You’ve seen the headlines. Optus. Medibank. Latitude. Qantas. Millions of Australians, household-name companies, weeks of news coverage and a fresh wave of “change your passwords” texts from worried relatives.

And if you run a small business, I know exactly what went through your head, because owners tell me every time one of these breaks: that’s big-end-of-town stuff. Nobody’s coming after my little website.

I want to gently take that idea apart — not to scare you, because fear-mongering is the laziest genre in IT and I refuse to write it, but because the actual lesson of those breaches is genuinely useful to you, and it’s not the lesson the headlines suggest. Stay with me; I promise to only use numbers I can point to.

The scale, briefly and accurately

The big ones were enormous, and worth stating precisely. The Office of the Australian Information Commissioner alleges the 2022 Optus attack “seriously interfered with the privacy of approximately 9.5 million Australians” (OAIC), and that the Medibank breach the same year affected 9.7 million (OAIC). Latitude Financial’s 2023 breach exposed roughly 14 million records, including driver-licence numbers and identity documents dating back to 2005 (SecurityWeek). In 2025, Qantas confirmed a breach affecting 5.7 million customers — via a third-party platform, through social engineering (Computer Weekly).

Now read that last sentence again, because it contains the entire useful lesson: a third-party platform, through social engineering. Not a cinematic master-hacker defeating a supercomputer. A gap in the boring stuff — process, access, maintenance, the things nobody was watching closely enough. That pattern repeats across almost every headline breach, and it’s the thread that leads directly back to your website.

Why attackers absolutely do care about your site

Here’s the mental model to replace “nobody would bother with me”: attackers, by and large, aren’t choosing targets at all. Automated bots scan the entire internet, around the clock, checking every site they find for one thing — software with known, unpatched holes. Your website gets probed not because of who you are, but because it exists and it’s reachable. It’s less “burglar casing your house” and more “someone walking every street in the country, trying every door handle.”

The evidence for this is solid. In Sucuri’s 2023 Hacked Website Report, 39.1% of the compromised CMS installs they cleaned were out of date at the point of infection, and 13.97% still had a known-vulnerable plugin or theme sitting there (Sucuri). WordPress accounted for 95.5% of the infections they saw — and Sucuri is explicit that this “reflects market share, not inherent weakness.” I’ll say that louder for the people up the back: WordPress is not the problem. Neglected WordPress is the problem. It’s the difference between a car and a car nobody’s serviced since 2021.

And the speed of it is what most owners underestimate. When a critical flaw was disclosed in the LiteSpeed Cache plugin in 2024 — installed on more than 5,000,000 sites — the security firm Wordfence blocked 58,952 attacks against it in the first 24 hours (Wordfence). Twenty-four hours. If your site ran that plugin and nobody was on update duty that week, the bots were already knocking. That’s the modern reality: the window between “flaw published” and “flaw exploited at scale” is measured in hours, which is precisely why “we update it every few months, when we remember” doesn’t hold anymore.

“But what would they even want with my site?”

Fair question, and the answers are more mundane — and more expensive — than you’d think:

  • Your customers’ trust. A defaced site, a malware warning, or Google slapping a red “this site may harm your computer” screen over your business name undoes years of reputation in an afternoon. And after Optus and Medibank, Australians are acutely sensitised to who’s careless with their details.
  • Your traffic and your name. Hacked small-business sites get quietly repurposed — hosting spam pages, redirecting your visitors to scams, lending your domain’s good reputation to someone else’s crimes. Often the owner is the last to know.
  • Your data. Even a humble contact form holds names, numbers and emails. A small online store holds much more. Small isn’t the same as nothing.
  • A stepping stone. The 2024 polyfill.io incident showed the supply-chain version of this: one trusted third-party script turned malicious and injected malware across the 100,000+ sites embedding it (Sansec). You don’t have to be the target to be a casualty — sometimes you’re just standing nearby.

And when it goes wrong, it isn’t cheap. The Australian Signals Directorate’s FY2024-25 reporting puts the average self-reported cost of cybercrime to a small business at $56,600, against a backdrop of a cybercrime report lodged in Australia roughly every six minutes (ASD). For plenty of small businesses, that figure isn’t an inconvenience — it’s the year’s margin.

The good news: the defences are boring, cheap and effective

Here’s the part I actually want you to remember, because it’s genuinely hopeful. The big breaches weren’t enabled by attackers being unstoppable geniuses. They were enabled by gaps in fundamentals — and at small-business scale, the fundamentals are neither expensive nor complicated. You don’t need a security operations centre. You need six boring habits:

  1. Keep everything updated. Core, plugins, themes, PHP — promptly, not seasonally. This single habit closes the door on the overwhelming majority of automated attacks, because the bots are looking for exactly the holes that patches close.
  2. Take backups you’ve actually tested. Automated, stored off the server, and restored at least once as a drill. A backup you’ve never restored is a hope, not a plan.
  3. Use HTTPS. Non-negotiable in 2026 — it’s the padlock customers look for and a baseline trust signal to browsers and search engines alike.
  4. Lock down your logins. Strong, unique passwords; two-factor authentication on the admin; and retire the username “admin” — it’s half of every bot’s first guess.
  5. Run fewer, better plugins. Every plugin is a door into your site. Audit them yearly, keep the well-maintained ones, and delete — not just deactivate — the rest.
  6. Know your own setup. Who hosts the site? Who can log in? Who applies updates? If any answer is a shrug, that shrug is the vulnerability. (If the answer is “we’ve lost track entirely,” I’ve written a calm recovery guide for exactly that.)

None of this is exciting. All of it works. That’s rather the theme of security at this scale: the boring stuff, done consistently, beats the clever stuff done occasionally.

Where we come in

The honest pitch: most small businesses shouldn’t be doing any of the above themselves — not because it’s beyond them, but because it needs doing every week, forever, and that’s precisely the kind of job that loses to “busy” every time. That’s what a managed care plan is for: updates applied promptly, backups taken and tested, security watched, so you’re never the 39.1% running yesterday’s software when tonight’s bots come knocking.

We’re engineers, not plugin-installers, we’re local — Campbelltown, serving Macarthur and greater Sydney — and we’ll happily start with a free, no-jargon health check of your site: what state it’s genuinely in, and the three things we’d fix first. No scare tactics. Just a straight answer.

Book a free website health check →

Sources linked inline. Figures quoted exactly as published by the OAIC, ASD/ACSC (FY2024-25), Sucuri (2023), Wordfence (2024), SecurityWeek (2023) and Sansec (2024) — we don’t round, re-date or reframe them.