An invoice email arrives from a supplier you've paid a dozen times before. Same logo, same tone, same invoice number format, just a new bank account "due to a system upgrade". The bookkeeper pays it. It is two days before anyone realises the supplier never sent it. This is not a rare story. It is the single most common way Australian businesses lose money to cybercrime, and it does not require a hacker, a virus, or anything most people would recognise as an attack. Cyber security for a small or mid-sized business is not primarily about exotic threats; it is about a short list of ordinary precautions, done consistently, that close off the ways criminals actually get in. This guide covers what those precautions are, what the numbers say about why they matter in 2026, and where to start if you are doing this for the first time.
What cyber security covers for a business
Ask a room of small business owners what cyber security means, and most will say "antivirus" or "a firewall." Both are part of it, but they cover a shrinking share of how businesses get hit. Modern cyber security for a business covers five overlapping areas.
| Area | What it covers | A simple example |
| Access | Who can get into your accounts and systems, and how they prove who they are | Multi-factor authentication (MFA) on email and banking logins |
| Devices | Protecting laptops, phones and servers from malware and unauthorised use | Antivirus, automatic updates, a lock screen after a few minutes idle |
| Data | Keeping information available, accurate and only visible to the right people | Backups that are tested, and access limited to what each role actually needs |
| People | Whether staff can recognise and safely respond to a scam or manipulation attempt | Training on phishing emails and fake invoice requests, and a habit of double-checking unusual payment requests by phone |
| Response | What happens in the first hours after something goes wrong | A written, one-page plan: who to call, what to isolate, and who tells customers if needed |
A business with a firewall and an antivirus subscription but no MFA and no staff awareness has covered one of these five areas and left the other four open. That mismatch, not a lack of any single tool, is what most incidents exploit.
The threats most Australian businesses face
Marketing material about cyber security often leads with the most dramatic scenario: a nation-state attack, a zero-day exploit, a headline-grabbing breach. For the average business, the everyday reality is more mundane and more preventable.
| Threat | How it works | What blunts it |
| Phishing | An email or message designed to trick someone into clicking a link, entering credentials, or opening an attachment. Now often written or polished with AI, which has made poor grammar a less reliable warning sign than it used to be. | Email filtering, MFA (so a stolen password alone isn't enough), and staff who pause before clicking |
| Business email compromise (invoice fraud) | An attacker impersonates a supplier, customer, or executive, usually by compromising or closely mimicking a real email account, and requests a payment or a change of bank details. | A rule that any change of payment details is verified by phone, using a number you already have, not one in the email |
| Ransomware | Malicious software encrypts a business's files and demands payment to unlock them, often after first copying the data out to threaten a leak as well. | Backups that are stored separately and have been restored, plus the access and patching controls below that make the initial break-in harder |
| Unpatched software and weak passwords | Attackers scan constantly for known, already-fixed vulnerabilities and for accounts still using default or reused passwords. | Automatic updates, unique passwords via a password manager, and MFA everywhere is offered |
| Insider error | A staff member sends data to the wrong recipient, misconfigures a shared folder, or loses a device without encryption. No malice required. | Least-privilege access (people can only see what their role needs), device encryption, and clear, simple policies |
The essential protection
The Australian Signals Directorate publishes a set of baseline mitigation strategies for organisations called the Essential Eight. It is written for IT teams, but the underlying ideas translate directly into six things a business owner can check for themselves.
- Turn on multi-factor authentication (MFA) everywhere it is offered: Starting with email, banking and any remote access. This single step blocks most account takeovers, because a stolen password alone is no longer enough.
- Keep software and devices updated: Enable automatic updates for operating systems, browsers, and business applications. Most exploited vulnerabilities were already fixed by the vendor months before the attack; the gap is patches that were never applied.
- Back up your data and test the restore: A backup that has never been restored is hope, not a plan. Keep at least one copy separate from your main network so ransomware cannot reach it too.
- Restrict who administrator access has: Most staff never need it day to day. Fewer admin accounts mean fewer accounts worth stealing, and less damage if one is compromised.
- Filter email and the web before it reaches staff: A decent email security service catches a large share of phishing before anyone has the chance to click it.
- Train staff to recognise a scam and normalise double-checking: The invoice fraud example at the top of this guide is stopped by one habit: verifying unusual payment or bank-detail changes by phone, using a number you already had, not one supplied in the message.
None of these six requires an enterprise security budget. They require consistency: MFA turned on for every account, not just some; updates applied on a schedule, not eventually; a restore tested annually, not assumed to work.
What Australian law expects of your business
1. The Privacy Act and the small business exemption
Most businesses with an annual turnover of $3 million or less are exempt from the Privacy Act 1988. However, there are exceptions (health service providers, businesses that trade in personal information, and a few other categories are covered regardless of size). If your business is not exempt, Australian Privacy Principle 11 requires you to take reasonable steps to protect the personal information you hold, and what counts as reasonable depends on how sensitive that information is.
2. Notifiable data breaches
If your business is covered by the Privacy Act and a data breach is likely to cause serious harm, you are required to notify the Office of the Australian Information Commissioner (OAIC) and the people affected. The OAIC received 1,205 data breach notifications across Australia in 2025, the highest annual total since the scheme began in 2018, so this is a live, tested process, not a rarely used formality.
3. Ransomware payment reporting
Since 30 May 2025, businesses with an annual turnover above $3 million must report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours, whether the payment was made directly or on the business's behalf. There is no obligation to report if no payment is made, though the notifiable data breach rules may still apply if information was accessed or stolen.
4. Industry-specific obligations
Some sectors carry additional requirements on top of the general rules above: healthcare has its own accreditation and My Health Record obligations, financial services has APRA's prudential standards, and businesses handling payment cards have PCI DSS obligations. If you operate in one of these sectors, check what applies to you specifically rather than relying on the general rules here.
Where to spend first if you're starting from zero
A business with no formal cyber security spending yet does not need to buy everything on a vendor's list. Sequencing matters more than budget size, and the highest-impact steps are also, conveniently, the cheapest.
| Priority | What to do | Typical cost |
| Free or near free | Turn on MFA on email, banking, and any cloud accounts. Enable automatic updates. Set unique passwords via a free or low-cost password manager. | Free to low cost; mostly time |
| Low cost, high impact | Subscribe to a proper email filtering service (beyond what comes free with a mailbox). Encrypt laptops. Run a short, plain-language staff training session, even a 30-minute one. | Tens of dollars per user per month |
| Moderate investment | Set up automated, tested backups with offsite or immutable storage. Restrict and audit administrator accounts. | Depends on data volume and existing infrastructure |
| Larger investment, usually with help | A proper incident response plan, a security-focused review of your network, and ongoing monitoring, typically through a managed security provider. | Varies by provider and scope; get a specific quote rather than assuming a figure |
A business that only ever completes priority 1 or wants a fuller picture of managed security options has still closed off the single largest category of incidents: phishing and credential theft. That is a reasonable place to stop for a very small operation with limited resources, and a reasonable place to start for everyone else.
Conclusion
Businesses that get hurt by cybercrime are rarely the ones with no security budget at all; they are the ones with some protection in place and gaps nobody checked. Cybersecurity for an Australian business in 2026 is a short, achievable list done consistently: MFA everywhere, updates applied on schedule, backups that are tested, access limited to what each role needs, and staff who know to verify an unusual request by phone. None of them requires an enterprise budget. Start with the 30-day checklist above and revisit it at least once a year as the ASD publishes its next Annual Cyber Threat Report.




