Skip to content
Business owner reviewing a cybersecurity readiness dashboard that highlights SMB1001 control areas, symbolising the shift from “too small to target” denial to clear risk awareness.
Cyber security Business Practices

Are You in the 38%? Most SMEs Think They're Too Small to Hack

Dale Jenkins
Dale Jenkins

More than one in three Australian small businesses — 38%, to be exact — believe they're too small to be worth a hacker's time. It's a comforting thought. It's also, according to the data, dangerously and absolutely wrong.

The Denial Problem Is Bigger Than You Think

Recent research reported by Inside Small Business found that a significant share of SMEs are in denial about their cyber exposure, incorrectly assuming their size makes them invisible to attackers.

This isn't an isolated finding — separate reporting from ARN found only 40% of Australian small businesses actively prioritise cyber security at all, meaning the majority are either unaware of their risk or simply not acting on it.

Attackers don't discriminate by revenue; they discriminate by weak points, and small businesses without formal security controls are exactly that.


Why "Too Small to Target" Is a Myth

Small businesses are more attractive to attackers, not less.

Typically, they hold valuable client data, banking details, and supply chain access, but rarely have dedicated security staff or monitoring in place to catch an intrusion before damage is done.

Without an objective benchmark, most business owners have no real way of knowing whether they're actually secure or just lucky so far — which is precisely the gap the SMB1001 standard was built to close.

What SMB1001 Actually Checks

SMB1001 is Australia's purpose-built cyber security certification for small and medium businesses, structured around five practical domains:

  1. Technology Management – firewalls, antivirus, patching, and device security
  2. Access Management – multi-factor authentication, password hygiene, and user permissions
  3. Backup & Recovery – data backup frequency, testing, and recovery capability
  4. Policies & Processes – documented incident response and risk management practices
  5. Education & Training – staff awareness of phishing and social engineering

The standard is tiered from Bronze through to Diamond, so businesses can start at a level that matches their current maturity and build up over time rather than facing an all-or-nothing compliance burden.

For most SMEs, the real value isn't the certificate itself — it's finally seeing, in plain terms, which of these five areas are exposed.


Find Out Where You Stand

You don't need to guess whether you're in the 38%!

Microsolve has built two ways to get a clear answer, depending on how deep you want to go right now.

  • Option 1: Take the free SMB1001 Security Check (2 minutes)
    Answer a short set of questions about your current setup and get an instant, personalised snapshot of your SMB1001 readiness — plus your likely starting tier.
  • Option 2: Book a full SMB1001 Readiness Assessment (20 minutes)
    Skip the guesswork and speak directly with a Microsolve advisor for a proper gap assessment against the SMB1001 domains, with a clear roadmap to certification.

Whichever you choose, you'll walk away knowing exactly where your business stands — instead of hoping you're the exception to the 38%.

Share this post