#NSBCS.129 - Leave No Organisation Behind: Building Australia's Cyber Resilience Starts with SMEs
Leave No Organisation Behind: Building Australia's Cyber Resilience Starts with SMEs
Australia's ambition to become one of the world's most cyber-secure nations by 2030 can't be achieved one large organisation at a time. It depends on strengthening the whole economy, which means leaving no organisation behind.
Last week, the Government took the next step in that direction, moving Australia into Horizon 2 of the 2023–2030 Australian Cyber Security Strategy.
Horizon 1 was about strengthening foundations and protecting critical infrastructure and large organisations. Horizon 2 widens the lens to the whole economy, and that explicitly includes small and medium enterprises (SMEs) and not-for-profits.
It’s a shift practitioners have been waiting for. Australia’s most significant cyber vulnerabilities aren’t concentrated in well-resourced enterprises. They sit in the supply chains that connect organisations, and in the smaller businesses that underpin them.
SMEs are Structural, not Peripheral
Most major organisation in Australia depends on a network of smaller suppliers: managed services, software, logistics, finance, professional support. These SMEs matter to national resilience for reasons that reach well beyond any single supply chain:
The backbone of the economy, making up the overwhelming majority of Australian businesses.
Custodians of sensitive personal data that, while smaller in scale than an enterprise’s, can cause the same harm to the people affected if it’s exposed.
Trusted business relationships that make them integral to continuity.
That creates a simple risk reality: when an SME is compromised, the larger organisations connected to it are often exposed too. So SME resilience isn’t a “small business issue.” It’s a structural component of national cyber resilience, and Horizon 2 now reflects that.
The Reframe
We shouldn’t expect SMEs to just act as scaled-down enterprises required to aspire to enterprise-grade maturity on a fraction of the budget. They’re essential nodes in Australia’s digital supply chains, and they need approaches that are practical, proportionate, and sustainable.
Shifting the Dial
The Horizon 2 Action Plan (2026-2028) is here but the harder question is already in front of us: How do we lift SMEs without simply asking less-resourced businesses to behave like enterprises?
The answer isn’t just raising the bar. It’s lowering the barrier, making strong cyber capability something SMEs can actually reach and adopt. Three levers matter most:
Make it Accessible. This will cost money, but cost isn’t the only barrier, and often it isn’t the main one. Adoption depends on making strong cyber capability something SMEs can actually take up.
Make it Pragmatic. SMEs don’t need enterprise-grade programs they can’t run. They need right-sized frameworks with clear, prioritised actions that map to real risk, not compliance for its own sake.
Give them Line of Sight. You can’t manage what you can’t see, and most SMEs are flying blind, with no clear view of their exposure, their weak points, or the threats actually targeting businesses like them. The answer isn’t an enterprise-grade security operations centre. It’s a clear, current picture of the cyber risks and threats most likely to hit them, in a form they can understand and act on without a dedicated team.
Get this right and SME maturity stops being an aspiration and becomes something achievable at scale.
What we read this week
Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager - Cisco has patched CVE-2026-20262, an arbitrary file-write flaw in Catalyst SD-WAN Manager that let authenticated attackers escalate to root. It was already being exploited in limited, targeted attacks before fixes landed, and CISA wants federal systems remediated by 29 June 2026. Patch now, restrict management-interface access, and check vmanage logs for suspicious file uploads.
China-Linked UNC6508 Abused Google Workspace Mail Rules to Steal Research and Defence Emails - Google's Threat Intelligence Group has detailed a year-long espionage campaign against North American medical, academic and military research networks. Attackers backdoored REDCap servers, then quietly reconfigured victims' own Google Workspace rules to silently copy targeted emails to an external inbox, leaving almost no trace. Patch and de-duplicate REDCap installs, audit mail-forwarding rules, and enforce phishing-resistant MFA on admin accounts.
Malicious JetBrains Marketplace Plugins Exfiltrate Developers' AI API Keys - Aikido Security found 15 JetBrains plugins, posing as AI coding assistants, that quietly send entered API keys to an attacker-controlled server. They've been downloaded almost 70,000 times since October 2025, and some were still live at time of reporting. Treat IDE plugins as untrusted, and rotate any keys entered into the affected ones.
ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures - Three new loaders - BabaDeda, Lorem Ipsum and Potemkin - are being delivered via fake CAPTCHA and browser-update prompts that trick users into running malicious commands themselves. Lorem Ipsum, linked to the Rapid Brigantine group, ultimately hands off to Rhysida ransomware. Train staff to spot fake verification prompts and restrict PowerShell execution where possible.
Critical FortiSandbox Vulnerabilities Under Active Exploitation - Defused has observed active exploitation of three critical FortiSandbox flaws (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089, all CVSS 9.1), two of which were patched back in April. Because FortiSandbox feeds verdicts to other Fortinet products, a compromise here can let malicious files slip through as "clean" elsewhere. Upgrade to the latest builds without delay and restrict access to the management plane.
NSW Government Disputes Nova Ransomware Group's Data Breach Claims - The Nova ransomware gang listed the NSW Government as a victim on 15 June, claiming 200GB stolen, but the sample data released was old and publicly available. Cyber Security NSW says there's no evidence of a genuine breach. A reminder that dark web leak claims need verification before they're treated as fact.
References
https://thehackernews.com/2026/06/chinese-hackers-abused-google-workspace.html
https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys
https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html
https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html

