The Australian Cyber Security Centre received more than 84,700 cybercrime reports through ReportCyber in FY2024–25 — down 3% on the previous year. Numbers at that scale can feel abstract, like weather statistics for a storm somewhere else. They are not. Each report represents a person or organisation that reported a cybercrime, while the ACSC cautions that much cybercrime remains unreported.
The more useful question is not “how big is the number” but “who is behind it, and why.” The honest answer runs against the instinct most business owners have.
01Why smaller businesses, not larger ones
Smaller businesses still deserve the same deliberate controls as larger organisations. They hold valuable client records, financial details, and system access, while often having fewer internal security resources. Attackers are running a numbers game, so the practical question is whether the controls around a smaller business are visible, tested, and monitored.
02What a report actually costs
The ACSC's current report separates self-reported cybercrime costs by business size rather than publishing one universal SMB breach figure. That distinction matters: a report count is not a complete loss estimate, and self-reported figures do not capture every downstream cost. The useful response is to identify the controls that reduce both the likelihood and impact of an incident.
03What the report change does — and does not — tell us
A year-on-year fall in reports does not mean the threat has disappeared, and a rise would not by itself prove that attacks became more severe. Reporting behaviour, attack tooling, and the mix of incidents all affect the number. Treat the official figure as a signal to keep controls and reporting processes current, not as a complete measure of business exposure.
04What actually moves the needle
The businesses that reduce exposure are not necessarily the ones spending the most. They are the ones with fewer gaps in a short list of controls: multi-factor authentication enforced everywhere, endpoints protected with monitored detection rather than consumer antivirus, backups that are tested and cannot be encrypted alongside the rest of the network, and a plan for the first hour after something goes wrong.
That question is worth resolving this quarter, not next year. A ten-question self-assessment gives you a prioritised starting point; a Cyber Readiness Assessment can then establish what to verify and fix in what order.
Where this leaves you
Knowing the risk is not the same as knowing your own exposure.
The Cyber Readiness Assessment gives you a written, prioritised answer in ten business days — enquire for scope and terms.