Skip to content

CYBER SECURITY · 3 AUGUST 2026 · 2 MIN READ

Cyber hygiene for Australian SMBs in 2026: the eight things that still matter

Threats change; the fundamentals have not. A short, current list mapped to the Essential Eight and ISO 27001 so the work counts twice.

The ACSC's annual threat report reads the same way every year with the names changed: credential theft, business email compromise, ransomware through unpatched edge devices, and now identity attacks that bypass weak MFA. The defences are not exotic. They are the ones nobody finishes.

  1. Phishing-resistant MFA everywhere: passkeys or FIDO2 for admins first, then everyone. SMS codes are the weakest acceptable form and no longer acceptable at Essential Eight ML2. (E8 strategy 3 · 27001 A.5.17)
  2. Patch the edge within days: VPNs, firewalls, mail gateways. Most 2025 ransomware entry points were known vulnerabilities in internet-facing appliances. (E8 1–2 · A.8.8)
  3. Separate admin accounts: no email, no browsing from an account that can change tenant settings. Review who holds them quarterly. (E8 4 · A.5.18, A.8.2)
  4. Application control on endpoints: allow-listing is the single highest-impact control against malware and the least implemented. (E8 5 · A.8.19)
  5. Kill legacy authentication and unsigned macros: both are still on by default in more tenants than you would think. (E8 6–7 · A.8.9)
  6. Test a restore: not a backup, a restore. Record the date and the outcome. (E8 8 · A.8.13)
  7. Log and look: central logs for identity and endpoints, and someone (or an MSP) who reads the alerts. (A.8.15–16)
  8. Know your suppliers: which SaaS holds your data, where, and what happens if it is breached. A one-page vendor register is enough to start. (A.5.19–23)

Make the work count twice

Every item above evidences both an Essential Eight requirement and an ISO 27001 control. If you record it once (dated export, owner, next review), you are most of the way to a maturity report and a Statement of Applicability without a second project. That is the reason ISO Assist maps evidence across frameworks instead of per framework.

By ISO Assist. Tagged CYBER · SMB · ESSENTIAL-EIGHT · BASICS.

More in Cyber security

Reading about it is the slow way.

Book a demo and see the standard adopted in a workspace.