Topics:

Content
Resources Hub / Real-life cyber stories / Kersti Eesmaa: Why small businesses need to stop asking, ‘Why would anyone target us?’

Kersti Eesmaa: Why small businesses need to stop asking, ‘Why would anyone target us?’

Topics:

Content

When Kersti Eesmaa talks to small businesses about cyber security, she often hears the same question: “Why would anybody be interested in us?”

It is an understandable reaction. Many small businesses do not think of themselves as obvious targets. They may not hold millions of dollars or manage large government systems. But Kersti, COO of Vertical Scope Group, says that is not how cyber criminals think.

“The criminals work pretty much like SMEs,” Kersti says. “They all want to get the best return on the investment.”

That means attackers are often looking for the easiest pathway. A small business can be attractive because it may hold customer information, use shared software, connect to a larger client or sit inside a supply chain.

A florist may hold delivery addresses for high-profile clients. A contractor may have access to files from a larger organisation. A bookkeeper may manage payroll information. Even a sole trader can be part of a wider network.

Supply chains are changing the risk

Kersti grew up in Estonia, a country with first-hand experience of major cyber attacks. That background shapes how she thinks about cyber security in Australia.

She believes small businesses need to better understand their role in supply chains. They may not see themselves as connected, but the software they use, the clients they serve and the data they hold can make them part of a much larger cyber picture.

“Even a sole trader can be part of that supply chain,” Kersti says. “That’s not the mindset we have at the moment.”

Start with the basics

Kersti is clear that cyber security does not need to be mysterious. In many cases, it starts with using existing tools properly.

“Cyber is not some magic, hacking, hoodie kind of complicated stuff,” she says. “When you do cyber well, then you do IT well.”

For small businesses, that might mean making sure email, cloud storage and accounting systems are configured correctly. It also means training people to recognise everyday risks, such as phishing emails, weak passwords and suspicious links.

Kersti says training does not need to be long or expensive. Even short, repeated learning can help.

“Repetition is the only way that people learn,” she says.

 

Kersti's advice for small businesses

Hospitality Cyber Attacks

Map what data your business holds. Think about who you work with, what systems you use and where your business connects to others.

Then make a simple plan. Who would you call if something went wrong? What would you do first? Do staff know how to report something suspicious?

Cyber Wardens training gives small businesses a practical starting point, helping teams understand the risks and build safer habits before something happens.

 

Learn easy and simple cyber security tips for your small business

cyber-wardens

More helpful resources for you and your business

It happened to me!

Have you got a Cyber attack story to share? Your story can help other small businesses protect themselves.

It happened to me!

Have you got a Cyber attack story to share? Your story can help other small businesses protect themselves.