Perspective2026-07-30·5 min read

Be a Harder Target Than the House Next Door

Most cyber attacks are opportunistic, and attackers are on the clock. In June 2026 the median Australian small business scored an F on web security. Be the C.

Picture an opportunistic burglar scoping out your street. He gets to your place: security screens on the windows, a camera over the door, and a dog that goes from zero to a hundred the moment anyone comes within five metres of the front gate. Then he looks at the house next door. No screens, no camera, no dog, side gate open.

Picture an opportunistic burglar scoping out your street. He gets to your place: security screens on the windows, a camera over the door, and a dog that goes from zero to a hundred the moment anyone comes within five metres of the front gate. Then he looks at the house next door. No screens, no camera, no dog, side gate open.

Even a thoroughly sub-par criminal knows which house just moved up his to-do list. He's not assessing whether your place is impenetrable - it almost certainly isn't. He's assessing which house on the street costs him the least and risks him the least. That's the entire decision.

I spent part of my early career as a police intelligence officer, and the thing that stays with you from that work is how rarely opportunistic offenders behave like the criminal masterminds on television. They behave like contractors quoting a job. Effort in, payoff out, next address.

The burglar got a rebrand

In my industry we don't call them burglars. We call them "malicious actors", which sounds grander and bills better. Strip the jargon and the behaviour is the same trade: someone walking a street, checking for the soft option.

The difference is the street. An attacker's street is every domain on the internet, walked by automated scanners at a few thousand houses a second. And what those scanners see is exactly what our own quarterly scan sees - response headers, email authentication, the state of your public surface. Whether your digital dog is asleep is visible from the road.

That matters because - in everything I saw in intelligence work, and everything I've seen in thirty years of ICT since - most of what hits a small business is exactly this kind of drive-by. You weren't chosen. You were sorted - by a script, into a pile marked easy or a pile marked not worth it.

The economics of attacking a small business

Here's the part the fear-based sales pitches never mention: the people attacking you have a cost base. Crime, at this scale, is a business with margins.

Spend one hour gaining access to systems that yield a thousand dollars - that's a good business. Spend a thousand hours to make one dollar - that's a hobby, and a bad one. Nobody runs the second model, which means almost nobody is bringing a thousand hours of effort to a twelve-person accounting firm. They're bringing the scanner, the phishing kit and the list of unenforced domains, and they're moving on the moment your house looks dearer than the next one.

The easy pile pays well, too. ASD's Annual Cyber Threat Report 2024-25, released in October 2025, put the average self-reported cost of cybercrime for an Australian small business at $56,600 per report - up 14% in a year (ASD, Annual Cyber Threat Report 2024-25, 2025). One open gate covers a lot of one-hour jobs.

And the next one looks cheap. In June 2026, our Posture Research scan of 150 Australian small-business domains found a median web-security grade of F across the scored cohort, with only 43% enforcing DMARC (Red Bridge Cyber SMB Posture Baseline, June 2026). The street, in other words, is mostly houses with the side gate open. Against that field, you don't need to be a fortress. A boring, configured, C-grade public surface puts you ahead of most of the country - and an afternoon on the small-business basics gets you there.

The two questions everyone asks me

Am I wishing a break-in on my neighbour? Not at all. I'd rather the whole street was hard to rob - it's why we publish the research and the plain-English explainers instead of keeping the findings for paying clients.

Would I voluntarily let my own home be the one that gets done over, given the choice? No to that one too. And that's the honest shape of the decision every owner faces: you don't control how many attackers walk the street, and you can't fix the whole suburb. You control one thing - where your house sits in the sort order.

There's a name for this in security circles - raising the cost of attack - and it's about the least glamorous idea in the field. No threat-intelligence platform, no AI-powered anything. Just deadlocks and dogs, translated: enforce HTTPS, finish your DMARC, patch what you run, turn on multi-factor authentication. Make the quote for robbing you come in over budget.

Where the metaphor stops

I'll be straight about the limits, because this logic has one. Being harder than the neighbour works on opportunists, and opportunists are most - but not all - of the field. If you're specifically worth targeting - you hold unusually valuable data, you're a stepping stone into a defence supply chain, you've publicly fallen out with someone motivated - then the burglar isn't scoping the street anymore. He's scoping you, and the economics change. That's a different conversation, and pretending the neighbour trick covers it would be selling you comfort.

But for the corner clinic, the trades business, the twelve-person firm? The maths is the maths. The attacker has a budget. Your job is to be over it.

So how much cyber security does a small business need? Not the best in the world - anyone selling you that standard is selling to someone else's risk profile. Better than the house next door? At minimum. Should you set an uncomfortably high standard anyway, for your own sleep and your customers' data? That one's your call - but you already know which side of the street you'd rather live on.


Sources

#perspective#australian-business#small-business