The short answer
Most attacks on Australian businesses succeed through a stolen password or a convincing email — not sophisticated hacking. Turn on multi-factor authentication everywhere, verify any change to bank details by phone, review who can access your accounting systems, and train your staff to spot the scams. Those four things prevent the majority of incidents.
For many small businesses, cyber criminals are no longer targeting only large corporations. Increasingly they target everyday businesses that hold valuable financial information: tax records, payroll data, supplier details and banking credentials.
At Crest Accountants we work with businesses across a wide range of industries from our Burleigh Heads office, and we see the same handful of attacks succeed again and again. The encouraging part is that they are largely preventable, and the fixes are neither expensive nor technical.
Why does cyber security matter for a small business?
Because the consequences land on the business, not the attacker. A single incident can mean:
- Money paid to a fraudulent bank account and rarely recovered
- Confidential client and employee information exposed
- Days of downtime while systems are rebuilt
- Identity theft using stolen tax and payroll records
- Damage to a reputation built over years
- Notification obligations under the Notifiable Data Breaches scheme where personal information is involved
Criminals target small and medium businesses precisely because they usually have fewer controls in place than a large organisation — while still holding information worth stealing.
What are the most common threats facing Australian businesses?
What does a phishing email look like?
Phishing remains the most common way in. An employee receives what appears to be a legitimate email from Microsoft, a supplier, a bank, the ATO or even a colleague, containing a link asking them to sign in or verify something. Once credentials are entered, the attacker has the account.
Warning signs to train your team on:
- Unexpected requests for urgent action
- Links that lead to unfamiliar web addresses
- Unprompted password reset requests
- Sender addresses that are close to, but not exactly, the real one
- Unexpected invoices or payment requests
When in doubt, verify through a separate channel. Never use the phone number or link in the message itself.
What is business email compromise?
Business Email Compromise (BEC) occurs when a criminal gains access to a mailbox and quietly monitors conversations, sometimes for weeks. They then send a fraudulent invoice or alter payment instructions — usually at the exact moment a payment is expected, so nothing looks unusual.
We see this most often around settlement dates, large supplier payments and end of financial year, when volumes are high and everyone is moving quickly. Always confirm any change to bank details by telephone, using a number you already hold — never a number supplied in the email requesting the change.
How do ATO and tax-time scams work?
Tax time brings a predictable wave of impersonation. Criminals pose as the ATO or as your accountant, claiming a refund is waiting or a debt is overdue, and ask for personal details or immediate payment. Some attempt to gain access to your myGov account or to link themselves to your business as a tax agent.
Two things worth knowing:
- The ATO will not threaten immediate arrest, demand payment in gift cards or cryptocurrency, or ask you to click a link to claim a refund.
- Client-to-agent linking in ATO Online means you nominate your agent yourself. If you receive an unexpected notification that a new agent has been nominated, treat it as an incident and contact us straight away.
Why are weak and reused passwords still a problem?
If one website suffers a breach and the same password is used elsewhere, attackers will try it across every service they can find — automatically, at scale. One reused password can unlock email, accounting software and banking.
- Use a strong, unique password for every service
- Never share logins between staff — give each person their own
- Turn on multi-factor authentication
- Use a reputable password manager so unique passwords are practical
Why is multi-factor authentication so important?
Multi-factor authentication (MFA) is the single most effective control available to most businesses. Even if an attacker has your password, they still need a code or approval from a device you hold. In a great many cases, MFA is what stops a stolen password from becoming a serious incident.
Enable it on, at minimum:
- Microsoft 365 and Google Workspace accounts
- Xero, MYOB and other accounting platforms
- Business banking
- myGov and ATO Online services
- Cloud storage and file sharing
- Your password manager
MFA also appears in the Australian Signals Directorate’s Essential Eight, the baseline set of mitigation strategies recommended for Australian organisations — a useful reference point if you want a structured way to assess where you stand.
Is staff training really one of the best defences?
Yes — technology alone cannot eliminate cyber risk, because most attacks are aimed at people rather than systems. Your team is the control that decides whether a convincing email succeeds.
Regular, short training should cover:
- Identifying phishing and impersonation attempts
- Verifying payment and bank detail changes
- Password security and using a password manager
- Handling sensitive client and employee information
- Reporting suspicious activity without fear of blame
- Secure use of mobile devices and home networks
The last point matters more than it sounds. Staff need to feel safe reporting a mistake immediately — the cost of an incident rises sharply with every hour it goes unreported.
How should I protect financial and tax information specifically?
Financial information is particularly attractive to criminals because it converts to money quickly. If you do nothing else, review these:
- Keep accounting systems and devices updated
- Restrict access to authorised staff, and match permissions to the role
- Use a secure portal for sensitive documents wherever one is available, rather than email attachments
- Remove access for former employees, contractors and previous advisors on their last day
- Review who can access your accounting software, tax records and payroll at least twice a year
- Retain and dispose of financial records securely
The access review is the step most often skipped and most often regretted. Old logins belonging to people who left years ago are a common way in.
Start here this week
Four steps that remove most of the risk, in order of value.
- Turn on multi-factor authentication for email, accounting software and banking.
- Write a rule that bank detail changes are always verified by phone, and tell every staff member.
- List everyone with access to your accounting and payroll systems, and remove the ones who should not be there.
- Spend twenty minutes with your team on what a phishing email looks like, and agree how to report one.
Cyber security is an ongoing process
Cyber security is not a one-time project. Threats change, staff change and systems change, so systems, policies and training all need periodic review. But that review does not have to be daunting. Enabling multi-factor authentication, strengthening passwords, tightening access and educating staff will move most businesses a long way forward.
By taking a proactive approach, you protect your financial information, your clients and the reputation you have spent years building.
Frequently asked questions
What is the single most effective cyber security step for a small business?
Turning on multi-factor authentication across email, accounting software and banking. It means a stolen password on its own is not enough for an attacker to get in, and it is free or low cost on almost every major platform.
How do I know if an email from the ATO is genuine?
The ATO will not threaten immediate arrest, demand payment in gift cards or cryptocurrency, or send a link to claim a refund. If you are unsure, do not use any contact detail in the message — log in to ATO Online directly, or contact your accountant.
A supplier has emailed asking us to update their bank details. What should we do?
Treat it as fraudulent until proven otherwise. Telephone the supplier on a number you already hold from an earlier invoice or contract — never a number in the email — and confirm the change with a person you know.
What should we do if we think we have been compromised?
Act quickly. Change passwords and revoke sessions on the affected accounts, stop any pending payments, tell your bank, and contact your IT provider and your accountant. If personal information may have been exposed, you may have obligations under the Notifiable Data Breaches scheme.
How often should we review who has access to our financial systems?
At least twice a year, and immediately whenever someone leaves the business or changes role. Access reviews are one of the least expensive and most frequently skipped controls.
This article is general information only and does not take your specific circumstances into account. For advice tailored to your business, please get in touch.

