A supplier's security incident can leave a substantial hole in your accounts even when your own systems remain intact.
Queensland's Department of Customer Services, Open Data and Small and Family Business recorded a $809,000 loss arising from a July 2025 cyber incident, according to ABC News's report of 30 September 2026.
The department says its own systems were not compromised. Its account places the illegal access at a third-party telecommunications provider, and it says no Queensland Government data or sensitive information was compromised.
There is now some further detail: the current ABC report quotes a department spokesperson saying a third-party messaging service was misused to generate an inflated volume of unauthorised SMS messages for financial gain. That describes the service misuse; it does not establish the technical entry point or precisely how the $809,000 loss was calculated. There is no basis here to label the incident invoice diversion or business email compromise.
For a small-business owner, the useful lesson is already clear. The place where an incident starts and the business that carries its consequences can be different.
Your suppliers are inside the security boundary
Australian SMEs depend on other businesses to operate. Microsoft 365 or Google Workspace handles email and documents. A telco supplies communications. Other providers manage website hosting, DNS and domains, web development, accounting, payments, CRM, backups, managed IT and assorted SaaS platforms.
Outsourcing those functions is normal and often sensible. A capable specialist can provide better maintenance, availability and security than a small team could manage alone.
But every arrangement gives someone a particular relationship with your business. They may hold your customer information, administer your accounts, publish under your domain or operate a service that incurs charges on your behalf. That relationship needs boundaries.
Your attack surface includes the suppliers you trust as well as the systems you own.
Think of the security boundary as everything that can materially affect your systems, information or financial processes. It extends beyond the office router. A supplier does not need a login to your office network to create a business problem.
Ask what the supplier can actually do
“They look after our IT” is too vague to be useful during an incident.
I would start with one important supplier and ask what access it has, what data it can see and whether it holds administrator permissions. Then compare the answer with the actual accounts and integrations. Include delegated access, application permissions and recovery contacts, rather than counting only familiar usernames.
A web developer might need to publish content without reading customer mailboxes. An accountant might need financial records without access to every shared document. A managed IT provider may genuinely need broad privileges, but those privileges should have a defined purpose and an agreed way to withdraw them.
This is the practical application of least privilege: give the supplier enough access to deliver the work, and review that access when the work changes.
Ask about subcontractors too. If your provider delegates support, establish who else can reach your systems and whether the same access rules apply. The person you signed an agreement with may not be the person using the account.
Website hosting comes with divided responsibilities
Website arrangements are a good place to find assumptions that have never been written down.
The host may maintain the server while the developer maintains the application. The owner may control the domain, or the original agency may still hold it. Backups might exist in a separate service with a different administrator. Each arrangement can work, provided someone understands the whole picture.
My article on website security and developer access looks at how permissions accumulate across hosting, WordPress, DNS and deployment systems. A supplier access review should cover those connections together.
For a straightforward brochure website, simpler architecture can reduce the components and permanent privileges that need attention. A static site can remove the public CMS login and production database. Hosting, DNS, deployment credentials and external services still need protection and clear ownership.
Before accepting “security is included”, establish who patches what, who checks backups, who notices an unexpected change and who can restore the service. A hosting invoice rarely answers all four.
Notification needs an agreed process
Will the supplier tell you promptly if a breach could affect your business? Who receives that message, and what happens if your normal email service is unavailable?
These details belong in the arrangement before an incident. Ask for a clear notification timeframe, an emergency contact and a commitment to share information needed to assess your exposure. The first notice may be incomplete; it should still let you begin making decisions.
The Queensland Audit Office's March 2026 report, Managing third-party cyber security risks, provides broader context. It identified weaknesses in supplier access controls and found that only two of 36 contracts reviewed required third parties to report cyber security incidents and vulnerabilities.
The audit examined selected, unnamed entities. Those findings do not establish that the entities tested were involved in the $809,000 incident.
For an SME, the practical response is manageable: make reporting expectations explicit and decide who in your business will act on a warning. Ask what records the supplier can provide and how long they retain them. You may need to establish which accounts, services or data were affected before deciding what to disconnect.
Access needs an end date as well as a start date
An old supplier's credentials can survive long after everyone has forgotten the project.
When a relationship ends, can you revoke its access cleanly? An individual account is easier to remove than a shared owner password. API tokens, remote support tools and recovery addresses need attention too. Changing one password may leave several other routes open.
Plan the handover while the relationship is working. Keep business ownership of important accounts clear, confirm that somebody authorised can recover them, and agree how data will be exported. Find out what the provider retains afterwards, including backups, and when agreed deletion occurs. Removing access does not retrieve copies already held elsewhere.
There is also a continuity question. If you disconnect the supplier tomorrow, can staff still work, customers still contact you and the business still recover its information? Test a small, safe part of that handover before relying on it during a dispute or breach.
The same principle applies to private clients
Private-client and family-office-style environments rely on accountants, advisers, assistants, property managers, IT providers, smart-home installers and security providers. Their permissions can overlap across personal, household and business systems. Solway Web Consulting's personalised cybersecurity consulting for private clients in Sydney can include reviewing those relationships: who can access what, why they need it and how the family can remove access when responsibilities change.
Start with the supplier you would struggle to lose
You do not need a procurement department to improve this. Choose the provider whose interruption or misuse would cause the most trouble, then document its access, your emergency contact and the steps needed to regain control.
Have the provider review that record with you. Resolve one concrete gap, whether that is an unnecessary administrator account, an outdated recovery address or a missing notification agreement. Set a date to review it again. Solway Web Consulting's small-business cyber security checklist places that work alongside the other basics.
You can delegate technical work and still make informed decisions about the exposure it creates. A good supplier should be able to explain its responsibilities, the access it needs and what you can expect when something goes wrong.
Start by asking for that explanation.
Tags: security, small-business, private-client, australia