Small businesses do not need to be large or well-known to become targets for cyber attacks. Australian businesses of all sizes are facing growing cyber risks, from phishing and business email compromise to ransomware, data breaches and stolen credentials.
According to the Australian Signals Directorate (ASD), more than 84,700 cybercrime reports were received in Australia during FY2024–25, averaging approximately one report every six minutes. The average self-reported cost of cybercrime for Australian businesses increased by 50% to $80,850 per report, while the average cost reported by small businesses reached $56,600, up 14%.
At the same time, the Office of the Australian Information Commissioner (OAIC) recorded 1,205 data breach notifications in 2025, the highest annual total since Australia’s mandatory data breach reporting scheme began.
So why are Australian SMEs attractive targets for cybercriminals, and what can small businesses actually do to reduce their risk?
Why Are Australian SMEs Targeted by Cyber Attacks?
There is no single reason why cybercriminals target small and medium-sized businesses.
Attackers look for opportunities where they can gain access to systems, steal information, disrupt operations or make money.
Some SMEs may have fewer dedicated cybersecurity resources than larger organisations. They may also have limited IT staff, outdated systems, weak passwords, poorly configured cloud services or insufficient security training.
Common security gaps include:
- Weak or reused passwords
- Lack of multi-factor authentication
- Outdated software and devices
- Poorly protected email accounts
- Limited employee security training
- Inadequate backups
- Excessive user permissions
- Cloud security misconfigurations
- Unsecured remote access
- Third-party access
- Lack of an incident response plan
Being a small business does not automatically make an organisation vulnerable. However, attackers can take advantage of security gaps wherever they find them.
Are Australian SMEs Really at Risk From Cyber Attacks?
Yes. Australian government reporting shows that cybercrime continues to affect businesses across the country.
ASD’s Annual Cyber Threat Report 2024–25 recorded more than 84,700 cybercrime reports during the financial year.
Among businesses, email compromise without financial loss accounted for 19% of reported cybercrime, while business email compromise involving financial loss accounted for 15%.
This shows that a cyber attack does not always require sophisticated malware.
A compromised email account, stolen password or fraudulent payment request can be enough to cause serious financial damage.
Why Do Cybercriminals Target Small Businesses?
1. SMEs May Have Fewer Dedicated Cybersecurity Resources
Large organisations may have dedicated cybersecurity teams, security analysts and IT departments.
A small business may have:
- One internal IT employee
- An external IT provider
- An employee handling IT alongside another role
- Or no dedicated IT support at all
This can make it difficult to manage cybersecurity consistently.
The issue is not necessarily a lack of interest in security. Small business owners are often managing sales, customers, employees, finances and daily operations at the same time.
As a result, security tasks such as patching, access reviews and backup testing can easily be delayed.
2. Small Businesses Still Hold Valuable Information
Being a small company does not mean you have nothing worth stealing.
Australian SMEs may store:
- Customer information
- Employee records
- Financial information
- Payment details
- Business documents
- Contracts
- Supplier information
- Login credentials
- Intellectual property
- Personal information
A compromised account can also give attackers access to other business systems.
This makes data protection important regardless of the size of the organisation.
3. Automated Attacks Can Find Vulnerable Businesses
Modern cyber attacks are not always manually targeted.
Attackers can use automated tools to search for:
- Vulnerable software
- Exposed devices
- Weak passwords
- Unsecured services
- Outdated systems
- Misconfigured cloud applications
This means an SME does not have to be famous or strategically important to experience an attack.
If a business has an exposed vulnerability, automated attacks may eventually find it.
4. Business Email Is a Major Attack Target
Email is one of the most important systems in a modern business, which also makes it attractive to cybercriminals.
A compromised business email account can potentially be used to:
- Send fraudulent payment requests
- Impersonate executives
- Steal sensitive information
- Redirect invoices
- Reset other accounts
- Send phishing emails
- Target customers and suppliers
ASD’s 2024–25 reporting identified email compromise and business email compromise among the leading reported cybercrime categories affecting Australian businesses.
How Can Small Businesses Protect Business Email?
Businesses should consider:
- Multi-factor authentication (MFA)
- Strong, unique passwords
- Password managers
- Email security controls
- SPF
- DKIM
- DMARC
- Phishing awareness training
- Payment verification procedures
For financial requests, employees should independently verify unusual payment or bank-account-change requests before taking action.
5. Supply Chain Relationships Can Increase Cyber Risk
Australian SMEs rarely operate completely on their own.
A business may work with:
- IT providers
- Accountants
- Software providers
- Contractors
- Suppliers
- Marketing agencies
- Larger corporate customers
- Cloud service providers
Some of these relationships may involve access to business systems or sensitive information.
This creates third-party cybersecurity risk.
Businesses should regularly ask:
- Who has access to our systems?
- Why do they need access?
- Is MFA enabled?
- What information can they access?
- Is their access still required?
- What happens when the relationship ends?
Third-party access should be reviewed regularly rather than being left permanently active.
6. Limited Cybersecurity Budgets Can Create Security Gaps
Cybersecurity requires ongoing investment.
Businesses may need to budget for:
- Security software
- Endpoint protection
- Backups
- MFA
- Employee training
- IT support
- Monitoring
- Security assessments
- Hardware upgrades
- Software updates
For SMEs, these costs compete with many other business priorities.
The solution is not necessarily to purchase every security product available.
Instead, businesses should identify their highest-risk areas and address the fundamentals first.
For many SMEs, this means prioritising:
- Multi-factor authentication
- Software patching
- Secure backups
- Endpoint protection
- Email security
- Restricted administrator access
- Employee security awareness
7. Remote and Hybrid Work Creates Additional Security Challenges
Remote and hybrid work has changed how employees access business systems.
Employees may connect from:
- Home networks
- Personal devices
- Public Wi-Fi
- Shared environments
- Different locations
Without appropriate controls, this can create additional security risks.
Businesses should establish clear policies for:
- Company devices
- Remote access
- MFA
- Wi-Fi security
- Software updates
- Endpoint protection
- File sharing
- Cloud applications
Where possible, employees should use managed and secured business devices to access sensitive systems.
8. Cloud Services Are Not Automatically Secure
Microsoft 365, Google Workspace and other cloud platforms offer strong security features, but those features still need to be configured correctly.
Common cloud security problems include:
- MFA not being enabled
- Former employees retaining access
- Excessive permissions
- Public file sharing
- Unprotected administrator accounts
- Unnecessary third-party application access
- Poorly configured security policies
Businesses should regularly review cloud accounts and permissions.
Ask:
Who has access?
What can they access?
Do they still need that access?
Are administrator accounts properly protected?
9. Human Error Still Plays a Role
Not every cyber incident begins with an advanced technical attack.
A staff member may accidentally:
- Click a phishing link
- Open a malicious attachment
- Send information to the wrong person
- Approve a fraudulent invoice
- Reuse a password
- Share credentials
- Lose a company device
The answer is not to blame employees.
Instead, businesses should make secure behaviour easier through technology, policies and regular training.
Useful measures include:
- MFA
- Password managers
- Security awareness training
- Phishing simulations
- Clear payment verification procedures
- Access controls
- Endpoint protection
- Regular security reminders
10. Ransomware Can Have a Major Business Impact
Ransomware remains a significant cybersecurity threat for Australian organisations.
ASD’s Annual Cyber Threat Report 2024–25 reported that the Australian Cyber Security Centre responded to 138 ransomware incidents during the financial year.
For an SME, the biggest cost of ransomware may not be the ransom itself.
A successful attack can lead to:
- Business downtime
- Lost productivity
- Recovery costs
- Lost sales
- Customer disruption
- Data recovery work
- Legal or regulatory obligations
- Reputational damage
This is why businesses should maintain reliable backups and regularly test whether critical systems and data can actually be restored.
What Do the Latest Australian Cybersecurity Numbers Show?
Current Australian data highlights the scale of the cyber risk.
More than 84,700 cybercrime reports
ASD received more than 84,700 cybercrime reports during FY2024–25, equivalent to approximately one report every six minutes.
$56,600 average cost for small businesses
The average self-reported cost of cybercrime for Australian small businesses increased to $56,600 per report, up 14% from the previous financial year.
$80,850 average cost for businesses
Across Australian businesses overall, the average self-reported cost of cybercrime increased to $80,850 per report.
1,205 data breach notifications
OAIC recorded 1,205 data breach notifications during 2025, the highest annual total since Australia’s mandatory data breach reporting scheme began.
716 breaches linked to malicious or criminal activity
Of those 1,205 notifications, 716 were attributed to malicious or criminal activity.
These figures do not mean that every Australian SME will experience a cyber attack.
They do demonstrate that cyber risk is an ongoing business issue that organisations need to manage.
Has Cybersecurity Regulation Changed for Australian SMEs?
Australia introduced a mandatory ransomware and cyber extortion payment reporting regime on 30 May 2025.
The regime applies to businesses with annual turnover of $3 million or more, as well as certain critical infrastructure entities, when a ransomware or cyber extortion payment is made.
Covered entities generally have 72 hours to submit a report after a payment is made.
This does not mean every SME must report every ransomware incident.
The specific reporting requirements depend on whether the organisation falls within the scope of the regime and the circumstances of the incident.
Businesses should understand which obligations apply to them and seek appropriate professional advice when required.
What Can Australian SMEs Do to Reduce Cybersecurity Risk?
The good news is that improving cybersecurity does not always require an enterprise-sized budget.
Start with the fundamentals.
1. Enable Multi-Factor Authentication
MFA adds an additional layer of protection beyond a password.
Prioritise MFA for:
- Business email
- Microsoft 365
- Administrator accounts
- Cloud services
- Remote access
- Financial systems
2. Keep Software Updated
Regularly patch:
- Operating systems
- Applications
- Browsers
- Firewalls
- VPN devices
- Network equipment
- Business software
Legacy technology should also be identified and replaced when it creates unacceptable security risks.
3. Protect and Test Backups
Maintain regular backups of critical business information.
Then test restoration.
A backup is only useful if your business can successfully recover from it.
4. Secure Business Email
Review and implement appropriate email security controls, including:
- SPF
- DKIM
- DMARC
- MFA
- Email filtering
- Suspicious login monitoring
5. Restrict Administrator Access
Employees should not automatically have administrator privileges.
Use least-privilege access wherever practical.
6. Train Employees
Security training should cover:
- Phishing
- Password security
- MFA
- Invoice fraud
- Social engineering
- Suspicious attachments
- Data handling
- Incident reporting
7. Review Third-Party Access
Create a list of suppliers and service providers that have access to your systems.
Review that access regularly and remove permissions that are no longer required.
8. Create an Incident Response Plan
Your business should know what to do if:
- An email account is compromised
- Ransomware is detected
- Customer data is exposed
- A laptop is stolen
- A fraudulent payment is discovered
- A critical system goes offline
An incident response plan should clearly identify who is responsible for containment, communication, recovery and reporting.
9. Consider Managed IT and Cybersecurity Support
Many SMEs do not have the internal resources to continuously monitor systems, patch devices, manage Microsoft 365, protect endpoints, test backups and respond to security events.
A managed service provider can help businesses establish and maintain these controls.
However, businesses should also assess the MSP’s own security practices before giving it privileged access to business systems.
Should Small Businesses Use an MSP for Cybersecurity?
A Managed Service Provider can be useful when an SME does not have the internal expertise or resources to manage IT and cybersecurity consistently.
An MSP may provide:
- 24/7 monitoring
- Endpoint protection
- Patch management
- Microsoft 365 security
- Network management
- Backup management
- MFA support
- User access management
- Security awareness
- Incident response
- IT strategy
However, hiring an MSP does not automatically make a business secure.
Before choosing a provider, ask:
- How do you protect your own systems?
- How do you manage privileged access?
- Is MFA mandatory for your staff?
- How do you respond to security incidents?
- How often are backups tested?
- How do you manage vulnerabilities?
- What cybersecurity controls are included?
- What happens if your organisation experiences a security incident?
Cybersecurity Checklist for Australian SMEs
Use this checklist to identify potential security gaps:
- MFA enabled on critical accounts
- Business email properly secured
- SPF, DKIM and DMARC reviewed
- Operating systems patched
- Applications regularly updated
- Endpoint protection installed
- Critical data backed up
- Backup restoration tested
- Administrator access restricted
- Cloud permissions reviewed
- Third-party access reviewed
- Security awareness training provided
- Incident response plan documented
- Critical systems identified
- Legacy technology reviewed
- Cybersecurity responsibilities assigned
If several of these boxes are unchecked, it does not necessarily mean your business has already been compromised. It does indicate that there may be opportunities to strengthen your cybersecurity posture.
Final Thoughts
Australian SMEs are not targeted simply because they are small. They can become attractive targets when valuable information, connected systems and business-critical technology are combined with security gaps that attackers can exploit.
The good news is that many important security improvements are practical and achievable. Enable MFA. Keep systems patched. Protect business email. Secure administrator accounts. Maintain tested backups. Review third-party access. Train employees. Have an incident response plan.
Cybersecurity should not be treated as a one-time project. It is an ongoing part of operating a modern Australian business. If your business does not have the internal resources to manage these areas consistently, LucidByte can help with managed IT, cybersecurity, monitoring, cloud management and ongoing IT support for Australian businesses.
Need to understand where your business is exposed? Contact LucidByte for a practical assessment of your IT and cybersecurity environment.


