Can a Small Business Actually Get Hacked?
It is the question we are asked more often than any other, usually about ten minutes into a health check and usually phrased as an apology. Surely a business with twenty staff is not worth anybody's attention.
The honest answer is yes, and it does not require anyone to decide that you are worth it. Most small business incidents do not begin with a person choosing you. They begin with something you own being found.
What the Australian Numbers Actually Say
The Australian Cyber Security Centre, part of the Australian Signals Directorate, received more than 84,700 cybercrime reports in the 2024-25 financial year, an average of one every six minutes, and responded to more than 1,200 incidents itself, an 11% increase on the year before.
Smaller businesses carry a disproportionate share of the cost. In the ACSC's Annual Cyber Threat Report 2024-25, the average self-reported cost of cybercrime per report was $56,600 for a small business, up 14% in a year, against $97,200 for a medium business and $202,700 for a large one. Those are self-reported averages rather than audited costs, so read them as an order of magnitude.
The Australian Institute of Criminology's Cybercrime in Australia 2024 survey found that an estimated 22.2% of small and medium business owners, operators and managers said cybercrime had affected their business in the previous 12 months. Among those who were victims, 42% reported at least one impact on the business: disruption to everyday operations for 25.6%, additional business expenses for 15.3%, plus reputation, revenue and information loss.
The notified breaches behind the headlines point the same way. The Office of the Australian Information Commissioner received 1,205 data breach notifications in the 2025 calendar year, the highest number since the scheme began in 2018, and 716 of them were attributed to malicious or criminal activity.
"We're Too Small To Be Worth Targeting"
That belief causes more damage than any single piece of unpatched software. It assumes an attacker drawing up a shortlist, and most incidents do not work that way.
The ACSC describes many cyber incidents as opportunistic in nature. Its reporting also documents an active market in initial access brokerage, where access to a victim network, credentials included, is advertised on the dark web with the business's sector, country and revenue listed, and priced low enough that a criminal with no particular skill can buy their way in.
The criminology data undercuts the idea that being small protects you. Small and medium business owners, operators and managers reported significantly higher rates of every type of cybercrime than other survey respondents. Scale did not make them invisible. It made them easier, because a business with nothing watching has no way to notice a stranger in its mail.
None of this asks you to be selected. Scanning for exposed services and known vulnerabilities runs across the whole internet, and stolen credentials get tried in bulk. Your exposure is found by a machine.
How It Actually Happens
Three routes account for most of what we find.
1 Email, and then a person
Phishing was recorded as an initial access technique in 38% of the incidents the ACSC responded to in 2024-25, which makes it the most common way in. It is the most reported cybercrime for businesses too: email compromise with no financial loss accounted for 19% of business reports, business email compromise fraud with a loss 15%, and identity fraud 11%.
Why it works: The message looks like a supplier invoice, a Microsoft 365 password notice, or a short note from the managing director asking for a favour. One click and one password typed into a lookalike page is enough to hand over a mailbox.
What stops it: MFA that phishing cannot satisfy, email filtering tuned to your actual suppliers and banks, and a team that knows how to report a suspicious message in one click.
2 Credentials that were already circulating
In the incidents where data was encrypted, the ACSC found the most common route in was already-compromised credentials, paired with access through legitimate external-facing remote services.
Why it works: The password is not cracked. It was reused, phished in an earlier campaign, or bought. With no MFA on remote access or on an administrator account, a valid username and password is a complete set of keys, and the login looks like an ordinary employee arriving at work.
What stops it: MFA on every remote access path and every admin account, unique passwords kept in a password manager, and alerts on logins from new locations.
3 The equipment that answers from the internet
In 2024-25 the ACSC observed more than 120 incidents involving attacks on edge devices, the firewalls, VPN gateways and remote access systems that connect a business to the internet. 96% of those attacks succeeded.
Why it works: Edge devices sit outside most of the protection you have bought, they can only be patched by whoever owns the patch queue, and a flaw in one is reachable from anywhere on the internet. The 2026 advisories show how wide that surface has grown: a large-scale campaign against website content management systems that hit many small and medium Australian businesses, a widespread credential exposure campaign against Fortinet firewalls and VPN gateways, active exploitation of the N-able N-central remote monitoring platform within Australia, plus exploited flaws in TeamCity, Adobe Commerce and Magento, and Citrix NetScaler. In several of those, the ACSC's advice to small and medium business was to contact their MSP or IT provider and confirm the product had been patched and was being monitored.
What stops it: An inventory of everything that answers from the internet, patched within days rather than at the next maintenance window, with MFA enforced on every management interface.
What It Costs When It Lands
The $56,600 average is the part that fits in a spreadsheet. The criminology survey covers the rest: everyday operations disrupted for about a quarter of affected businesses, extra expenses for another 15%, and reputation or revenue damage and lost information for roughly one in eight.
What none of these surveys capture is what owners describe afterwards. A fortnight where nobody does their real job. An invoice paid twice, once to a fraudster. Six weeks of a client quietly wondering whether their files were in it.
Businesses and organisations must operate with a mind-set of "assume compromise", and consider which assets or "crown jewels" need the most protection.
That is the ACSC's own framing in its Annual Cyber Threat Report 2024-25, and it is the right starting point for a business of any size.
What Actually Moves The Needle
The ACSC's guidance for organisations comes down to a short list, and none of it is exotic: logging good enough to reconstruct an incident, replacing or mitigating legacy technology, choosing products that are secure by design, and preparing for what follows, including post-quantum cryptography and AI-enabled attacks. Its Cyber Security Action Month campaign, running this October under the theme "Take a second. Stay secure.", gives the everyday version of the same advice: apply the updates, keep backups, switch on multi-factor authentication, use long unique passwords, and know how to report a scam.
Translated into what matters first for a business of 10 to 40 seats:
- Turn on MFA everywhere, starting with remote access, email and admin accounts. Most of the advice above keeps coming back to this one control.
- Know what answers from the internet, and patch it within days. Firewall, VPN, website, remote access tool. A monthly maintenance window is too slow when exploitation follows disclosure by days.
- Test a restore, not just a backup. An untested backup is a hope. A business that recovers in a day has a different story to tell than one that spends three weeks guessing.
- Filter email, and make reporting easy. One click for your staff, with somebody at the other end who acts on it.
- Reduce admin rights, and remove access the day someone leaves. Most accounts holding the keys to everything never needed them.
One more is worth adding: ask your IT provider what tools they run on your network and how they patch them. The ACSC has spent most of 2026 asking small and medium businesses to do exactly that.
The Short Answer
Yes. Small Australian businesses are hit in volume, the entry points are unglamorous, and being small changes the odds less than most owners assume.
What sits in your control is how an incident ends. Tested backups, MFA, patched internet-facing systems and somebody watching the alerts decide whether it is a bad afternoon or a bad quarter, and whether you find out from your own logs or from a customer.
Want to know where your business actually stands?
Our free 30-minute health check reviews endpoint security, backups, Microsoft 365 configuration and the gaps in your current support. You get a one-page report in plain English, Red, Amber and Green. No obligation, no pitch.
Book Your Free Health Check