
The Australian Signals Directorate reported over 94,000 cybercrime incidents in Australia in the 2022–23 financial year — one every six minutes. Small and medium businesses account for a disproportionate share of these incidents, often because they lack the dedicated security resources of larger enterprises while holding the same types of valuable data that attract attackers.
The average cost of a cyber incident for an Australian small business is now over $46,000. For many businesses, a single serious incident — particularly ransomware — can be existential.
Phishing remains the single most common attack vector. Attackers send convincing emails — often impersonating banks, the ATO, Microsoft, or known suppliers — to trick staff into revealing credentials or clicking malicious links. Business email compromise (BEC), a sophisticated form of phishing that impersonates executives to authorise fraudulent payments, has cost Australian businesses tens of millions of dollars.
Ransomware encrypts your files and demands payment for the decryption key. Modern ransomware attacks also exfiltrate data before encrypting it, threatening to publish sensitive information if payment isn’t made. Recovery without a tested backup is extremely difficult and expensive.
Stolen usernames and passwords — often obtained through phishing, data breaches, or password reuse — give attackers direct access to your systems. Without multi-factor authentication (MFA), a single compromised password can lead to a full business compromise.
The Australian Government’s Essential Eight framework provides a practical baseline that, when fully implemented, mitigates the vast majority of common cyber attacks. The eight strategies are: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.
Beyond the Essential Eight, every business should have:
A professional cyber security assessment for an Australian SMB typically covers: a Microsoft Secure Score review, identity and access management audit, email security configuration, endpoint security posture, data classification and loss prevention, and alignment with the Essential Eight. The output is a prioritised remediation plan in plain English — not a 60-page technical report.
At a minimum, a formal security review should occur annually. However, given how rapidly the threat landscape evolves, most organisations benefit from continuous monitoring as part of a managed services agreement, supplemented by periodic focused assessments when significant changes occur — new staff, new systems, office moves, or regulatory changes.