The $56,600 question: what a cyber incident really costs a small Australian business
The ASD puts the average cybercrime cost for a small Australian business at $56,600 — up 14%. Where the money goes, and the affordable controls that change the maths.
The Australian Signals Directorate's latest figures put the average cost of cybercrime for a small business at $56,600 — up 14% in a year. Here's where that money actually goes, and the cheap controls that change the maths.
Cyber risk conversations usually stall on vague fear. Numbers work better. The ASD's most recent annual threat report lands on an average of $56,600 per cybercrime report for small Australian businesses — and averages hide the ugly tail: a business email compromise that redirects one large settlement, or a week of ransomware downtime, can multiply that several times over.
Where does $56,600 actually go?
The cost of a cyber incident spreads across five buckets, and the direct theft is often the smallest:
Downtime.
Staff paid to not work while systems are down — for a 15-person firm, every day offline is thousands in wages producing nothing, before a dollar of lost revenue.
Recovery.
Emergency IT help, rebuilt machines, restored data, after-hours rates. Unplanned work is always the most expensive kind.
Direct loss.
The redirected payment, the fraudulent invoice, the drained account — money that rarely comes back.
Obligations.
If personal information was involved, notification under the Privacy Act, legal advice, and potentially reporting duties. None of it is free.
The slow costs.
A client who quietly moves on, an insurance premium that jumps at renewal, a tender question you now have to answer awkwardly.
Why small businesses wear more of the pain
A large company absorbs a $56,600 hit as a bad quarter for one department. For a small business it can be the year's profit — and unlike big companies, small firms rarely have in-house security staff, incident response retainers or war-chest reserves. That asymmetry is exactly why attackers aim at the small end of town: thinner defences, faster payouts, and owners under enough pressure to pay. The "too small to be a target" myth gets more expensive every year.
The controls that change the maths
The encouraging part: the attacks behind most of these losses are stopped by a short list of controls that cost a fraction of one incident:
Multi-factor authentication
shuts down the stolen-password attacks behind most email compromise.
Patching that actually happens
closes the known holes automated attacks scan for.
Tested, tamper-proof backups
turns ransomware from an existential threat into a bad day.
Endpoint detection and response
catches the intrusion while it is one machine, not the network.
A payment-verification habit
one phone call before changing any supplier's bank details.
That list maps directly onto the Essential Eight — the Australian government's baseline — which is why we build every client on it. Compare the monthly cost of doing those five things properly against $56,600, and the business case writes itself.
Frequently asked questions
Is $56,600 the worst case?
No — it is the average. Business email compromise incidents routinely run into six figures when a large payment is redirected, and extended ransomware downtime costs more still. The tail is long and expensive.
Doesn't cyber insurance cover all this?
Good policies cover a meaningful slice — if your controls matched what you attested to. Insurers now verify MFA, backups and EDR before paying. Insurance is the backstop, not the plan; see our guide to what insurers check at renewal.
What should a small business spend on security?
Enough to cover the short list above, done properly — for most small businesses that is a modest, predictable monthly amount inside a managed IT plan, not a big capital project. The right comparison is against the cost of one incident.
What's the single first thing to fix?
MFA on email, today. It is free-to-cheap, takes an afternoon, and removes the entry point behind the most common and most expensive attack on small businesses.
Related Key IT services
More insights
'Too small to be a target' myth
Why small businesses are now prime cyber targets, the data behind it, and what affordable…
Read article →RansomwareRansomware hits Australian construction
An Australian construction consultancy was listed by a ransomware crew this month. Why project…
Read article →Windows 10Windows 10 ESU: free vs paid
Consumer Windows 10 security updates now run to 2027 — but business terms are unchanged. What's…
Read article →Book your free IT & Cyber Security Review
See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.