Got that picked-on feeling? Sadly, it’s not in your head.

Australian SMBs are very much in the line of fire for cybercrims looking for easy income. And it’s a real struggle to regain what you lose (from money to reputation) if attacked.

Reality bites: Cybercrime does hit Aussie SMBs hard

The Australian Institute of Criminology (AIC) says that SMBs experience a range of harms from cybercrime that extend beyond financial costs – impacting personal health and creating legal issues. “Large businesses hit by a cyberattack typically recover. For small and medium businesses, the same attack can be terminal,” says Australian Cyber Security Minister Clare O’Neil.

With Cybersecurity Awareness Month (October 2026) coming up fast, it’s a good time to take stock of how well you can protect your business – and find out how (with a little help from your friends at Colton) you can shore up your defences.

So, what are the most common cybersecurity threats facing Australian SMBs? And what can you do to minimise their impact?

Your ‘be-on-the-lookout’ list!

According to the ASD (Australian Signals Directorate) Annual Cyber Threat Report for 2024-2025, BEC (business email compromise) and ransomware remain the leading threats to Australian businesses, with credential theft close behind. Phishing is now increasingly the delivery mechanism for BEC rather than the standalone threat category it used to be.

If you compare this with 2023 – when the ASIC Cyber Pulse Survey had phishing first (26%), then ransomware (17%), then BEC (13%) – the ‘what you’re at risk from’ list has changed over the last few years.

Here’s what to watch out for – and what you can do to protect your business, your data,  people, and customers:

1. Business email compromise (BEC)

BEC is a targeted cybercrime where scammers trick your staff into sending money or data by pretending to be their boss, a coworker, or a vendor.

BEC fraud resulting in financial loss accounts for 15% of top self-reported cybercrime threats for Australian businesses. The average loss is AUD +$55,000, and one in three successful breaches began with a BEC.

So, who in the office should you be worried about?

BEC is increasingly aimed at your finance team, with AI now generating near-perfect invoice wording – making it much harder to spot. Once a scammer gets access to a mailbox in your business, they typically change the bank details on a large invoice. And because many businesses won’t think to verify new account details with a supplier, the attacker gets paid. Easy money for them. Terrible for you.

How can Colton help?

One solution we recommend to all our clients looking to up their cybersecurity game is LastPass. We often describe it as a secure ‘digital keyring’ for your business.

It stores every login your team needs – from email to banking to software – in one encrypted vault. Your staff only need to remember one strong password to access everything, and LastPass generates and fills in the rest automatically. No more “password123” or ‘123456’. No more yellow sticky notes in the top drawer. And no more using the same password for everything and hoping for the best!

How does it work? We set up LastPass with MFA (multi-factor authentication) on your email accounts. That means scammers can’t get into your inboxes with just a stolen password – they’d also need access to employee phones or other devices. It’s one less way for the bad guys to waltz through the front door.

We also connect LastPass directly to your Microsoft 365 login, so your team gets easy, fuss-free access (and the bad guys get nothing). Your password vault is encrypted in a way that nobody else can see into. Not us. Not your IT manager. And not LastPass.

2. Ransomware & Ransomware-as-a-Service (RaaS)

While only (!) second on the ASD list, ransomware is still the most disruptive cybercrime threat you can face as an SMB. A ransomware attack can result in serious operational, financial, and reputational outcomes. And what’s worse is that cybercriminals can now subscribe to ready-to-use ransomware as a service – much as you’d subscribe to Microsoft 365 or Netflix.

Ransomware accounted for 24% of all notifiable data breaches in Australia in the first half of 2024. In FY2024-25, the average self-reported cost of cybercrime per report for businesses was up 50% overall ($80,850). For small businesses: $56,600 (up 14%), and for medium businesses: $97,200 (up 55%).

How can Colton help?

To be straight with you – LastPass doesn’t directly prevent or contain ransomware once it executes. That’s not its job. You need to use LastPass alongside endpoint protection, backups, and an incident response plan (ask us about all of those!). But it plays an important supporting role.

Most ransomware begins with an initial access step – compromised credentials or a phishing attack are the most common entry points. Poor password practices remain the easiest entry point for attackers to get around your traditional defences and move through your network undetected. Closing the credential gap significantly reduces the chances of ransomware gaining a foothold in the first place.

  • MFA prevents attackers from using stolen credentials to access your systems. Even if they have the password, they can’t get in without the second factor.
  • Like retrieving office swipe cards from departing employees, LastPass’s automated offboarding removes ex-employee credentials from your systems immediately – so they can’t be used as ransomware entry points down the track.

3. Credential theft and identity fraud

Criminals are dining out on credential theft – purchasing stolen usernames and passwords from the dark web to access personal email, social media, and financial accounts. Using that stolen data, they launch follow-on attacks to compromise your business network and accounts.

Compromised or stolen credentials accounted for 24% of all notifiable data breaches in Australia in the first half of 2024 – making it equal second with ransomware as a leading cause of breach. And 54% of cyberattacks on SMBs involved compromised credentials.

How can Colton help?

We set up LastPass for your team – and honestly, it’s one of those tools that makes you wonder how you managed without it.

Every staff member gets their own encrypted vault. As mentioned earlier, nobody else can see in – not your IT manager, not us, not even LastPass. Passwords are strong, unique, and auto-generated, so if one ever gets out, it can’t be used to get into anything else. Think of it as giving every account its own separate lock.

We also watch the dark web around the clock. If your credentials ever pop up somewhere dodgy, you’ll hear about it straight away. No nasty surprises two weeks down the track.

And if you’re wondering whether it’s worth the effort – nearly half of all small business breaches come down to compromised passwords. So yeah, it’s worth it.

What else should you be watching for?

There’s a bit more to the list – but don’t panic. Here’s a plain-English rundown of the other threats worth knowing about (and feel free to ask us how LastPass and Colton’s other cybersecurity services can help with any of them):

  • Phishing and social engineering – fraudulent emails that look genuine but are designed to trick your people into handing over their credentials. Phishing is now the main door-opener for BEC attacks.
  • Supply chain attacks – criminals exploit your trusted vendor relationships to steal information or deliver malware. If a supplier’s systems are compromised, yours can be too.
  • AI-powered attacks and deepfakes – AI is making phishing faster, more convincing, and harder to detect. Voice-cloned executives requesting urgent payments and deepfake audio are happening as you read this.
  • Legacy IT and edge device vulnerabilities – older IT systems increase the likelihood and impact of a cyber incident, often giving the bad guys a foothold before anyone notices. Routers, firewalls, and VPNs facing the internet are common targets and can be difficult to secure without the right support.

  • Insider threats – hybrid workplaces have introduced new risks, particularly when offboarding isn’t handled pronto. It’s easy to forget about former staff who still have access to your systems and accounts, but it’s also an easy fix.

A quick list of fixes – start here

  • Follow or benchmark against cybersecurity standards like the Essential Eight
  • Perform risk assessments of third parties and vendors
  • Adopt multi-factor authentication (MFA) across your business
  • Patch your apps – yes, those update prompts matter
  • Perform regular vulnerability scans
  • Make sure you’ve got tested, working backups in place
  • Book a free cybersecurity risk review with Colton – we’ll help you figure out where your gaps are and what to do about them

Not sure where to start? That’s exactly what we’re here for. Book your free cybersecurity risk review with us today: https://coltoncomputers.com.au/get-in-touch/