Start with a business activity

Choose an activity people recognise, such as taking orders or paying suppliers. Ask which information, accounts, devices and outside services it needs. These are assets and dependencies: things of value and things the activity relies on.

Then describe a specific concern. In plain language, a threat is a potential cause of harm; a vulnerability is a weakness that could be exploited. Think about risk through the likelihood of something going wrong and its possible impact, including what remains uncertain. A control is a measure intended to change that risk. These explanations support a practical conversation; they are not quoted framework definitions. The NIST Cybersecurity Framework (CSF) 2.0, ID.RA-05.

Instead of writing “email risk”, a useful discussion might ask: “What happens if we cannot access incoming orders, or someone sends payment instructions from a compromised account?” That makes the business impact easier to examine.

Choose measures that work together

Account protection, software updates and recoverable backups address different problems. Include them in your initial discussion, alongside how staff recognise concerns and where they report them. A product purchase alone does not establish that these activities are covered. ACSC’s business guidance introduces complementary measures rather than a single protective product. Small business cyber security guide

The right next step depends on what is already in place, what is missing and what matters most to the business. Someone needs authority to approve the work, and someone needs responsibility for checking its result. Those roles may belong to different people.

An invented example

A small office receives orders by email and records them in shared files. Its operations manager discovers that nobody can explain how those files would be recovered. Rather than assume a new tool is the answer, the manager asks the IT owner to establish what is backed up and what evidence exists of a restore.

This is an illustration of finding an evidence gap, not a completed risk assessment or a claim that backups must always be everyone’s first priority.

A practical starting worksheet

Use these questions for an initial planning conversation:

  • Which activity are we considering, and what does it depend on?
  • What would interruption, loss or unauthorised change mean for that activity?
  • Who owns the business decision and the technical work?
  • Which measures are already operating, and what evidence supports that?
  • What needs investigation, and who will report back?

Keep unanswered questions visible. “We have not checked” is more useful than recording an unsupported assurance.

Optional depth: use a framework carefully

The NIST Cybersecurity Framework groups outcomes under Govern, Identify, Protect, Detect, Respond and Recover. These are connected concerns, not six tasks that must be finished once in sequence. The NIST Cybersecurity Framework (CSF) 2.0

Australia’s Essential Eight can inform a deeper discussion, but its stated focus is internet-connected IT. It does not cover every threat or environment. Choosing a maturity target needs organisational context; completing a checklist is not a guarantee of protection or certification. Essential Eight maturity model

For business-specific priorities, involve someone able to assess the relevant systems and operational consequences. This guide provides a starting conversation, not an assessment of your business.

  • MFA and passkeys — Compare authentication approaches.
  • Recognizing and reporting suspicious messages — Handle suspicious requests.
  • Backups and restore tests — Understand recoverability.