The most common objection we hear from Australian business owners is some version of the same sentence. We are too small to be worth attacking.
It is worth testing that against the actual listings from the past few weeks. The Qilin group listed a commercial flooring supplier, claiming around 45 gigabytes of data. The Settra group claimed a collectables and coin dealer, alleging roughly 550 gigabytes. Neither is a household name. Neither holds state secrets. Both are the kind of business that would have described itself as too small to bother with.
Why the assumption is wrong
It rests on a picture of attackers choosing targets the way a burglar might case a specific house. That is not how most works now.
The common pattern is opportunistic. Affiliates scan broadly for a known weakness, an exposed remote access service, an unpatched edge device, a set of credentials bought from an access broker. What comes back is a list of reachable organisations, not a list of interesting ones. The decision about whether you are worth extorting happens after they are already inside and can see what you have.
By that point your size has stopped being protective. It has become an advantage to them, because a mid-size business is more likely to pay quickly, less likely to have practised recovery, and far less likely to have anyone watching at two in the morning.
What the mid-market actually has
Businesses in this range often underestimate their own data. A flooring supplier holds commercial contracts, pricing, supplier terms and customer records across a decade of jobs. A dealer in collectables holds high-value client lists, valuations, and details of what is stored where, which has an obvious secondary market that has nothing to do with cyber crime.
There is a second reason attackers like this segment. Operational leverage. A business with one site, one server room and no meaningful redundancy cannot absorb three days offline. A large enterprise can route around damage. A 40 person company usually cannot, which shortens the negotiation considerably.
What actually helps
The controls that matter at this size are not exotic. on everything reachable from the internet, which closes the single most common entry path. Backups that are genuinely offline or immutable, and that someone has restored from in a test rather than assumed. Patching on edge devices, because firewalls and remote access appliances are where opportunistic scanning lands first.
Then something watching outside business hours. This is the gap that defines the mid-market. Intrusions in Australian businesses very often start on a Friday evening, precisely because the attacker knows nobody is looking until Monday. Detection you only read during office hours is not detection.
None of that requires an enterprise budget. It requires deciding that being unremarkable is not a security strategy, because the groups working through Australian networks right now are not checking whether you are famous. They are checking whether you are reachable.



