"We're too small for anyone to bother with" is the reason most often given for putting off business email protection — and it doesn't hold up. Most attacks on small businesses aren't aimed at them by name. They're automated: scans and mass phishing runs that catch whoever's exposed, then a real person takes over once they're in. October is Cyber Security Awareness Month in Australia (cyber.gov.au), which makes now as good a time as any to check where things actually stand.

How it actually happens

It rarely starts with a dramatic break-in. The pattern showing up most often in Australian cybercrime reports is business email compromise: a criminal gets into one inbox — through a reused password, a convincing phishing link, or a weak sign-in — then quietly watches. They learn who invoices whom, how the business writes its emails, and when a payment is usually due. At the right moment, they send a fake invoice or "updated bank details" from the real inbox, because by then it is the real inbox. Business email compromise fraud resulting in financial loss was the second most-reported cybercrime type among Australian businesses last year, behind online scams generally (ACSC Annual Cyber Threat Report 2024–25).

Why "too small" isn't a defence

Automated tools don't check how many staff a business has before trying a leaked password against its inbox, or before a phishing email goes out to ten thousand addresses at once. Being small doesn't make a business invisible — it usually just means fewer people watching for the warning signs, and less time to catch something before money has already moved. Small businesses that reported a cybercrime incident in FY2024–25 lost an average of $56,600, up 14% on the year before (ACSC).

What actually helps

None of this requires becoming a security expert. The things that make the biggest difference are ordinary, and mostly set-and-forget:

  • Turning on multi-factor authentication (a second check, like a one-time code on your phone, alongside your password) so a leaked password alone isn't enough to get in
  • Setting up alerts for unusual sign-ins or mailbox rule changes — a common trick once someone's already inside
  • Keeping a backup of email and files that's separate from the mailbox itself, so a compromised account isn't also your only copy of anything
  • Having a real person to call if something looks off, rather than working it out alone

Common questions

Are small businesses actually targeted by cybercriminals, or is it mostly large companies? Small businesses are hit constantly — usually not by name, but through automated attacks that scan for exposed or weakly protected inboxes and catch whoever's there. Being small doesn't make a business invisible to these tools.

What's the most common way a small business email account gets compromised? Business email compromise is the leading pattern: a criminal gets into one inbox, studies how the business communicates, then sends a fake invoice or bank-detail change from that real, trusted address.

How much does a cyber incident typically cost an Australian small business? Small businesses that reported a cybercrime incident in FY2024–25 lost an average of $56,600, up 14% on the year before, according to the ACSC's Annual Cyber Threat Report.

What's the single most useful step a small business can take to reduce the risk? Turning on multi-factor authentication is the highest-impact step, since it stops a leaked or guessed password alone from being enough to get into an account.

Where to next

A lot of business owners assume Microsoft already covers all of this by default. The honest answer is more nuanced than yes or no — and that's worth unpacking properly next.