Skip to main content

The IT Agency

Cyber Security, Compliance

Is your small business at risk of a cyber attack?

  • Small businesses reported average losses of $56,600 per cybercrime incident in the past financial year, an increase of 14 per cent, according to the ASD Annual Cyber Threat Report 2024–25
  • According to the OAIC’s Notifiable Data Breaches report for January–June 2025, malicious and criminal attacks caused 59 per cent of reported data breaches nationally, and human error accounted for a further 37 per cent, showing that risk sits inside everyday operations as much as technical defences
  • Businesses collecting customer names, emails, payment details or other personal information carry data protection responsibilities that are expanding, with reform underway to remove the small business exemption from the Privacy Act
  • Small businesses are targeted because defences tend to be lighter and a single small business can provide a path into the larger organisations it supplies
  • A small set of practical controls, including multi-factor authentication, a documented incident response plan and a verification process for payment and banking requests, addresses most common attack paths
  • SMB1001 gives small businesses a structured, tiered way to formalise and prove these controls are in place, without needing an external auditor at the entry levels

Questions answered

  • How do I know if my small business is at risk of a cyber attack?
  • My small business handles customer data, what cyber security do I need?
  • Why are small businesses being targeted more broadly?

Is your small business at risk of a cyber attack?

Most small businesses carry more cyber risk than they realise, and plenty are already being targeted. Attackers favour small businesses because their defences tend to be lighter than a larger organisation’s and because a single small business can offer a path into the bigger clients and suppliers with which it works.

If your business collects personal information, a customer’s name, an email address or payment details, you carry a responsibility to protect it under the Privacy Act, and that responsibility is growing as reform to the small business exemption moves forward.

The surest sign a business is exposed is the absence of a handful of basic controls: multi-factor authentication, a documented incident response plan, backups that have actually been tested and a verification step for anything involving payments or banking changes.

Why small businesses are being targeted more broadly

For years, small business owners took some comfort in the idea that their size made them unremarkable to cyber criminals. Why would an attacker bother with a five-person bookkeeping firm when there are banks and multinationals to chase? That assumption has stopped being true and in many cases, it is now working against the businesses that still believe it.

Attackers weigh up effort against reward, and small businesses often tip that balance in their favour. Defences tend to be lighter, dedicated security staff are rare and decisions about payments, access and data often rest with one or two people, without the layer of formal approval a larger organisation would have in place. An attacker does not need to out-manoeuvre a sophisticated security team when a single, well-timed email can do the job just as well.

Small businesses are also valuable for their connections to other organisations. A bookkeeper, an accounting firm or a small supplier will often hold access to the systems, invoices or data of much larger clients. Compromise one small business and you may have opened a door into several bigger organisations at once – which is exactly why small businesses have become such an efficient target within the wider supply chain.

We see this pattern through the businesses we work with at The IT Agency. The ones who get hit hardest are often the ones who believed their size protected them, when if anything it makes them a more efficient target, since attackers know the defences are lighter and the payoff, through access to clients and suppliers, can be significant.

Artificial intelligence has changed the economics of these attacks too. A convincing phishing email, a cloned voice or a message that references a genuine supplier or project used to take real skill and time to accomplish. Now it barely takes either. That shifts more of the load onto internal process, because the traditional tells employees were trained to look for, poor grammar, generic greetings, unfamiliar senders, are becoming far less reliable.

How do I know if my small business is at risk of a cyber attack?

Every business that sends email, stores a customer record or takes a payment carries some level of cyber risk, so that isn’t really the useful question. The better question is how exposed your business is right now, and the answer usually comes down to a short, familiar list of gaps.

  • No multi-factor authentication on email, banking or admin accounts
  • No documented process for verifying payment or banking detail changes
  • Software and devices that are not regularly patched or updated
  • Backups that have never been tested for actual recovery
  • No incident response plan, meaning nobody has a defined role in the first hour of a suspected breach
  • Broad or shared administrator access across the team
  • Limited visibility over which third-party tools or vendors can access your systems
  • Staff who have not received security awareness training in the past 12 months

None of this is unusual – it’s the default state for plenty of small businesses that have grown quickly without ever building a formal IT or security function. Two or three of these gaps sitting together is generally enough to put a business in a higher risk bracket, especially given how convincing AI-generated scams have become.

We run a security assessment with our clients at The IT Agency and the pattern is consistent. It’s rarely one big gap, it is usually four or five small ones stacked together and any one of them can be the entry point an attacker needs.

According to the ASD Annual Cyber Threat Report 2024–25, small businesses reported average losses of $56,600 per cybercrime incident last financial year, 14 per cent higher than the year before. Nationally, the Australian Cyber Security Centre responded to more than 1,200 incidents and fielded a cybercrime report roughly every six minutes.

My small business handles customer data, what cyber security do I need?

We’re often asked whether a business needs to comply with the Privacy Act because of its turnover. Rather than considering your cyber security by the size of business, asking whether your customers would expect their data protected and whether you could explain your process to them if something went wrong, may be a more useful question to ask.

If your business collects, stores or processes personal information about customers, staff or suppliers, a name, an email, a payment detail or a delivery address, you are already carrying a responsibility to protect it, whether or not you have thought about it in those terms.

Under the Privacy Act 1988, most businesses with an annual turnover of $3 million or less currently sit outside the Act, with a handful of exceptions including health service providers and businesses that trade in personal information.

That exemption will not last indefinitely. The Attorney-General’s Department has progressed the case for removing it as part of broader privacy reform and from 1 July 2026, anti-money laundering reforms bring more than 80,000 additional small businesses, including those providing real estate, legal, accounting and conveyancing services, under the Act regardless of turnover.

Even where the exemption still technically applies, customers, insurers and larger clients increasingly expect evidence of good data protection practice as the price of doing business, independent of what the law currently demands.

  • Knowing exactly what personal information your business collects and where it is stored
  • Applying access controls so only people who need customer data can see it
  • Using multi-factor authentication on any system that stores or processes personal information
  • Having a documented process for responding to a suspected data breach
  • Understanding your obligations under the Notifiable Data Breaches scheme if a breach is likely to cause serious harm

How small businesses can reduce cyber risk

Frameworks such as SMB1001 offer a structured way to formalise these protections. It’s a certification built specifically for small and medium businesses, with five tiers, Bronze, Silver, Gold, Platinum and Diamond, the first three of which a director can self-attest through the CyberCert platform without needing an external auditor. For a business handling customer data, working toward SMB1001 is generally the most practical way to turn ‘we take this seriously’ into something a client or insurer can actually verify.

Key takeaways

Small business cyber risk isn’t going away and the regulatory ground is shifting at the same time, with the Privacy Act exemption narrowing and anti-money laundering reforms already bringing tens of thousands of small businesses into scope. The businesses that come through this well are the ones that get the basics right: multi-factor authentication, tested backups, a documented incident response plan and a verification step for anything involving money. SMB1001 gives you a structured, tiered way to prove those basics are in place, before a breach or an audit forces the question.

Frequently asked questions

What is the most common way small businesses get breached?

Phishing and business email compromise are still the most common way in, often followed by a payment redirection scam where a request to change banking details looks like it has come from a genuine supplier. Weak or reused passwords on email and admin accounts are usually somewhere in the mix as well.

Do I need cyber insurance if I’m a small business?

It isn’t mandatory, but a growing number of insurers now expect baseline controls, multi-factor authentication and documented backups among them, before they will offer cover at all. A good policy can help offset the cost of recovering from an incident and works best sitting alongside preventative controls you already have in place, not as a substitute for them.

How much does basic small business cyber security cost?

It depends on the size of your business and what you already have in place, but the core controls, MFA, endpoint protection and staff training among them, are within reach for most small businesses without an enterprise-sized budget. Many of the highest-impact improvements come down to process and configuration more than new spend.

Is my business exempt from the Privacy Act because of my size?

Businesses with an annual turnover of $3 million or less are currently exempt from most of the Privacy Act, with exceptions for health service providers and businesses that trade in personal information. That exemption is under active review, and separate anti-money laundering reforms will bring many additional small businesses under the Act from 1 July 2026 regardless of turnover.

What is SMB1001 and do I need it?

SMB1001 is a cyber security certification built specifically for small and medium businesses, structured into five tiers so a business can start at Bronze and advance from there. It’s voluntary, but it’s the most practical way for a business handling sensitive information to demonstrate its controls are real, and it’s increasingly turning up in tenders, insurance reviews and client questionnaires.

What should I do first if I think my business has already been compromised?

Contain the incident first, isolating affected systems and accounts, then get your IT or cyber security provider on the phone along with the Australian Cyber Security Centre on 1300 292 371. Keep a record of what happened and when, since that timeline supports both your response and any reporting obligations that follow.

Continue reading

Do Australian small businesses need cyber security certification?
What is a cyber security framework, and what does implementing one involve?
What’s the easiest way for a small business to become cyber compliant?
What is SMB1001? The complete guide for Australian small businesses
Essential Eight vs SMB1001 vs ISO/IEC 27001: Which cyber security framework is right for your business?
Should I use a managed service provider to implement SMB1001, or can I do it internally?
How much does SMB1001 cost? Is it worth the investment?
SMB1001 implementation roadmap: from assessment to certification
Cyber governance for Australian small businesses: Building resilience and trust
Why choose The IT Agency for SMB1001? How to choose the right implementation partner

About The IT Agency

The IT Agency helps keep businesses connected, protected, productive and supported through cyber governance, compliance, AI and managed IT solutions. As a Microsoft Solutions Partner and SMB1001 Gold Certified MSP, we help businesses simplify IT, implement technology securely and strengthen resilience. Talk to us about building a more secure and future-ready business.

References

https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025
https://www.oaic.gov.au/news/blog/latest-notifiable-data-breach-statistics-for-january-to-june-2025
https://www.ag.gov.au/rights-and-protections/publications/privacy-act-review-report
https://www.oaic.gov.au/privacy/notifiable-data-breaches
https://cybercert.ai
https://www.austrac.gov.au/industry-and-business/about-amlctf-reforms/about-reforms

The IT Agency

The IT Agency

SMB1001 GoldMicrosoft Solutions PartnerCyber and IT Experts

The IT Agency helps businesses stay connected, protected, productive and supported through cyber governance, compliance, AI and managed IT solutions.