Any business is a potential cyber security target

A Brisbane accounting firm we work with received a ransomware demand on a Tuesday morning. Their systems were locked, their backups had not been tested in months, and the ransom was $85,000. They were not a large organisation. They had about 20 staff. The attackers did not care.
If you run a small or medium-sized business and you think cyber criminals would pass you by, the numbers say otherwise. ASD’s Annual Cyber Threat Report 2024-25 found that the average self-reported cost of a cybercrime incident for a small business rose 14% to $56,600. For medium-sized businesses, the average jumped 55% to $97,000. These are not abstract figures. They represent real businesses, real disruption, and in some cases businesses that did not recover at all.
The same report recorded over 84,700 cybercrime reports to the Australian Cyber Security Centre (ACSC) in FY2024-25 – that is one report every six minutes. Incidents handled by ASD rose 11% year on year. The threat is not slowing down.
Why small and medium businesses are being targeted
Attackers are increasingly automated and opportunistic. They use scanning tools to probe thousands of businesses at once, looking for weak passwords, unpatched software, or systems with no multi-factor authentication (MFA) in place. When they find an opening, they move in – regardless of the size of the business. A 20-person firm is just as useful a target as a 2,000-person company if the defences are thin.
Your business data has real value to criminals. Customer and employee records, financial account details, contracts, supplier information, and intellectual property can all be sold on criminal markets or used to launch further fraud. The ACSC notes that information-stealing malware is increasingly used to harvest credentials silently, which are then sold or used in follow-on attacks against your accounts and those of your clients.
Ransomware has also evolved. Attackers now commonly steal data before deploying encryption, so they can threaten to publish it even if you restore from backup. This “double extortion” tactic puts businesses under pressure from two directions at once – system recovery and potential exposure of client data.
What the regulatory environment now requires
The landscape is not just about attack risk. There are now legal obligations tied to how businesses respond to incidents.
Australia’s mandatory ransomware payment reporting regime commenced on 30 May 2025 under the Cyber Security Act 2024. Since 1 January 2026, full enforcement has been in place. If your business turns over more than $3 million a year and pays a ransom – or someone pays one on your behalf – you have 72 hours to report it to ASD. Separate to this, the Privacy Act 1988 requires businesses to protect personal data and notify the Office of the Australian Information Commissioner (OAIC) if a data breach is likely to cause serious harm to individuals. Failing to report a notifiable breach can compound penalties significantly.
For businesses operating with government, health, finance, or large corporate clients, minimum cyber security standards are increasingly a condition of doing business – not just a compliance nicety.
Prompt patching: closing the window attackers rely on
Most successful attacks exploit known vulnerabilities, not exotic new techniques. Attackers look for software that has not been updated and use publicly available exploit tools to get in. The fix is straightforward: keep software and operating systems current.
The ASD’s Essential Eight framework sets clear patching timeframes. Internet-facing applications with known active exploits should be patched within 48 hours. Other applications should be patched within a month. Every business should also ensure they are running supported software. Windows 10 reached end of support in October 2025 – any device still running it is unpatched by design, with no further security fixes coming from Microsoft.
In practice, keeping on top of patching across a mixed environment of workstations, servers, and cloud apps is harder than it sounds. This is one area where a managed IT support arrangement pays for itself quickly.
Multi-factor authentication: the most effective single control
Multi-factor authentication (MFA) requires a user to verify their identity with at least two factors – something they know (a password) plus something they have (an authenticator app, a hardware token, or a biometric). Even if a password is stolen, the attacker cannot get in without the second factor.
MFA should be applied across every access point in your environment:
- Web and cloud-based email accounts.
- Collaboration platforms such as Microsoft Teams.
- Virtual private network (VPN) connections.
- Remote access services and devices.
- Cloud applications and on-premises servers.
- Admin and privileged accounts in particular.
One important update: basic SMS-based MFA is no longer considered sufficient against more targeted attacks. Session hijacking techniques can bypass standard app-based codes. The ASD now recommends phishing-resistant MFA – hardware security keys or passkeys – for privileged accounts and sensitive systems. For most SME staff accounts, an authenticator app remains a strong and practical baseline.
The Essential Eight: a baseline for any Queensland business
The ACSC’s Essential Eight is the Australian Government’s recommended baseline of eight cyber security controls. It covers patching, MFA, application control, restricting administrative privileges, Office macro settings, user application hardening, and regular tested backups. The framework is structured into maturity levels (ML1 to ML3). For most SMEs, reaching Maturity Level 1 across all eight controls addresses the bulk of practical cyber risk.
In our experience working with businesses across South-East Queensland, the gap between where most SMEs think they are and where they actually sit on the Essential Eight maturity scale is surprisingly wide. The controls look straightforward on paper. Getting them configured correctly, consistently, across every device and user account is a different matter. Businesses that do the work find that cyber insurance becomes easier to obtain, and clients and partners start asking about it as part of their own due diligence.
A good starting point is an IT security audit that maps your current position against the Essential Eight and identifies your highest-priority gaps. From there, the improvement can be staged to fit your budget and business operations.
Backups: tested and isolated
Backups are your last line of defence against ransomware. If your systems are encrypted and you have a clean, tested backup, you can recover without paying anyone. If your backup is untested, out of date, or connected to the same network as your primary systems, it may be encrypted or corrupted alongside everything else.
Good backup practice means daily backups of critical data, at least one copy stored offline or in a separate cloud environment, and regular restoration tests. Knowing you have a backup and knowing you can restore from it quickly are two different things. Many businesses discover the gap between the two only under pressure. Our data backup and recovery services are built around that distinction.
What a cyber incident actually costs a small business
The $56,600 average for small businesses is a self-reported figure. The real cost of an incident is often higher once you account for downtime, lost productivity, emergency IT support, legal advice, customer notifications, regulatory engagement, and reputational damage. For some businesses, the reputational cost outlasts the technical recovery by years.
The ASD report also noted that state-sponsored cyber actors continue to target Australian networks alongside financially motivated criminals. You do not need to be a government contractor to be caught in the crossfire. Supply chain attacks – where an attacker compromises a supplier to reach their clients – are a growing vector for businesses of all sizes.
The cost of protection is a fraction of the cost of a serious incident. That calculation has not changed. What has changed is the frequency, the sophistication, and the regulatory obligations that now attach to how you respond.
A quick self-check for your business
Before speaking to anyone, it is worth asking these questions internally:
- Is MFA turned on for all staff, not just administrators?
- Are all devices and applications kept current with security patches?
- Have you tested your backups in the last 90 days?
- Do you know who has administrative access to your systems?
- Does your team know how to recognise a phishing email?
If the answer to any of these is “no” or “I’m not sure”, those are the gaps most likely to be exploited first. Our post on strengthening small business cyber security covers practical steps you can take without a large IT budget.
Where to start
TTA works with small and medium businesses across Brisbane and South-East Queensland to assess cyber risk, put the right controls in place, and prepare a business continuity plan for when – not if – something goes wrong. We are not here to sell fear. We are here to make sure your business is actually protected, not just hoping for the best.
Get in touch with the TTA team to talk through your current position. A conversation costs nothing. An unaddressed vulnerability can cost a great deal more.



