Risk Management

Cost of a Cyber Attack on Australian Small Business

HB
HMC Bot
7 min read

The Numbers Are Getting Worse

The Australian Signals Directorate’s Annual Cyber Threat Report 2023–2024 paints a stark picture: the average cost of cybercrime for a small business in Australia is approximately $46,000 per incident. For medium-sized businesses, that figure climbs to around $97,200. And these are just the reported cases — many incidents go unreported because businesses fear reputational damage or simply do not realise the full extent of the breach.

More than 87,400 cybercrime reports were lodged with the ACSC in the 2023–24 financial year, up nearly 7% year-on-year. Cyber attacks are not slowing down, and the costs are not shrinking. Understanding exactly where the money goes can help you justify the relatively modest investment in prevention.

Direct Costs: The Immediate Financial Hit

Ransom Payments

Ransomware remains one of the most damaging attack types for Australian SMEs. While the ACSC advises against paying ransoms, many businesses feel they have no choice when their data is encrypted and backups are inadequate. The average ransom demand for small businesses in Australia ranges from $10,000 to $50,000 — but paying does not guarantee you will get your data back. Around 20% of organisations that pay never receive a working decryption key.

For guidance on defending against ransomware before it strikes, see our ransomware protection guide.

Incident Response and Forensics

After an attack, you need to understand what happened, how the attacker got in, what data was accessed, and whether they are still in your network. Engaging a cyber security incident response firm typically costs between $5,000 and $25,000 for a small business, depending on the complexity of the breach.

System Recovery and Rebuilding

Restoring systems from backups (if they exist and are clean), rebuilding compromised servers, replacing hardware and reconfiguring software can easily cost $5,000 to $20,000 in labour and licensing. If your backups were also compromised, costs escalate dramatically.

Legal and Compliance Costs

If personal information was accessed, you may need legal advice on your notification obligations under the Notifiable Data Breaches (NDB) scheme. Legal fees for breach assessment and notification typically run $3,000 to $15,000.

Indirect Costs: The Slow Bleed

Direct costs are often just the tip of the iceberg. The indirect costs of a cyber attack can far exceed the immediate financial outlay and persist for months or even years.

Business Downtime

For many small businesses, the most damaging cost is lost productivity. The average downtime from a ransomware attack in Australia is 16 days, according to industry reports. If your business generates $5,000 per day in revenue, that is $80,000 in lost income — before you spend a cent on recovery.

Reputational Damage and Customer Loss

Trust is hard to build and easy to destroy. Studies consistently show that 60–70% of consumers would consider switching providers after a data breach. For a small business that relies on repeat customers and word-of-mouth referrals, the reputational damage can be existential.

Lost Contracts and Tender Opportunities

Larger organisations increasingly require suppliers to demonstrate cyber security maturity. A breach on your record can disqualify you from tenders and partnership opportunities for years.

Staff Time and Morale

Your team will spend weeks dealing with the aftermath instead of doing productive work. The stress and disruption can also lead to increased staff turnover, adding recruitment costs on top of everything else.

Regulatory Costs: Fines and Enforcement

The regulatory landscape in Australia has tightened considerably in recent years.

Privacy Act Penalties

Following amendments to the Privacy Act 1988 in late 2022, maximum penalties for serious or repeated privacy breaches increased substantially:

  • Individuals: up to $2.5 million
  • Bodies corporate: up to $50 million, or three times the value of the benefit obtained from the breach, or 30% of adjusted domestic turnover — whichever is greatest

While maximum penalties are reserved for egregious cases, even an OAIC investigation is costly and disruptive. Demonstrating that you had reasonable security measures in place is a significant mitigating factor.

Mandatory Ransomware Reporting

Australia’s Cyber Security Act 2024 introduced mandatory ransomware reporting obligations for businesses with turnover above $3 million. Failure to report a ransom payment within the required timeframe can attract additional penalties.

Industry-Specific Requirements

If you operate in healthcare, financial services, or government contracting, additional regulatory frameworks may apply, each with their own penalty regimes.

Quantifying risk and demonstrating governance is exactly what the Assurance pillar of the IDIA framework addresses. IDIA organises every cybersecurity control into four pillars — Identity, Data, Infrastructure and Assurance — with Assurance covering risk management, compliance tracking and continuous improvement. When regulators or insurers ask what your business has done to manage cyber risk, an IDIA-aligned posture gives you a structured, documented answer that maps to ISO 27001, NIST CSF, the Essential Eight and SMB1001.

What Does Prevention Actually Cost?

Compared to the cost of a breach, prevention is remarkably affordable for most SMEs:

Control Typical Annual Cost
Password manager (team) $100–$500
MFA (authenticator app) Free
Cloud backup solution $300–$1,500
Endpoint protection $200–$1,000
Staff awareness training $500–$2,000
Email authentication (SPF/DKIM/DMARC) Free (DNS config)
Cyber insurance $1,000–$5,000

For an annual investment of roughly $2,000 to $10,000, most small businesses can dramatically reduce their risk. Compare that to a single incident costing $46,000 or more — the maths is clear.

A Real-World Scenario

A 12-person accounting firm in regional NSW received a phishing email that appeared to come from the ATO. One staff member clicked the link and entered their Microsoft 365 credentials. The attackers gained access to the firm’s email, intercepted client invoices and redirected payments to fraudulent accounts. Total losses exceeded $120,000 across the firm and its clients. The firm spent an additional $35,000 on forensics, legal advice and system hardening. Two major clients left within six months.

This scenario is not hypothetical — it mirrors dozens of real cases reported to the ACSC each year. Having a documented incident response plan could have reduced the damage significantly.

Know Your Risk Before It Costs You

The first step to avoiding these costs is understanding where your vulnerabilities lie. Platforms like How’s My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard. Start with the free CYBER9 assessment to benchmark your business across nine critical security domains in under 10 minutes. You will get a clear, jargon-free view of your current posture, the highest-risk gaps and a prioritised action plan — before a breach does the benchmarking for you.

Share

How secure is your business?

Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.

Try CYBER9 Free