Australia recorded over 84,700 cybercrime reports in the 2024-25 financial year – roughly one every 6 minutes, according to the Australian Signals Directorate. The average self-reported loss for small businesses was $56,600 per incident.
These weren’t sophisticated attacks on large enterprises. Most were opportunistic. Automated tools scanning for unpatched systems, phishing emails landing in ordinary inboxes, ransomware deployed through a compromised credential. The technical barriers to pulling off a successful attack on a small business have dropped significantly over the last decade.
And Australian SMBs aren’t incidental targets. They’re the primary ones.
The real reason small businesses are targets
A small professional services firm holds payroll data, client records, financial information, and supplier contracts. That data has value to an attacker whether it’s extracted and sold or encrypted and held for ransom.
What makes an SMB more attractive than a large enterprise isn’t the data – it’s the security posture. Larger organisations have dedicated security teams, formal incident response plans, and layered technical controls. Most SMBs don’t. That asymmetry is exactly what attackers are looking for.
The ACSC reports that small businesses are disproportionately affected by cybercrime relative to their size. The losses per incident are lower in absolute terms than enterprise breaches, but they represent a much larger share of the business’s revenue and reserves. A $56,600 loss that a large company absorbs as a rounding error can be genuinely damaging for a business turning over $2 million a year.
Email is responsible for the majority of successful attacks
The attack vector that causes the most damage to Australian businesses isn’t a sophisticated network intrusion. It’s an email.
Phishing campaigns, business email compromise, and malicious attachments account for the bulk of successful breaches. An attacker sends a convincing email – sometimes impersonating a supplier, a bank, or Microsoft – and a staff member either clicks a link, opens an attachment, or enters credentials into a fake login page.
From there, the attacker has a foothold. They might move laterally through the network, escalate privileges, exfiltrate data, or deploy ransomware. The initial compromise often takes seconds. The damage plays out over hours or days before anyone notices.
Technical controls reduce this risk. Email filtering, attachment sandboxing, and link inspection catch a significant proportion of malicious emails before they reach inboxes. Multi-factor authentication means a compromised password alone doesn’t hand over account access.
Staff training matters too. Employees who know what a phishing attempt looks like, and who know they can report a suspicious email without consequences, are a meaningful part of the defence. Security awareness training doesn’t need to be expensive or time-consuming to have an effect.
Ransomware has changed the stakes for businesses without tested backups
Ransomware encrypts your files and demands payment for the decryption key. Five years ago it was largely opportunistic. Now it’s industrialised – criminal groups operate it as a managed service, targeting specific sectors and business sizes based on their ability to pay.
The ASD’s Essential Eight positions regular backups as one of its 8 core controls specifically because a reliable, tested backup is what lets a business recover without paying a ransom. Without it, the options are to pay, try to rebuild from scratch, or accept the loss.
The problem is that most businesses have a backup but haven’t tested it. A backup that’s never been restored is an assumption. It might work. It might be corrupted. It might be complete. It might be missing 6 months of data because the schedule wasn’t configured correctly.
Ransomware attackers have also learned to target backup systems specifically. If your backup is connected to the same network as your production environment and uses the same credentials, it’s vulnerable to the same attack. Offline or immutable backups – where the backup can’t be modified or deleted once written – are considerably more resilient.
Testing recovery quarterly, at minimum, turns a backup from an assumption into a verified capability.
The Essential Eight is the right starting point for Australian businesses
The Australian Signals Directorate developed the Essential Eight as a baseline set of controls that, implemented properly, stop the vast majority of common cyberattacks. It’s the framework the Australian government uses internally and recommends to businesses across the economy.
The framework uses maturity levels from Zero to Three. Zero means your current posture has gaps a basic attack could exploit. Level One addresses opportunistic attacks. Level Two addresses more deliberate targeting. Level Three is for high-value targets like government suppliers and critical infrastructure operators.
For most Australian SMBs, Level Two is the appropriate target. It’s not achievable overnight, but the path there is well-defined. A gap assessment against the framework tells you exactly where you sit and what needs to be addressed in what order.
The common gaps that leave businesses exposed
Across small and medium businesses, a few security gaps come up consistently.
- MFA isn’t enabled everywhere it should be. Many businesses enable MFA on one or two systems and leave others unprotected. Email, file storage, accounting software, and remote access tools all need it. A single unprotected account is the one that gets compromised.
- Patching happens slowly or inconsistently. Software vendors release patches when they discover vulnerabilities. The window between a patch being released and attackers scanning for unpatched systems is measured in days, sometimes hours. Monthly patching cycles aren’t fast enough for critical vulnerabilities.
- Administrative privileges are too broadly assigned. When staff have administrator-level access they don’t need for their role, a compromised account gives an attacker far greater reach. Restricting privileges to what each role actually requires limits the damage from any single compromise.
- Backup recovery has never been tested. An untested backup is an assumption, not a control.
- No incident response plan exists. When something goes wrong, the response is improvised. Having a documented plan – even a simple one – that covers who gets called, what gets isolated, and how you communicate with clients and staff means less chaos and faster recovery.
A gap assessment is the practical starting point
A security gap assessment maps your current posture against the Essential Eight maturity model and produces a prioritised list of what to fix. It looks at what controls you actually have in place, tests whether they’re configured correctly, and identifies the specific gaps that need addressing.
From there, you build a remediation plan: what to fix first, what to fix next, and a realistic timeline. The framework is designed for progressive implementation – you don’t need to jump straight to Level Three.
The cost of a gap assessment is a fraction of the average incident cost. For most SMBs, it’s the clearest possible picture of where you’re exposed and what to do about it.
Windstil provides Essential Eight audits and ongoing cyber security support for businesses across Melbourne, Brisbane, and Adelaide.
If you’re not sure where your business sits, that’s the right place to start.