Cybersecurity Expert Warns of Major Weaknesses in Australian Small Businesses

A recent study by a cybersecurity firm reveals that a typical cyber attack on small businesses in Australia can cost at least $50,000.

As the government enforces stricter penalties for inadequate security measures, a large portion of Australian small-to-medium enterprises (SMEs) still struggle with inadequate digital defenses.

ViCyber, a Sydney-based firm specializing in AI-driven cybersecurity assessments, frequently uncovers significant security gaps in these businesses, according to co-founder Aastha Gupta.

“It’s essential for businesses to strengthen their defenses because the security of our consumers depends on it,” Dr. Gupta emphasized.

Government data shows that about half of Australian businesses with fewer than 200 employees rely on do-it-yourself cybersecurity measures, spending under $500 annually.

Shockingly, a quarter of SMEs still operate on outdated systems like Windows 7, leaving them vulnerable to attacks.

“You’d be amazed at how exposed some businesses are,” Dr. Gupta noted, citing pharmacies and accounting firms as examples of clients still using obsolete software.

The three most common cybersecurity threats faced by Australian SMEs include misconfigurations in IT systems, privacy issues due to poor data management, and cyber extortion, such as ransomware attacks.

“Manufacturers are particularly vulnerable as competitors seek access to critical business information,” Dr. Gupta explained.

She also highlighted how attackers exploit platforms like Office365 by sending out fraudulent invoices.

ViCyber’s research indicates that the average financial loss from a cyber incident for Australian small businesses is around $50,000 per incident, with potential losses ranging from $25,000 to $200,000 depending on the business size and nature of the attack.

Pharmacies, which often change ownership, are especially at risk, with patient records and personal information frequently being overlooked. Hackers see this data as valuable and often use it for extortion following a ransomware attack.

“The regulatory landscape is changing, with new standards on the horizon, but the threat of fines alone won’t improve security,” Dr. Gupta warned. “SMEs in Australia need affordable and straightforward solutions.”

ViCyber offers affordable compliance checks for small businesses without significant IT budgets, helping them adhere to the new regulations.

Although a proposed government ban on ransom payments has been postponed, businesses still face new costs and regulations in the wake of high-profile breaches like those at Optus and Medibank.

Amendments to the Privacy Act in 2022 introduced fines ranging from $15,000 to $2.1 million for small businesses that experience significant or repeated data breaches.

For larger corporations, fines start at $2.2 million and can reach the higher of $50 million, three times the benefit gained by the attackers, or 30% of the company’s adjusted turnover.

While some small business owners have criticized the new penalties, the potential damage to their reputation and business continuity could far exceed these fines.

In a related case, the financial impact of Medibank’s 2022 data breach could be massive. The Office of the Australian Information Commissioner has filed Federal Court proceedings, alleging multiple violations of the Privacy Act for each of Medibank’s 9.7 million customers, as reported by the Australian Financial Review.

Medibank plans to contest the case, but with potential fines of $2.2 million per customer, an unfavorable ruling could result in a staggering $21.5 trillion penalty.

More Articles & Posts