Do I actually need cyber security?
It's one of the most common things we hear: 'We're too small to be a target.' The reality is the opposite. Small businesses are targeted precisely because they're less likely to have decent security in place. You don't need to be a bank to get hit. You just need to have email, a bank account, and staff who click things.
Last updated
The short answer
Yes. Every business that uses email, stores customer data, or takes payments needs some level of cyber security. You don't need to spend a fortune or turn your office into a fortress, but doing nothing is genuinely risky. The average cost of a cyber incident for an Australian small business runs into tens of thousands of dollars, and that's before you count the downtime, lost trust, and stress.
What to consider
You're a target by default
Most attacks aren't targeted at specific businesses. They're automated scans and phishing campaigns that hit thousands of companies at once, looking for anyone without basic protection.
Email is the front door
The vast majority of business compromises start with a phishing email. One click from one staff member can give an attacker access to your entire system.
Ransomware doesn't discriminate
Ransomware gangs encrypt your files and demand payment. They don't check your revenue first, and a small business without backups has very few options.
Your obligations are real
Under Australia's Privacy Act and the Notifiable Data Breaches scheme, businesses that hold personal information have legal obligations if that data is compromised.
Insurance is changing
Cyber insurers are increasingly requiring evidence of basic security controls before they'll offer cover. If you don't have MFA, you may not get a policy.
The basics go a long way
You don't need military-grade security. MFA, email filtering, patching, decent passwords, and proper backups stop the vast majority of attacks.
Who this guide is for
- Business owners who think they're too small to worry about cyber security.
- Anyone who's been putting off dealing with security because it seems too complicated or expensive.
- Businesses that hold customer data, process payments, or use email (so basically everyone).
- Owners who've seen a competitor or contact get hit and are wondering if they're next.
What to do next
- Turn on multi-factor authentication. This single step stops the majority of account takeovers. Do it on email, banking, and anything important.
- Make sure your email has filtering. Microsoft 365 and Google Workspace both have built-in phishing protection, so check it's turned on and configured properly.
- Check your backups. Confirm what's being backed up, how often, and whether it's been tested. Backups are your last line of defence against ransomware.
- Keep your software updated. Patches fix known security holes. Delaying updates is like leaving a window open with a sign saying 'come in'.
- Get a security check. We can do a quick review of your setup and tell you where the gaps are. We'll give you an honest picture without the scare tactics.
How WaTo can help
- We do practical security assessments for small businesses. You get clear actions you can take, not a 200-page report.
- We set up MFA, email security, and endpoint protection without making your team's life harder.
- We align your security with the Essential Eight framework so you've got a recognised baseline.
- We monitor for threats and respond fast if something does get through.
- We explain everything in plain English and only recommend what you actually need, without scare tactics or upselling.
Related questions
How much does basic cyber security cost for a small business?
For a business with 5 to 20 staff, getting the basics right (MFA, email filtering, endpoint protection, backups and patching) typically costs between $50 and $150 per user per month as part of a managed IT plan. That's a fraction of what a single incident would cost.
Can't we just use antivirus?
Antivirus is one piece of the puzzle, but it doesn't cover phishing, weak passwords, unpatched software, or missing backups. Modern security needs layers, and antivirus alone hasn't been enough for years.
What happens if we get breached and we didn't have security?
Beyond the direct costs of recovery, you may have legal obligations to notify affected individuals and the OAIC under the Notifiable Data Breaches scheme. There can also be reputational damage and potential liability if you didn't take reasonable steps to protect data.
We've been fine so far. Doesn't that mean we're okay?
Not being attacked yet isn't the same as being secure. Many businesses don't know they've been compromised until weeks or months later, and automated attacks hit new targets every day. It's not a matter of if, but when.
Still not sure?
If you're not confident about your security but don't know where to start, get in touch. We'll have an honest chat about what you actually need and give you practical advice in plain language, without the fear-mongering.
Mon to Fri, 8:30am to 5pm
