Small Business Cyber Security: Get to Know the Basics

According to government data, a cybercrime is reported every six minutes in Australia. For a small-medium business, the average cost of an attack is $56,600.

Both of these facts point to one difficult truth: cyberattacks are frequent and they have real consequences for your business.

We’re not here to scare you. We’re here to help you feel more prepared. The reality is, cybercrime is not going away – but, there are steps you can take to help protect your business.

This article outlines the basics of cybersecurity for small business owners, including:

• How cybercriminals attack your business
• The main reason they want your business data
• Common cyber threats to be aware of
• And, key cybersecurity steps we recommend

How do cybercriminals access your information?

While there are many different ways that a cybercriminal might try to steal your data, there are two methods that are used most often: phishing and malware.

Phishing

In 2024-25, phishing attacks made up 25% of all cyberattacks reported by Australian businesses. This attack relies on human error as the cybercriminal tries to trick you into sharing access to your systems or specific data.

A simple example is a scam email with a suspicious link. The emails often require urgent action, which puts pressure on you to respond.

The link will send you to a fake login page that captures your details when you submit them. This could be your username and password or even financial details like your saved cards or bank accounts.

Another method is a phone call from a ‘service provider’. The scammer uses social engineering to slowly build your trust. They start by asking simple questions but eventually, begin directing your actions – such as opening an attachment, visiting a website or transferring funds.

Small Business Cyber Security

Malware

Malware is short for malicious software. It’s designed to steal information – such as usernames or passwords, your browsing history, saved or autofill details like credit cards, addresses and phone numbers.

In order to steal your information, malware needs to be installed on a device. While you might think it’s easy to avoid – cybercriminals are very good at hiding malicious code.

It could be planted in the link from an SMS, an email, an online advertisement or even a file that you’ve downloaded.

Why do cybercriminals want your business data?

The main reason that cybercriminals are interested in your data is they can use it for financial gain.

The first option is selling your data on the dark web. It’s likely that your business holds personal data from your employees and customers, like their phone number or email address. These contact details are valuable for scammers who need potential targets for their crimes.

What is the dark web?

The dark web is a hidden part of the internet which is not accessible in a regular browser, such as Chrome, Safari or Firefox. It is encrypted and anonymous which makes it hard to trace activity. Cybercriminals use the dark web for illegal activity, but it can also be used by journalists or activists who need to communicate in secret.

The second option is identity theft. If cybercriminals access your personal ID details (e.g. passport, driver’s license), they can use these to open bank accounts, take out loans or commit crimes in your name. This is one reason that people affected by a data breach are told to replace their identity documents.

A third option is holding your business data to ransom. The cybercriminals might threaten to release your data unless you pay them.

Common cyber threats to be aware of

Cyber threats are constantly evolving, which means it’s not possible for us to list them all. But we can share a few of the typical methods to help increase your cyber awareness.

Small Business Cyber Security 3

Links via SMS or email

Receiving a link via SMS or email is a popular method for cybercriminals to capture your information or spread malware. Whenever you receive a link in an email or text message, the safest action is avoiding clicking and go directly to the service provider’s website instead.

Business email compromise

Cybercriminals are very good at impersonating businesses. A common example is an email requesting a change in bank account details. Their goal is to get you to make a payment to the wrong destination.

Sometimes they are copying the brand or style of legitimate businesses, but other times they have gained access to the real business through a successful hack.

If you receive new instructions from a business you work with, the safest option is to reach out to your main contact to confirm the steps are real.

Unsolicited phone calls

If cybercriminals have your phone number, they might contact you directly. In this situation, social engineering is a big risk. The scammer will try to keep you talking to gain your trust.

If you receive any unexpected phone calls from a service provider, the safest action is to hang up. You can always call them back on a phone number listed on their official website.

Seasonal scams

Certain times of year come with increased risk of scamming and cyber threats. For example; Christmas, EOFY and tax time. Cybercriminals know you are busy and might be more likely to interact with their communications.

At these times of year, pay extra attention to where the communication is coming from. Is it a legitimate source that you can trust?

Some companies are targets for scamming all year; such as package deliveries (Australia Post, FedEx), government services (ATO, Centrelink, MyGov), finance providers (PayPal, banks), and large retailers (Amazon).

When dealing with large or popular services like these, it’s a good idea to slow down and double check the communications. Scammers will often use a sense of urgency to push you to act. Taking your time can help you spot the inconsistencies that show it’s a scam.

Key steps to protect your business

When it comes to cybersecurity, prevention is better than cure. Here are 5 steps we recommend to build up your business’ defences and how GravIT can help you implement them.

Small Business Cyber Security 4
1. Use Multi-Factor Authentication (MFA)

It might seem annoying each time your login asks you for an extra code, but it’s one of the most effective steps to prevent unauthorised access to your systems. We always recommend turning on MFA in settings. Our team can also help with complex MFA setups, such as multiple accounts or users.

2. Update software regularly

Software updates typically contain patches for security vulnerabilities which makes them a simple, but powerful step to protect your systems. Best practice is using auto-updates to ensure they are installed as soon as they’re available. If you’d like support, we manage updates as part of our Service and Maintenance contracts.

3. Replace old technology

Using legacy technology is like leaving a door unlocked for cybercriminals. Upgrading all your old technology is a good way to lock that door.

A recent example was the end of Windows 10 support by Microsoft. While you can still use this operating system, it no longer receives security or performance updates.

Our team can help assess your technology setup to identify gaps or vulnerabilities. We’ll also recommend new software or hardware to improve your business operations and security.
4. Follow the Essential Eight

The Essential Eight are a set of basic cybersecurity steps recommended by the Australian Government. They’re an important starting point for every business.

Sometimes, the language used for cybersecurity is technical. If you’re unsure, it can help to work with an IT partner like us. We can help you implement each of the steps and understand why they matter.

5. Advanced protection from your IT partner

Many of the strongest cybersecurity steps require an in-depth knowledge of technology. This is where partnering with trusted IT experts can help.

At GravIT, we combine basic and advanced security techniques to provide complete protection to your business. Examples of advanced steps include:

• 24/7 threat monitoring
• Firewalls, malware and ransomware protection
• Regular data backups
• Patching system vulnerabilities
• And more

Building layers of protection for your business

Cybersecurity isn’t just one step – it’s a layered approach. We know it can feel overwhelming at times, which is why we want to assure you that we’re on your team.

GravIT help businesses in Geelong and surrounds take proactive steps that prevent security breaches. Call us on 03 5280 8088 to discuss small business cybersecurity.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *