Module 1 of StartCloud's Cyber Hygiene for Staff learning pathway, in five short units with a knowledge check: why cyber attacks are automated rather than personal, the four things criminals actually want (money, mailboxes, data and relationships), the common entry points including the anatomy of a typical invoice fraud attack, and the pause-and-check habit plus no-blame reporting culture that make staff the strongest defence.
Why Cyber Criminals Target Businesses Like Yours
It is not personal, it is automation
Let us clear something up on day one: nobody in a hoodie sat in a dark room, studied your business, and picked you. That is the movies. Real attacks are mostly automated. Software scans every address on the internet for weak spots, and phishing emails go out by the million to any inbox that exists. Your business gets probed the same way your neighbour's does: constantly, cheaply, and without a single human thinking about you.
That sounds almost comforting until you follow the logic. If the attacks are automated and free to send, criminals do not need to be picky. They just need someone, somewhere, to click. And when a bite comes back from a small business, it is often the better catch: real money in the bank, and thinner defences than the big end of town. No security team, no fancy monitoring, one very busy owner.
How often a cybercrime was reported to the Australian Signals Directorate in 2024-25. Over 84,700 reports in a single year.
Average self-reported cost of a cybercrime for an Australian small business in the same report, up 14 per cent on the year before.
Bots do not sleep, take leave, or care what industry you are in. They scan everything connected to the internet, all the time.
This is the most expensive sentence in Australian small business. Being small does not make you invisible, it makes you easier. The bot that found your login page has no idea whether you are a two-person plumbing outfit in Balcatta or a bank. It only knows whether the door opened. The good news, and the whole point of this course, is that most of those doors are easy to keep shut.
So what is the prize? People imagine hackers hunting for state secrets, then assume a small business has nothing worth taking. The truth is criminals want four very ordinary things, and every business in Australia has all four of them.
Your money
The obvious one. A fake invoice with changed bank details, a spoofed email from the boss asking for an urgent transfer, or ransomware that locks your files and demands payment to unlock them. Direct, blunt, and still remarkably effective.
- Fake or altered invoices with new bank details
- Urgent payment requests that impersonate the owner
- Ransomware that holds your files hostage
Your mailbox
Less obvious, more valuable. A work email account is a master key. It receives password resets for almost every other service you use, and it lets a criminal send convincing messages as you. Many of the worst incidents start with one quietly compromised inbox.
- Password resets for other accounts land in email
- Sent from your real address, scams look legitimate
- Invoice fraud is usually run from inside a real mailbox
Your data
Client records, payroll details, ID documents, supplier lists. Anything personal or commercial can be sold, used for identity theft, or held over you as a second ransom: pay up or we publish. Even a modest client list has real value to the wrong people.
- Client and staff personal details sell on criminal markets
- Payroll and ID documents feed identity theft
- Stolen data becomes leverage: pay or we leak it
Your relationships
The sneaky one. Your clients and suppliers trust email from you. A criminal inside your account can ride that trust straight into their businesses: fake invoices to your clients, malware to your suppliers, all wearing your name. You become the stepping stone.
- Clients pay fake invoices because they came from you
- Suppliers open attachments because they trust you
- The reputational damage lands on your business
That fourth target matters more than most people realise. Even if a criminal takes nothing from you directly, your account can be the tool that robs your best client. Plenty of small businesses have had the awkward phone call that starts with "we paid the invoice you sent last week". Protecting your login protects everyone who trusts you.
Forget the Hollywood version with green text raining down a screen. Real attackers rarely break anything. They walk through doors that were left open, and the same few doors come up again and again.
The workhorse of cybercrime. An email that looks like Microsoft, Australia Post, the ATO or your bank, nudging you to click a link and type your password into a convincing fake page. Module 2 teaches you to spot these on sight.
Some website you signed up to years ago gets breached, and the password you used there was also your work password. Criminals feed old breach lists into login pages automatically. If it matches, they are in without sending you anything.
Updates mostly exist to patch security holes that criminals already know about. A laptop that has been snoozing its updates for months is advertising exactly which holes are still open.
The file shared with the whole internet instead of one client. The email sent to the wrong Karen. No villain required, just a busy Tuesday. Later modules cover the habits that catch these before they matter.
Here is how those doors combine into the attack that costs Australian small businesses the most. It is worth reading slowly, because every step is ordinary until the last one.
It looks like a Microsoft sign-in alert. Someone on the team is busy, clicks the link, and types their work password into a fake login page. Takes about twenty seconds.
The criminal now signs in to the real mailbox with the real password. If there is no second check like MFA, nothing stands in the way. No alarms, no broken glass.
They do not announce themselves. They read. Who pays invoices, who approves them, what the templates look like, which clients owe money. Patience is free.
A perfect copy of your real invoice lands with your real clients, from your real address, with one change: the bank details. The money goes to the criminal, and you find out when a client asks why you are chasing a bill they already paid.
Notice what did not happen anywhere in that story. No code was hacked, no firewall was breached, no genius was required. One person had one busy moment, and everything after that was just patience. Which is exactly why the fix is not more technology. It is the next unit.
Here is the part of security training nobody says plainly enough: the technology already catches most of it. Email filters bin the obvious rubbish, antivirus handles the known nasties, and the IT side quietly blocks thousands of attempts you never see. What gets through is the small, clever remainder that was crafted to fool a person. Which means the last line of defence is you, and honestly, a switched-on person is a better defence than any filter we can buy.
You do not need to become a security expert. You need one habit and one attitude.
Every scam depends on you acting fast. Urgent payment, account suspended, boss needs it now. The counter-move costs three seconds: pause, and ask whether this is normal. Unexpected invoice? Ring the supplier on the number you already have. Odd request from the boss? Check in person or by phone. A criminal can fake an email. Faking a phone call to a number they do not control is much harder.
People click things. Smart, careful people, on busy days. The difference between a near miss and a disaster is almost always speed: a click reported in five minutes is usually fixable, a click hidden for five days rarely is. So the deal in a healthy team is simple. Saying "I think I clicked something dodgy" gets you a thank you, never an eye-roll. Fast reporters save businesses. Quiet ones cost them.
Module 2: Spot the phish. The red flags in a dodgy email, the scam texts and calls that follow, and the invoice fraud you just read about, in detail.
Module 3: Passwords and MFA. Why one reused password can sink you, and the habits that make a stolen password nearly worthless.
Module 4: Devices and Wi-Fi. Lock screens, updates, public Wi-Fi and mystery USBs, at the office, at home, and at the airport.
Module 5: Share safely. Most data leaks are accidents: the wrong recipient, the too-open link. Easily fixed habits.
Module 6: When something looks off. Clicked the link? Lost the laptop? What to do in the first five minutes, when it matters most.
- Australian Cyber Security Centre: ASD Annual Cyber Threat Report 2024-25
- Australian Cyber Security Centre: Small business cyber security guide
- Australian Cyber Security Centre: Report a cybercrime or cyber security incident (ReportCyber)
The report frequency and cost figures in this module come from the Australian Signals Directorate's Annual Cyber Threat Report 2024-25 and were current at the time of writing (July 2026). The ASD updates these numbers each year, so check the report page for the latest.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. Why did cyber criminals come after your business in the first place?
2. Why is a work email account such a valuable prize for a criminal?
3. Which of these is a common way criminals actually get into a small business?
4. In the typical invoice fraud attack, what do criminals usually do right after stealing a login?
5. A teammate says "I think I just clicked something dodgy". What is the right response?