
flat for the full report

Start with two minutes, not a sales call

No jargon, no login, and the fastest honest answer to ‘how exposed are we?’ It is the same lens cyber insurers use before they pay a claim.

1

Answer 17 questions

Plain English, no jargon and no login. Two minutes, honestly.

2

Get an exposure score

An instant snapshot, scored the way a cyber insurer reads your business.

3

See your top gaps

The handful of fixes most likely to matter, ranked so you know where to start.

The small business cyber security checklist

The controls that matter most, in the order most small businesses should tackle them. Every item here is checked in our assessment. Multi-store retailer, professional firm or clinic? See the retail, professional services and healthcare streams.

  1. Multi-factor authentication everywhere, email first. The single control insurers check first and attackers hate most.
  2. A backup ransomware cannot reach, off-network or immutable, and restore-tested at least once.
  3. A call-back rule for bank-detail changes. Any request to change payment details gets verified on a known phone number before money moves.
  4. A password manager, replacing the shared spreadsheet, the browser, and the sticky notes.
  5. Real endpoint protection (EDR) on every computer, not just whatever came with Windows.
  6. Individual logins, no shared accounts, and access removed the day someone leaves.
  7. Updates applied promptly, and nothing running an operating system that no longer gets them.
  8. Staff awareness training, increasingly a condition of cyber insurance cover.
  9. Know your legal obligations if customer data is breached, before it happens.
  10. Control who else has access: agencies, contractors, your old IT provider, your social media accounts.

Want this scored against your actual business instead of read as a list? That is what the free check does in two minutes, and what the full assessment does properly.

And if cyber insurance is what brought you here, our free briefing ‘When the Insurer Moves the Goalposts’ explains what insurers now require before they pay a claim.

When you want more than a checklist

Consulting

Small business cyber security consulting

When you want a human: an expert-led assessment with verification and a tailored roadmap, or ongoing consulting scaled to a small team. Quoted on scope, and sized honestly, we will tell you when the self-service tier is all you need.

Talk to us

Why a mid-market firm runs a small business stream

Because the threats are identical and only the budget differs. Vintaris was founded by an ex-CrowdStrike analyst who watched the same attacks land on companies of every size. The small business stream exists so that the methodology built for mid-market, verified controls, insurer-grade evidence, maturity-based roadmaps, is available at a price a small team can justify, without pretending a small business needs a big-business engagement.

Every Service, Sized for Small Business

Everything in the Vintaris catalogue is available to the small business stream, deployed and priced for smaller teams. Select any service to explore it.

// Click any node to view the full service page

FAQ

Frequently asked questions

What cyber security does a small business actually need?

At minimum: MFA everywhere, a tested off-network backup, real endpoint protection, a password manager, individual logins, prompt updates, staff awareness, and a call-back rule for payment-detail changes. The free check tells you which of these you are missing in about two minutes.

How much does cyber security cost for a small business?

The foundational controls above cost little beyond time: MFA and a call-back rule are free, a password manager and EDR are modest subscriptions. Our self-service assessment is $479 flat. Expert help is quoted on scope and sized to small teams.

What is the best cyber security for a small business?

The best security is the set of controls you will actually maintain: MFA, tested backups and EDR beat any single product. Start by measuring where you stand, then fix the highest-risk gaps first, which is exactly the order our assessment's roadmap gives you.

Do small businesses really get targeted?

Constantly, and often automatically: attackers scan for weak doors at scale and do not check company size first. Invoice-redirection fraud and ransomware are the two that most often end up existential for small businesses.

Can we do this ourselves, or do we need a consultant?

Most small businesses can implement the foundational controls themselves, and the self-service assessment is built for exactly that. A consultant earns their fee when you have compliance obligations, an insurer asking for evidence, multiple sites or systems, or a gap you cannot close alone.

Vintaris provides cybersecurity assessment and advisory services. General information on this page is not legal, financial or insurance advice.

Prepared and reviewed by the Vintaris security team.