Tech, Tools & AI

Backups & Cyber Basics

The five things every small business must do to avoid a ransomware disaster.

Notes from Randall Harper. Thirty years working alongside owner-operators, executives and boards — companies of all types and sizes — across entertainment & media, hospitality, service based business, lifestyle businesses, financial services, retail and not-for-profit, in Australia, Asia, the United Kingdom and the United States. What follows is the thinking I keep returning to.

Small businesses are the prime target

Owners often assume cybercriminals target large companies. The opposite is true. Small businesses are attacked far more often because they are easier — fewer defences, less training, more likely to pay a small ransom rather than rebuild. The cost of basic cybersecurity is trivial; the cost of recovering from a serious incident is often existential.

The five essentials

  • Multi-factor authentication on every important account — email, banking, accounting, cloud storage.
  • Strong, unique passwords stored in a password manager, never reused.
  • Automatic backups of all important data, with at least one copy off-site or in a separate cloud.
  • Software and operating systems updated promptly — most attacks exploit known vulnerabilities.
  • Basic team training — how to spot phishing, what not to click, what to do if something feels wrong.

Backups are the safety net

If everything else fails — and occasionally it will — backups are the difference between a bad week and a closed business. Use a backup tool that runs automatically, includes versioning (so you can roll back before an incident), and is tested quarterly. An untested backup is a guess; a tested one is a plan.

Email is the front door

The vast majority of attacks start with email — a spoofed invoice, a fake login link, a request from a 'supplier' to change bank details. Train the team to verify any payment-related request by a separate channel (phone call to a known number, not the one in the email). One five-minute conversation, repeated annually, prevents most of what would otherwise hit you.

Have a plan for when it goes wrong

Write down — and store somewhere other than the computer — what you would do if you lost access to your systems tomorrow. Who would you call? Where are the backups? What would you tell customers? An incident plan you have never thought through is a plan you will not execute well under pressure. An hour of thinking calmly now is worth a week of panic later.

Want this as a PDF?

Tell us where to send it and we'll email you a copy to keep.

The contents of this paper are the opinion of Clear Point Advisory only. Readers should rely on their own judgement and obtain professional advice appropriate to their circumstances.

Clear Point Advisory · Randall Harper · randall@clearpointcollective.com.au · 0402 416 266
© 2026 The Clear Point Collective. All rights reserved.