Small business owners need help – not regulation – to battle growing cyber threats, industry groups say.
Business representatives addressed a cybersecurity inquiry at small and medium-sized enterprises in Canberra on Tuesday, as threats from artificial intelligence-assisted criminals continue to grow.
Plain-spoken government guidance and tax-breaks for security improvements could help protect entrepreneurs, policymakers heard.
Small businesses want help to become more cyber resilient. (Dan Peled/AAP PHOTOS)
The Australian Chamber of Commerce and Industry called for fewer regulations to ease business owners’ workloads.
Digital policy lead Ross Creelman said the problem was not a lack of cybersafety awareness.
“It is a capability and capacity problem,” he said.
“Our objective should be to help small businesses become more cyber resilient, rather than simply giving them more cyber reporting obligations.”
Labor MP Basem Abdo asked if the chamber considered mandated standards would protect suppliers and customers.
Mr Creelman said the desire for cybersecurity protections came from the realities of business.
“The biggest cost of non-compliance is not coming primarily from the government,” he said.
Any minimum requirements for small businesses must reflect an understanding of existing pressures on smaller businesses, he suggested.
Small businesses fall outside of many of the existent cyber-security standards upheld for companies of specific sizes and sectors.
The overwhelming majority of business owners fear they wouldn’t survive a cyber attack. (Dan Himbrechts/AAP PHOTOS)
But security is one of the most significant issue facing Australian businesses, Canberra Business Chamber CEO Greg Harford said.
The Australian Signals Directorate, overseeing national cybersecurity, estimated the average cost of cyber incidents to small businesses in 2024-25 was $56,000 – up 14 per cent year-on-year.
About 79 per cent of business owners surveyed by the Council of Small Business Organisations feared they would not survive a cyber attack.
The council’s chief executive Skye Cappuccio called for specific, plain-language guidance on safe AI adoption as a matter of urgency.
Chief operations officer William Harris said the government should back incident response initiatives to support business and not-for-profits during crises.
The council also urged the government to provide “plain-language” security baselines, government services and guidance on safe AI use.
It requested help in establishing industry associations as intermediaries for cybersecurity information.
COSBOA head Skye Cappuccio wants the government to back a new form of the Cyber Wardens program. (Mick Tsikas/AAP PHOTOS)
Mr Creelman further suggested the government could expand instant asset write-off benefits to intangible cyber-security capabilities.
Any write-offs could be pinned to the Australian Signals Directorate’s “Essential Eight” mitigation strategies for cyber threats.
The council on Tuesday also repeated calls for the government to restore funding for an axed Cyber Wardens security training program, free for businesses.
It ceased operating after funding was not extended in the latest federal budget.
The house select committee inquiry into small-to-medium business cyber security continues to examine existing practices and business’s needs.
Max Aldred and Jacob Shteyman
(Australian Associated Press)



