Sponsored Sponsored

The small-business cyber gap: Why attackers go for the under-resourced first

| | comments |
(Image via Wikimedia Commons)

In recent years, small Australian firms face cyber pressure from attackers, clients, tenders and insurers. A practical response starts with verifiable controls.

Small-business cyber security now shapes access to contracts, insurance and larger clients.

Attackers favour reachable targets and one compromised supplier account may expose payments, data or trusted access.

Ideally, a proportionate response requires evidence matched to the commercial request, a baseline the team can maintain and one accountable owner.

Why small businesses became the preferred target

Attackers favour small businesses when reusable tactics can reach them cheaply and still expose money, data or larger clients.

Stolen passwords and false payment requests also cost less than a campaign built for one well-defended corporation.

The OAIC's 2025 breach statistics recorded 1,205 notifications, the highest annual total since mandatory reporting began in 2018. Malicious or criminal activity caused 716 of them.

The data covers reporting entities across the economy, so it confirms the wider pattern rather than an SMB-specific attack rate.

That wider pattern matters to a small firm because routine delivery pressure can leave ordinary gaps open. In practice, the risk often builds through four connected conditions:

When one person handles operations, suppliers and IT, updates and access reviews can slip behind client delivery.

If departed staff or contractors keep access, an old account can become a live entry point.

When email, cloud services and payments rely on weak sign-in controls, one stolen password can travel across the business.

Because suppliers are trusted, a compromised account can also support invoice fraud or convincing messages to larger clients. Closing these everyday gaps is the work Redscale takes on for small firms.

The pressures now landing on small owners

The pressure now lands through three business gates: client onboarding, tenders and insurance.

Because each can affect revenue or cover, cyber evidence has become a commercial requirement.

Each gate tests a different part of the business, which is why a weak answer creates a different commercial consequence:

  • Corporate clients: A supplier questionnaire may ask who controls access, how incidents are reported and what evidence is reviewed. If the answers cannot be supported, onboarding or contract renewal can stall.
  • Government tenders: A named standard, maturity target or certificate may be scored or treated as mandatory. Missing it can cost points or make an otherwise competitive bid non-conforming.
  • Cyber insurers: Application and renewal forms may ask about multi-factor authentication, backups, updates and incident response. Unsupported answers can delay a decision or affect the terms offered.

The practical job is to turn each question into a control, an owner and acceptable proof.

Therefore, RedScale, one of Australia's managed security service providers, can help translate the request, although the contract, tender or policy wording must still set the target.

Why "just get ISO 27001" is the wrong first answer

ISO 27001 is the wrong default when no buyer, regulator or contract has asked for a full information security management system.

The standard can suit organisations of any size, yet certification creates an ongoing operating commitment.

That commitment includes a defined scope, risk assessment, policies, internal review, external audit and continual improvement.

The auditor's fee is therefore only one part of the cost. Someone must also maintain the risk record, collect evidence and close findings while the team delivers client work.

Because that work continues between audits, the decision rests on four commercial tests:

  • Required assurance: Whether the client or tender requires ISO 27001 certification or will accept another form of assurance.
  • Certified scope: Which services, offices, people and data fall within the certification boundary.
  • Accepted evidence: Which records the buyer, insurer or assessor expects to inspect.
  • Operational ownership: Who will run and maintain the management system between audits.

An explicit ISO 27001 clause leaves no room for a lighter substitute unless the buyer agrees.

Where the requirement is credible cyber maturity or working controls, a smaller certifiable pathway may meet the commercial need sooner.

A realistic first step: tiered, certifiable, built for SMBs

A realistic first step uses the Essential Eight for control priorities and SMB1001 for tiered, certifiable proof.

For reference, the Australian Signals Directorate recommends the Essential Eight as a baseline, while its maturity model shows how consistently an organisation's controls operate.

However, the Essential Eight provides guidance, not a business certificate and ASD states that no set of strategies guarantees protection from every threat.

That distinction matters because the required evidence depends on what a stakeholder expects:

  • The Essential Eight suits requests about core safeguards or ASD alignment. Its maturity model shows how consistently each control operates, but it does not certify a business or guarantee protection.
  • SMB1001 suits requests for formal, tiered assurance. Working through a tiered SMB1001 readiness checklist gives small and medium businesses a staged standard, a certificate and a digital badge at the selected tier. It cannot replace a named ISO, legal or policy requirement.
  • A named requirement determines the route. An Essential Eight maturity target requires assessment against that level, an SMB1001 request calls for the relevant tier and an explicit ISO 27001 clause requires ISO 27001.

Getting there without a dedicated security team

A small business can progress without a full-time chief information security officer (CISO) when a senior decision-maker owns the target and specialists take on defined tasks.

Specialists may complete technical work, but commercial risk remains with the business.

That split works only when each task produces evidence for the requirement being pursued:

  • Source requirement: The tender clause, client questionnaire or insurance form sets the deadline and accepted evidence.
  • Internal owner: A senior decision-maker holds authority over priorities, budget, exceptions and sign-off.
  • Current baseline: Existing controls and records are confirmed before new tools are purchased.
  • Priority gaps: Gaps that block the target take priority, so delivery capacity is spent on controls that affect tender eligibility, customer assurance or insurance evidence.
  • Reusable proof: Policies, settings, test results and review dates are retained for the next bid, client review or renewal.

Where a lean team lacks the capacity to carry that work alongside client delivery, an SMB1001 certification pathway for small teams provides a structured route from gap assessment through control improvements to evidence preparation.

The resulting records can then address the tender, client or insurer requirement.

What "good enough to start" looks like

"Good enough to start" means each core safeguard has an owner, a routine and evidence that it operates.

Because clients and insurers can only assess visible evidence, that starting position should include:

  • A named senior owner who can approve priorities and accept risk.
  • A current list of important systems, accounts, suppliers and the data they handle.
  • Multi-factor authentication for email, banking and administrator accounts.
  • A documented routine for software updates and removing old access.
  • A tested backup with the result recorded.
  • A short incident plan that names who decides, communicates and records events.
  • An evidence folder with review dates tied to daily practice.

This baseline will not satisfy every tender or policy. It replaces broad claims of being secure with records of what works, which gaps remain and what happens next.

 
Recent articles by
The small-business cyber gap: Why attackers go for the under-resourced first

In recent years, small Australian firms face cyber pressure from attackers, clie ...  
Life insurance in Australia: How a broker finds you better cover than you'd find yourself

Life Insurance in Australia: How a broker finds you better cover than you'd find ...  
Seven lawn mowing hacks every homeowner should know

Your lawn looks brilliant for about 48 hours after you mow it. Then, after you cut ...  
Join the conversation
comments powered by Disqus

Support Fearless Journalism

If you got something from this article, please consider making a one-off donation to support fearless journalism.

Single Donation

$

Support IAIndependent Australia

Subscribe to IA and investigate Australia today.

Close Subscribe Donate