tech
Brisbane's Cyber Security Conundrum: Most SMEs Still Flying Blind as Threat Landscape Worsens
Only one in five local businesses has formal cyber training, even as AI-powered attacks and ransomware push average losses past $49,000 a year.
How we reported this

Four out of five small and medium businesses in Brisbane have no formal cyber security policy or staff training programme, according to industry data reviewed by The Daily Brisbane. That means most employees are left to rely on instinct rather than informed behaviour when they spot a suspicious email or encounter a potential breach.
The numbers are stark. Only 20 percent of Brisbane SMEs have put a formal policy or training regime in place, even as cybercrime costs small Queensland businesses an average of A$49,600 per year. Separate figures show that 80 percent of small businesses experienced a cyber incident in the past 12 months.
Nationally, more than 60 percent of Australian businesses report a security incident every year. For Brisbane companies, the top threats include phishing, ransomware, weak passwords and AI-powered attacks, a list that has grown more menacing as generative AI tools lower the barrier for convincing email scams and automated intrusion attempts.
One cyber professional for every 240 businesses
The talent shortage makes matters worse. Brisbane has just one dedicated cybersecurity professional for every 240 businesses, creating severe resource strain for local firms that cannot afford to hire specialists or subscribe to expensive managed security services. This under-resourcing leaves many companies reliant on ad hoc measures and staff goodwill.
Brisbane City Council and the Queensland Government have been actively promoting the 'Cyber Wardens' initiative, which frames security awareness training as a critical and cost-effective step that even the smallest business can take. The program, which offers practical tips for everyday security, is part of a broader push to close the gap between threat levels and actual preparedness.
The message from both levels of government is consistent: training staff to recognise phishing emails, avoid weak passwords and report unusual activity is the single most affordable way to reduce risk. A single employee clicking a malicious link can trigger a ransomware event that costs tens of thousands of dollars to remedy.
The promise, and the risk, of AI tools
AI-powered attacks are emerging as a particular concern for Brisbane businesses. The same technology that allows firms to automate customer service or analyse data is now being used by attackers to generate convincing fake invoices, impersonate executives and craft phishing messages free of the spelling errors that once gave them away.
For businesses that have embraced AI tools without updating their cyber hygiene, the risks multiply quickly. An employee who has never been trained to verify unusual payment requests is just as vulnerable as one who shares a password across multiple platforms. The ethical question, some local tech observers say, is whether companies that adopt AI systems have a responsibility to ensure their workforce understands the new attack surfaces those systems create.
For now, the practical advice from Brisbane City Council and the Queensland Government remains the same: invest in awareness training, adopt multi-factor authentication and treat cyber security as a recurring operational cost rather than a one-off IT project. The Cyber Wardens program and resources available through council libraries offer a low-cost entry point for firms that have not yet begun.
The alternative, relying on staff instinct, is no longer a defensible strategy in an era where the average breach costs a small business nearly $50,000. Brisbane's cyber security gap is measurable, but so are the steps to close it.