Cyber Security Awareness Month: How to Protect Your Business
As businesses move more of their operations online, cyber security is no longer just an IT issue. It is a financial and operational risk that every business needs to manage.
During the 2024–25 financial year, the Australian Signals Directorate’s Australian Cyber Security Centre received more than 84,700 cybercrime reports through ReportCyber – an average of one every six minutes. The ASD also notes that the vast majority of cybercrime is likely to go unreported.
While the number of reports decreased slightly from the previous year, the average self-reported cost to Australian businesses increased by 50 per cent to $80,850 per report. The average cost was $56,600 for small businesses and $97,200 for medium businesses.
Source: ASD Annual Cyber Threat Report 2024–25
How can cybercrime affect a business?
Cybercriminals often look for weaknesses in email accounts, software, networks, payment processes and employee security practices.
A cyber incident does not need to involve sophisticated hacking. It can begin with an employee clicking a fraudulent link, using a compromised password, paying an altered invoice or losing a business device.
Common cyber risks include:
- Business email compromise
- Invoice and funds transfer fraud
- Phishing emails and messages
- Ransomware and malware
- Identity theft
- Theft of confidential business information
- Customer and employee data breaches
- Unauthorised access to business systems
- Encryption or loss of critical data
- Disruption to websites, networks and operations
Businesses that operate predominantly offline can still be exposed through email, accounting software, point-of-sale systems, mobile devices and online banking.
Practical ways to protect your business
Cyber insurance can help manage the financial impact of an incident, but it does not replace strong security practices.
The Australian Cyber Security Centre recommends several practical measures businesses can take.
Use multi-factor authentication
Multi-factor authentication adds another verification step when someone signs in to an account. It should be enabled for email, banking, accounting software, cloud storage and other important business systems.
Keep software and devices updated
Software updates often include fixes for known security weaknesses. Enable automatic updates where possible and replace technology that is no longer supported by its provider.
Use strong, unique passphrases
Avoid reusing passwords across different systems. Use a strong, unique passphrase for each account and consider using a reputable password manager.
Back up important information
Regularly back up critical business data and keep at least one backup separate from your main network. Test your backups to make sure information can be restored when needed.
Train your employees
Employees should know how to recognise suspicious emails, payment requests, login pages and file attachments. Create a clear process for reporting anything unusual.
Verify changes to payment details
Changes to supplier bank details should always be confirmed through a trusted contact method. Do not rely only on the phone number or contact information included in the email requesting the change.
Prepare an incident response plan
Document who needs to be contacted, how affected systems will be isolated and how the business will continue operating following an incident.
The Australian Cyber Security Centre’s Small Business Hub provides free guidance and resources for Australian businesses.
A common cybercrime scenario
A civil contractor received an invoice by email for $125,000 worth of stock.
The contractor transferred the funds to the bank account listed on the invoice. When the supplier later advised that payment had not been received, it was discovered that cybercriminals had intercepted the email and changed the account details.
The payment had been redirected to a fraudulent account.
This type of business email compromise can be difficult to identify because the invoice and email may appear legitimate. A simple verification process for new or changed bank details can help prevent this type of loss.
What can cyber insurance cover?
Cyber insurance is designed to help protect a business from certain financial and operational consequences of a cyber incident.
Depending on the insurer and policy selected, cover may include:
- Cyber incident response costs
- Business interruption losses
- Data and system restoration
- Cyber extortion and ransomware response
- Privacy and security liability
- Legal and regulatory expenses
- Forensic investigation costs
- Customer notification expenses
- Public relations and crisis management
- Certain forms of funds transfer fraud
Cover, limits and exclusions vary between policies. Businesses should carefully review whether their insurance reflects their systems, data, turnover, security measures and potential exposure.
Review your cyber risk before an incident occurs
Cyber Security Awareness Month is a timely reminder to review both your security practices and insurance arrangements.
MKP Insurance can help you understand your business’s cyber risks and review whether your current insurance provides appropriate protection.
Contact MKP Insurance for a no-cost, no-obligation discussion about your cyber insurance requirements.