Cost of sales: Formula, calculation, and tips for SMEs
Learn how to calculate cost of sales for Australian SMEs. Discover the standard formula, key direct inclusions, FX landed costs, and common mistakes to avoid.
Scammers and cybercrims swindle hard-working Aussies out of $2 billion each year.1 And for the Aussie SMB operating on razor-thin margins, financial crimes like payment fraud can become an immediate, existential threat.
By adopting more secure payment methods, managers can close security loopholes and mitigate risks, protecting their once-vulnerable businesses from a range of nefarious threats.
In this post, we’re covering the essentials an Aussie SMB should know about secure payments, from definitions to features, procedures, types, and challenges.
| Table of Contents |
|---|
A secure payment method uses technology to make a transaction safer. Examples include encryption, authentication, tokenisation, and fraud detection. Secure payment methods may also adhere to certain standards, such as the Payment Card Industry Data Security Standard (PCI DSS), a global ruleset designed to safeguard sensitive card details.2
Not all payments are equal; some are substantially more secure than others. Businesses may choose to adopt more stringent methods for high-risk transactions, such as international or card-not-present payments.
Australian businesses can leverage a plethora of secure payment technologies and features.
Encryption means turning sensitive data – such as personal information or credit card numbers – into scrambled ‘ciphertext’ code. The jumbled code cannot be read if intercepted, and can only be converted back into plain text data using a decryption key.
There are two types of encryption. Symmetric encryption uses a single key for both encryption and decryption, making it faster but more vulnerable. Asymmetric encryption uses two different keys, one public and one private, allowing the public key to be safely shared.
Encryption and tokenisation use different methods to achieve similar means. While encryption adopts a mathematical formula, tokenisation replaces the data with random substitutes called ‘tokens.’ A secure database, known as a ‘token vault’, is required to match the tokens to real data and read the information.
Tokenisation provides high-level protection because hackers can’t reverse-engineer tokens with a decryption key. Plus, during payment processing, randomised tokens circulate rather than encrypted data.
Tokenisation is also useful for protecting stored information. For example, during a data breach, the technology could turn a catastrophe into a non-event.
Multi-factor authentication, as the name hints, requires users to authenticate their identity using multiple factors, typically two or more of the following:
MFA provides a potent extra layer of protection against unauthorised payments, as bad actors can rarely authenticate multiple factors. Some payment platforms have replaced SMS with in-app notifications due to the prevalence of SIM swap scams.
MFA may trigger for every transaction, or only during high-risk events, such as card-not-present payments from unexpected locations.
Europay, Mastercard, and Visa (EMV) cards have tiny built-in microprocessors that generate unique one-time transaction codes that can’t be reused if intercepted⁸. Fraudsters find it harder to clone or counterfeit EMV cards than traditional magnetic strips, which are susceptible to skimming.

Instead of swiping a magnetic strip through an EFTPOS machine, the customer pays by tapping the chip or inserting the card. A PIN may be required for higher-value transactions over a certain threshold. Due to their high uptake in Australia, many businesses prefer POS systems that accept EMV card payments.
Financial institutions can use fraud detection systems (FDS) to identify and block dodgy transactions in real time. Through a sophisticated combination of algorithms, pattern recognition, and machine learning, FDS can flag high-risk payments, giving businesses or customers the chance to investigate before losses occur.
Core capabilities include:
Red flags that could trigger a review include unexpected payment locations or multiple customers with identical contact information but different names. Medium-risk transactions might prompt additional authentication, such as MFA, while high-risk payments could be suspended until manually verified.
PCI DSS is a set of global card security standards developed for businesses that accept card payments, including merchants, service providers, and financial institutions. The standard supports implementing secure practices, technologies, and processes for handling customer card data.2
Many Australian SMBs comply by outsourcing payments to third-party payment processors, which operate Point of Sale (POS) terminals for in-person transactions and payment gateways for secure online payments.
PCI Security Standards cover a range of factors, including:
PCI DSS mandates include encryption when transmitting cardholder data, strict access control measures, and monitoring and testing, among others.2
Your average small Australian business doesn’t have the expertise to handle things like compliance, fraud monitoring, or encryption in-house. Many outsource payments to a third-party provider, which manages the complexities for a fee.
For small businesses setting up secure payments, the typical process looks something like this:
Australian businesses can accept in-person and online payments using various methods. While the following options are generally secure, all payment methods have a degree of vulnerability.
Convenient but costly in fees, cards are a classic option favoured by many Australian consumers⁹. Strict PCI DSS regulations govern card payments, and built-in security features like EMV chips and Card Verification Value (CVV) reduce vulnerabilities.

Banks may use MFA and FDS to prevent fraudulent transactions, while card schemes – Visa, Mastercard, American Express, etc. – sometimes offer zero-liability protection against unauthorised transactions, which affected two million Australians in 2023-2024.3
For small Australian businesses trading online, chargeback fraud has become a big concern. Fraudsters dispute legitimate purchases and claim refunds, leaving the business out of pocket for lost stock and chargeback fees.4
Businesses use POS machines to accept in-person card-present payments, and payment gateways for riskier online card-not-present transactions.
BPAY lets you pay bills directly from your existing online banking portal or mobile app. The payer enters the receiver’s Biller Code and Customer Reference Number (CRN) into the BPAY section and submits the payment request¹⁰.
As BPAY operates through a secure online banking portal, it’s safe when done correctly. However, BPAY is still vulnerable to redirection fraud if a scammer provides you with a phony Biller Code and CRN. Once a BPAY payment has been submitted, it’s often impossible to reverse.
Digital wallets, such as Google Pay and Apple Pay, store card details in a secure digital environment called a ‘wallet’, which uses encryption and tokenisation to keep data anonymous. That means customers can pay without ever disclosing card details, which many security experts believe makes the digital wallet more secure.

Businesses can accept in-person digital wallet payments through a POS machine using near-field communication (NFC) to connect with a user's smartphone. Online digital wallet payments typically occur through a payment gateway.
Many Australian businesses prefer bank transfers for high-value, business-to-business (B2B) transactions due to their lower fees. While generally secure, bank transfers are susceptible to redirection scams, where cybercriminals impersonate a legitimate business and invoice customers using fraudulent account details. The scam cost Aussie businesses $227 million in 2021.5
Domestic Australian payments can use PayID, an easier and safer type of bank transfer. Instead of manually entering account numbers, the sender types in a unique identifier, such as a mobile number or email, and then receives the sender’s name for cross-referencing, which helps reduce redirection fraud.6
A type of recurring payment in which the business debits funds directly from the customer's bank account on an agreed-upon schedule, such as monthly, quarterly, or annually. This secure payment type is common for ongoing expenses, such as utilities.
To commence a direct debit, the business must acquire a signed authorisation form from the customer. While generally safe, direct debit fraud can occur when a criminal signs a forged authorisation form using stolen account details and personal information.
Despite the rise of digital payments, cash still lingers in the Australian economy. In-person businesses accepting physical notes and coins will need to record transactions and provide change.
The security risk of dealing in cash, of course, is theft. Businesses accepting large quantities are especially vulnerable.

Traditional paper cheques have fallen out of favour in Australia, making up just 0.1% of all non-cash retail payments, according to the Reserve Bank7. The Federal Government plans to phase them out entirely by 2029.¹¹
In addition to being inconvenient and slow to clear, cheques are susceptible to signature forgery and spot alteration.
Aussie businesses must overcome extra payment-related hurdles when trading overseas.
Wise Business offers a safe, transparent way to send and receive cross-currency payments. As a multinational fintech serving 700,000 businesses worldwide, Wise employs a wide range of security features, including MFA, biometrics, encryption, real-time notifications, and customisable controls.

A Wise Business account allows users to send, receive, and hold in multiple currencies. Experience hassle-free global transactions by transacting like a local business. Here's what you get with a Wise Business account:
Sign up for the Wise Business account! 🚀
This general advice does not take into account your objectives, financial circumstances or needs and you should consider if it is appropriate for you.
**Capital at risk, growth not guaranteed. Interest is the name of a custody and nominee service provided by Wise Australia Investments Pty Ltd in partnership with Franklin Templeton.
1. How do I know if an online payment method is safe?
When selecting a safe payment method for your business, look for security features like encryption, tokenisation, PCI DSS compliance, and MFA.
2. Are bank transfers safer than card payments?
Both have a degree of risk for businesses. Bank transfers are susceptible to redirection scams, while card payments can lead to chargeback headaches.
3. How to make secure online payments?
Customers can make secure online payments by looking for a platform that offers PCI DSS compliance, encryption and/or tokenisation, and HTTPS.
4. What are some secure ways to collect client payments?
Businesses can securely collect payments from clients by credit card, bank transfers, or embedded invoices with clickable pay-here buttons.
Sources
*Please see terms of use and product availability for your region or visit Wise fees and pricing for the most up to date pricing and fee information.
This publication is provided for general information purposes and does not constitute legal, tax or other professional advice from Wise Payments Limited or its subsidiaries and its affiliates, and it is not intended as a substitute for obtaining advice from a financial advisor or any other professional.
We make no representations, warranties or guarantees, whether expressed or implied, that the content in the publication is accurate, complete or up to date.
Learn how to calculate cost of sales for Australian SMEs. Discover the standard formula, key direct inclusions, FX landed costs, and common mistakes to avoid.