The bad day that actually hits most small businesses isn't a headline-style cyberattack — it's an ordinary Tuesday where an account gets locked, a folder gets deleted, or an inbox quietly gets taken over before anyone notices. None of these need a sophisticated attacker. A reused password, a convincing phishing link, or a moment of misclicking is usually all it takes.
What the day actually looks like
It rarely announces itself. A staff member can't log in and assumes it's a glitch. A client folder that took months to build is suddenly empty. An email thread with a supplier goes quiet because it was never actually delivered — it was intercepted, read and redirected somewhere else first. By the time anyone realises what's happened, the immediate question isn't "how do we stop this" — it's "can we get it back."
Three ordinary versions of this show up again and again:
- The locked-out account. A phishing email asks someone to "verify" their account. They click, type in their password, and within minutes the account belongs to someone else — or the business owner, trying to be careful, locks it themselves and then can't remember how to get back in without help.
- The vanished folder. A staff member tidying up their inbox deletes the wrong folder, or a well-meaning "spring clean" wipes months of client correspondence nobody thought to check first. Nobody notices until someone goes looking for an old invoice or a signed quote.
- The quiet redirect. This is the one with the highest financial stakes: someone sits inside a compromised inbox, learns the business's normal rhythm — who invoices whom, how much, and when — then sends a bank-detail change or a fake invoice from the real address at exactly the right moment. Nothing looks wrong until the money's gone.
It doesn't have to involve an attacker at all
Not every bad day involves a criminal. Ordinary business change causes just as many of these moments — a staff member leaves and their account is deleted before anyone copies out what was in it, an admin login gets handed over without a proper handover, or a "let's tidy up the mailbox" afternoon turns into an accidental mass-delete. None of this requires anyone to be careless in an obvious way — it's simply what happens when several people share access to the same inboxes and folders over a period of years, and nobody is specifically responsible for what happens if something goes missing.
That matters because it changes who needs to think about recovery. It isn't just businesses worried about being deliberately targeted — it's any business that has ever had staff come and go, done a bulk mailbox cleanup, or trusted more than one person with a shared inbox. That covers almost every business your size.
What it costs, in real terms
Small businesses that reported a cybercrime incident in FY2024–25 lost an average of $56,600, up 14% on the year before (ACSC Annual Cyber Threat Report 2024–25). That figure is the headline number, but it's really several smaller costs added together:
- The direct loss — money paid to a fraudulent invoice or redirected account, or the cost of specialist help to contain and clean up the incident.
- The hours nobody budgeted for — working out what happened, checking what was accessed, contacting anyone whose information might have been exposed, and doing all of that instead of running the business that week.
- The awkward conversations — telling a client their invoice was intercepted, or that an email "from you" wasn't actually from you, tends to cost more in trust than the incident cost in dollars.
- The part that's hard to put a number on — the time it takes to feel confident in the inbox again, and the extra double-checking that becomes a habit afterwards.
None of that is included in the $56,600 average. It's simply the most measurable part of a much longer list.
Why "it's in the cloud" isn't the same as "it's backed up"
A lot of the surprise on a bad day comes from an assumption that turns out not to be true: that because email lives in Microsoft's cloud, it's automatically protected against being lost for good. Deleted items sit in a recovery folder for a limited window before they're gone, and that window is shorter than most people expect. Something similar applies if a subscription itself lapses — Microsoft's own documentation describes an expired subscription moving through an "Expired" stage (roughly 30 days, with access still working normally), then "Disabled" (roughly 90 days, admin-only access), before data is permanently deleted, and if a subscription is cancelled outright rather than left to lapse, some data can be removed immediately (Microsoft: what happens to my data and access when my subscription ends).
None of that is a flaw in Microsoft 365 — it isn't designed to be a backup service, and it's upfront about that in its own documentation. But it does mean the safety net most people assume is there by default is considerably smaller than "the cloud will remember it for me."
Why recovery matters as much as prevention
Most small business owners think about email security as a wall: something to stop the bad day from happening. That matters, but it's only half the picture. The other half is what happens after — whether a deleted folder, a wiped account or a locked-out mailbox can actually be put back the way it was, quickly, without it becoming a drawn-out process. A business that's hard to break into but impossible to recover from is still one bad day away from a very bad month.
What separates a stressful afternoon from a genuinely bad month usually comes down to three things decided long before the bad day happens: whether an independent copy of the mailbox exists somewhere Microsoft's own default settings can't touch it, whether someone actually knows how to act on that copy without waiting in a support queue, and whether that person can be reached quickly. None of those three things can be arranged after the fact — by definition, they're either already in place or they aren't.
Which of these is most likely for a business your size
The exact version of a bad day tends to match how a business actually uses email. A small, family-run operation with one or two shared inboxes is more exposed to the vanished folder, simply because fewer people check each other's work, so a mistake sits unnoticed for longer. A trade or field-based business running email mostly from a phone is a common target for the quiet redirect, since a fake invoice sent from a real, trusted address is hard to catch on a small screen between jobs. A business that has changed email providers or staff over several years tends to be the one facing the locked-out account, because nobody currently there fully remembers how the original settings were configured.
None of these scenarios require a business to be a particular size or a specific target. They're simply a function of how ordinary, everyday email use works over time — which is exactly why "we're too small for this to happen to us" doesn't hold up as a reason to skip thinking about it.
Common questions
What's the most likely way a small business actually loses access to its email? Not a dramatic outage — usually something ordinary: an account locked out after a phishing click, a folder or thread deleted by mistake, or a compromised account used to send fraudulent messages before anyone notices.
Does a bad day have to involve a cyberattack? No. Staff turnover, a bulk mailbox cleanup, or an admin account handed over without a proper handover cause just as many of these moments as a deliberate attack does. Anyone who has ever shared an inbox with more than one person is exposed to this kind of ordinary mistake, not just to criminals.
How much does a bad cyber incident typically cost an Australian small business? Small businesses that reported a cybercrime incident in FY2024–25 lost an average of $56,600, up 14% on the year before, according to the ACSC's Annual Cyber Threat Report — and that figure doesn't include the staff hours, client conversations and lost time that usually come with it.
Is losing email data actually recoverable? It depends entirely on what's in place before it happens. Deleted items and lapsed subscriptions both move through limited recovery windows by default, so whether something can be recovered — and how much of a scramble that recovery is — usually comes down to whether an independent backup already existed beforehand.
What matters more: preventing a bad day, or being able to recover from one? Both, but recovery is the part businesses most often skip. Prevention reduces how often something goes wrong; recovery determines how bad it is when something inevitably does.
Where to next
The next question worth answering is exactly what happens when you need to get something back — how email backup actually recovers a deleted folder or a lost thread, and what Microsoft does and doesn't do for you by default.