Prevention
Cyber basics for small businesses
The small number of controls that prevent most losses for a business without a security team, and the one that matters most.
Small businesses get targeted precisely because they hold real money and rarely have anyone whose job is security. The good news is that a very short list of controls prevents most of what actually happens.
Invoice fraud is the expensive one
The pattern is consistent. Someone gets into a mailbox, often a supplier's rather than yours, and watches quietly. They wait for a real invoice to be discussed, then send a message from that genuine mailbox saying the bank details have changed. Everything about it is authentic, because it is authentic. Only the account number is wrong.
It is not caught by looking harder at the email. It is caught by picking up the phone.
The short list
Two-factor authentication on every business account
Email first, then banking, then anything holding customer data. This is the highest value hour you will spend.
Call-back verification for payment changes
Written down, applied to everyone including the owner, with no exception for urgency. Urgency is the tell.
Separate accounts for each person, and remove leavers the same day
Shared logins make it impossible to tell who did what, and dormant accounts belonging to former staff are a standard way in.
Backups that are not reachable from your network
Ransomware operators look for backups first and encrypt them too. A backup on a connected drive is not a backup.
Keep devices and software updated
Unglamorous, and it closes the holes that automated attacks rely on.
We are too small to be a target. Is that not true?
No, and it is the most costly assumption in this area. Most attacks are automated and indiscriminate, and they find you because you exist rather than because anyone chose you. Small businesses are also attractive precisely because the controls are usually weaker while the bank balance is still real.
Do we need cyber insurance?
It is worth pricing, particularly if you hold customer data or move significant payments. Read what is actually covered, since social engineering and invoice fraud are commonly excluded or capped separately, and those are the most likely claims you will ever make. Ask that question specifically before buying.
This happened to them too
First-hand accounts from people who went through the same thing.
I lent my phone hotspot to a stranger at the airport
“I was sitting at Ngurah Rai airport in Bali, just killing time before my flight back. This guy walks up to me pretty…”
A fake alert inside my crypto app cost me $28,000
“I'm still reeling from this, but I need to get the story out there because it’s honestly terrifying how easily it…”
I clicked a fake Fair Work email and my account emailed our suppliers
“Honestly, I still feel like a total muppet over this. I was the restaurant manager of a massive buffet in Sydney CBD.…”