Cyber Ethos

How Data Exposure Increases Cyber Risks for Australian Businesses

Nobody sets out to have a data breach. What actually happens, in most of the cases Cyber Ethos investigates, is smaller and slower than that. A single piece of information ends up somewhere it shouldn’t, and months later it’s the thread a criminal pulls to unravel everything else.

That’s the part most explanations of cyber security risk skip over. It’s easy to picture ransomware or phishing as if they strike out of nowhere. They usually don’t. They follow on from something that was already exposed. Below is what that progression actually looks like, built from the patterns we see across Australian businesses of all sizes.

What is cyber security actually protecting against?

Before getting into the story, it’s worth being clear about what we mean. Cyber security is the practice of protecting the systems, networks, and data a business depends on from unauthorised access, disruption, or theft. Most people picture it as firewalls and antivirus software. In practice, a large part of it is about visibility — knowing what data and access you have, where it sits, and who can reach it. Exposure is what happens when that visibility breaks down.

Stage one: the exposure nobody notices

A mid-sized professional services firm — accounting, engineering, construction, it doesn’t much matter which — has an employee leave. Her laptop comes back, and her email is disabled eventually, but the login she used for a third-party scheduling tool never gets revoked. The tool itself isn’t the problem. Eighteen months later that vendor is breached, and her login, an old work email paired with a password she also used elsewhere, turns up in a data dump traded among criminals.

Nobody at the firm knows this happened. There’s no alert, no ransom note, nothing to investigate yet. By most definitions, nothing has “gone wrong.” But the exposure exists now, sitting in a criminal marketplace, waiting to become useful.

This pattern shows up in Australia’s own figures. The Office of the Australian Information Commissioner recorded 1,205 data breach notifications in 2025, the highest total since mandatory reporting began in 2018 and 8% up on the year before. A good share of these didn’t start as a dramatic hack. In the first half of 2025, 37% of reported breaches came down to ordinary human error — information sent to the wrong recipient, a missed BCC, an unintended release. Before it’s dangerous, exposure is usually just untidy.

Stage two: someone goes looking

Months pass. The old credential sits unused until an automated tool, one of thousands quietly working through leaked-data marketplaces and the open internet, picks it up. This isn’t a hacker sitting there personally targeting the firm. It’s infrastructure running around the clock, testing old logins against current sign-in pages across thousands of businesses at once, on the chance a password got reused somewhere it still works. Credential stuffing, in the industry’s own term, and one of the more common types of cyber attacks precisely because it needs almost no skill — only patience and a large enough list of leaked passwords.

Separately, a more targeted effort starts building. The firm’s staff directory, its “meet the team” page, an old press release naming a finance manager — all publicly discoverable. None of it required breaking into anything. It was simply left visible. Someone is quietly assembling a picture of who approves payments, who they deal with regularly, and what their emails tend to sound like.

This is the point where exposure stops being passive. Every extra detail available about a business becomes raw material for whichever of the common cyber threats an attacker decides suits the target best.

Stage three: the opening

The old credential doesn’t work against the firm’s main email system, which sits behind multi-factor authentication. But it does work against a smaller, forgotten system — a file-sharing portal set up for a single project years ago, never decommissioned, still holding client documents and a handful of internal spreadsheets. No MFA there, because nobody remembered it needed any.

From inside that portal, the attacker doesn’t need anything dramatic. A few real invoices and a genuine email thread between the finance manager and a regular supplier is enough. Combined with the earlier reconnaissance, they now know the tone, the format, and the timing of a real payment cycle.

This is roughly where Business Email Compromise begins in most real cases — impersonating a supplier or executive to redirect a payment. It’s consistently reported as the costliest form of cybercrime facing Australian businesses, and for a simple reason: it relies on exposed, seemingly harmless details rather than any technically sophisticated break-in.

Stage four: the escalation

In this composite case, the attacker sends a convincing email from a lookalike domain, referencing a real project and real figures, asking for the next payment to go to “updated” bank details. Without a habit of verifying changes by phone, it goes through.

Not every version of the story ends there. In a growing share of incidents, the same access is instead used to deploy ransomware, encrypting systems and, increasingly, stealing data first, since attackers know a business with solid backups will often still pay to keep stolen client data from being published. Whichever path is taken, the exposure that got them in the door is what gives them leverage once they’re inside.

Either way, the firm now has a genuine incident on its hands: a financial loss or a locked-down system, and a legal question about whether the breach is likely to cause serious harm under the Privacy Act — which may mean notifying the OAIC and every affected client directly.

Stage five: the bill, and what follows it

The direct loss is only part of the cost. There’s the investigation, the notification process, and the conversations with clients who now know their information was involved. Increasingly there are also questions from government and corporate clients, asked before a contract is renewed, about how it happened and what’s changed since. Public patience is thinning on this front: 82% of Australians now say they’re concerned about data breaches, up from 74% just a few years earlier, and that concern shows up directly in which suppliers get re-engaged.

None of this needed a criminal mastermind. It needed one unrevoked login, one forgotten system without MFA, and enough visible detail to make a fake email convincing. The technical break-in is usually the easy part, once the exposure has already done the groundwork.

Where the story could have been interrupted

Every stage above is a point where good cyber security management would have changed the outcome. That’s a more useful way to think about exposure than as a single risk to eliminate — it’s a chain, and it can be broken at almost any link.

At stage one, an offboarding checklist that revokes every account a person had, not just email, closes the door before it’s opened. At stage two, understanding what information about your business and staff is sitting publicly available takes away the attacker’s raw material — which is exactly what a proper cyber risk assessment is meant to surface, well before anyone comes looking. At stage three, applying multi-factor authentication consistently, including to the systems everyone forgets about, removes the easiest way in. At stage four, one habit — verifying any change to payment details by phone, using a number you already have — stops the most expensive attack category in the country. At stage five, an incident response plan and a working knowledge of your Privacy Act obligations turn a chaotic scramble into a managed process, which matters for both cost and reputation.

None of this is about buying more technology. It’s about knowing what your business is carrying and who can reach it — which is really the whole discipline of managing cyber security risk in one sentence.

Where does your business stand?

Most organisations can’t say with confidence what data of theirs is currently exposed: sitting in an old account, a forgotten system, a supplier’s database, or a leaked-credential list they’ve never checked. That uncertainty is the real risk, more than any single vulnerability on its own.

Cyber Ethos is a Queensland-based cyber security firm led by Dr Kiran Kewalramani, a PhD-qualified specialist with CISSP, CISA, and GAICD credentials and over 20 years of experience across government, critical infrastructure, and private industry. We help Australian businesses find out where their exposure actually sits, through cyber risk assessments, penetration testing, cloud and application security reviews, and Essential Eight and ISO 27001 uplift, and then close the gaps before someone else finds them first.

Kiran Kewalramani

Kiran Kewalramani

Kiran Kewalramani stands as an acclaimed technologist with over two decades of robust executive experience in technology, cybersecurity, data privacy and cloud solution enablement. His illustrious career has been marked by transformative roles in esteemed organizations, including Cyber Ethos, Queensland Department of Education, Gladstone Area Water Board, NSW Rural Fire Service, NSW Police Force, Telstra, American Express, and more.