Module 1 - What attackers actually want from your business
What attackers actually want from your business
“We’re too small to be a target” is the most expensive sentence in New Zealand small business. Attacks are automated and indiscriminate. Being small does not make you invisible — it often makes you cheaper to attack and less likely to have strong defences.
Learning focus
- Understand what criminals are actually after
- See why small businesses are structurally vulnerable
- Prioritise the six controls that address most realistic risk
The four things they are actually after
| Target | How it is used | Typical cost to a small NZ business |
|---|---|---|
| Your email account | Watch invoicing, intercept or redirect payments, or email your customers as you. | Often the single most damaging event. Losses commonly reach tens of thousands plus trust damage. |
| Your bank access | Direct transfers or added payees. | Immediate. Business reimbursement rules are weaker than for consumers. |
| Your data | Encrypt and demand payment (ransomware), or sell customer records. | Days of downtime; possible notifiable privacy breach. |
| Your identity and reputation | Impersonate your business to defraud customers and suppliers. | Hardest to recover from — your customers experience the fraud. |
The NCSC regularly reports hundreds of incidents each quarter with multi-million-dollar direct losses. Phishing and credential harvesting remain among the largest categories. A small number of high-value incidents account for the vast majority of reported financial loss — attackers actively pursue businesses with money moving through email.
Under-reporting among small businesses is significant, so the real figures are higher.
Why small businesses are structurally vulnerable
- No dedicated IT function. Security becomes “whoever is least busy”.
- Shared logins. One account used by several people destroys accountability and clean off-boarding.
- Everything lives in email. Quotes, invoices, bank details and contracts sit in mailboxes.
- Trusted supplier relationships. An email that looks like it comes from a regular supplier is rarely questioned.
- Unclear escalation. Staff who suspect something often stay quiet, and delay turns an incident into a loss.
The honest priority order for a small NZ business
Fix these in roughly this order and you address the overwhelming majority of realistic risk:
- Multi-factor authentication on email — blocks the majority of account takeovers. Costs nothing.
- A verification rule for any change to bank details — stops the most common high-value fraud.
- Tested backups that include an offline or immutable copy — turns ransomware from existential to recoverable.
- Unique accounts per person, removed promptly when people leave.
- Automatic updates on devices and browsers.
- A one-page written plan for who to call when something happens.
Four of these six cost little more than a decision and some consistency.
Cyber insurance policies increasingly require MFA and tested backups. Claims can be declined if basic controls were missing. Larger customers and government contracts now routinely ask security questions in procurement. Being able to answer them is becoming a sales requirement as well as a risk control.
- List every system the business depends on and who has access to each.
- Identify the one mailbox whose compromise would do the most damage — secure it first.
- State the no-blame reporting rule clearly to the team.
- Attacks are automated — size does not equal invisibility.
- Email compromise is the top practical threat because money and trust flow through email.
- Six controls cover most realistic risk; four of them are essentially free.
- Culture (no-blame reporting) multiplies the value of every technical control.
What attackers actually want from your business
“We’re too small to be a target” is the most expensive sentence in New Zealand small business. Attacks are automated and indiscriminate. Being small does not make you invisible — it often makes you cheaper to attack and less likely to have strong defences.
Learning focus
- Understand what criminals are actually after
- See why small businesses are structurally vulnerable
- Prioritise the six controls that address most realistic risk
The four things they are actually after
| Target | How it is used | Typical cost to a small NZ business |
|---|---|---|
| Your email account | Watch invoicing, intercept or redirect payments, or email your customers as you. | Often the single most damaging event. Losses commonly reach tens of thousands plus trust damage. |
| Your bank access | Direct transfers or added payees. | Immediate. Business reimbursement rules are weaker than for consumers. |
| Your data | Encrypt and demand payment (ransomware), or sell customer records. | Days of downtime; possible notifiable privacy breach. |
| Your identity and reputation | Impersonate your business to defraud customers and suppliers. | Hardest to recover from — your customers experience the fraud. |
The NCSC regularly reports hundreds of incidents each quarter with multi-million-dollar direct losses. Phishing and credential harvesting remain among the largest categories. A small number of high-value incidents account for the vast majority of reported financial loss — attackers actively pursue businesses with money moving through email.
Under-reporting among small businesses is significant, so the real figures are higher.
Why small businesses are structurally vulnerable
- No dedicated IT function. Security becomes “whoever is least busy”.
- Shared logins. One account used by several people destroys accountability and clean off-boarding.
- Everything lives in email. Quotes, invoices, bank details and contracts sit in mailboxes.
- Trusted supplier relationships. An email that looks like it comes from a regular supplier is rarely questioned.
- Unclear escalation. Staff who suspect something often stay quiet, and delay turns an incident into a loss.
The honest priority order for a small NZ business
Fix these in roughly this order and you address the overwhelming majority of realistic risk:
- Multi-factor authentication on email — blocks the majority of account takeovers. Costs nothing.
- A verification rule for any change to bank details — stops the most common high-value fraud.
- Tested backups that include an offline or immutable copy — turns ransomware from existential to recoverable.
- Unique accounts per person, removed promptly when people leave.
- Automatic updates on devices and browsers.
- A one-page written plan for who to call when something happens.
Four of these six cost little more than a decision and some consistency.
Cyber insurance policies increasingly require MFA and tested backups. Claims can be declined if basic controls were missing. Larger customers and government contracts now routinely ask security questions in procurement. Being able to answer them is becoming a sales requirement as well as a risk control.
- List every system the business depends on and who has access to each.
- Identify the one mailbox whose compromise would do the most damage — secure it first.
- State the no-blame reporting rule clearly to the team.
- Attacks are automated — size does not equal invisibility.
- Email compromise is the top practical threat because money and trust flow through email.
- Six controls cover most realistic risk; four of them are essentially free.
- Culture (no-blame reporting) multiplies the value of every technical control.
There are no comments for now.