The .au Domain Administration (auDA), the administrator of the .au domain name system, has issued its sixth annual Digital Lives of Australians report, finding that the cyber security confidence of SMBs is limited and that small business size is fuelling false perceptions and cyber security risk.
Digital Lives is an annual research study, conducted by auDA since 2021, into the online experiences of Australian consumers and small businesses.
Just over a third of SMBs have no idea how much they spend on cybersecurity, indicating it is not always a visible or strategic budget line, the report stated. Of those who do know what they’re spending, the median is $500, up from $300 last year.
Most SMBs, despite the evolving threat landscape, also have no plans to increase their cybersecurity spend, with just one in five indicating they will devote more budget to it compared to 65% of respondents who said they expect to maintain current spend when looking ahead.
"Many small businesses acknowledge gaps between concerns about cyber security and workforce capability. Cyber security practices tend to be reactive, ad hoc and dependent on external support," the report stated.
"They recognise the importance of strong cyber security practices but report uncertainty around best-practice implementation, and investment in cyber security varies widely."
Those SMBs that have employed a dedicated or external IT consultant tend to have more measures in place, with survey findings this year highlighting the cost and time barriers that prevent small businesses from implementing cyber security measures.
Over half (51%) of small businesses that did not provide staff with regular cyber security training but were interested in doing so said cost was a barrier, and 39% didn’t have the time to organise this.
Size fuelling false perceptions and cyber risk
The report also found that despite nearly all small businesses holding personal or sensitive business data, few are confident they can protect this data against increasingly sophisticated cyber threats.
Despite this, those that hold personal identification documents for employees, clients or suppliers were found to be more likely to talk about cyber security with others in the business (43% vs 22% of all SMBs); provide staff with cyber security training (36% vs 18% of all SMBs); have a documented cyber security policy (29% vs 15% of all SMBs); and have an incident response plan (29% vs 16% of all SMBs).
Almost half of small businesses surveyed feel helpless against cyber security threats on the basis their limited resources pale in comparison to larger corporate organisations that have fallen victim to cyber criminals.
At the same time, two in five believe they do not need to worry about cyber criminals, believing they won’t be targeted by cyber criminals due to their small size.
Looking at the overlap between these attitudes, 52% of those who think their business is too small to be a target also feel they are powerless to stop cyber attacks due to their small size.
When the topic was raised in qualitative discussion, many noted they were unaware that attacks against small business by cybercriminals are often fully automated, with thousands of businesses being attacked at the same time, regardless of business size.
In 2026, the Digital Lives report comprised of an initial qualitative phase comprising in-depth interviews and focus groups, as well as a survey completed by 408 small business owners or managers, encompassing sole traders, micro businesses and small businesses.




