Skip to content
Contact us
  • About Us
  • Services
    • Managed IT Support
    • Business IT Support
    • Cyber Security & Risk Management
      • Firewall Solutions
      • End Device Security Solutions
      • Device and Patch Management Services
      • Cyber Security Risk Assessments
      • Incident Response Planning
      • Cybersecurity Training and Policy Development
    • Business Telephone Systems
  • Blog
  • About Us
  • Services
    • Managed IT Support
    • Business IT Support
    • Cyber Security & Risk Management
      • Firewall Solutions
      • End Device Security Solutions
      • Device and Patch Management Services
      • Cyber Security Risk Assessments
      • Incident Response Planning
      • Cybersecurity Training and Policy Development
    • Business Telephone Systems
  • Blog
Contact us

ACSC 2024–25 Annual Cyber Threat Report: Key Takeaways for Tasmanian SMEs


Introduction


The Australian Cyber Security Centre (ACSC) has released its Annual Cyber Threat Report 2024–25, offering a comprehensive overview of the current cyber threat landscape. This report highlights that malicious cyber activity remains a persistent and costly problem for Australians, affecting individuals and businesses in terms of frequency, financial impact and severity. Small and medium businesses (SMEs) in Tasmania should pay close attention to these findings, as they underscore the importance of strong cyber security practices even for businesses in smaller markets. Despite Tasmania’s size, local businesses are not immune to cyber threats – Tasmania accounted for about two per cent of all cybercrime reports nationally in FY2024–25, which still represents a significant number of incidents. Below, we outline the key findings from the report and what they mean for Tasmanian SMEs, along with practical steps to strengthen your cyber security.


Key Findings from the 2024–25 Threat Report


The ACSC Annual Cyber Threat Report 2024–25 reveals several important trends and statistics about cyber threats in Australia over the last financial year:

  • High volume of cybercrime reports: Over 84,700 cybercrime reports were submitted to the ACSC in FY2024–25 (about one report every 6 minutes). This rate is roughly consistent with the previous year, indicating that cyber incidents continue to be reported at a steady, frequent pace.
  • Increase in cyber security hotline calls: The ACSC received over 42,500 calls to the Australian Cyber Security Hotline, a 16% increase from the previous year. This suggests that more businesses and individuals are seeking help or reporting cyber incidents, reflecting heightened awareness and possibly a growing number of issues being encountered.
  • Rise in serious incidents: The ACSC responded to over 1200 cyber security incidents during FY2024–25, which is an 11% increase in incidents from the prior year. This uptick indicates that serious cyber attacks (those warranting ACSC response) are becoming more frequent.
  • Surge in threat notifications: Perhaps most striking, the ACSC notified entities more than 1700 times about potentially malicious cyber activity, an 83% increase compared to last year. This sharp rise in notifications highlights an ongoing need for vigilance, as attackers are increasingly active and being detected more often on Australian networks. It underscores that businesses need to stay alert and responsive to cyber threats at all times.
  • Escalating financial impact: Cyber incidents are becoming more costly for businesses. The average self‑reported cost of a cybercrime incident for Australian businesses jumped by 50% over the year, reaching roughly $80,000 per incident on average. Notably, small businesses saw an average cost of about $55,600per incident (a 14%increase from last year), while medium businesses faced about $97,200 dollars per incident (a 55% increase). This trend shows that the financial impact of cyber attacks on SMEs is growing significantly, potentially threatening their profitability and even viability. By contrast, the average cost per incident for individuals was around $33,000, highlighting that businesses tend to suffer much greater losses when breaches occur.
  • Persistent ransomware and fraud threats: The report notes that ransomware remains a prevalent threat, accounting for roughly 11% of all cyber incidents the ACSC responded to, a figure consistent with last year. Meanwhile, identity fraud continued to be the most reported type of cybercrime (about 8% of reports, and increasing). Other common threats included business email compromise, phishing and scams, which continue to target businesses and individuals alike.

Overall, these findings portray a cyber threat environment that is active and evolving. Attackers, ranging from organised cybercriminal groups to state‑sponsored hackers are not relenting. The increase in calls, incidents and especially notifications of threats suggests that while detection and reporting have improved, the sheer volume of malicious activity is growing. For Tasmanian SMEs, the key takeaway is that cybersecurity risks are very real and growing, even if you are a smaller organisation or located outside major population centres.


Evolving Threat Landscape: Cybercriminals and State Actors


The ACSC report underscores that both state‑sponsored actors and cybercriminal syndicates continue to pose serious threats to Australian organisations:

  • State‑sponsored threats: State‑sponsored cyber actors (often linked to foreign governments) are identified as a serious and growing threat to Australia. These adversaries target networks across government, critical infrastructure and businesses to advance their strategic goals. They may seek to steal sensitive data, disrupt critical services or gain a strategic foothold in our networks. While their primary targets might be government agencies or large infrastructure operators, businesses of all sizes (including SMEs) can become collateral targets or entry points into larger supply chains. The message for businesses is that a heightened threat environment exists due to global cyber espionage and cyber warfare activities.
  • Cybercrime trends: On the criminal side, the report confirms that cybercrime is causing greater economic and social harm. It notes that average financial losses, the frequency of ransomware attacks and the number of reported data breaches all increased throughout FY2024–25. In other words, cybercriminals are succeeding in causing more damage. Ransomware attacks and data breaches have become more frequent, and the costs of these crimes are rising for victims (as seen in the cost statistics above). This aligns with recent high‑profile cyber incidents in Australia and globally, where businesses have suffered severe losses from ransomware or had sensitive customer data stolen.
  • Credential theft and fraud: One tactic highlighted is an aggressive campaign of credential theft by cybercriminals. Attackers are actively purchasing stolen login credentials (usernames and passwords) on the dark web and using them to break into email, social media, banking and other accounts. For businesses, this means that poor password practices or reused passwords can easily lead to breaches. A single compromised password could allow hackers to infiltrate a company’s network, leading to fraud or further attacks. This trend underlines the importance of practices like strong, unique passwords and multi‑factor authentication for all business accounts.

In summary, the threat landscape described in the report is one where sophisticated adversaries (like state‑sponsored hackers) and opportunistic cybercriminals are both active. They are exploiting any vulnerabilities available; whether technical weaknesses or human factors; to achieve their objectives, be it espionage, financial theft or disruption. Tasmanian SMEs should not assume that they are too small or geographically removed to be noticed. In fact, automated scanning and mass‑scale attacks can strike anywhere, and smaller businesses are often seen as softer targets. The significant increase in ACSC notifications (over 1700 alerts, up 83%) implies that many organisations, possibly including SMEs, were found to have malicious activity in their systems. Being complacent is no longer an option.


What This Means for Tasmanian Businesses


For business owners and managers in Tasmania, the ACSC report’s findings carry some clear implications:


1. Cyber security is a business priority. The rising number of incidents and the growing costs associated with them mean that cyber security deserves urgent attention at the executive level. Even if your business has not experienced a major cyber event yet, the trends suggest that the risk is increasing. A successful ransomware attack or major data breach could potentially cost tens of thousands of dollars (or more) in damages, not to mention reputational damage and operational downtime. Investing in preventative measures now is far cheaper than dealing with the fallout of an incident later.


2. SMEs are targeted. While large enterprises and government agencies often make headlines, SMEs are very much in the firing line. Cybercriminals often view smaller businesses as attractive targets because they may have weaker defences and valuable data. The fact that *small and medium businesses saw significant increases in average loss per incident* (up 14% and 55% per cent respectively) indicates that attackers are succeeding against businesses like yours. Additionally, with Tasmania contributing a share of national cybercrime reports, we know incidents are happening here. SMEs should not assume “it won’t happen to us”, the data shows it can and does happen, in Tasmania and across the country.


3. Vigilance and reporting are critical. The ACSC’s steep increase in threat notifications (more than 1700 instances of malicious activity detected) highlights that many attacks are being discovered. Businesses need to remain vigilant for signs of compromise, such as unexpected system behaviour, suspicious emails or reports of credential leaks. Importantly, if a cyber incident or suspicion occurs, it should be reported to authorities such as ReportCyber or the ACSC. Reporting not only helps you get support, but also helps law enforcement and ACSC track threats and alert others. Early reporting can potentially limit damage and lead to broader community warnings.


4. State actors and supply chain risks. While your SME might not be “critical infrastructure,” the report’s emphasis on state‑sponsored actors is a reminder that national‑level threats can trickle down. Supply chain attacks are one example: a state hacker might target a small software vendor in Tasmania as a way to eventually access a bigger target. Additionally, certain sectors (like healthcare providers, even small clinics) might be targeted for the data they hold. If your business is part of a supply chain for larger companies or government projects, recognise that you could be targeted as an entry point. In any case, following best practices will help protect you against both indiscriminate cybercriminal attacks and more targeted threats.


How to Improve Your Cyber Security: Practical Steps


The good news is that many cyber attacks can be prevented or mitigated by implementing basic security practices. The ACSC report reinforces the message that “the basics” are often the most effective defence. In fact, the ACSC notes that simple security measures could prevent the majority of incidents reported. Here are some practical steps Tasmanian SMEs should take right away to bolster their cyber security:

  • Enable multi‑factor authentication (MFA): Turn on MFA for all important accounts and systems (email, banking, IT admin logins, remote access, etc.) wherever possible. MFA adds an extra verification step (such as a code from your phone) and significantly reduces the chance of unauthorised access, even if passwords are compromised.
  • Use strong, unique passwords or passphrases: Ensure that all passwords are long, complex and unique to each account. Consider using passphrases (a string of random words) which are easier to remember but hard to crack. Never reuse passwords across different services. Using a reputable password manager can help generate and securely store unique passwords for all your accounts.
  • Keep software updated: Regularly install updates and security patches for your operating systems, software applications and devices (including computers, phones and networking gear). Outdated software is a common way attackers exploit businesses. Where possible, enable automatic updates so you don’t miss critical patches.
  • Be alert for phishing and scams: Educate yourself and your employees about phishing emails or messages, which are attempts to trick you into giving away credentials or clicking malicious links. Scammers often impersonate trusted entities or create a sense of urgency. Always verify unexpected requests, and train staff to recognise common scam tactics. When in doubt, don’t click links or provide information; contact the supposed sender through a trusted channel instead.
  • Regularly back up important data: Maintain regular backups of your critical business data, and keep at least one backup copy offsite or in the cloud, disconnected from your main network. Backups ensure that even if your data is encrypted by ransomware or wiped, you can restore your information and keep your business running. Test your backups periodically to make sure they can be restored successfully.
  • Report incidents and seek help: If your business experiences a cyber incident (even a minor one), report it to the appropriate authorities such as ReportCyber (the national portal for cybercrime reporting) or contact the ACSC. Early reporting can get you the help you need and can contribute to broader threat intelligence. Additionally, don’t hesitate to seek professional cyber security advice for your business. For example, consulting with an IT security provider or utilising government resources aimed at small businesses.

By implementing these steps, even small businesses with limited IT resources can dramatically reduce their risk. The ACSC emphasises that basic cyber hygiene can prevent the majority of cyber incidents. In other words, doing these few things diligently puts you in a much safer position against the most common threats.


Conclusion


The ACSC 2024–25 Annual Cyber Threat Report makes it clear that cyber threats are not abating, they are an ongoing challenge that is increasing in many respects (frequency, cost, sophistication). Tasmanian small and medium businesses must take these findings to heart. While the digital economy offers great opportunities for growth and efficiency, it also comes with risks that cannot be ignored. Businesses that invest time and resources in cyber security preparedness will be far better positioned to avoid incidents or withstand them if they occur.


Crucially, improving cyber security doesn’t always require huge budgets or deep expertise; as the report suggests, start with the fundamentals: secure your accounts with MFA and strong passwords, keep your systems updated, educate your team and back up your data. These steps provide a solid foundation and are often enough to thwart the majority of attacks by opportunistic criminals. For more advanced guidance, the ACSC and Tasmania’s local business support organisations (like Business Tasmania) offer resources tailored for SMEs to uplift their cyber resilience.

In this heightened threat landscape, organisations that are proactive in implementing best practices and fostering a culture of cyber awareness, will greatly reduce their risk of becoming the next victim. The ACSC report ultimately delivers a dual message: the threats are real and growing, but with knowledge and proactive measures, we can organise and defend ourselves effectively. As a Tasmanian business owner, staying informed and vigilant is key. Cyber security is now an essential part of business responsibility, as fundamental as financial management or workplace safety. By taking the warnings from the 2024–25 report seriously and acting on the recommended precautions, SMEs can continue to thrive securely in the digital age.



For further reading, you can download the full ACSC Annual Cyber Threat Report 2024–25 here.

For Info about how Emerge Business Solutions can help, click Here


This Article was produced by Brady Clements, for More info on Brady see his LinkedIn profile here


3/94 Central Ave, Derwent Park TAS 7009

© 2024 Emerge Business Solutions.
All Rights Reserved.

3/94 Central Ave, Derwent Park TAS 7009

© 2024 Emerge Business Solutions.
All Rights Reserved.