← Articles
RIPOSTE research · 2026

Who Would Actually Target a Business Like Mine?

“If they can hack the Pentagon, what hope does a business like mine have?” It is one of the most common things we hear, and it quietly leads people to the wrong conclusion — either that serious security is hopeless, or that they must somehow defend against the world's most capable attackers. Both are wrong. The useful question is narrower: who would realistically come for an organisation like yours, and what would it take to stop them?

You are not the Pentagon — and your attackers know it

Capable, well-resourced attackers spend their capability where it pays. A nation-state intelligence service has no interest in a suburban firm for its own sake, and it will not burn a valuable technique on one. The overwhelming majority of attacks on small and medium businesses are not targeted at all: they are opportunistic, automated and indifferent to who you are. You are not singled out; you are simply reachable. That is good news, because reachable-and-ordinary is a threat you can actually plan against.

The realistic threat spectrum

It helps to think of adversaries as tiers rather than a single faceless “hacker.” At the bottom is commodity, opportunistic activity: automated scanning, mass phishing, credential stuffing and off-the-shelf ransomware, sprayed at everyone. Above that is organised cybercrime — professional, financially motivated groups who will invest real effort when the payoff is there, through business email compromise, targeted ransomware and invoice fraud. Higher still are targeted attackers with specific intent, and at the top, nation-state actors with deep resources and patience. Each tier brings different capabilities — and, this is the point, different organisations realistically face different tiers.

What actually comes for a small or medium business

For most businesses the real threat lives in the bottom two tiers, and it is remarkably consistent: a phishing email that harvests a password; a compromised mailbox used to redirect an invoice; reused credentials that unlock an account; a commodity scanner that finds an exposed service you had forgotten about. These attacks are cheap, automated and relentless precisely because they work at scale. They are also, overwhelmingly, the ones that stop when you get the fundamentals right — which is why proportionate security is not a polite word for doing less. It is doing the right things against the threat that is actually arriving.

When the threat escalates

Some organisations genuinely face more, and it is worth being honest about whether you are one. If you hold data that is valuable in its own right — health records, legal confidences, valuable intellectual property, large volumes of personal data — you become worth deliberate effort. If you sit in the supply chain of a larger, more attractive target, you can be attacked as a stepping stone to them, regardless of your own size. And some sectors attract sustained, sophisticated attention as a matter of course. The tier that applies to you is a judgement about your data, your position and your adversaries — not a default, and not the worst case you can imagine.

Security proportionate to the threat

This is the principle the whole thing turns on: your security should be strong enough for the threats that are real for you, without wasteful investment against threats that are not. The environment facing a small firm is not the one facing a defence contractor or a critical-infrastructure operator, and spending as though it were is not prudence — it is money and effort taken from where they would actually reduce your risk. Proportionate does not mean minimal. It means matched: calibrated to the adversary who would realistically target you, so that what you spend genuinely buys you resilience.

But the line does not stand still

There is one important caveat. What a sophisticated attacker can do today has a way of becoming commodity tomorrow: techniques once confined to well-resourced actors get packaged, automated and sold down the chain until they reach the opportunists. So proportionate security is not a setting you reach once and forget — it is a line that has to be revisited as attacker capability evolves. Part of assessing your threat properly is keeping that picture current, rather than defending against last year's version of the adversary.

How to work out your real threat

You do not have to guess. Working out the highest adversary tier that credibly applies to your organisation is a considered judgement — one we reach with you during scoping, informed by our DarkRose threat-and-risk intelligence, rather than something a tool assumes on your behalf. From there, every assessment we run is calibrated to emulate that tier rather than a generic checklist, so the result reflects your actual exposure. The outcome is a posture that is proportionate, defensible and able to evolve with the threat — strong where it needs to be, and not wasteful where it does not.

If you have ever caught yourself thinking “but they could hack anyone,” this is the conversation worth having. The honest, specific answer to “who would target a business like mine?” is almost always more manageable than the fear — and it is the foundation everything else should be built on.

Sources

  1. ASD's ACSC Annual Cyber Threat Report 2024–25 (cyber.gov.au)
  2. ASD Essential Eight — Australian Signals Directorate (cyber.gov.au)
  3. OAIC Notifiable Data Breaches publications (breach statistics)
About the author

Cameron McCollum — Director & Founder, RIPOSTE. He spent two decades in Australian Army intelligence — serving as Head of Intelligence on operations across the Asia-Pacific and Afghanistan — before building and leading the cyber-risk program at Lexon Insurance. He holds Master's degrees in Cyber Security Operations and Business (UNSW) and is an ISO/IEC 27001 Lead Implementer.

RIPOSTE helps organisations turn analysis like this into action.

Talk to us