New Zealand's Cyber Smart Week runs from 5–11 October 2026. The National Cyber Security Centre's new SME research gives business owners a useful reason to look beyond the awareness campaign and ask what actually needs fixing.
Its 2026 SME Cyber Security Behaviour Tracker found that 43% felt their organisation was vulnerable to cyberattacks, up from 34% in 2025. That measures perceived vulnerability; greater awareness could contribute to the rise. It does not establish that businesses have become less secure.
53% reported experiencing a cyber threat or attack in the preceding six months, rising to 76% among businesses with 20–49 full-time-equivalent employees. The category includes scam calls and phishing, so it should not be read as a count of successful breaches. Among affected businesses in that 20–49 group, 44% reported moderate or severe impact.
These are New Zealand findings, not Australian statistics. The survey covered 373 SME decision-makers in businesses with 0–49 full-time-equivalent employees.
The problems will nevertheless look familiar to Australian owners. A stolen mailbox, a redirected invoice or an inaccessible customer database can interrupt a working week on either side of the Tasman.
Australia's ACSC small business cyber security guide starts with three practical measures: multi-factor authentication, software updates and backups. It also covers phishing, account access and staff awareness. There is plenty a business can do before buying another security subscription.
What could realistically ruin Monday morning?
Small-business cybersecurity does not need to look like cybersecurity for a bank.
A five-person company can lose interest quickly when the conversation starts with frameworks, acronyms, dashboards and a long compliance programme. Even sensible advice becomes difficult to use when nobody explains which job should happen first.
I would start with a less impressive question: what could realistically ruin Monday morning?
Perhaps the owner cannot get into email. A customer has paid an invoice into a criminal's bank account. The domain registrar account has been stolen and both the website and email are affected. Ransomware has locked the shared files, and the backup turns out to be unusable.
Or the old contractor still has administrator access. Nothing has happened yet, but nobody knows who is responsible for that account.
Those are specific business problems. You can work out what would prevent them, who needs to act and how to check the result.
Make a short list before making a purchase
Write down the systems the business depends on: email, accounting, payments, customer records, shared documents, bookings, website and domain. Include the services managed by suppliers.
For each one, establish who owns the account, who has administrator access, what important data it holds and how you would recover it. Ask what happens if it stops working, if someone changes it, or if its contents are copied.
That last distinction matters. Recovering a stolen customer file from backup does not undo its disclosure.
Put the consequences into ordinary language. “We cannot take bookings.” “Someone could change payment instructions.” “Our clients' confidential documents could be exposed.” Then consider how easily each failure could happen under the current arrangements.
A shared email administrator password with no MFA deserves prompt attention. So does an exposed, unsupported service. An optional dashboard can usually wait. Security software and specialist help may be necessary; their purpose should be clear before the invoice arrives.
Spend the first cybersecurity dollar on the failure most likely to hurt the business, not the product with the best marketing.
Give the first few fixes an owner and a finish date. “Check backups” is a reminder. “Restore the booking data to a safe test location and confirm we can use it” is a job somebody can finish. Revisit the list when staff, suppliers or systems change.
Protect the accounts that control everything else
One compromised identity can cause disproportionate damage. Business email may hold invoices, private correspondence and password-reset messages for other services.
Check Microsoft 365 or Google Workspace administration, the domain registrar, hosting, accounting and the email used for banking correspondence. Confirm that the business controls the accounts and their recovery methods. An account registered to a former employee's personal address is an ownership problem as well as a security problem.
Enable MFA, use unique passwords and check which sign-in methods the important services support. My guide to stronger MFA and account protection explains the options, including phishing-resistant methods. Recovery needs attention too: losing a phone should not leave the business permanently locked out.
Review administrator lists with the people who use the systems. Remove stale access once dependencies are understood, and give current staff only the access their work requires.
For payment-detail changes, agree a separate verification step. Call a known contact using a number already on file. Replying to the same email thread does not establish that the request is legitimate if somebody controls the mailbox.
A simpler website can mean fewer security jobs
This is where cybersecurity overlaps with the web work at Solway Web Consulting.
A five-page business website may not need PHP, a live database, a CMS administrator panel, a plugin ecosystem or a permanent public login. Keeping those components creates maintenance responsibilities, including server-side application patching, whether or not the business uses their capabilities.
A suitable static architecture can remove that public application runtime and reduce the attack surface. The website review and migration service includes assessing whether a simpler build would suit the site's actual requirements.
Static does not mean unhackable. Hosting, DNS, deployment credentials, build dependencies, third-party scripts, forms and account security still need care. The useful question is which components earn their place. Unnecessary complexity brings unnecessary maintenance and security responsibility.
Find out whether the backup works
Having a backup is not the same as knowing it restores.
Is there more than one copy of the important data? Is one protected from changes or deletion through the primary system? Has anybody restored from it recently?
Choose a safe test that does not overwrite live information. Open the recovered files and check whether the business has the software, settings and credentials needed to use them. Record how long it takes and what is missing.
A successful document restore is useful evidence, but it does not prove that an entire accounting or booking system can recover. The test should reflect the failure you are trying to survive.
Staff need permission to speak up
The NZ tracker found 32% of SMEs took no action to train or upskill staff in cybersecurity.
An annual presentation is not much help if somebody clicks a suspicious link on Tuesday and spends the afternoon worrying about being blamed.
Use a short conversation about the work people actually do. Who should they contact after an unexpected login prompt? What should they do if they have entered a password on a suspicious page? How are changed bank details checked? Who covers the usual contact's day off?
Make it clear that reporting a mistake quickly is helpful. Practise with an example invoice or message, and leave the contact details somewhere accessible when email is unavailable. Technical controls still matter; staff should not have to identify every convincing fake unaided.
A report does not require a catastrophe
In the NZ tracker, 68% of affected SMEs reported or disclosed the incident, leaving roughly a third who did not. This is broader than reporting to authorities. Among non-reporters, common reasons were that the issue seemed too small or reporting seemed pointless.
New Zealand businesses can use the NCSC reporting page and select the individuals and small-business route. Australian businesses can report cybercrime or a cyber security incident through ReportCyber on cyber.gov.au.
Reporting an issue is not the same as publicly announcing a catastrophic breach. The NCSC explains that reports help it identify threats and warn others. A smaller incident can contribute to recognising a wider campaign.
Keep a brief record of what happened, when it happened and which accounts or payments were involved. If money has moved, contact the bank promptly as well. My article on patching and incident response covers why fixing the immediate weakness does not settle what happened beforehand.
Start with the environment you actually have
The same prioritisation works for private clients and high-net-worth households. Start with primary email, Apple, Google and Microsoft accounts, banking, cloud documents, family devices and the home network. Include assistants and advisers with access, and check recovery arrangements. The useful first question is what needs protecting and who can reach it.
At Solway Web Consulting, a practical review means understanding that real environment, identifying the biggest risks and fixing consequential gaps without adding unnecessary complexity or spending.
If you are unsure where to start, an inventory and a short list of what would hurt most if it failed are usually useful first steps. The small-business cyber security review describes that work for Sydney businesses. Wherever your business operates in Australia or New Zealand, that list should give the next security job a clear purpose.
Tags: security, small-business, consulting, australia