Email security for small businesses

Download this fact sheet (PDF)

Business email compromise, email phishing and false invoice fraud are among the most commonly reported incidents to IDCARE by small businesses. Effective email security is essential for preventing cyberattacks, protecting sensitive information and maintaining client trust.  

This fact sheet provides practical tips to strengthen email security and help small business owners better protect their inboxes. 

Common ways criminals target business email accounts 

Business email compromise (BEC) 

Business Email Compromise (BEC) is a targeted cyberattack in which a threat actor gains access to a company’s email account.  

Once inside the account, the attacker may: 

  • Manipulate financial transactions. 
  • Redirect payments. 
  • Steal sensitive information. 
  • Distribute phishing emails to your contacts. 
  • Impersonate employees, executives, or vendors. 
  • Obtain password reset codes to other online accounts, such as social media, or invoicing software, allowing for account takeover  
  • Automatically forward any received email to a different address. 

False invoice fraud 

False invoice fraud happens when a scammer sends fake invoices to deceive businesses or individuals into paying money. They may do this by compromising trusted email accounts or impersonating an email address. 

IDCARE highly recommends checking for any exposures your business email address may have had by visiting haveibeenpwned.com and update any passwords that appear to be breached.  

Tips for securing your email 

Forwarding rules 

Email forwarding rules are settings in your email account that automatically send incoming emails to another address. If a scammer accesses an email account, they can create a hidden forwarding rule to receive copies of your emails. Additionally, these rules can also be set to delete emails once they are forwarded. 

  • Check your email forwarding settings regularly. Unauthorised changes could indicate compromise. 
  • Note you will likely need to login via a web-browser to view these settings, as forwarding rules aren’t typically available directly via the settings page of the mobile app. 
  • Gmail: Please see Google’s guidance regarding email forwarding rules.  
  • Outlook: Please see Microsoft’s guidance regarding email forwarding rules.  
  • iCloud: Please see Apple’s guidance regarding email forwarding rules. 

Multi-factor authentication (MFA) 

MFA adds an extra layer of security, requiring a second, verifying factor beyond your password, such as a code sent to your phone or an authenticator app. Set this up to reduce unauthorised access risks. 

Password resets 

Ensure that your password is strong and unique and update it regularly. Never use the same or similar password twice. Visit haveibeenpwned.com to understand if your password(s) have been involved in any known online breaches. 

Recovery emails 

If you forget your password or are locked out, a recovery email allows you to receive a one-time password (OTP) to help you restore access. Ensure your recovery email is kept up to date so you can regain access to your account if you’re locked out. 

Signed in devices 

Regularly review devices signed into your email. If you see a device you don’t recognise, it can be a strong indication your account has been compromised. 

Additional recommendation 

If you use Microsoft Defender for Office 365, which is a paid service, you can enable Impersonation Insight to help reduce the risk of falling for an impersonated email address. You will receive warnings when you are sent emails from domains that are similar to yours, but not quite the same. This means you will be alerted to someone potentially impersonating staff members or your clients. 

Detection 

1. Recent activity 

Look for any unusual logins from devices and locations you don’t recognise. 

2. Review security settings 

Resecure and check for further suspicious activity.  

  • Ensure multi-factor authentication MFA is enabled 
  • Check your recovery methods are correct 
  • Look for any unauthorised forwarding rules  
  • Reset your password 
  • Check login alerts 
  • Check signed in devices  

3. Linked online accounts 

Review all online accounts linked to your email, including both sensitive and lower-risk ones. Check accounts such as: 

  • Online banking  
  • Government accounts such as ATO and myGov 
  • Superannuation and insurance  
  • Business CRM, accounting or invoicing software and websites 
  • Social Media 

‍

For additional support or information, contact IDCARE by submitting a Get Help Form or call 1800 595 160 (Aus) or 0800 121 068 (NZ).

If you would like to provide feedback please use our Feedback Form.

Join the global list of organisations making a real difference in people’s lives by supporting our service.

SBS Bank
HSBC
ANZ
Department of home affairs
Curtin University
Suncorp
Powercor Australia
ING
Regional Australia Bank
Culture Amp
Mercy Health
Queensland Country Bank
Sportsbet
NGM Group
City of Goldcoast
ConnectID
TPG
Western Sydney University
BOQ
Department of Premiere and Cabinet off of Digital Government
ABC
Coles
REA Group
Equip Super
Return to Work SA
Urban Utilities
Transurban
Westpac
Internal Affairs
Allianz
Commonwealth Bank
Bupa
Services Australia
Qantas
NAB
Australia Post
Victoria State Government
NBN
NDIS
Kiwi Bank
Tasmanian Government
Telstra
UTS
Makesure
Australian Super
Australia Post
Urban Utilities
Brisbane City Council

Copyright © 2025, IDCARE. All Rights Reserved.

ABN 84 164 038 966