Emerging Technology Threats Facing Australian Small Businesses

Emerging Technology Threats Facing Australian Small Businesses

author_img
Zectron IT
Published · Updated

Cyber threats change quickly, but the businesses that get hurt usually fall to the same handful of tricks, now made faster and more convincing by new technology. This article looks at the threats that matter most to Australian small and medium businesses right now, and the practical steps that blunt each one.

For context, ASD’s Annual Cyber Threat Report 2024 to 2025 recorded more than 84,700 cybercrime reports through ReportCyber, about one every six minutes. The average self-reported cost per cybercrime report was $56,600 for small businesses, up 14%, and $97,200 for medium businesses, up 55%.

1. AI-powered phishing and impersonation

Generative AI has removed the spelling mistakes and clumsy wording that used to give phishing emails away. Attackers can now write polished, personalised messages in seconds, using details from your website and LinkedIn. The same tools can clone voices and create convincing video, so a “call from the director” asking for an urgent payment is no longer proof of anything.

What helps: agree a rule that any request for money, gift cards or bank detail changes is confirmed through a second channel, such as a call back on a known number. Run short, regular phishing awareness sessions so staff know what current attacks look like.

2. Business email compromise

Email compromise is the most commonly reported cybercrime affecting Australian businesses. In the same ASD report, email compromise without financial loss made up 19% of business reports, and business email compromise fraud with a financial loss made up 15%. Once inside a mailbox, attackers quietly watch conversations and then redirect invoice payments.

What helps: multi-factor authentication on every account, alerts for suspicious sign-ins and inbox rules, and phone verification of any change to bank details. Our guide to implementing MFA is a good place to start.

3. Attacks on sign-ins that get around basic MFA

As more businesses turn on MFA, attackers have adapted. Fake login pages can capture a password and a one-time code at the same time, and repeated push notifications are used to wear people down until they tap “Approve”.

What helps: move towards phishing-resistant sign-in methods such as passkeys or security keys for admin and finance accounts, use number matching for app approvals, and teach staff never to approve a sign-in they did not start.

4. Ransomware and data extortion

ASD’s report found ransomware remained a significant threat, involved in 11% of incidents in 2024 to 2025. Modern groups often steal data before encrypting it, then threaten to publish it if you do not pay. That means backups alone no longer solve the problem, although they are still essential for getting back up and running.

What helps: patch quickly, restrict admin rights, keep offline or immutable backups and test that you can restore them.

5. Supply chain and third-party risk

Your business is only as secure as the suppliers who can reach your systems or data: software vendors, IT providers, cloud apps and contractors. ASD lists managing third-party risk as one of its priority “big moves” for organisations.

What helps: keep a list of the suppliers that hold your data or have remote access, ask them how they protect it, remove access you no longer need, and make sure every supplier login uses MFA.

6. Old and unsupported technology

Windows 10 reached end of support on 14 October 2025. Computers still running it no longer receive regular security fixes unless enrolled in Microsoft’s paid Extended Security Updates program. The same applies to old routers, firewalls, NAS drives and line-of-business software that vendors no longer update. ASD also names replacing legacy IT as a priority.

What helps: keep an up-to-date list of your devices and software, with support end dates, and plan replacements before they become urgent.

7. Staff using AI tools with business data

Not every AI risk comes from attackers. Staff pasting client details, contracts or financial data into free AI tools can expose information you are obliged to protect. Our article on setting up AI rules for your staff explains how to allow useful AI use without leaking data.

8. Preparing for quantum computing

Large-scale quantum computers are expected to eventually break some of the encryption in use today, and ASD includes preparing for post-quantum cryptography in its priorities. For most small businesses there is nothing to do yet beyond keeping systems and software current, so you receive updated encryption as vendors release it.

Quick checklist

  • MFA on every account, with phishing-resistant methods for admins.
  • Call-back verification for any payment or bank detail change.
  • Updates applied promptly, and no unsupported operating systems.
  • Backups that are separate from your network and regularly tested.
  • A supplier access list that is reviewed at least yearly.
  • Clear AI usage rules and regular staff awareness training.
  • Progress against the ASD Essential Eight. Our Essential Eight checklist shows where to start.

Not sure where your gaps are? Our free cyber risk scan is a quick way to find out.

Want these threats handled for you? See our managed IT security services.

Is your business ready for today’s cyber threats?

Our free IT Health Check reviews your accounts, devices, backups and email security against the threats in this article and gives you a clear, prioritised list of fixes.

Book a free IT Health Check

Or call 1300 133 770.

IT Support vs Managed IT Services: What Is the Difference?
IT Support vs Managed IT Services: What Is the Difference?

IT support fixes problems when you call. Managed IT services take ongoing responsibility for keeping...

Read more ›
Microsoft 365 Business Premium vs Business Standard: Which Does Your Business Need?
Microsoft 365 Business Premium vs Business Standard: Which Does Your Business Need?

Business Standard gives you the Office apps, email and Teams. Business Premium adds the security...

Read more ›
Windows 10 End of Support: What Sydney Businesses Must Do Now
Windows 10 End of Support: What Sydney Businesses Must Do Now

Windows 10 support ended on 14 October 2025, and the first year of paid Extended...

Read more ›