Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • Australian Government Launches Small Business Cybersecurity Guide
  • Technology

Australian Government Launches Small Business Cybersecurity Guide

Do Son January 12, 2018 4 minutes read
Small Business Cybersecurity
Add Daily CyberSecurity as a preferred source on Google

The Australian Government Small Business and Family Enterprise Ombudsman Panel ( ASBFEO ) recently released the Guide to Cyber Security for Small Business Cybersecurity – Best Practices Guide to Cybersecurity. This guide covers three steps of “self-protection” to help small business operators in Australia prevent or better respond to cyber-attacks and help the audience understand current risks and how to prevent cyber-attacks.

Small businesses will face more security threats

The guide cites a study released in early 2016 that said 43% of cybercriminal activities are targeted at small businesses.

The Ombudsman said that as a result of rampant WannaCry and Petya ransomware in 2017, 22% of small businesses have been unable to continue operations due to a serious attack, and another 60% of them are due to be significantly over the next six months Network security breach and closure.

According to another statistics, 87% of small businesses consider themselves very secure – because they are using anti-virus software.

Kate Carnell, Australia’s small business and family business inspector, argues that a significant portion of small businesses lack the time and resources and cybercriminals are becoming more complex, making them more vulnerable to such activities. Online threats are as real as physical threats and cybersecurity issues need to be taken seriously.

Carnell also said that small businesses should not be afraid of “going to the Internet,” because there are tremendous opportunities and benefits for development on the Internet. Many small businesses have successfully opened virtual stores and physical stores combined with the development, and thus establish a sustainable mode of operation

Network Security Best Practices Guide

This Guide to Cyber Security Best Practices provides three quick steps to “protect yourself”: prevention, improvement, and response:

  • Encourage small businesses to regularly back up, repair applications, adopt complex passwords and two-factor authentication, and restrict access to administrator accounts and sensitive information.
  • In order to “work in a safe manner,” this guide requires small businesses to regularly communicate security practices and discuss cyber-security issues in the workplace, while browsing secure websites and installing only trusted applications.
  • The guidelines emphasize: “If you think a cyber attack has occurred, notify your staff and report it to the authorities, and then use the backup copy before the incident to recover, and consider buying cyber security.”

Karell said at the Asian Security Conference in Sydney last year that many small and medium-sized businesses operating in Australia often mistakenly believe criminals will only target “large enterprises.” In fact, however, it is clear to cybercriminals that large enterprises have strong security systems, whereas small enterprises have various security weaknesses.

97% of Australian businesses are small businesses

In 2017, 30% of small businesses reported having experienced cybercrime, an increase of 109% over the previous year. Carnell said the actual figures will be staggering than this figure, so a considerable number of small businesses are more likely to choose to hide facts after being attacked.

Australia has a number of small businesses, the Ombudsman defines small businesses as businesses with fewer than 20 employees, and the Australian Tax Office gives a definition of a turnover of less than $ 10 million.

As of July 2017, 97% of Australia’s businesses are small businesses with fewer than 20 employees – meaning that the total number of employees in small businesses is around 2.1 million.

Carnell added that most small businesses do not have COOs, in-house lawyers or IT staff at all. Although these small businesses are aware of this issue, their cybersecurity capabilities are still seriously lacking. In addition, CEOs tend to actively conduct their daily business around their office systems, ignoring the importance of network protection. More seriously, many SMEs do not even know how to protect themselves. The Australian federal government has many different agencies in the area of cybersecurity, and small businesses often find it hard to ascertain their specific functions.

Source: zdnet

Related coverage

  • Fedora 29 makes BootLoaderSpec the default
  • Siri Restricts External URL Summarization in iOS 27 Beta
  • Collections Retired: Microsoft Edge Sunsets Research Tool Amid Data Loss Fears
  • GitHub Blocks New Outlook and Hotmail Sign-Ups
  • Security Shift: Google Retires Dark Web Report Service, Citing Inability to Offer Concrete Remedies
  • X (Twitter) Fights Link Frustration with a Feature Designed to Boost Engagement
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Small Business Cybersecurity

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-93674CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
  • CVE-2026-104334CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106501CVSS 9.6
    Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106414CVSS 9.6
    Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106329CVSS 9.6
    Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106239CVSS 9.6
    Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to...
    📅 Updated: Oct 6, 2026
  • CVE-2026-102322CVSS 9.6
    Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code...
    📅 Updated: Oct 6, 2026
  • CVE-2024-46484CVSS 9.8
    TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.