Add Think Technology as a trusted source What Cyber Attacks Cost Australian Businesses | TTA

What cyber attacks actually cost Australian businesses

cyber attacks

Cyber attacks are not just a problem for big corporations. The businesses we support across Brisbane and South-East Queensland are seeing this first-hand. Attackers target SMEs precisely because smaller organisations tend to have fewer controls in place, and the financial consequences of a single incident can be severe. The ASD Annual Cyber Threat Report 2024-25 puts real numbers on what that means for Australian businesses right now.

The numbers from the ASD’s latest report

The Australian Signals Directorate (ASD) received more than 84,700 cybercrime reports in the 2024-25 financial year. That is roughly one report every six minutes. The ACSC (Australian Cyber Security Centre) also responded to more than 1,200 cyber security incidents during the same period, an 11% increase on the year before.

The financial impact is rising sharply. Average self-reported losses per incident, by business size, now sit at:

  • Small businesses: around $56,600 per incident (up 14% year on year).
  • Medium businesses: around $97,200 per incident (up 55%).
  • Large organisations: around $202,700 per incident (up 219%).

These are self-reported averages from businesses that actually lodged a report. Many incidents go unreported, so the true cost to Australian business is higher still. The figures also capture only direct losses. Downtime, reputational damage, legal costs, and lost customers compound the bill over months.

The attack types causing the most damage

Not all cyber attacks look the same. The ASD’s 2024-25 report identifies several types that are causing the most harm to Australian businesses. Understanding them is the first step to building a sensible defence.

Business Email Compromise (BEC). BEC is consistently the top reported cybercrime for Australian businesses. Attackers compromise or spoof an email account, then trick staff into transferring funds or handing over sensitive information. The ASD found BEC fraud with financial loss accounted for 15% of all business cybercrime reports in 2024-25. Phishing drives around 85% of BEC cases, and attackers now use AI to make their messages harder to spot.

Ransomware. The ASD responded to 138 ransomware incidents in 2024-25. Small and medium businesses made up 71% of Australian ransomware victims identified on criminal leak sites. Modern ransomware often involves stealing data before encrypting it, so paying the ransom does not guarantee your data stays private. As of May 2025, businesses with annual turnover above $3 million must report ransomware incidents to the Australian Government under the new mandatory reporting regime.

Data exfiltration. Attackers quietly copy or transfer data out of your systems, often without triggering obvious alerts. Stolen data is sold, used for further attacks, or published to pressure victims into paying. A stolen credential is typically all it takes to get started.

Identity fraud and credential theft. Phishing, fake login pages, and QR code scams (known as “quishing”) are used to capture usernames, passwords, and multi-factor authentication (MFA) prompts. Once an attacker has a valid credential, they can move through your systems quietly. Identity fraud was the top cybercrime reported by individuals in 2024-25.

Online banking fraud and payment redirection. Fraudsters change supplier banking details in emails or invoices to redirect payments to their own accounts. The National Anti-Scam Centre reported Australians lost $2.18 billion to scams in 2025, with payment redirection fraud a major contributor for businesses.

Why SMEs are a growing target

Attackers are rational. They go where defences are weakest and the chance of a payout is highest. SMEs often lack dedicated security staff, run older software, and have not formally tested their incident response plans. That makes them attractive.

AI is accelerating the problem. Cybercriminals now use AI-generated phishing emails, deepfake voice impersonations, and cloned websites to run more convincing scams at much greater scale. The ACSC’s hotline received more than 42,500 calls in 2024-25, a 16% increase, and issued more than 1,700 notifications of potentially malicious activity, up 83% on the previous year. The volume of proactive warnings alone shows how much the threat environment has shifted.

For a business with 20 or 30 staff, a $56,600 loss is not a line item. It can wipe out a quarter’s profit, force redundancies, or in serious cases close the business entirely.

What practical protection looks like

The ACSC’s Essential Eight framework is the standard starting point for Australian businesses. It covers eight foundational controls, including patching, MFA, restricting admin privileges, and backing up data. Implemented well, the Essential Eight stops the majority of common attacks before they take hold.

Beyond the framework, a few practical habits matter:

  • Verify any change to supplier banking details by phone, using a number you already have on file, never a number from the email itself.
  • Enable MFA on every account that allows it, especially Microsoft 365, email, and banking portals.
  • Keep backups isolated from your main network so ransomware cannot reach them.
  • Train staff regularly. Phishing attacks succeed through human error, not technical wizardry.

Our IT security assessments give Brisbane businesses a clear picture of where their exposure sits and what to fix first. If you want an independent view of your current posture, that is usually the right place to start.

For businesses that need ongoing cover, managed security services including email security, DNS filtering, and managed anti-virus keep controls working between reviews. Our cyber insurance compliance support also helps businesses meet the technical requirements insurers now expect before they will pay out on a claim.

Frequently asked questions

How much does a cyber attack cost an Australian small business on average?

According to the ASD Annual Cyber Threat Report 2024-25, the average self-reported cost per cybercrime incident for a small business is around $56,600. This figure covers direct losses only. Downtime, recovery costs, legal fees, and lost customers are typically on top of that.

What is the most common cyber attack on Australian businesses?

Business Email Compromise (BEC) is consistently the top reported cybercrime for Australian businesses. Attackers use compromised or spoofed email accounts to trick staff into transferring money or sharing sensitive data. Phishing is the most common way BEC attacks begin.

Do small businesses need to report ransomware attacks in Australia?

As of May 2025, businesses with annual turnover above $3 million must report ransomware incidents to the Australian Government. If your business is below that threshold, reporting is not yet mandatory, but the ACSC still encourages reporting through ReportCyber so the national picture stays accurate.

What is the Essential Eight and should my business use it?

The Essential Eight is a set of eight foundational cyber security controls published by the ACSC. It covers areas including patching, multi-factor authentication, application control, and data backups. It is designed for Australian organisations and is the most practical starting point for any SME that wants to reduce its cyber risk systematically.

How can TTA help with cyber security in Brisbane?

TTA works with Brisbane and South-East Queensland businesses to assess their current security posture, put the right controls in place, and provide ongoing managed security services. We can help with IT security assessments, Essential Eight alignment, email security, and cyber insurance compliance requirements.

How do we get started?

If you want to understand your current risk and know what to fix first, we are happy to help. Get in touch with the TTA team and we can arrange a straightforward conversation about where your business stands.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.