Cybersecurity budgets do not fix unclear ownership

Spending more on cybersecurity won't help if nobody owns the decisions.

Wesley Harvett
Wesley Harvett
IT Management and Security Tools · 5 Oct 2026 · 2 min read
Above Cybersecurity budgets do not fix unclear ownership. Dynamic Business

Australian small businesses are often told to spend more on cybersecurity. That advice is incomplete. A business can buy reputable tools, outsource support and still be exposed because nobody can answer a more basic question: who owns the decision when something changes or goes wrong?

The Australian Signals Directorate's 2024-25 Cyber Threat Report gives that question real weight. ASD's Australian Cyber Security Centre received more than 84,700 cybercrime reports during the financial year—about one every six minutes. For small businesses, the average self-reported cost per report was $56,571, up from $49,615 the year before.

Those figures do not mean every incident costs the same. They are based on self-reported cases, and ASD cautions that reporting volume and outliers affect the averages. But they make one point difficult to dismiss: unclear technology ownership is not an administrative nuisance. It becomes expensive when a business has to make decisions under pressure.

The gap between a provider and an owner

An external provider may manage devices, Microsoft 365, backups or security alerts. Internal staff may approve access, purchases and operational changes. Problems develop when each side assumes the other owns the space between those tasks.

The result is familiar: an administrator account nobody wants to disable, a departed staff member who still owns a shared workflow, a backup dashboard that nobody has tested, or an alert that reaches a person without authority to act.

The fix is not another dashboard. It is an ownership register that names a decision-maker, a technical operator, the evidence required and the escalation path for each critical control.

Identity needs a business owner as well as a technical owner

Identity is where operational ambiguity becomes security risk. ASD reports that email compromise without financial loss represented 19% of the leading cybercrime reports from businesses in 2024-25. Business email compromise with financial loss accounted for another 15%, while identity fraud represented 11%.

A technical team can enable multifactor authentication, but the business still needs to decide who approves privileged access, how emergency accounts are controlled, when contractors lose access and what evidence is checked when a payment request changes.

Microsoft's current Entra roadmap makes that work more urgent. Passkeys began becoming the default authentication experience from 1 September 2026 for users enabled for SMS or voice as the rollout reaches their organisation. Microsoft-provided SMS and voice delivery is scheduled to retire for most users on 1 February 2027.

Passkeys are designed to resist phishing, but their introduction still needs operational decisions: which devices are allowed, how people enrol, what happens when a device is replaced, how high-risk administrators recover access and which exceptions remain. A secure method without a recovery owner is still an operational risk.

A successful backup is not the same as a successful recovery

Backup reports are another source of false confidence. A green status can show that data was copied. It does not prove that the right information can be restored within the time the business can tolerate.

The control becomes meaningful when somebody owns a representative restore test. The evidence should record what was restored, where it was restored, how long it took, whether permissions were preserved and which dependencies were missing.

ASD's ACSC responded to 138 ransomware incidents in 2024-25. Not every organisation will face ransomware, but every business relying on backups should know whether recovery has been demonstrated rather than assumed.

Patching needs coverage evidence

Most organisations can produce an invoice for endpoint protection or managed support. Fewer can immediately show which devices are covered, which are stale, which are missing and which exceptions have been accepted.

That distinction matters because a control should be judged by coverage and evidence, not by the existence of a subscription. Someone must own the device inventory, the exception process and the follow-up when a laptop stops checking in.

Incidents need decision rights before they need a document

An incident-response plan can contain dozens of pages and still fail if nobody knows who can isolate systems, contact legal advisers, notify customers or approve urgent expenditure.

For an SME, a useful first version can be one page. It should identify:

- the person authorised to declare an incident;

- the technical contact who can contain access or devices;

- the business contact who understands critical operations;

- the legal, insurance and communications escalation paths;

- the systems that cannot be switched off without executive approval; and

- the secure channel used if normal email is unavailable.

The document is valuable because it records decisions made before the pressure arrives.

Build an ownership register, not a shopping list

A quarterly ownership review can be short. For each critical area—identity, devices, email, shared data, backups, networks and incident response—record four things:

1. Who is accountable for the business decision?

2. Who performs the technical work?

3. What evidence demonstrates the control is operating?

4. What is the escalation path when the evidence is missing?

This does not remove risk, and it does not replace technical controls. It makes the controls governable.

Australian SMEs do not need security theatre. They need to know who can make a decision, who can execute it and what proves the work happened. Budget matters, but ownership is what turns spending into resilience.

WH
Wesley Harvett
From the floor
Closer to this story than we are?
If you're building in this space — or watching it reshape your market — pitch us. We edit it; you get the byline.
More from the desk

Keep reading.

Expert ◆

The Fair Work Ombudsman is going looking for payroll mistakes

Fair Work recoveries are up 27%. Tiffany shares what small employers should review before a letter arrives.

Tiffany · 2 min
News ◆

A new ranking shows which cyber threats deserve your time first

Huntress has released its Tragic Quadrant, a ranking of cyber tactics based on how common they are and how close they sit to real business damage

Yajush Gupta · 2 min
News ◆

A liquidator's warning for businesses eyeing AI to cut costs

Redundancies, software costs and lost clients can arrive before any AI savings do.

Yajush Gupta · 2 min
0 people like this

Comments

Loading comments…