Software is now part of almost every business process, from quoting and invoicing to customer records, websites, stock control and staff communication. That makes software procurement a security decision, not only a buying decision.
New Australian Signals Directorate guidance published in September 2026 puts strong emphasis on software development controls, authoritative sources, separation between development and production, traceability and supply chain risk. Small and medium businesses may not run large government systems, but the principles are useful when selecting cloud platforms, managed IT providers, website plugins, business apps and custom development services.
Why supplier choice matters
A software supplier can influence how your data is stored, who can access it, how quickly vulnerabilities are fixed and what happens if the service changes ownership or stops operating. The risk also extends beyond the visible application. It can include subcontractors, hosting providers, integrations, open-source components, update channels and support accounts.
Before signing, ask the supplier to explain where data is hosted, which parties can access it, how privileged access is controlled, how security incidents are reported and how your data will be returned if you leave. A clear shared-responsibility statement is more useful than a general claim that a product is secure.
A practical procurement checklist
- Define the business process. Write down what the tool will do, whose work it supports and what would happen if it became unavailable for a day.
- Map the information. Identify customer, financial, health, employee and commercially sensitive information before it is uploaded or connected.
- Check supplier transparency. Ask for security documentation, vulnerability handling arrangements, incident contacts, backup practices and the location of relevant data and support operations.
- Confirm access controls. Require multi-factor authentication, separate administrator accounts, role-based permissions and a process for removing access when staff or contractors leave.
- Ask about updates. Find out how security patches are tested, communicated and deployed, and whether old versions remain supported.
- Review integrations. List every connection to email, accounting, CRM, storage, payment, identity or website systems. Remove connections that are not needed.
- Plan the exit. Confirm export formats, data deletion, licence termination, backup retention and the assistance available if you move to another provider.
Start with a small, controlled rollout
Do not connect a new tool to every business system on day one. Begin with a limited pilot, use test data where possible, keep production access separate and record the decision owner. Review logs, permissions, support activity and unexpected data flows before expanding.
For custom software or website work, require changes to be linked to a ticket or documented request. Keep development, testing and production environments separate. Make sure the business retains control of the authoritative code, configuration and documentation rather than relying on an individual contractor’s account.
Questions to ask this week
Choose one important software supplier and ask: What data do you hold for us? Who can access it? How do you notify us about incidents? How are updates tested? Can we export our information in a usable format? What happens if the service is unavailable or the contract ends?
The answers will show where your next risk-reduction task should start. Good procurement does not mean rejecting every cloud service. It means choosing tools with clear responsibilities, limiting access, keeping an exit path and making security part of the decision before the system becomes business-critical.
Sources
- Australian Signals Directorate: Guidelines for software development
- Australian Signals Directorate: Guidelines for procurement and outsourcing
- business.gov.au: Digital tools for business



Leave a comment