Small Business Cyber Posture in One Page
Australia recorded 1,205 notifiable breaches in 2025 and the average self-reported cost to a small business is $56,600. Here is the one page a small business owner actually needs, and the four things on it that matter.
Most cyber security advice aimed at small business is either a product pitch or a forty-page framework written for an organisation with a security team.
This is the one page. Four things, two numbers, and the questions that make it concrete.
The two numbers, and where they come from
Two figures get quoted at Australian small businesses constantly. Both are real, both are routinely misused, and neither is ours to take apart here — Cloud Geeks has done each of them properly:
- 1,205 notifiable data breaches were reported in Australia in 2025, 59% of them attributed to attacks rather than to error. What those figures support, and the three conclusions they do not, are in 1,205 Breaches, and the 59% That Were Attacks.
- $56,600 is the average self-reported cost of cybercrime to a small business. Where that money actually goes, and which parts of it you can remove before anything happens, are in What a $56,600 Breach Actually Buys You.
The one caution worth repeating here, because the rest of this page depends on it: if your turnover is under $3 million you are largely outside the Privacy Act, so you are not counted in the 1,205 — which is not the same as not being affected.
What follows does not depend on either figure.
The four things
1. Multi-factor authentication, on email first.
Reported breaches attributed to attack are overwhelmingly reached through accounts rather than through sophisticated exploits. Email is the first target because it is the reset path for everything else — whoever controls the mailbox controls the bank, the domain and the accounting package.
Turn it on for email, then for anything holding customer data. It is free on every major platform and it is the single highest-return control available.
2. A backup you have actually restored.
Not “backups run”. A restore, performed, timed, and confirmed to produce working data.
The difference matters because backup failures are silent. A backup job that has been writing an empty archive nightly for eight months reports success every night. You find out at the only moment you cannot afford to.
Restoring once tells you two things you otherwise do not know: whether it works, and how long your outage would be.
3. A written list of where personal information lives.
Which systems hold data about your customers, staff or patients, roughly what kind, and who can reach each one.
This is the least glamorous item and the one that saves the most time in an incident. If a breach is suspected, you have 30 days to assess whether it is notifiable — and the clock starts when you first have grounds to suspect, not when you confirm. An assessment that begins with “where would that even be?” has already spent days it did not have.
4. One name, written down, for who you ring.
A breach at 4pm on a Friday is a decision-making problem before it is a technical one. The failure mode is three hours of people deciding whether this is serious enough to escalate.
One name. Everybody knows it. Their job on day one is to write down the date, the time and what was reported — which later turns out to be the only evidence of when the clock started.
★ Insight ─────────────────────────────────────
Three of those four are records rather than technology, and that is not an accident. The expensive parts of an incident are downtime and working out what happened, and both are determined before anything goes wrong — by whether a restore has been rehearsed and whether anyone can say what data exists and where. The security products address the chance of an incident; the records address the cost of one, and the cost is the part you can control with an afternoon.
─────────────────────────────────────────────────
What changed this year that you may have missed
The small business exemption from the Privacy Act still exists — under $3 million turnover, generally not covered.
But from 1 July 2026, the Act applies to entities that became reporting entities under the second tranche of the anti-money-laundering regime, regardless of turnover. That brings in real estate agents, conveyancers, accountants, lawyers, and trust and company service providers.
If you are in one of those, “we are too small for the Privacy Act” is no longer correct for that work, and the breach notification obligations come with it. The change arrived through money-laundering legislation, so a practice watching for privacy amendments would not have seen it.
The five-minute version
Answer these. If any answer is uncomfortable, that is your next task.
- Is multi-factor authentication on your email? Not “available” — on.
- When did you last restore a backup? If the answer describes backups running, it is not an answer to this question.
- Can you name every system holding data about your customers? Write the list now and see how long it takes.
- Who do you ring, and is their number somewhere other than in your email?
- Does the notification scheme apply to you? Check rather than assume, particularly if you are in one of the professions above.
What this is not
It is not a security programme, and it will not satisfy an auditor or an insurer’s questionnaire.
It is the floor. The gap between a business with these four things and one without them is most of the difference in what an incident costs — and it is achievable in an afternoon, which is the only reason it gets done at all.
Sources: OAIC notifiable data breach statistics for 2025 and the ASD Annual Cyber Threat Report 2024-25. General information, not legal advice.
Ganda Tech Services runs technology for Australian businesses. Security, backup and email work is handled through Cloud Geeks; websites through Cosmos Web Tech.