Another week, another major company making headlines for the wrong reasons. This time it’s Qantas.
On July 2, the iconic Australian airline revealed that a cyberattack on a third-party provider may have exposed the personal data of up to 6 million customers. While investigations are ongoing, the sheer scale of this breach and the fact it happened via an external partner is a stark reminder that even the biggest organisations can be caught off guard through their supply chain.
Inside the Qantas breach
Qantas has confirmed that its own systems were not directly compromised. Instead, attackers breached a supplier that had access to Qantas customer data. This kind of supply chain attack is increasingly common: cybercriminals target a smaller vendor or service provider as a back door into a larger prize. In this case, sensitive information of millions of Qantas customers could be in the hands of hackers simply because a trusted third party was compromised.
The airline has notified regulators and affected customers, and stressed that no passwords or financial details were taken, but the incident still deals a blow to customer trust. It’s a scenario that could easily play out for any business that relies on vendors, which in today’s connected economy means just about everyone.
Why it matters for businesses of all sizes
High-profile breaches like Qantas make headlines, but they’re only the tip of the iceberg. The reality is that cybercriminals are opportunistic and increasingly target organisations of all sizes, especially small and medium businesses. In fact, cyber attacks are rising across the board: recent industry reports show a 126% increase in ransomware victims year-over-year, with Australia among the top 10 countries affected.
Big companies may appear to be the main targets, but thousands of smaller Australian businesses suffer incidents that don’t make the news. And those SMEs often have fewer defences, making them attractive targets.
A cyber breach is not just an “IT problem”. It’s a business problem with real operational and financial consequences. An incident can:
- Shatter customer trust and damage your brand. Clients who hear their data was leaked may take their business elsewhere.
- Disrupt operations and revenue. Whether it’s a ransomware attack freezing systems or a data breach investigation slowing things down, downtime costs money.
- Invite legal and regulatory trouble. Breaches can trigger privacy investigations, fines, or lawsuits, especially if it’s found that security measures were inadequate.
- Hit SMEs harder. For a smaller business, the recovery costs and effort can be overwhelming, and many never fully recover after a major cyber incident.
The bottom line: if a household name like Qantas can be hit indirectly, no organisation is “too small” or too obscure to be targeted. Every business holds something of value, whether it’s personal data, payment information, or simply access to bigger networks. Cyber threats are now part of the cost of doing business, and ignoring them is not an option.
What ‘good’ looks like: building strong cyber defences
Knowing the risks is one thing. Having the right protections in place is another. So, what does a strong security posture look like in practice? Every business, no matter the size, should put the following pillars in place to stay secure and resilient:
Layered security stack: Relying on a single line of defence is a recipe for disaster. A robust security stack means multiple layers working together, from firewalls and up-to-date endpoint protection, to email filtering, multi-factor authentication, and 24/7 network monitoring. This multi-layered approach can catch threats at different stages, reducing the chance that an attacker slips through.
Managed Security as a Service (MSaaS): For many organisations, especially SMEs, building an in-house security team isn’t feasible. MSaaS is an efficient alternative: you get a dedicated team of security experts monitoring your systems around the clock, leveraging the latest threat intelligence and tools on your behalf. It’s like having an enterprise-grade Security Operations Centre (SOC) on call, without the enterprise price tag.
Business Continuity and Disaster Recovery (BCDR): Even with great defences, breaches can still happen, which is why a solid BCDR plan is essential. This covers regular data backups, rapid recovery solutions, and step-by-step processes to keep your critical operations running during a crisis. With a tested BCDR plan, a cyber incident doesn’t have to mean crippling downtime or permanent data loss. You can respond, recover, and keep serving your customers even in the midst of an attack.
One partner for IT and security: Too often, companies split their general IT support (MSP) and their security provider (MSSP) between different vendors. The result can be gaps in coverage or finger-pointing when something goes wrong. By contrast, working with a provider that manages both your IT and your security means nothing falls through the cracks. An integrated MSP/MSSP team takes end-to-end responsibility for protecting your environment. They know your systems inside out and can align security seamlessly with your IT needs. When one trusted partner has your back on all fronts, you get less complexity and greater peace of mind.
Remember: cyber resilience isn’t something you can bolt on after the fact. It has to be built before an incident happens. Every breach you prevent is a victory. And if one does slip through, it should be a bump in the road, not a dead end for your business.
Let’s review your risks now and make sure you’re covered before it counts. Get in touch with the expert team at Virtual IT Group today.



