# Cybercrime Risk Shifts to SMBs

> Cybercrime risk in Australia is declining for large corporations while SMBs become the primary target due to weak security postures.

**URL:** https://www.ciptadusa.com/blog/cybercrime-risk-shifts-to-smbs-20260705  
**Type:** blog  
**Author:** PT Cipta Dua Saudara  
**Category:** Application Security  
**Published:** 2026-07-05  
**Cover:** https://cdn-uagents.enitip.com/uploads/blog/2026-07/daily-appsec-20260705-014629.jpg  

## Article

Recent data from the Australian Signals Directorate shows declining cybercrime reports against individuals and large enterprises. But there is a shift that deserves more attention: attack pressure is migrating to SMBs that have long considered themselves too small to be targets.

## Summary

Cybercrime risk in Australia is declining for large corporations thanks to massive security investments, while SMBs are becoming the primary target due to weak security postures and more efficient attack ROI for threat actors.

## The Challenge

This shift is not coincidental. Large enterprises have allocated significant budgets to EDR, 24/7 SOC operations, and zero-trust architecture over the past five years. Their attack surface has contracted. For profit-motivated threat actors, attacking one large enterprise with trained incident response teams is less efficient than targeting dozens of SMBs still relying on consumer-grade antivirus.

**Attack patterns shifting toward SMBs:**
- **Business Email Compromise (BEC)** — requires no technical exploit, only social engineering against untrained finance staff
- **Ransomware-as-a-Service** — barrier to entry has dropped dramatically; affiliates only need initial access, operators handle the rest
- **Supply chain pivot** — SMBs as enterprise vendors become lateral entry points to higher-value targets

## Implications

For the Southeast Asian context — including Indonesia — this pattern is directly relevant. The majority of businesses in Indonesia are SMBs, and cybersecurity investment is still viewed as a cost center rather than risk mitigation. As regulations like Indonesia's Personal Data Protection law begin enforcement, SMBs experiencing breaches will face dual consequences: operational losses and regulatory penalties.

Practical steps SMBs can take without enterprise budgets:
1. **Mandatory MFA** on all email and financial accounts — stops 90%+ of credential-based attacks
2. **Offline backups** following the 3-2-1 rule — eliminates ransomware leverage
3. **Monthly security awareness training** for staff — BEC cannot be stopped by firewalls
4. **Simple vendor risk assessment** — ensure digital suppliers also meet security baselines

## References

- [Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs — Dark Reading](https://www.darkreading.com/cybersecurity-analytics/aussies-face-reduced-cybercrime-risk-pressure-shifts-smbs)
- [ACSC Annual Cyber Threat Report 2025 — Australian Signals Directorate](https://www.cyber.gov.au/about-us/reports-and-statistics/annual-cyber-threat-report)
- [Indonesia Personal Data Protection Law — Komnasham](https://www.komnasham.go.id/files/1664426886-uu-nomor-27-tahun-2022-$R4GJU.pdf)

---

*Markdown version of https://www.ciptadusa.com/blog/cybercrime-risk-shifts-to-smbs-20260705 — generated for AI agents and LLM crawlers.*
