Back to Security

Cybersecurity Isn’t About How Big You Are. It’s About What You Have to Lose.

Cybersecurity Isn’t About How Big You Are. It’s About What You Have to Lose.

Most business owners size up their cybersecurity needs the same way they size up their insurance: by headcount. Ten employees, do this much. Fifty employees, do that much. Two hundred, time to get serious. It's an understandable instinct, but it misses the thing that actually matters: your cybersecurity risk profile.

At Affinity MSP, we've worked with businesses across almost every size and sector, and the pattern holds up every time. We've seen a 15-person medical billing company with more security exposure than a 200-person marketing agency. Same size range, completely different risk. The billing company holds patient financial records and answers to compliance obligations. The agency mostly manages its own internal files. One of them is a genuine target. The other is background noise to an attacker.

Headcount tells you how big your business is. It doesn't tell you what's worth stealing, who's watching, or what you're obligated to protect. That's why we assess clients by risk profile, not by size.

How to Find Your Cybersecurity Risk Profile

Before spending a dollar on tools or services, answer three questions honestly.

1. Do you store sensitive data?
Health records, financial details, government IDs, payment information, legal case files. If your business touches any of this, you're already a more interesting target than you might think.

2. Are you regulated or contractually obligated to prove security?
Healthcare, finance, legal, government contracts. Or simply a client who sends you a security questionnaire before they'll sign. If someone outside your business can demand proof of your controls, that changes what "enough" looks like.

3. Would a breach be publicly damaging, or nationally significant?
Think large customer base, public trust, critical infrastructure, or the kind of incident that ends up in the news.

Your answers place you in one of four profiles. The moment you sign a government contract, take on a healthcare client, or start handling payment data, your profile can shift overnight, which is exactly why we recommend clients revisit it whenever their client base or data handling changes, not just once a year.

Profile 1: Low Exposure

This is where most small, locally-focused businesses sit. Trades, small retail, local agencies, businesses that run internal operations for a nearby client base without touching particularly sensitive data. You're not invisible to attackers, but you're not a deliberate target either. Most of the risk here comes from opportunistic attacks: mass-sent phishing emails, credential stuffing from old data breaches, or ransomware that doesn't care who you are, only that you're reachable.

The good news is that this profile is genuinely low-cost to protect well, because the risk is largely generic rather than targeted.

Must-haves:

  • A password manager for the whole team, so nobody's reusing passwords across personal and business accounts
  • Multi-factor authentication (MFA) on email, banking, and cloud storage, which alone blocks the vast majority of opportunistic attacks
  • Automatic backups stored separately from your main account, so a ransomware attack on your main system doesn't take your backup down with it
  • Auto-updates and disk encryption turned on across all devices
  • A proper business-grade firewall, not just your ISP's default router
  • Role-based access, so a new hire in reception isn't automatically able to see the finance folder
  • A written offboarding checklist, so access gets revoked the day someone leaves, not whenever someone remembers

Nice-to-haves:

  • Centrally managed endpoint protection instead of everyone installing their own antivirus
  • Basic security awareness training, even a short quarterly session
  • An on-call IT contact or co-managed arrangement, rather than fixing things only when they break

Profile 2: Client Data Business

This profile covers businesses that hold personal or financial information on customers, but aren't formally regulated and wouldn't make national news if something went wrong. Think e-commerce stores, consultancies, professional services firms, agencies managing client campaigns or data. The exposure here is real: you're sitting on data that has resale value on the dark web (emails, payment details, personal information), even if you're not legally required to meet a specific framework.

This is also the point where "we'll deal with it if something happens" stops being a workable strategy, because the volume of data and number of systems in play makes manual oversight unreliable.

Must-haves:

  • Everything from Low Exposure, plus:
  • Centralised identity management (Microsoft Entra ID, Google Workspace), so one login system controls access across every tool, and a departing employee can be cut off everywhere in one action
  • Endpoint protection deployed and managed centrally, with visibility across every device rather than device-by-device guesswork
  • A one-page incident response plan: who gets called, what gets shut down, and in what order, if something goes wrong
  • VPN or zero-trust access for remote workers, so remote logins aren't just an open door into the network
  • Regular vulnerability scanning, which is cheap enough and automatable enough that there's no good reason to wait on it once you're holding customer data

Nice-to-haves:

  • Phishing simulation campaigns, testing staff with realistic fake phishing emails rather than just training them in theory
  • Data loss prevention (DLP) tools, flagging when sensitive data tries to leave the network unexpectedly
  • Cyber insurance, which increasingly requires proof of MFA and backups before insurers will even quote
  • Dark web monitoring for leaked company credentials, so you find out about a breach before an attacker uses it against you

Profile 3: Regulated Business

This is where legal and contractual obligation enters the picture. Healthcare providers, financial services, legal practices, and government contractors typically sit here, along with any business whose clients routinely send security questionnaires before signing a contract. At this level, "we take security seriously" isn't good enough. You need to be able to prove it, in writing, against a recognised standard.

The stakes also change here. A breach isn't just a bad day, it can mean regulatory penalties, loss of accreditation, or losing contracts that require ongoing compliance evidence.

Must-haves:

  • Everything from Client Data Business, plus:
  • A recognised framework, most commonly the Essential Eight in Australia, benchmarked to an actual maturity level rather than adopted informally
  • Managed detection and response (MDR), meaning someone is actively watching for threats around the clock, not just software sitting installed and unmonitored
  • A documented and tested backup and disaster recovery plan, with real recovery time targets, not just an assumption that backups will work when needed
  • Vendor and third-party risk assessments, since your compliance exposure extends to every supplier and software integration touching your data
  • Cyber insurance, which stops being optional at this level and starts being a standard cost of doing business
  • Formal access policies for contractors and temporary staff, so short-term access doesn't become a long-term gap

Nice-to-haves:

  • Annual penetration testing, actively trying to break into your systems rather than just scanning for known vulnerabilities
  • Privileged access management (PAM), adding extra controls specifically around admin-level accounts, which are the highest-value target for attackers
  • Tabletop incident response exercises, running a simulated "what if we got hit today" scenario with leadership present
  • SIEM-level log aggregation across sites and systems, so unusual activity in one location can be correlated with activity elsewhere instead of reviewed in isolation

Profile 4: High-Value Target

This profile applies to organisations where scale, public trust, or critical function make you a deliberate target, not just an opportunistic one. Large healthcare networks, financial institutions, critical infrastructure providers, and publicly listed companies typically live here. At this level, cybersecurity stops being an IT function and becomes a governance responsibility, reported on at board level and scrutinised by regulators, insurers, and the public alike.

The threat model also changes. You're no longer primarily defending against generic ransomware, you're defending against attackers who research you specifically, sometimes over months, before acting.

Must-haves:

  • Everything from Regulated Business, plus:
  • 24/7 Security Operations Centre (SOC) monitoring, with continuous human and automated oversight across every site and system
  • Formal compliance certification, audited by an accredited third party, not just internally aligned to a framework
  • A dedicated Chief Information Security Officer (CISO) or senior security lead, owning strategy and accountability
  • Board-level security reporting, typically quarterly, treating cybersecurity as a standing governance item rather than an occasional update
  • A business continuity plan covering full site loss, ransomware response, and the reputational and legal fallout of a serious incident, not just IT outages

Nice-to-haves:

  • Red team exercises, adversarial simulations that test detection and response speed, not just the strength of existing controls
  • Cyber threat intelligence feeds specific to your industry, giving early warning of emerging attack patterns targeting similar organisations
  • A bug bounty program, inviting external security researchers to responsibly disclose vulnerabilities before malicious actors find them

If you're not sure which profile your business falls into, or you suspect you've outgrown your current setup, our cybersecurity services team can walk through it with you. It's a conversation, not a sales pitch, and it usually takes less time than you'd expect to get real clarity on where you stand.

Franchesca Michaela Antonio
Franchesca Michaela Antonio
Back to Security