While COVID trading restrictions and rules have been consigned to the rear-view mirror, significant new challenges for small businesses across Australia have emerged.
One set of challenges is well known, and the other less so.
The first involves navigating strong consumer demand amid a tight supply of labour and inflationary pressures. While big businesses largely have been holding their own, Australia’s nearly 100,000 small-to-medium franchised businesses have faced a tougher road.
While this situation has developed gradually over the past year, the second challenge facing small businesses - heightened cybersecurity risks – has only gained prominence in recent weeks.
Modern small businesses have accelerated their adoption of digital technologies to enable remote work, improve operations and grow sales. They have increasingly collected larger amounts of data from their customers in order to support enhanced sales and marketing efforts. Both trends were accelerated by the pandemic.
Virtually everything has become digital. All sensitive personal files are stored on computers and banks and credit card accounts are accessed online, as is the financial information of companies, big and small.
Franchising is the predominant business model in the small-to-medium business sector and while growth is strong, largely due to the strength and underlying support for individual small businesses in franchise networks, there are persistent risks of cyber-attacks.
Most small businesses do not include cybersecurity in their list of immediate practical concerns. However, this thinking often relies on the incorrect belief that they are too small for cyber criminals to worry about, and don’t have enough data to warrant a breach.
According to reporting in the Australian Financial Review, there were 428 data breaches at Australian companies in the first six months of 2022. While 11 data breaches each affected up to 10,000 people, the majority of cases (71 per cent) involved the personal information of 100 people or less.
This reflects the fact that small businesses with limited, yet valuable stores of data are increasingly being targeted by cyber criminals.
During 2020 and 2021, data breaches at small businesses globally soared 152% in comparison to the two previous years, according to RiskRecon, a MasterCard unit that assesses companies’ cybersecurity risk. This figure is twice as large as it was among larger companies in the same period.
The fundamental truth is that cybersecurity breaches can result in significant costs for businesses.
There are financial costs, which are often represented by additional expenses on the general accounting ledger, including ransomware payments, lost productivity, increased payroll hours, investigations, regulatory filings and legal fees.
And there are reputational costs associated with negative publicity. A 2020 survey by Arcserve found a link between data breaches, consumer purchasing behaviour and brand loyalty – with 59 per cent of consumers saying that they’d avoid companies hit by a cyberattack in the past year.
In the wake of recent high-profile data breaches, the Federal Government has signalled that it is considering new laws that would force companies to take more effort to protect sensitive customer and employee data.
Rather than focus on any single data breach, there is a growing movement within the government to fundamentally change the way Australian companies use data. This attitude can be seen in the comments of the Attorney-General, Mark Dreyfus MP, who said on Sunday 2 October, that companies should “stop regarding all of this personal data of Australians as an asset for them, they actually should think of it as a liability.”
Legislative and regulatory reforms could include significantly raising penalties, new protections on personal information, and mandating that small businesses with turnover under $3.1 million report data breaches to customers – removing their exempt status.
As the peak body for the $172 billion franchise business segment, which employs more than 565,000 people, the Franchise Council of Australia is committed to working with all levels of government to help improve cybersecurity, while also ensuring that small businesses are not unnecessary burdened by bureaucratic red tape which only serves to increase the cost of doing business.
As outlined by the former Head of the Australian Cyber Security Centre, Alastair MacGibbon, compliance-centred reforms often burden companies, and rarely work. From cybersecurity to workplace safety, embedding the right culture beats box ticking regulation every time.
While new laws may be some time away, there are several concrete steps which small-to-medium franchised businesses can take now in order to reduce their cyber risk:
- Embed cyber safety into your business culture. Studies have found that human error was involved in over 85% of breaches. This risk can be reduced if cyber education and awareness was added to a business’s normal training program.
- Deploy malware prevention software and keep it updated.
- Regularly review who inside the business has access to sensitive data and if that access is still required.
Mary Aldred is the CEO of the Franchise Council of Australia, the peak body for the nation’s $172 billion franchise sector. Mary commenced in the role in April 2018, bringing with her extensive experience across government, industry and the corporate sectors. As CEO, Mary has led the FCA in developing and delivering strategic priorities to strengthen the FCA’s role as an effective peak business organisation and advocate for a complaint, sustainable and profitable franchise sector.
Franchise Council of Australia
Phone: 03 9508 0888
Email: [email protected]
Web: www.franchise.org.au




