The cybersecurity landscape for 2025 – are you equipped to navigate it with confidence?

While the team at Pinpoint IT prefers to be optimistic, we’re not given to whitewashing the facts.

The cybersecurity landscape for 2025 is as bad, if not worse, than it has ever been, with a dramatic escalation in the size and complexity of attacks due to the evolution of ever more nimble and fast-moving adversaries – and the help of advanced technologies like AI.

In the executive summary of its Annual Cyber Threat Report 2023-2024, the Australian Government ASD (Australian Signals Directorate) says: “Australia faces the most complex and challenging strategic environment since the Second World War.”

ASD’s report also highlighted that our critical infrastructure networks are an increasingly attractive target due to the sensitive data they hold, and that email compromise, online banking fraud and business email compromise fraud were the top self-reported cybercrimes for businesses in Australia.

Are Australian businesses holding their own?

No. Despite the increased level of danger, Australian businesses are lagging behind those in other countries in their preparedness to respond to, resist, recover from, and remediate cyberattacks.

In their 2024 survey of 150 C-suite executives from Australian businesses, leading accounting firm RSM Australia reported that only 50% were confident that their staff had the capacity to manage cybersecurity risk. By comparison, 84% of UK leaders had faith in their staff. As for being prepared to respond to an attack? 64% of Australian leaders say they are ready, vs 94% of UK leaders. RSM Australia’s other findings include:

  • Cyberattacks: Almost 30% of large Australian businesses and over 15% of medium businesses experienced one or more attacks in the previous 2 months
  • Third-party data breaches: In the last year, 32% of Australian businesses (vs 26% in the UK and US markets) experienced a third-party data breach. 23% reported that their finances, reputation, or operations were impacted.
  • Forms of attack: 20% of all attacks are via phishing, 13% are data leaks, and 10% are ransomware
  • Phishing facts: Sadly, for those 45% of large organisations that experienced phishing attempts, 42% were unsuccessful in limiting the damage. And 40% took anywhere between a week and a month to recover from the ransomware and extortion that followed.
  • Checking for vulnerabilities: 34% of Australia’s large organisations have either never (ever) been vulnerability tested (or not tested in the last year). The rate rises to 45% for mid-sized firms, making them exceptionally vulnerable to cyberattacks. (ASD reported a 31% increase in common vulnerabilities and exposures in their 2023-24 report.)
  • Cyber insurance: Even though it’s not “if” they will be attacked, but when, 25% of large Australian firms (and 58% of mid-sized) don’t have cyber insurance

Why a just-in-time approach won’t cut the mustard

Time is fleeting, and preparation is everything. A retrospective approach to cybersecurity is never ideal, and ignoring it altogether isn’t based in reality.

Here’s why: Once you are aware that you are under attack, any weaknesses in your systems or applications can be exploited in as little as 3 minutes. According to the 2025 Sophos Active Adversary report, attackers can take full control of a system in just 11 hours. But even the average time of 79 minutes for a criminal to laterally access your systems is horrifying.

At this stage, calling in the experts in the hope they can cut your attacker off at the knees, or trying to use outdated or inadequate cybersecurity tools internally to counter an attack, are strategies that are destined to fail.

What do you risk by doing nothing?

  • Compromise the personal data of those who trust you. This can range from employees’ details (physical and digital contact information, licenses, bank details, and more), which can be used to conduct identity theft or apply for credit cards or loans in the person’s name. Depending on the data you store, you can also expose your customers’ details, potentially compromise their information and significantly endanger their hard-won loyalty to your business.
  • Endanger your cashflow. With bank account numbers and passwords exposed, the money you count on for operational expenses and more can be extracted from your accounts.
  • Find your data up for grabs on the Dark Web. Criminals can sell or rent your data to third parties on the Dark Web. This can include your customer database, as well as intellectual property such as products, plans, designs, or other confidential information.
  • Lose access to your own data. Some attacks can leave your data encrypted and unrecoverable, leaving you in the time-consuming position of having to rebuild your document files from other sources (such as emails).
  • Business closure. With ASD reporting the average cost of cybercrime per report as $49,600 for small businesses, $62,800 for medium businesses, and $63,600 for large businesses, recovery (of data, money, and reputation) can be impossible, and closure inevitable.
  • Liability for data loss. Your business could be held liable for breach of contract with customers or suppliers if their information is leaked or sold. In some cases, the ASD requires mandatory reporting of ransomware payments from businesses with a certain turnover, and non-compliance can result in significant fines.
  • Significant stress on your people. A cyberattack can have a profoundly negative impact on a wide range of individuals within a business, leaving some unable to work and fearing job loss. Even the fear of a cyberattack can place undue stress on those responsible for the safety of your business or managing everyday operations.

What do you need to protect your business from cybercrime?

Cybercrime has grown at such a rapid pace and with such complexity that protection needs to come from every angle. The basics are:

An incident response plan is a written playbook designed to help you identify, manage, remediate, and report cybersecurity incidents. At a minimum, it should contain the plan’s purpose and scope, roles and (24/7) contacts, incident categories and severity levels, step-by-step actions, evidence handling rules, communication rules, and a post-incident review process.

A disaster recovery plan (DRP) is a concise, written blueprint for resuming critical IT services and data after a significant disruption, such as cyberattacks, server failures, or natural disasters like fires and floods. It should cover the plan’s purpose, scope, and assumptions, clear recovery objectives for data and systems, roles, responsibilities, and (24/7) contact list, an inventory and priority list of critical assets, backup and replication details, step-by-step recovery procedures, a communication plan, and a schedule for testing, maintenance, and continuous improvement.

Cyber insurance is a policy that reimburses your business for costs and liabilities from a cyber incident. These costs can include breach forensics, data restoration, lost revenue, customer notifications, legal defence, and some fines. Each insurer will have its own list of exclusions. Like any business insurance, the onus is on your company to meet specific cybersecurity standards and achieve minimum levels of compliance. Frameworks typically include Australia’s Essential 8 and NIST to help you manage and reduce cybersecurity risks. How well you comply with these types of frameworks will impact your premiums or even your ability to gain coverage.

Cybersecurity awareness training turns your employees from your weakest link into one of your strongest lines of defence against a cyberattack. According to the 2025 Verizon Data Breach Investigations Report, 60% of breaches “involve a human element.” This makes it crucial to invest in training, refresher courses, and regular testing to maintain awareness and reinforce good habits.

Multilayered cyber protection – given the growing complexity of cybercrime, no single control can block every threat hitting today’s mix of cloud, on-prem, and mobile systems. This means that layered defences, including email filtering, MFA, endpoint detection, network segmentation, firewalls, automated patching, backups, best practice access rules and controls, user training, and more, are all needed to provide overlapping barriers that catch what others miss.

Where does this leave you?

We’d like to think you are one of 64% of Australian leaders who are ready to respond with confidence to an attack. But if you’re not, you are vulnerable to attack – and the time to shore up your defences is now.

Please reach out if you’d like to discuss how ready you are to resist and recover. We offer both standard and premium solutions that utilise industry-leading tools and best practices designed to keep your business, data, people, and customers safe and sound.



Leave a Reply