Aura

No weak links: the case for whole-of-society cyber resilience

By Josh Owen-Thomas

Cyber security

Digital technologies have transformed the world, changing the way we communicate and do business, and improving our daily lives in a multitude of ways.

But there are drawbacks.

Tech-savvy criminals pervade cyberspace. Acting alone, in organised groups or on behalf of nation states, they target individuals, businesses and governments for financial gain, strategic disruption and espionage.

The threat is severe. The 2026 Global Risks Report lists cybersecurity in the top 10 global risks. In Australia, cyberattacks are constant, with the Australian Cyber Security Centre responding to 1200 cybersecurity incidents between 2024 and 2025, an increase of 11% on the previous year. And as technology continues to advance in areas like AI and quantum computing, these attacks will only become more sophisticated, frequent and costly.

Historically, national cybersecurity efforts have been left to experts and specialist government agencies who monitor threats and develop strategies, legislative frameworks and technical tools to mitigate and respond to them. But Adelaide University cybersecurity expert Associate Professor Mamello Thinyane says effective cybersecurity requires a different approach.  

“Society is interconnected through digital technologies, and cybersecurity is inherently systemic,” he says.

“The system is only as strong as its weakest link.

“Minor breaches through techniques like phishing can affect major networks and critical infrastructure, for example, and attacks can cascade across domains and sectors.  

“Cybersecurity is complex and requires an ‘all hands on deck’ approach. No single government or agency can protect the system against all types of attacks.”

Associate Professor Thinyane is a strong advocate for whole-of-society cyber resilience.

While cybersecurity focuses on preventing attacks, cyber resilience recognises that adverse cyber incidents will inevitably occur and focuses on society’s ability to withstand, recover from and adapt to disruption. The concept emphasises the role that every part of society must play to keep Australia digitally resilient, from average citizens to governments.

Cybersecurity falls over without small business protections

While Australia’s national cybersecurity strategy recognises the importance of this approach, Associate Professor Thinyane says implementation remains focused largely on protecting and upskilling government and large organisations that own or operate critical infrastructure and services, leaving other parts of society vulnerable. He points to Australia's small and medium-sized businesses (SMBs) as an important example.

In Australia, SMBs are a critical pillar of the economy, employing more than 40% of the private sector labour market and contributing more than A$500 billion to annual gross domestic product. Yet limited time, resources and technical capability make them attractive targets for cybercriminals.

“It isn’t uncommon for SMBs to be using legacy and outdated systems, which are easier to break into,” Associate Professor Thinyane says.

“The cybersecurity governance, risk and compliance landscape is also difficult to navigate, and the frameworks and guidelines in place are typically tailored to large organisations.

“And SMBs aren’t getting much help from industry, where more money is made at the bigger end of town.”  

SMBs are disproportionately affected by cyberattacks with cybercrime costing small businesses an average of $56,000 and medium businesses $97,200 between 2024-2025. Such costs can cause bankruptcy, leading to disruptions in larger supply chains as well as devastating impacts on the lives of owners and employees.

Being easy targets, SMBs can also act as ‘vectors’, giving cybercriminals access to larger organisations. This was the case last year when Qantas suffered a major cyber-attack after cybercriminals used a call centre based in the Philippines to access the personal information of almost six million customers. According to an international survey by Verizon, these third-party breaches are becoming more frequent, having increased by 60% from 2025.

Associate Professor Mamello Thinyane Associate Professor Mamello Thinyane says Australia's small and medium-sized businesses are disproportionately affected by cyberattacks.

Creative solutions needed to bring everyone along

This flow-on effect demonstrates the interconnectedness of digital life, Associate Professor Thinyane says, and necessitates the whole-of-society approach.

“Our SMBs aren’t the only vulnerable groups,” he says.

“Civil society, community and non-government organisations, as well as regional and remote communities, are all being left behind.

“Importantly, we can’t just demand that these groups get their act together and invest in cybersecurity measures. They don’t have the resources nor the capacity and are working hard to make ends meet in an increasingly challenging economic climate.

“We need to come up with creative solutions.”

Associate Professor Thinyane is working on those solutions now. In addition to raising awareness among vulnerable groups and developing ways to mitigate social engineering attacks, he is exploring how actionable cyber threat intelligence can effectively be shared across different sectors of society.

“To achieve whole-of-society resilience, collaboration across industries and sectors is key,” he says.

“One of the best ways we can foster cooperation is to share cyber threat intelligence broadly, beyond the government and industry networks.

“This will help all Australians stay ahead of threats and respond proactively.”

Associate Professor Thinyane says we have our work cut out for us, but he is optimistic about the future.

“We just need to start by shifting our understanding of cybersecurity as an issue and, as we move forward, always pay attention to those groups that might get left behind.”

South Australian small businesses underprepared

According to a survey:

  • 61% of South Australian small businesses think they’re too small to be a target
  •  73% of SA small businesses do not have a cybersecurity response plan
  • Only 7% of SA small businesses run cybersecurity training for staff

Nationally:

  • 35% of small businesses have been involved in cyber incidents
  • 52% of small businesses believe they’re not a target
  • One in five small businesses spend no time on cyberattack prevention

Source: Research commissioned by Optus for Scams Awareness Week

Republish this article

Republish our articles for free, online or in print, under Creative Commons licence. See our republishing guidelines for details.