Does a small business really need cyber security services?
Yes, though not the enterprise version. Most attacks on Australian small businesses are automated: phishing, stolen passwords and ransomware that scan for easy targets rather than choosing important ones. Being small is not camouflage. The Australian Signals Directorate puts the average cost of a cybercrime incident at $58,666, and the basic defences cost a fraction of that.
The reason size does not protect you is that nobody is choosing targets. Attack tools work like spam: they try everyone and harvest whoever is easy. A ten-person business is worth attacking because it has money moving through its accounts, an email domain that suppliers and customers trust, staff identity documents on file, and, increasingly, a connection into bigger partners who are the real prize. On that list, small mostly means fewer defences, which to an automated attacker reads as ideal. The trusted email domain is the underrated item there: an intruder inside your mailbox is an intruder your customers and suppliers already trust.
It is not hypothetical for Adelaide businesses. Karidis Corporation, a hospitality and retirement living group running 13 sites across Adelaide and Melbourne, was hit by malware, the day every operator quietly dreads. The rebuild took the business to one hundred per cent Essential Eight coverage with 99.99 per cent uptime since. The recovery is the proof that the damage is survivable; the lesson is that building the defences before the malware is enormously cheaper than building them after. Thirteen sites of guests, staff and point-of-sale systems do not pause while computers are rebuilt; the business had to trade through it, which is the part no invoice captures.
So what does need actually mean at ten people? Four things. Multi-factor authentication on every account, so a stolen password is not a skeleton key. Patching and application control, so known holes close and unapproved software cannot run. Backups that someone has actually restored, so ransomware becomes an inconvenience rather than an extinction event. And monitoring, because every one of these controls fails silently, and eyes on alerts are what turn a quiet failure into a Tuesday ticket. That list is the Australian Government's Essential Eight at Maturity Level 1, more or less exactly, and it is buyable as a monthly service rather than a project. Notice what the four have in common: none is a product you install once, and all of them decay without attention, which is why the buying unit is a month, not a box.
Just as important is what a ten-person business can skip: the enterprise version. You do not need a chief information security officer, a SIEM platform, a quarterly penetration test or a threat intelligence subscription. Those solve problems you will be delighted to have at two hundred staff. Spending on them now, while multi-factor authentication is half-deployed, is buying a burglar alarm for the third floor of a house with the front door open. If a proposal to a ten-person business leads with any of those, it was written for a different business.
The honest caveat cuts the other way too. A sole trader with no staff, no client records and nothing but a laptop and a cloud accounting login can get most of the way with the free ACSC guidance: turn on multi-factor authentication, update everything, back up the laptop. The paid service earns its fee at the point where there are employees, shared systems and customer data, because that is when doing it once becomes keeping it done, every week, while everyone is busy. That threshold is also where the Privacy Act and your customers' expectations quietly start assuming competence, whether or not anything was written down.
The other honest note: some of the risk is not buyable at all. No provider can stop a staff member being tricked into paying a fake invoice if the business has no habit of verifying account changes by phone. Services carry the technical load; the owner still sets the culture. A ten-minute habit of verifying changed bank details by phone costs nothing and quietly outperforms several products on this list.
If you want to know which of the four things you already have, our Essential Eight Cyber Security Scorecard is free and takes minutes to request, or call us on 1800 456 567.
Which of the four things do you have?
Multi-factor authentication, patching and application control, tested backups, monitoring. The free Scorecard tells you which are in place and which are not.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business