Skip to Content

Module 1 - What attackers actually want from your business

Staying Safe Online

What attackers actually want from your business

⏱ About 12 minutes

“We’re too small to be a target” is the most expensive sentence in New Zealand small business. Attacks are automated and indiscriminate. Being small does not make you invisible — it often makes you cheaper to attack and less likely to have strong defences.

Learning focus

  • Understand what criminals are actually after
  • See why small businesses are structurally vulnerable
  • Prioritise the six controls that address most realistic risk

The four things they are actually after

Target How it is used Typical cost to a small NZ business
Your email account Watch invoicing, intercept or redirect payments, or email your customers as you. Often the single most damaging event. Losses commonly reach tens of thousands plus trust damage.
Your bank access Direct transfers or added payees. Immediate. Business reimbursement rules are weaker than for consumers.
Your data Encrypt and demand payment (ransomware), or sell customer records. Days of downtime; possible notifiable privacy breach.
Your identity and reputation Impersonate your business to defraud customers and suppliers. Hardest to recover from — your customers experience the fraud.
🇳🇿 The New Zealand picture

The NCSC regularly reports hundreds of incidents each quarter with multi-million-dollar direct losses. Phishing and credential harvesting remain among the largest categories. A small number of high-value incidents account for the vast majority of reported financial loss — attackers actively pursue businesses with money moving through email.

Under-reporting among small businesses is significant, so the real figures are higher.

Why small businesses are structurally vulnerable

  • No dedicated IT function. Security becomes “whoever is least busy”.
  • Shared logins. One account used by several people destroys accountability and clean off-boarding.
  • Everything lives in email. Quotes, invoices, bank details and contracts sit in mailboxes.
  • Trusted supplier relationships. An email that looks like it comes from a regular supplier is rarely questioned.
  • Unclear escalation. Staff who suspect something often stay quiet, and delay turns an incident into a loss.

The honest priority order for a small NZ business

Fix these in roughly this order and you address the overwhelming majority of realistic risk:

  1. Multi-factor authentication on email — blocks the majority of account takeovers. Costs nothing.
  2. A verification rule for any change to bank details — stops the most common high-value fraud.
  3. Tested backups that include an offline or immutable copy — turns ransomware from existential to recoverable.
  4. Unique accounts per person, removed promptly when people leave.
  5. Automatic updates on devices and browsers.
  6. A one-page written plan for who to call when something happens.

Four of these six cost little more than a decision and some consistency.

⚠ Insurance and contracts

Cyber insurance policies increasingly require MFA and tested backups. Claims can be declined if basic controls were missing. Larger customers and government contracts now routinely ask security questions in procurement. Being able to answer them is becoming a sales requirement as well as a risk control.

✅ Do this week
  • List every system the business depends on and who has access to each.
  • Identify the one mailbox whose compromise would do the most damage — secure it first.
  • State the no-blame reporting rule clearly to the team.
Key takeaways
  • Attacks are automated — size does not equal invisibility.
  • Email compromise is the top practical threat because money and trust flow through email.
  • Six controls cover most realistic risk; four of them are essentially free.
  • Culture (no-blame reporting) multiplies the value of every technical control.
Need a hand putting any of this in place? Syntralyn Technologies021 406 293 · Enquiry@syntralyntech.nz · syntralyntech.nz

Rating
0 0

There are no comments for now.

to be the first to leave a comment.