Cyber Security for Trade & Service Businesses: What You Should Know Heading Into 2026

Cyber Security for Trade & Service Businesses: What You Should Know Heading Into 2026

By Daniel Doller (General Manager), Nectar

Cyber security has become a critical issue for trade and service businesses across New Zealand and Australia. While many owners assume cyber attacks only target large organisations, the truth is that small and mid-sized trade and service companies are now prime targets.

In recent years, the team at Nectar has seen a sharp increase in cyber incidents affecting trade and service businesses. The reason is simple: these businesses rely heavily on cloud systems, mobile devices, remote work, and fast communication – all of which create opportunities for attackers if the right safeguards aren’t in place.

In this guide, we break down the top risks, what they look like in real life, and practical steps you can take to protect your business, your customers, and your operations.

Why Trade & Service Businesses Are Being Targeted

Attackers see trade and service companies as high-value, low-barrier targets. Common vulnerabilities include:

  • Heavy reliance on smartphones and tablets
  • Frequent use of cloud systems
  • High volume of quotes and invoices sent via email
  • Fast-paced communication, leading to hasty clicks
  • Multiple staff working remotely or on-site
  • Sensitive customer information stored on devices
  • Limited in-house IT or security resources

Most attacks aren’t sophisticated, they’re simple, preventable, and often caused by day-to-day habits rather than technology failures.

1. Invoice Fraud (Still one of the biggest threats today)

Invoice fraud remains one of the most damaging cyber threats facing trade and service businesses.

Here’s how it works:

  • A hacker gains access to your email
  • They monitor outgoing quotes and invoices
  • They quietly change the bank account details
  • Your customer pays the attacker instead
  • Funds disappear overseas within minutes

Many businesses don’t realise what happened until customers question overdue invoices, long after the money is gone.

How to Protect Your Business

✔ Send invoices as PDFs rather than editable text
✔ Enable multi-factor authentication (2FA) for Xero and email
✔ For large jobs, confirm bank details verbally
✔ Avoid storing invoice templates inside your inbox
✔ Encourage customers to check account information if unsure

2. Lost or Stolen Devices (A Major Security Weak Point)

A misplaced or stolen phone/tablet isn’t technically a cyber attack, but it is one of the most common ways attackers gain access to sensitive information.

A device used by your business may contain:

  • Customer information
  • Addresses and job notes
  • Work photos
  • Access to email
  • Cloud systems like Simpro, Tradify, or Xero
  • Saved passwords in browsers

If the device isn’t secured, someone could impersonate your business or gain access to critical systems.

How to Reduce the Risk

✔ Enable auto-lock (30 seconds recommended)
✔ Use strong PINs plus fingerprint/Face ID
✔ Turn on remote wipe (Apple/Google)
✔ Avoid storing passwords in unsecured apps
✔ Disable auto-login for sensitive systems

Device security should be treated the same way as tool security, essential, not optional.

3. Fake Job Enquiry Scams (A Rapidly Growing Threat)

One of the biggest growing threats is fake job enquiries designed to trick businesses into opening malicious attachments or links.

These messages often say:

“Can you quote this job? Plans attached.”

Warning signs include:

  • No phone number
  • Poor spelling or grammar
  • Unusual file types (.zip, .rar, .exe)
  • Unexpected urgency
  • Suspicious Google Drive or Dropbox links

Opening these files can give attackers full access to your inbox or device.

How to Stay Safe

✔ Don’t open attachments from unknown senders
✔ Request a phone number and call to confirm
✔ Ask for cloud links instead of file downloads
✔ Delete suspicious emails immediately
✔ Report serious cases to CERT NZ

A few seconds of caution can prevent major downtime.

4. Weak Passwords & Shared Logins

Weak or reused passwords and shared logins are extremely common in trade and service businesses — and attackers know it.

Examples we still see:

  • BusinessName2025
  • Company123!
  • Shared Simpro or Xero logins
  • Passwords stored in Notes or plain text

These issues make it easy for attackers to gain access to sensitive systems.

Your Best Defence

✔ Use strong, unique passwords for each system
✔ Enable two-factor authentication (2FA) everywhere possible
✔ Give each staff member their own login
✔ Remove access immediately when staff exit
✔ Use a secure password manager if required

A few changes dramatically reduce risk.

5. Public WiFi Risks (A Persistent Security Weakness)

Public WiFi networks in cafés, hotels, airports remain unsafe environments for logging into business systems.

Cyber criminals often intercept data or create fake networks that look legitimate.

Protect Yourself

✔ Use mobile data instead of public WiFi
✔ If remote, use a VPN
✔ Avoid entering passwords on shared networks

It only takes one compromised session to expose an entire business.

The Bottom Line

For trade and service businesses, cyber security doesn’t need to be complex.
Most incidents we see today can be avoided with simple, consistent habits:

  • enabling 2FA
  • securing devices
  • using strong passwords
  • verifying bank details
  • avoiding unsafe networks
  • being cautious with attachments

These small actions protect your operations, your customers, and your revenue.

As Daniel puts it:

“For most trade and service businesses, cyber security isn’t about buying fancy tools – it’s about simple habits done consistently. A few small changes can prevent the majority of cyber incidents we see.”

If you’d like Nectar to review your setup, strengthen your protections, or help your team adopt better security habits, we’re here to help.

Find out how we can work together

Contact us