Plenty of business owners treat cyber security as something the IT team handles, filed alongside password resets and printer problems. That framing is understandable, and it is also the reason so many Australian businesses are caught off guard. Cyber security is a business risk, and like any material risk it deserves a place on the leadership agenda.
Why smaller businesses get hit
There is a common assumption that attackers only go after big names with big balance sheets. In practice, most attacks are not aimed at anyone in particular. They are automated, running around the clock, scanning for exposed logins, unpatched systems and inboxes that will click. Your business does not need to be a target to become a victim. It just needs to be reachable and a little easier to get into than the next one.
That is where small and medium businesses tend to come unstuck. Defences are often thinner, one person may be wearing several hats, and there is rarely someone whose actual job is to watch for trouble. None of that reflects badly on the business. It simply means the gaps that automated attacks are built to find are more likely to be there.
The risks that actually matter
It helps to be specific about what can go wrong, because the honest list is shorter than the headlines suggest. Three risks account for most of the real damage we see.
- A data breach. If personal information is exposed, you may have obligations under the Notifiable Data Breaches scheme, which sits within the Privacy Act and is overseen by the OAIC. That can mean notifying the affected people and the regulator, on top of the work of cleaning up. Knowing what data you hold, and where, is half the battle.
- Ransomware and downtime. The lasting cost of ransomware is usually not the ransom. It is the days your business cannot operate while systems are rebuilt and data is restored. A business that can recover quickly is in a very different position to one that cannot.
- Business email compromise. This is the quiet one, and it is where the money actually moves. An attacker gets into a mailbox, watches how you invoice and pay, then slips a fake bank-account change into a genuine conversation at exactly the right moment. No malware, no drama, just a payment sent to the wrong place.
A governance question, not just a technical one
Each of those risks is really a business decision in disguise. How much downtime could we absorb before it hurts? Who is allowed to change bank details, and how do we verify it? What would we tell our customers if their data were exposed? Those are questions for the people who run the business, not only the people who run the servers. Treating cyber security as governance is what turns it from a vague worry into something you can actually manage.
What taking it seriously looks like
The good news is that taking it seriously does not mean spending a fortune or living in fear. A handful of unglamorous basics prevent the large majority of incidents:
- Multi-factor authentication on Microsoft 365 and anything else that faces the internet, so a stolen password is not enough on its own.
- Backups that are actually restore-tested, not just running. A backup you have never tried to recover from is a hope, not a plan.
- Someone genuinely monitoring, so unusual activity is noticed and acted on rather than discovered weeks later.
- Staff who can spot a scam, because your people are the ones who receive the dodgy invoice or the too-good login prompt.
- A recognised baseline to measure yourself against, such as the ASD Essential Eight or the SMB1001 framework, which is pitched sensibly at the size of most Australian businesses.
If you are not sure where you stand today, our free Cyber Health Check is a straightforward way to find out, and our AgileSECURE service exists to put these controls in place and keep them there.
The local reality
Two things have changed the conversation in Australia. The first is that reporting is now expected. If something does go wrong, you can and should report it through ReportCyber at cyber.gov.au, which is also where you turn for guidance during an incident. The second is that proof of controls is becoming the price of doing business. Insurers now ask pointed questions at renewal, and getting the answers wrong can affect a claim, which is why we wrote a guide on answering cyber insurance renewal questions. Larger clients increasingly ask the same questions before they will sign a contract.
None of this needs to be alarming. It simply means cyber security has moved from the too-hard basket to the ordinary business of running a company well. Put it on the agenda, decide what good looks like for your business, and revisit it like you would any other risk. We are always happy to talk it through.
Common questions
Is cyber security really a concern for small businesses?
Yes. Most attacks are automated and untargeted, so any reachable business can be caught, and smaller ones often have thinner defences that these attacks are built to find.
What is the most common way businesses actually lose money?
Business email compromise, where an attacker watches a mailbox and slips a fake bank-detail change into a genuine payment. Verifying account changes by phone stops most of it.
Do we have to report a cyber incident in Australia?
If personal information is exposed you may have obligations under the Notifiable Data Breaches scheme, and you can report incidents through ReportCyber at cyber.gov.au.