Skip to main content

Seven Cyber Gaps in Sydney Trade Businesses

8 September 2026 | By Birender Chahal

A trade business does not feel like a cyber target. You are an electrician, a plumber, a builder. There is no shopfront full of card numbers, no database of medical records. The whole operation runs out of a van, a phone, and an accounting app. Surely there is nothing here worth attacking.

That assumption is exactly why tradies get caught. The business moves real money through quotes and invoices, runs almost entirely off a phone, and works with a rotating crew of casuals and subbies. For an attacker chasing a payment, that is close to ideal, and the defences are usually thin because nobody thought they needed any. If you want the wider picture, start with our guide to IT for trades and contractors. Here are the seven gaps we find most often, and the practical fix for each.

Gap 1: Quote and Invoice Fraud

The single biggest risk in trades is not data theft. It is payment fraud. You send quotes and invoices by email all day, and that is exactly what attackers exploit.

Someone gets into a mailbox in the chain, watches the back and forth, and then sends an invoice that looks like it came from you, or from a supplier, with the bank details quietly changed. The customer pays the wrong account, or you pay a fake supplier, and the money is usually gone before anyone notices. This pattern, business email compromise, does the most damage in this sector by a wide margin. The defence is multi-factor authentication on every mailbox plus a hard rule that any change to bank details is confirmed by a phone call to a known number, never by replying to the email.

Gap 2: The Phone Is the Business, With No Controls On It

For most tradies the phone is the office. Quotes, photos, customer numbers, the accounting app, the banking app, all of it lives on one device that goes everywhere with you, including up ladders and onto building sites where it gets dropped, lost, or pinched.

A lost phone with no controls is a straight line into your business and your customers’ details. The fix is not complicated: a proper screen lock and encryption so a lost phone is not a breach, and the ability to remotely wipe it if it goes missing. The protections travel with the device, so the worst case is an annoying replacement rather than a fraud.

Close-up of hand picking up desk phone
For a trade business, the phone holds the whole operation.

Gap 3: The Same Password Everywhere

When you run lean and fast, one password tends to do everything. The email login, the accounting app, the supplier portal, the banking, all on the same handful of passwords you have used for years.

The problem is that passwords leak constantly through breaches at completely unrelated companies. Reuse one, and an attacker who finds it has the keys to several of your systems at once. The fix is a password manager so every account has its own strong password without you having to remember them, and a second verification step on the accounts that matter most, so a leaked password alone is not enough to get in.

Gap 4: No Backup of Job and Customer Data

Years of quotes, job photos, customer contacts, and compliance certificates often live in one place: the accounting app, a phone, or a single laptop. There is no second copy. If that device dies, gets stolen, or is hit by ransomware, the history of the business goes with it.

A backup nobody has is not a safety net, and a backup nobody has tested is a guess. The fix is to make sure your job and customer data is backed up automatically, with at least one copy an attacker cannot reach or encrypt, and to actually test that you can restore it. Then a dead phone or a bad day is a few hours of hassle, not the loss of everything you have built.

Gap 5: Personal Devices Doing Business Work

Trades mix personal and business constantly. The work goes through your own phone, an apprentice uses their own tablet, a partner logs into the accounting app from the home computer. Each personal device doing business work sits outside whatever protection the business has.

That mix is productive, and it widens the attack surface. The fix is not to ban personal devices, it is to make sure any device touching business systems meets a basic bar: it is kept updated, it has a screen lock, and access is through accounts you control and can switch off. The work can stay flexible without leaving the back door open.

Gap 6: No Multi-Factor Authentication

Almost every trade business has a password on its email and its banking. Far fewer have a second lock. We regularly find multi-factor authentication switched on for nothing, leaving the email account that controls every password reset protected by a single password that may already have leaked.

Attackers look for the one account with only a password in front of it. The fix is to inventory every system that holds money or customer data, starting with email, and turn on a second verification step everywhere. It is the single control that blocks most account takeovers, and in this sector it is the one most often missing.

Gap 7: No Offboarding for Casual Labour

Trades work through crews that change constantly. An apprentice moves on, a subbie finishes a job, a casual covers a busy week. Each one may have picked up a login to the job app, a shared drive, or the email along the way, and the common gap is that the access never gets removed.

A former crew member who still has a login is a quiet way in months later. The fix is simple discipline: access is granted by role, written down somewhere, and switched off the day someone stops working for you. It takes a few minutes per departure and closes a gap that otherwise stays open for years.

Closing the Gaps

None of these are exotic. They are the everyday shortfalls that turn a busy, profitable trade business into a fraud victim or a recovery scramble. Most of them are settings you can tighten or simple habits around money and crew changes, not a major IT project.

The hard part is knowing which gaps apply to you, because most are invisible until someone looks. That is the value of an honest assessment.

Where to Start

If you recognised your business in more than one of these, you are normal, and you are in a good position, because every gap here has a clear fix. The starting point is the same for everyone: get a clear picture, then close the biggest gaps in order.

Our IT maturity assessment takes a few minutes and gives you a plain-English read on where you stand. From there you will know what to handle yourself and what to hand over.

We are a Sydney-based team in Bella Vista, and we work with trades and contractors across the metro area. We understand a business that runs off a phone and a van, and we secure it without slowing the work down. Talk to our team when you are ready.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.