G’day, small business warriors!

Cybersecurity Chronicles

In this special AFL Grand Final themed edition of Cybersecurity Chronicles, we’re shirtfront‘ing a topic that might make you want to hide underneath your desk, in the fear of making a hash of it – cybersecurity for SMEs.

But don’t worry, we promise to keep it light and breezy (and full of Footy puns), free of tech jargon that’ll make your head spin faster than a Bitcoin rollercoaster.

The Digital Dilemma

First up, let’s address the Lion(s) in the room – are Australian SMEs really at risk of cyber attacks?

Short answer: Yeah, mate. Big time.

According to the Australian Cyber Security Centre’s latest report, SMEs are increasingly finding themselves in the crosshairs of cybercriminals. In fact, a 2022 study found that 23.2 per cent of small to medium business victims paid a ransom to cybercriminals, with many millions of dollars being paid in ransoms and other associated costs. There has been a rise in the “average cost per cybercrime report” to over $39,000 for small business and $88,000 for medium business – an average increase of 14 per cent Yikes!

But why pick on the little guys? Well, turns out we’re a bit like a sausage roll at the pre-game barbie– small, juicy, and often left unattended. Cybercriminals know that many SMEs don’t have the resources for fancy security systems, making your business and ours, huge speccies for those digital crooks….

The Rule Book: What Should You Know?

Before we dive into the how-to’s, let’s quickly cover the rules of the game:

  1. Privacy Act 1988 (Cth): If your business turns over more than $3 million annually,you’re bound by this. But even if you’re smaller, it still is a good guidebook to follow, with talks of the Australian Government’s Privacy Act reforms potential to include small businesses in its later trenches of implementation.
  1. Notifiable Data Breaches (NDB) scheme: Part of the Privacy Act, this requires reporting certain data breaches. Trust us, it’s about as fun as a falcon, so best to avoid it!
  1. Australian Consumer Law: This bad boy requires you to take reasonable steps to protect customer data.  About as much pressure as the upcoming Granny, right?

Your SME Cybersecurity Game Plan

Now, let’s get down to the nitty-gritty. Here’s your step-by-step guide to turning your SME into a frequent flyer:

  1. Know Your Digital Assets: Take stock of what data you have and where it is stored.Pro tip: That USB stick from 2007 probably doesn’t count as secure storage.
  2. Update Everything. Yes, Everything: Means all software, systems, and devices being up to date. This prevents us being in situations where we can be dropped.
     
  3. Passwords: Make em Long, Strong, and Unique: Use a password manager to generate and store complex passwords. “Password123” is a bit of a shocker – don’t be that guy.
  1. Back It Up, Back It Up: Implement a robust backup strategy – both onsite and offsite, and regularly test them! Don’t kick a floater!
  2. Have a Plan for When Things Go Wrong: It happens, okay, so make sure to be proactive and have steps for containment, assessment, and recovery.

The Final Word: Your Digital Guardian Angel

Don’t worry if you hear footsteps, its really not as complicated as it seems! If you follow these simple steps, you can be sure to not have your number taken.

Remember, implementing good cybersecurity practices isn’t just about avoiding trouble – it’s about building trust with your customers and partners. In today’s digital world, being secure is as important as having a good product or service.

By barracking for your own business by being cyber aware, you, too, can wrap up the bad actors.

Need a hand getting your digital defences up to scratch? Our team at Arro Lawyers is here to help. We can guide you through the paddock without the techno-babble and ensure your SME is as good as Sicily’s roost. 

(And no, we still can’t help you get tickets to the Grand Final game this weekend….. That’d be a different kind of security problem altogether!)

Stay safe out there, and may your team win!