Risk management
Cyber Risks for Australian Small and Medium Businesses
Email fraud, ransomware and data breaches can affect businesses of any size. Here is a practical look at the risks and the steps that can reduce them.
By Tasman Insurance Group4 min read

Most businesses now rely on email, cloud software, online banking and stored customer information. That reliance brings real benefits, but it also means a cyber incident can disrupt trading and expose personal information.
Small and medium businesses can be attractive targets because their defences are often simpler. The good news is that many of the most useful protections are within reach of a small team.
Common cyber risks for smaller businesses
Email compromise and payment fraud
Criminals may gain access to an email account, or impersonate a supplier, and send fake invoices or requests to change bank details. Payments can be sent to the wrong account before anyone notices. These schemes often rely on urgency and familiar-looking messages.
Ransomware
Ransomware encrypts files or systems and demands payment to restore them. Even where data can be recovered from backups, the business may be offline for some time while systems are cleaned and restored.
Data breaches
A breach can occur through hacking, a lost device, a misdirected email or a misconfigured system. If personal information is involved, there may be legal obligations to assess and respond to the breach.
Phishing and stolen passwords
Phishing messages try to trick people into clicking a link or entering login details. Reused or weak passwords make it easier for attackers to move from one account to another.
Problems with suppliers
Many businesses depend on outside providers for software, payments and data storage. An outage or breach at one of those providers can affect your operations even when your own systems are secure. Knowing which providers you rely on, and what they hold, makes it easier to respond.
Your obligations if personal information is breached
Under the Notifiable Data Breaches scheme, organisations covered by the Privacy Act must notify affected individuals and the Office of the Australian Information Commissioner of an eligible data breach. In general terms, that is a breach likely to result in serious harm to the people whose information is involved.
Not every small business is covered by the Privacy Act, as there are thresholds and exceptions. Whether your business is covered depends on factors such as turnover and the kind of activities you carry out, so it is worth checking with an appropriate adviser.
Practical steps to reduce your risk
The Australian Cyber Security Centre (ACSC) publishes free guidance for businesses. This includes the Essential Eight, a set of mitigation strategies designed to make systems harder to compromise. Many of the basics are achievable for a small business.
- Turn on multi-factor authentication for email, banking and key software
- Keep operating systems and applications patched and up to date
- Make regular backups, keep a copy stored separately and test that you can restore them
- Limit administrator access to the people who genuinely need it
- Verify any change to supplier bank details by phone, using a number you already hold
- Train staff to recognise phishing and to report anything suspicious quickly
A simple written incident response plan also helps. It should set out who to call first and how to isolate affected systems, so people are not working it out under pressure.
Keep the plan somewhere you can reach it if your main systems are down, such as a printed copy. Review it when staff or key providers change.
How cyber insurance may help
Cyber insurance is designed to help businesses respond to and recover from cyber incidents. Depending on the policy, cover may include:
- Incident response support, such as IT forensic specialists and legal advice
- Costs of restoring data and systems
- Business interruption losses following a covered event
- Costs of notifying affected individuals
- Liability claims from third parties whose data was affected
Cover for social engineering or payment fraud is not always included as standard and may be subject to a lower sub-limit. Policies also commonly include conditions about security measures, such as multi-factor authentication and backups, so understanding those requirements matters.
Cyber wordings differ considerably, and what is included in one may be excluded in another. Tasman Insurance Group can help you understand how a cyber policy may fit with your existing cover and the controls insurers commonly expect businesses to have in place.
This article is general information only and does not take into account your objectives, financial situation or needs. Before making a decision about insurance, read the relevant Product Disclosure Statement and policy wording, and speak with a licensed adviser about your circumstances.


