Small Business Cyber Costs Hit $56k as Parliament's Hearings Begin
The average cyber incident now sets an Australian small business back about $56,000 — and that number climbed 14% in a single year. This week a federal parliamentary committee started hearing evidence on what small businesses actually need to defend themselves. If you run a business, both of those facts are worth two minutes of your time.
What's Happening
The Australian Signals Directorate's latest Annual Cyber Threat Report put the average self-reported cost of a cyber incident for a small business at roughly $56,000 in 2024–25, up 14% year on year. Alongside that, new survey figures reported this week found that 79% of small business owners fear they wouldn't survive a serious cyber attack, and about a third admit to sharing sensitive information with generative AI tools like ChatGPT.
The timing isn't a coincidence. The House Select Committee on Cyber Security for Small to Medium Sized Businesses, chaired by Sally Sitou MP, began public hearings on 6 October. Industry groups are pushing a clear line: small businesses need practical support — plain-English guidance, tax breaks for security spend, restored training programs — not another pile of reporting obligations.
| The Numbers | Figure | Trend |
|---|---|---|
| Average cost of an incident (small business) | ~$56,000 | Up 14% YoY |
| Owners who fear they couldn't survive an attack | 79% | High concern |
| Small businesses sharing data with AI tools | ~1 in 3 | Growing risk |
Why It Matters
A $56,000 hit is survivable for a big firm. For a cafe, an accounting practice, or a not-for-profit running on tight margins, it's the kind of number that closes doors. And here's the part the headlines miss: in our own client base across the Sydney Northern Beaches and Central West NSW, the businesses that come through an incident intact aren't the ones with the biggest security budgets. They're the ones with backups they've actually tested and multi-factor authentication switched on everywhere. The ones that struggle usually have neither — and didn't realise it until the day it mattered.
What to Do About It
You don't need to wait for Canberra to act. A handful of low-cost moves cover most of the risk:
- Turn on MFA everywhere. Email, banking, accounting software, remote access — multi-factor authentication stops the majority of account takeovers and costs nothing to enable.
- Test your backups. A backup you've never restored from isn't a backup — it's a hope. Run a real restore and confirm it works.
- Set an AI usage rule. Tell your team plainly: no client records, financials, or passwords in public AI tools. Use a business-grade option with data protections instead.
- Write a one-page response plan. Who to call, how to isolate a device, where the backups are. Decide it now, not mid-incident.
Hearings commence: cyber security for small businesses, Parliament of Australia media release, 1 October 2026
Small business delivers e-safety wishlist as risks grow, AAP, 6 October 2026
Written by Michael Sacco, IT Consultant, All IT Services. All IT is a Sydney-based managed IT provider supporting professional services, hospitality, and not-for-profit organisations across Australia.
Frequently Asked Questions
Want to know where your business actually stands?
We'll check your backups, MFA coverage and exposure — and tell you straight what needs fixing first. No jargon, no scare tactics. Talk to the All IT team today.
