Useful IT ideas, minus the jargon.
Practical cyber security, Microsoft 365 and business IT insights for Australian teams.
Fake Passkey Setup Scams: What Microsoft 365 Users Need to Know
An urgent “IT support” request can turn a security upgrade into an account takeover. Learn how the scam works, why genuine passkeys remain secure and which controls to check.
Latest quick reads
Average cybercrime cost per small-business report.
Australia · FY2024-25Small-business incident costs
ASD reports average self-reported costs of A$56,600 for small businesses (up 14%), A$97,200 for medium businesses (up 55%) and A$80,850 across business sizes (up 50%).
These are losses per cybercrime report, not insurance payouts or a prediction of your loss. More than 84,700 reports were received, roughly one every six minutes; that count includes individuals.
What would a disruption mean for payroll, supplier payments and cash flow?
Read the ASD 2024-25 reportUnderstand security costs
Businesses with 5-19 staff reported a cyber incident.
Australia · FY2024-25Cyber incidents by business size and industry
ABS rates by people employed: 0-4: 18.3%; 5-19: 24.0%; 20-199: 35.9%; 200+: 45.7%.
The survey includes scams, fraud and impersonation as well as technical attacks. These are reported experiences, not forecasts. Separately, 28% reported no preventive measures.
Could your team recognise an unexpected sign-in or payment-change request?
ABS release and cyber security data tablesRead about fake IT support requests
By industry
ABS FY2024-25 incident rates, across all business sizes in each industry, not SMB-only rates:
- Agriculture, forestry and fishing: 28.5%
- Information media and telecommunications: 27.9%
- Wholesale: 25.4%
- Accommodation and Food Services: 23.5%
- Healthcare and Social Assistance: 22.8%
- Rental, hiring and real estate: 22.7%
- Professional, scientific and technical services: 22.3%
- Manufacturing: 21.5%
- Retail: 20.2%
- Construction: 18.8%
- Financial and insurance services: 14.9%
Size and industry are separate breakdowns, not an SMB-by-industry comparison.
Source: ABS cyber security data cube, Table 1Email compromise or funds-transfer fraud.
Coalition global policyholders · 2025Email and payment fraud
These accounted for 58% of cyber incidents observed by Coalition. This is global insurer experience, including Australia, not the share of Australian businesses attacked.
Average claim losses: all cyber claims US$116,000; ransomware US$269,000; funds-transfer fraud US$141,000; business email compromise US$27,000. Overall frequency rose 3%, while average severity fell 19%.
Of ransomware claims, 70% involved encryption and data theft; 86% of ransomware victims refused to pay. Refusing a ransom does not remove recovery costs.
Verify changed bank details through an established contact, independently of the requesting email.
Coalition 2026 Cyber Claims Report findingsExplore email security
Businesses reported no cyber prevention measures.
Australia · FY2024-25The cyber prevention gap
In the ABS survey, 28% of Australian businesses reported having no measures to prevent cyber security incidents. This covers surveyed businesses across sizes, not just small businesses, and is not a breach probability.
Start by checking what is actually in place: strong authentication, supported software, tested backups and a clear way for staff to report suspicious requests.
Source: ABS business characteristics, 2024-25Breaches began with software vulnerabilities.
Global dataset · Verizon 2026 DBIRWhy patching matters
Software vulnerability exploitation was the initial entry point in 31% of breaches in Verizon’s 2026 DBIR dataset. The report covers global incidents from November 2024 to October 2025. This is a share of recorded breaches, not a percentage of Australian businesses.
Know which internet-facing systems you run, prioritise exploited vulnerabilities and plan replacements for unsupported software. Updates need an owner and a way to confirm they succeeded.
Source: Verizon 2026 DBIRHealthcare data breach notifications in one year.
Australia · Calendar 2025Healthcare and sensitive information
Health service providers reported 225 data breaches to the OAIC in 2025, around 19% of the 1,205 notifications received. This was the largest sector count. It does not mean 19% of healthcare organisations suffered a breach.
For practices and clinics, consider who can access patient records, how unusual access is detected and how care can continue during an outage.
Source: OAIC 2025 notification findingsAverage ransomware claim loss.
Coalition global policyholders · 2025Ransomware costs beyond the ransom
Approximate Australian-dollar equivalent, rounded to the nearest A$1,000, using the RBA rate for 14 September 2026: A$1 = US$0.7149. Conversion is for comparison only, not an Australian loss estimate or a historical exchange-rate adjustment.
Coalition reports an average ransomware claim loss of US$269,000 in 2025, approximately A$376,000. This is global policyholder experience, not an Australian small-business average or the ransom payment alone.
Ask when critical systems were last restored successfully, how long recovery took and who coordinates the response.
Source: Coalition 2026 Cyber Claims ReportMedian manufacturing business-interruption loss.
US insurance claims · 2019-Oct 2025When production stops
Approximate Australian-dollar equivalent, rounded to the nearest A$1,000, using the RBA rate for 14 September 2026: A$1 = US$0.7149. Conversion is for comparison only, not an Australian loss estimate or a historical exchange-rate adjustment.
Verizon’s 2026 Breach Impact Study reports a US$232,000 median manufacturing business-interruption loss, approximately A$325,000. Its dataset covers US insurance claims for incidents from January 2019 to October 2025, not Australian businesses.
Identify systems that production depends on and test a recovery sequence that brings the most important operations back first.
Source: Verizon 2026 Breach Impact Study, page 26Retail loss dollars attributed to business interruption.
US insurance claims · 2019-Oct 2025The cost of interrupted trading
Business interruption represented 44% of known retail loss dollars in Verizon’s 2026 Breach Impact Study. This is a share of recorded losses, not the percentage of retailers attacked. The study covers US claims for incidents from January 2019 to October 2025.
Consider how sales, payments and fulfilment would continue if the main systems were unavailable.
Source: Verizon 2026 Breach Impact Study, page 28Small insights. Smarter next steps.
See what businesses in your industry report. Select topics you want to hear more about.
Australia · FY2024-25 · All business sizes within the selected industry
Australian benchmark: 21.4%
reported a cyber security incident
Know what to protect first.
Cyber incidents
Percentage of all businesses in the selected ABS industry that reported a cyber security incident in the year ended 30 June 2025. Includes all business sizes, not just small businesses.
Survey results describe reported experiences, not the probability of your business being attacked. Categories may overlap.
ABS Cyber security data cube, Table 1Australian benchmark: 15.5%
reported scams or fraud
Spot payment and impersonation risks.
Scams & fraud
Percentage of all businesses in the selected ABS industry that reported scams or fraud in the year ended 30 June 2025. Includes all business sizes, not just small businesses.
Survey results describe reported experiences, not the probability of your business being attacked. Categories may overlap.
ABS Cyber security data cube, Table 1Australian benchmark: 34.8%
regularly backed up critical data
Make recovery part of the plan.
Backups & recovery
Percentage of all businesses in the selected ABS industry that regularly backed up critical data in the year ended 30 June 2025. Includes all business sizes, not just small businesses.
These are reported prevention practices. They do not measure whether a control is effective or whether the remaining businesses were unprotected.
ABS Cyber security data cube, Table 3Australian benchmark: 25.4%
regularly patched or updated software
Keep everyday systems protected.
Software updates
Percentage of all businesses in the selected ABS industry that regularly patched or updated software in the year ended 30 June 2025. Includes all business sizes, not just small businesses.
These are reported prevention practices. They do not measure whether a control is effective or whether the remaining businesses were unprotected.
ABS Cyber security data cube, Table 3Australian benchmark: 32.5%
used identity and access management
Control who can access your systems.
Identity & access
Percentage of all businesses in the selected ABS industry that used identity and access management in the year ended 30 June 2025. Includes all business sizes, not just small businesses.
These are reported prevention practices. They do not measure whether a control is effective or whether the remaining businesses were unprotected.
ABS Cyber security data cube, Table 3Australian benchmark: 17.3%
provided cyber awareness and training
Help staff recognise the warning signs.
Staff awareness
Percentage of all businesses in the selected ABS industry that provided cyber awareness and training in the year ended 30 June 2025. Includes all business sizes, not just small businesses.
These are reported prevention practices. They do not measure whether a control is effective or whether the remaining businesses were unprotected.
ABS Cyber security data cube, Table 3Choose topics above, or sign up for general ITFR Insights.
Source: Australian Bureau of Statistics, 2024-25. Australian benchmarks are the published all-business totals within the ABS survey scope, FY2024-25 (Tables 1 and 3), not averages of the industries listed here. Survey estimates, not a risk score. Select the i beside each widget for definitions.
Get useful IT ideas in your inbox
Choose monthly ITFR Insights or hear about practical learning sessions. Your topics, your choice.





