Many small business owners assume that cyber criminals target banks, governments and large corporations, not a twelve-person fabrication shop or a family distribution business. In reality, small businesses are attractive targets precisely because they usually have weaker defences, less monitoring and fewer specialists. Many attacks are automated and opportunistic. They do not care how big you are, only whether a door is open.
The consequences can be severe. A ransomware attack can lock every file and stop production for days or weeks. A fraudulent change to a supplier’s bank details can divert a large payment that is never recovered. Stolen customer data can bring legal obligations, reputational damage and lost trust. Some small businesses do not survive a major incident.
The good news is that a handful of well-understood measures prevent most common attacks. This article explains the main threats in plain language, the controls that matter most (drawing on the Australian Signals Directorate’s Essential Eight), the particular issues for workshops and factories, and how to prepare a simple response plan.
Why every business is exposed
You are exposed to cyber risk if any of the following apply:
- You use email, which almost every business does.
- You bank or pay suppliers online.
- You sell online or take card payments.
- Staff use computers, phones or tablets connected to the internet.
- You store customer, employee or supplier information electronically.
- Machines, cameras or building systems in your premises are networked.
Even a small retail shop that sells through an online marketplace, or a factory that emails drawings to customers and pays suppliers by bank transfer, depends on systems that can be attacked.
The most common threats
Phishing
Phishing messages impersonate a trusted organisation, such as a bank, delivery company, software provider or government agency, to trick you into clicking a link, opening an attachment or entering a password on a fake website. Phishing is the starting point for a large share of cyber incidents.
A common misconception is that the padlock symbol or “https” in the browser address bar proves a website is genuine. It does not. It only means the connection is encrypted, and criminals routinely use encrypted fake websites. Check the actual web address carefully, and go to important sites, such as your bank, by typing the address or using a saved bookmark rather than clicking links in messages.
Business email compromise and invoice fraud
Criminals either take over a real email account or impersonate one, often a supplier, a customer or the owner, and send convincing requests to change bank details or make urgent payments. Because the request appears to come from a known contact and often arrives in an existing email thread, it can be very convincing.
The defence is a process, not a technology: never change payment details based on an email alone. Verify every request to change bank details by phoning the supplier on a number you already have on file, not one provided in the email. Apply maker–checker controls so that no single person can change supplier details and approve payments.
Malware and ransomware
Malicious software arrives through infected attachments, downloads, compromised websites, pirated software or USB drives. Ransomware encrypts your files and demands payment for the key, and increasingly threatens to publish stolen data too. Paying does not guarantee recovery and may fund further crime. Good backups are the most important defence.
Identity theft and impersonation
Criminals misuse stolen personal or business information to open accounts, apply for credit or impersonate your business to your customers. Protect business and personal information, use privacy settings on social media profiles, and monitor for misuse.
Spoofing
Caller ID, email sender names and text message sender IDs can all be faked. A call that appears to come from your bank, or a text that appears to come from a known number, may not. If in doubt, hang up and call back on a number you know to be genuine.
Wireless network attacks
Poorly secured Wi-Fi lets attackers intercept traffic or join your network. Public Wi-Fi in cafés, airports and hotels is particularly risky for sensitive tasks.
The Essential Eight
The Australian Signals Directorate’s Australian Cyber Security Centre publishes the Essential Eight, a set of baseline mitigation strategies that, implemented together, make it much harder for attackers to compromise systems. They are:
- Patch applications. Apply security updates to web browsers, office software, PDF readers and other applications promptly, especially for internet-facing software.
- Patch operating systems. Keep Windows, macOS, mobile operating systems and server systems updated, and replace systems that no longer receive updates.
- Multi-factor authentication (MFA). Require a second factor, such as an authenticator app or security key, in addition to a password, especially for email, remote access, banking and administrator accounts.
- Restrict administrative privileges. Give administrator access only to those who need it, and have administrators use separate accounts for everyday work.
- Application control. Allow only approved programs to run, to stop unknown or malicious software.
- Restrict Microsoft Office macros. Block macros from the internet and allow only trusted macros, because malicious macros are a common attack route.
- User application hardening. Configure browsers and applications to block or limit risky content and features.
- Regular backups. Back up important data, software and settings, store backups so that they cannot be altered or deleted by an attacker, and test that you can restore them.
The Essential Eight is defined in maturity levels. Small businesses do not need to reach the highest level, but most will benefit greatly from implementing the basics of each strategy, starting with updates, MFA, backups and limited administrator access. The ACSC’s website at cyber.gov.au also publishes guidance written specifically for small businesses.
Practical steps for a small business
1. Train your team
People are both the main target and the best defence. Train staff to:
- Recognise phishing and suspicious requests, especially urgent payment requests or changes to bank details.
- Avoid downloading software or files from untrusted sources.
- Report suspicious messages and mistakes quickly, without fear of blame. Early reporting can stop an attack spreading.
- Follow your rules for using company devices, email and networks.
Short, regular reminders work better than an annual lecture.
2. Use strong authentication
Turn on MFA for email, banking, accounting software, cloud storage and remote access. Use long, unique passphrases, and a reputable password manager so staff do not reuse passwords across sites.
3. Keep everything updated and licensed
Turn on automatic updates wherever possible. Avoid pirated software. Beyond the legal issues, it does not receive security updates and may itself contain malware. Replace devices and software that have reached end of support.
4. Protect devices
Use reputable security software. The protection built into modern operating systems is adequate for many small businesses if kept enabled and updated. Encrypt laptops and phones, and make sure lost devices can be locked or wiped remotely.
5. Back up properly
Follow a simple rule of thumb: keep multiple copies of important data, on different types of storage, with at least one copy offline or otherwise protected from being changed or deleted. Cloud services can be part of the answer, but synchronised folders alone are not a backup, because a ransomware-encrypted file can sync over the good copy. Test restoration regularly. A backup you have never restored is only a hope.
6. Secure Wi-Fi and networks
Use strong encryption and a strong password on business Wi-Fi, change default router passwords, keep router firmware updated and provide a separate guest network for visitors. Avoid public Wi-Fi for sensitive work, or use a trusted VPN.
7. Control access
Give each person their own account. Grant access only to the systems and data each role needs, and remove access promptly when people leave.
8. Avoid false economies
Cheap or unsupported technology, shared passwords, unpaid-for software and ageing equipment save money until something goes wrong. Budget for security as part of the cost of operating, the same way you budget for insurance and maintenance.
9. Get an independent check
A periodic review by a qualified IT or security provider can identify gaps you cannot see yourself. For larger or higher-risk businesses, consider an independent audit against the Essential Eight.
10. Write a simple cyber security policy
Write down your rules in plain language: acceptable use, passwords and MFA, payment verification, handling of customer data, reporting incidents and what to do when someone leaves. Make sure everyone has read it.
Special considerations for workshops and factories
Manufacturing businesses have additional risks because production equipment is increasingly connected:
- CNC machines, PLCs and robots often run old operating systems that cannot be updated. Keep them on a separate network segment from office computers and the internet where possible.
- USB drives used to transfer programs to machines can carry malware. Scan them, or use a controlled transfer method.
- Remote access for equipment vendors should be enabled only when needed, protected with MFA and logged.
- CAD files and drawings are valuable intellectual property, both yours and your customers’. Control access and share them securely.
- Security cameras and building controls are frequently poorly secured. Change default passwords and keep them updated.
A ransomware attack that reaches production systems can stop the factory, not just the office.
When something goes wrong: a response plan
Prepare a one-page incident plan before you need it:
- Contain: disconnect affected devices from the network, but do not switch them off if forensic investigation may be needed.
- Contact help: your IT provider, and the bank immediately if money has been transferred, because fast action sometimes allows funds to be recovered.
- Report: report cybercrime to the ACSC through ReportCyber at cyber.gov.au. Victims of identity misuse can contact IDCARE for support.
- Change credentials: reset passwords and revoke access for compromised accounts, with MFA enabled.
- Restore from clean backups once the cause has been removed.
- Notify where required. If personal information is involved, assess whether the Notifiable Data Breaches scheme under the Privacy Act applies to your business, and seek advice.
- Learn: review what happened and fix the weakness.
Keep key contacts (IT support, bank, insurer, key customers and suppliers) somewhere accessible offline.
A worked example: a near miss
An office manager at a small engineering firm receives an email from a regular steel supplier, apparently in a genuine email thread, advising that the supplier has changed banks and asking that the next payment go to a new account. The invoice amount is correct and the email looks authentic.
The firm has a written rule: any change to supplier bank details must be verified by phone using the number already on file, and approved by a second person. The office manager calls the supplier’s accounts department, which knows nothing about the change. The supplier’s email account had been compromised. The payment of almost $40,000 is saved by a process that took five minutes.
A one-page cyber checklist
Use this as a starting point, and tick each item only when it is actually done:
- MFA enabled on email, banking, accounting, cloud storage and remote access.
- Automatic updates on for all computers, phones and key applications, with unsupported systems identified for replacement.
- Separate administrator accounts, with administrator access limited to those who need it.
- Backups running, with at least one copy that cannot be altered by an attacker, and a test restore completed in the past three months.
- A written rule that changes to payment details are always verified by phone on a known number, with second-person approval.
- Staff briefed on phishing and how to report suspicious messages within the past six months.
- Business Wi-Fi secured with strong encryption and a separate guest network.
- Production machines and cameras separated from office systems where possible.
- Accounts removed promptly when people leave.
- An incident plan with key contacts stored offline.
Frequently asked questions
Is cyber insurance worth having? It can help cover response costs, recovery and some losses, and insurers often provide incident response support. Read the conditions carefully, because many policies require basic controls such as MFA and backups.
Do we need a full-time IT person? Most small businesses do not, but they do need a reliable IT provider, clear responsibility for security within the business and the basics implemented.
What is the single most important step? There is no single fix, but MFA on email and banking, tested backups and a verification process for payment changes together stop a large share of common attacks against small businesses.
Summary
Every business that uses email, online banking or connected equipment is exposed to cyber risk, and small businesses are frequent targets. The most common threats are phishing, invoice fraud, ransomware, identity theft, spoofing and weak Wi-Fi. Train staff, enable MFA, keep systems updated and licensed, back up and test restores, secure networks, limit access, avoid false economies and write a simple policy. Use the Essential Eight as your framework, give production systems extra protection, and prepare a response plan before you need it.
Sources: small-business training notes on protecting companies from cyber attacks and digital tools, updated with current guidance from the Australian Signals Directorate’s Australian Cyber Security Centre (including the Essential Eight). This article is general information; seek qualified advice for your systems.
