Australia observes Cyber Security Awareness Month each October, and for most Perth businesses it comes and goes as a LinkedIn post or an email reminder from a supplier, nothing actually changes. Used properly, it's a useful forcing function: a fixed point in the calendar to catch up on the security basics that quietly slip during a normal year. Here's a four-week plan any Perth business can actually run, not just acknowledge.
Week 1: MFA and Password Audit
Start here, it has the highest impact for the lowest effort. Confirm MFA is enforced on every account that can access email, files, or financial systems, not just the accounts someone remembered to set up when it was first rolled out. Check for shared logins, and replace them with individual accounts. If your business hasn't reviewed password management practices in the last year, this is the week to do it. For a deeper look at phishing-resistant MFA options like passkeys, that's worth a read too.
Week 2: Phishing Awareness Refresh
Run a short refresher on current phishing tactics, not the generic "don't click suspicious links" training most staff have already switched off for. Cover what today's attempts actually look like: AI-written emails with no spelling errors, urgent requests that mimic a real supplier or executive, and QR codes replacing obvious links to dodge email filtering. If you've never run a simulated phishing test, October is a reasonable time to start.
Week 3: Backup and Incident Response Test
Having a backup and knowing it actually works are two different things. Pick one system and run an actual test restore, not a status check that says the backup job completed. Pair it with a short tabletop exercise: if ransomware hit today, does everyone know the first three things to do? Our guides to testing your backup and running an incident response drill walk through both in more detail.
Week 4: Patch and Permissions Review
Close the month by checking two things that quietly accumulate risk all year: outstanding patches across servers and workstations, and file and folder permissions that have never been reviewed since they were first set up. Stale, overly broad permissions are the single most common finding when we run a proper IT security audit for a Perth business, and they cost nothing to fix once found, just time to look.
Why One Month Isn't Enough on Its Own
A dedicated month is a good checkpoint, not a substitute for ongoing practice. As we cover in how often staff training should actually happen, annual or occasional training tends to be forgotten within weeks. Treat October as the month you catch up and reset the baseline, then keep the cadence going through the rest of the year.
Frequently Asked Questions
Is Cyber Security Awareness Month an official Australian campaign?
Yes, Australia observes Cyber Security Awareness Month each October, coordinated at a national level to encourage businesses and individuals to improve their security practices. The specific focus areas are announced closer to the date, but the practical value for a business comes from actually doing something with the month, not just acknowledging it.
We don't have a dedicated IT security team. Can we still run this?
Yes, that's exactly who this plan is for. Every week below is scoped to be run by a business owner, office manager, or outsourced IT provider in a few hours, not a dedicated security function.
What if we can only realistically do one of the four weeks?
Start with Week 1 (MFA and passwords). It has the highest impact for the lowest effort, and closes the single most commonly exploited gap in Australian business breaches.
Should this replace ongoing security training?
No. A dedicated month is a good forcing function to catch up on things that have slipped, but it works best as a checkpoint within a year-round approach, not a once-a-year substitute for it. See our guide on how often staff training should actually happen.
We can run this four-week plan for you, or just the parts you don't have time for.
Cybersecurity Services →Want a head start before October?
Call 0433 087 091 for a free, no-obligation IT health check that covers all four weeks in one visit.
Book a Free IT Health CheckFor related reading, see How Often Should Staff Cyber Security Training Happen?, Phishing & Staff Security Training, and Cybersecurity Checklist for Perth Small Businesses. Once October's wrapped up, the next seasonal risk window isn't far behind, see our guide to Black Friday and Cyber Monday scams targeting Perth businesses.