
Australia’s cyber security agency now receives a cybercrime report roughly every six minutes. In the 2024 to 2025 financial year, the Australian Signals Directorate logged more than 84,700 reports, and the average cost of cybercrime climbed to about $56,600 for a small business and $97,200 for a medium one. Those numbers sound alarming, but there is a quietly reassuring truth hidden inside them.
Attackers are not endlessly creative. Most break-ins arrive through the same small handful of doors, year after year. If you understand those doors and put a simple lock on each one, you close off the overwhelming majority of the ways a criminal could get into your business. This guide walks through the five most common entry points for Australian small businesses, in plain English, along with the practical step that shuts each one.
Entry point 1: Phishing emails and social engineering
The single most common way in is still the humble dodgy email. Phishing, a form of social engineering, was recorded in around 60 per cent of the incidents reported to the ACSC in 2024 to 2025. The reason is simple: it is far easier to trick a busy person into clicking a link or handing over a password than it is to break through technology.
A modern phishing email rarely looks like the clumsy scams of a decade ago. It might appear to come from a supplier you deal with every week, from Microsoft asking you to re-verify your login, or from someone claiming to be your own manager asking for an urgent favour. The goal is almost always the same: get you to enter your credentials on a fake page, or open an attachment that installs something nasty.
The fix is part training, part technology. Teach your team a few reliable checks and make reporting a suspicious message the normal, praised response rather than something to feel embarrassed about. Our guide on how to spot a phishing email gives your staff six checks they can run in seconds. Pair that awareness with spam filtering and you cut this entry point down dramatically.
Entry point 2: Stolen and reused passwords
Once phishing works, the attacker usually walks away with a password. That is why compromised accounts feature so heavily in the ACSC data, appearing among the top techniques in roughly a third of incidents. A stolen password is a master key, and most businesses hand out far more copies than they realise.
The problem is made worse by two very human habits: choosing weak, easy to guess passwords, and using the same one across many services. When a criminal buys a batch of leaked passwords from an unrelated website, they simply try those same combinations against your email, your accounting software and your online banking. If your team reuses passwords, one old breach somewhere else becomes a break-in at your business.
Two changes close this door almost completely. First, turn on multi-factor authentication everywhere it is offered, so a password alone is no longer enough to log in. It is the single highest-value security upgrade most businesses can make, and our guide to multi-factor authentication explains how to roll it out in an afternoon. Second, give staff a password manager so every account can have a long, unique passphrase without anyone needing to remember it.
Entry point 3: Software that has not been updated
Every piece of software, from Windows to your web browser to the plugin running your website, occasionally has a security hole discovered in it. When the vendor releases a patch, they also, in effect, publish a map of exactly where that hole was. Attackers read those maps closely, then scan the internet for businesses that have not yet applied the fix.
This is one of the cheapest attacks to run and one of the cheapest to prevent, which is a frustrating combination when it succeeds. The gap between a patch being released and criminals exploiting it can be a matter of days, so leaving updates for a rainy day is a genuine risk rather than a minor housekeeping task.
Turn on automatic updates wherever you can, cover operating systems and applications alike, and keep an eye on the devices that are easy to forget, such as routers, firewalls and anything still running an old version of software. Our article on why software updates matter covers how to make patching a habit rather than an afterthought.
Entry point 4: Remote access left open to the internet
Remote and hybrid work is now normal, and with it came a quiet expansion of the ways to reach your systems from outside the office. Remote desktop connections, virtual private networks and management portals are all incredibly useful, but each one is also a door facing the public internet. If that door is protected by only a password, attackers will find it and start trying keys around the clock.
Automated tools constantly sweep the internet looking for exposed remote access, testing common usernames and passwords millions of times over. A small business rarely notices this background noise until one of those attempts succeeds. Exposed remote services are a favourite starting point for ransomware crews in particular, because a single working login can give them the run of your network.
Do not expose remote desktop directly to the internet. Put remote access behind a properly configured VPN or a modern zero trust service, require multi-factor authentication on it, and lock access down to only the people who genuinely need it. If a service does not need to be reachable from outside, close it off entirely.
Entry point 5: Fake invoices and trusted suppliers
Not every attack breaks into your systems at all. Some simply exploit your trust and your habits around money. Business email compromise, where a criminal poses as a supplier, a colleague or a manager to redirect a payment, ranked as the second most reported cybercrime for businesses in 2024 to 2025, sitting behind only online banking fraud among self-reported losses.
The classic version arrives as a genuine-looking invoice with updated bank details, often from a supplier whose own email has been compromised. Your accounts team pays it exactly as they always would, and the money is gone before anyone notices the account number changed. Because no malware is involved, spam filters and antivirus never get a chance to catch it.
The defence here is a process, not a product. Verify any change to bank details by phoning the supplier on a number you already have, never the one printed on the new invoice. Set a rule that large or unusual payments always need a second person to approve them. Our guide to business email compromise breaks down how the scam works and the simple controls that stop it.
The good news: the fixes overlap
Look back over the five entry points and a pattern emerges. The same short list of habits protects against nearly all of them, which means you do not need a large budget or a dedicated security team to make real progress. A few well-chosen basics do most of the heavy lifting.
- Turn on multi-factor authentication across email, banking and every business app that offers it.
- Keep operating systems, applications and network devices updated automatically.
- Give staff a password manager so every login is long and unique.
- Train your team to pause on unexpected emails and to report anything suspicious without fear.
- Verify payment and bank detail changes by phone, and require a second approver for large transfers.
- Keep remote access behind a VPN with MFA, and take good backups in case something still gets through.
None of these steps is expensive or complicated on its own. Put together, they close the doors that the great majority of attacks rely on, and they line up neatly with the Australian Government’s Essential Eight baseline. The businesses that get breached are rarely the ones that did everything perfectly. They are usually the ones that left one obvious door unlocked.
Find out where you stand
The hardest part of security is often just knowing which of these doors is still open in your own business. That is exactly what our free self-assessment is for. Answer 27 plain-English questions about how your business works, and in about 5 to 10 minutes you will get a personalised PDF report that shows where you are strong, where you are exposed, and what to fix first. It maps your answers to the ACSC Essential Eight, ISO 27001 and SOC 2, so you can see your standing against the frameworks that matter.
There is no cost and no obligation. Take the free security self-assessment and find out which entry points still need your attention.