Understanding what a reasonable amount of cybersecurity is for your business can be confusing. With what seems like a barrage of news stories about ransomware, data breaches or companies being shut down by cyber attacks, no one wants to be complacent.
However, when you start researching solutions you quickly encounter an overwhelming number of tools, services and recommendations; all claiming to be essential. The shear scale of these solutions would send any small business broke were they to take them all onboard.
This raises a curious but important question:
How much cybersecurity is actually reasonable for a small business?
Not every organisation needs enterprise-grade security operations centres or rapid response teams. But doing nothing is obviously not an option either.
The goal should be appropriate security, not maximum security.
In other words, enough protection to materially reduce your risk without creating unnecessary cost or operational complexity. Let’s unpack what that typically looks like.
The Cyber Risk Reality for Small Businesses
There’s a persistent myth that cyber criminals primarily target large corporations.
Unfortunately, the opposite is often true.
Small and mid-sized businesses are frequently seen as easier targets because they typically have:
- Fewer security controls
- Less monitoring
- Less adhesion to best practices and standards
- Data, access & reputation that is valuable to them
According to the Australian Cyber Security Centre (ACSC), over 94,000 cybercrime reports were made in Australia in the last financial year, averaging roughly one report every six minutes.
Small businesses account for a significant proportion of these incidents. Why? because regardless of your size, every business represents an opportunity to make money. If the relative effort (cost) involved is low, even a small payoff can yield fantastic ROI. This leads many attackers to specifically target ‘high volume’, ‘low effort’ attacks on small to mid-sized businesses.
What are the common impacts to a small business following an attack?
Cyber incidents commonly result in:
- Operational downtime – days, weeks, even months
- Financial loss – commonly between $50k-$500k in direct cash losses
- Reputational damage – loss of customer & investor trust
- Regulatory exposure – risk of being shut down entirely
For many small organisations, the average loss (~$120k-$137k) can wipe out their cash flow entirely. An estimated 60% of small businesses are closed within 6 months of an attack. For those that survive, the recovery takes an average of 279 days (9 months).
The Goal Isn’t “Perfect Security”
Most businesses we speak with don’t have size appropriate cyber security. The reason being they’ve commonly fallen victim to one of two traps.
Trap #1 – Doing Almost Nothing
Many businesses assume they’re too powerless to effect their fate. They see the cost of putting everything in place as prohibitive, opting to accept their vulnerabilities and simply roll the dice.
Unfortunately, these businesses are mislead. They absolutely, 100% have the ability to significantly reduce their risk of attack through very affordable strategies. Criminals targeting small businesses are looking for ‘open doors’ and ‘unlocked windows’. They want positive ROI so they are looking for low hanging fruit. You don’t need to be Fort Knox to put off an attacker, just difficult enough to cause them to move on to the next target.
Trap #2 – Trying to do everything
At the other extreme, some businesses take on almost every security recommendation they get in an attempt to replicate enterprise-level security frameworks that are expensive, complex and difficult to maintain.
This often leads to:
- Overspending
- Operational disruption & outages
- Poorly configured solutions (retained risk)
A more sensible approach is to focus primarily on the controls that reduce the specific risks applicable to your business. Keeping the scope of the solution in alignment with real-world business requirements further ensures that solutions are optimised for the most effect.
Your protection doesn’t need to be perfect, it just needs to be strong in the areas it matters.
What “Reasonable Cybersecurity” Usually Looks Like
For most small and mid-sized businesses (typically 20–80 staff), a reasonable cybersecurity posture includes several core layers of protection.
These controls address the most common types of attacks without becoming overly complicated. Whilst it’s good practice to have at least something in place for each area, it’s important to keep things simple; only double down on the areas that align to your biggest risks.
1. Identity Protection
Most cyber attacks today start with compromised user accounts.
Phishing emails and credential theft remain one of the most common entry points for attackers.
At a minimum, businesses should have:
- Multi-Factor Authentication (MFA) on critical systems
- Secure password management
- Conditional access policies where possible
Microsoft has publicly stated that multi-factor authentication alone can block over 99% of automated attacks.
For such a simple control, the impact can be enormous.
2. Email Security
Email remains the number one delivery method for cyber attacks.
Common threats include:
- Phishing
- Business Email Compromise (BEC)
- Malware attachments
- Invoice fraud
We recommend all business ensure they have:
- Email Filtering
- DMARC, DKIM & SPF correctly configured
- User Awareness Training
- Phishing Susceptibility Testing
Human behaviour plays a major role which is why user education is one of the most important things commonly lacking in most businesses.
3. Patch Management and System Updates
Many cyber attacks exploit known vulnerabilities that already have available fixes.
Unfortunately, updates are often delayed or inconsistently applied across environments.
Regular patching of:
- Operating systems
- Applications
- Servers
- Network devices
is one of the simplest ways to reduce exposure.
In many cases, attackers are simply exploiting systems that haven’t been updated.
4. Data Backup and Recovery
Despite best efforts, incidents can still occur. It’s important to have a reliable safety net in place.
Unfortunately, not all backups are created equal. More important than the backup solution itself, is the way in which the backups are managed.
A reliable backup strategy should include:
- Automated backups
- Offsite or cloud-based storage
- Regular recovery testing
Ransomware incidents often become catastrophic when organisations discover their backups don’t actually work. Testing is just as important as the backup itself. Furthermore, attackers know that a backup is going to impede their ability to get paid. Backups need to have multiple copies, including inaccessible copies to ensure they don’t simply delete your backup during the attack.
5. Endpoint Protection and Monitoring
There are a magnitude of options regarding endpoint protection these days. Modern endpoint protection tools go far beyond traditional antivirus. Commonly these solutions include:
- Behavioural threat detection
- Ransomware protection
- Real-time monitoring
- Automated isolation of infected devices
Solutions range from tools built into Microsoft 365, to complex 3rd party systems and appliances. The ‘reasonable’ system for you is going to depend on your risk profile, but you do need something in place.
Cybersecurity Is Not Just Technology
One of the biggest misconceptions about cybersecurity is that it’s purely about tools.
In reality, most successful security outcomes come from process and discipline. It’s about doing the right things, consistently, again and again. In addition, right-sizing cyber security is a matter of strategy, not knowledge. In order to get the right solutions in place, a security management strategy should include:
- Specific evidence related to your environment.
- Discussions of business processes and the systems required to support them.
- Discussions of your options to mitigate your risks including ‘good’, ‘better’, ‘best’.
- Clarity as to what the impact will be to your business operationally if an event was to occur.
- A documented risk register providing full transparency of your current situation.
See https://sensible.com.au/need-better-cybersecurity/
The Cost Question
The next logical question is:
How much should a small business spend on cybersecurity?
There’s no universal number, but a useful way to think about it is through risk exposure.
Consider:
- What systems are critical to your operations?
- What would one day of downtime cost your business?
- What data do you hold for customers or partners?
- What regulatory obligations apply to your industry?
See 3 things to know when investing in cyber security services
When cybersecurity investments are framed around risk reduction and operational continuity, they become easier to justify. Understand that most attacks are not about stealing your data, but rather stealing your money, or disrupting your operations (costing you money).
For most small businesses, reasonable cybersecurity typically represents a modest portion of overall IT spend (~30%), but delivers disproportionate value in risk reduction.
The Role of an MSP in Cybersecurity
For many small businesses, building internal cybersecurity capability is unrealistic.
Security requires specialised skills, constant monitoring and evolving knowledge of emerging threats. This is where a Managed Service Provider can act as an extension of your business.
A good MSP should help you:
- Understand your risk exposure
- Implement practical security controls
- Maintain ongoing monitoring
- Continuously improve your environment
It’s important to note that most security recommendations are proactive and tend to be changes to existing security tools and platforms. Whilst investment is required from time to time, managing your security should be more akin to classic risk management.
If more than 50% of the security recommendations you receive are tied to a quote or proposal, you’re not getting recommendations, you’re being sold to. The goal is not to overwhelm you with technology, it’s to provide clarity and measurable reduction in risk.
Summary
Cybersecurity for small businesses doesn’t need to be extreme — but it does need to be deliberate.
The reality is that small and mid-sized businesses are increasingly targeted because they present a strong return on investment for attackers. The impact of an incident can be significant, often affecting operations, cash flow and long-term viability.
That said, the answer isn’t to implement every possible security tool. It’s to apply the right controls in the right areas, based on your actual business risks.
Importantly, effective cybersecurity is not just about technology — it’s about process, consistency, and strategy. Understanding your risks, documenting them, and making informed decisions is what ultimately drives better outcomes.
If you would like to learn more about how to right-size your cyber security strategy, you can learn more here, get in contact with us, or simply book a meeting directly!
