Perspectives on cyber risk · 2026
The real cost of a data breach in Australia
Breach notifications reached a record in 2025, the first civil penalty under the Privacy Act has been paid, a statutory right to sue for privacy invasion is in force, and one in four malicious breaches now involves AI. What a breach costs an Australian organisation in 2026, where the money goes, and what the evidence says reduces it.
Coder Trove Cyber Security Practice · Published 25 September 2026 · 12 minute read
$4.22m
Average cost of a data breach in Australia, up 38 per cent since 2019
IBM Cost of a Data Breach 2026
1,205
Notifiable data breaches reported to the OAIC in calendar 2025, the highest since the scheme began
OAIC, July 2026
6 min
One cybercrime report to the ASD every six minutes, at an average self-reported cost of $80,850 per business report
ASD Cyber Threat Report 2024-25
$5.8m
First civil penalty ordered under the Privacy Act, against Australian Clinical Labs, October 2025
Federal Court / OAIC
The headline number
The average cost of a data breach in Australia in 2026
IBM's 2026 study puts the average cost of a data breach in Australia at $4.22 million, with financial services at $6.31 million, technology at $5.51 million and healthcare at $5.09 million. The average incident exposed 22,400 records at a cost of $167 per record. Globally the figure rose 12 per cent in a year to a record US$4.99 million, reversing the improvement recorded in 2025.
These averages come from organisations large enough to be studied, and they measure the direct costs of an incident: detection, containment, notification, legal and forensic fees, lost business. Most Australian organisations will see a smaller number in absolute terms and a larger one in proportion to revenue. The ASD's figures, self-reported by the businesses making cybercrime reports, show the average cost per report rose 50 per cent in a year to $80,850, with medium businesses at $97,200 and large businesses at $202,700. Those figures are per incident and exclude what comes after.
Two thirds of Australian breaches in the first half of 2025 affected 100 people or fewer. The regulator's scrutiny, the customer's contract clause and the insurer's questionnaire apply regardless.
OAIC Notifiable Data Breaches, January to June 2025
The direct bill has grown only modestly since 2023. The costs that follow it have multiplied, and they now arrive on statutory timetables.
The costs that arrive later
Privacy Act penalties, litigation and reporting obligations after a breach
Regulatory penalties are now real money, with precedent
In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties plus costs over the 2022 Medlab Pathology breach: $4.2 million for failing to take reasonable steps to secure personal information across 223,000 contraventions, $800,000 for failing to assess the breach in time, and $800,000 for failing to notify in time. It was the first civil penalty ever imposed under the Privacy Act, and it established that the failure to assess and notify promptly is penalised separately from the failure to secure.
The OAIC has civil penalty proceedings on foot against Medibank, over the data of 9.7 million people, and against Optus, filed in August 2025 over roughly 9.5 million. Each carries a maximum of $2.22 million per contravention under the penalty regime that applied at the time. For breaches occurring after December 2022 the maximum for a serious or repeated interference with privacy is the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover. A mid-tier penalty of up to $3.3 million, and infringement notices, were added in December 2024 for conduct that falls short of serious.
Individuals can now sue directly
Since 10 June 2025 a statutory tort for serious invasions of privacy has been in force. A person whose privacy is seriously invaded, including through misuse of their information, can bring an action without needing to show financial loss. Combined with the representative complaint mechanism that Maurice Blackburn has used for Qantas customers, and the class actions that followed Optus, Medibank and Latitude, the litigation exposure from a breach now runs on two tracks in parallel with the regulator.
Ransomware payments must be reported within 72 hours
Under the Cyber Security Act 2024, any business with annual turnover of $3 million or more that makes a ransomware or cyber extortion payment must report it to the Australian Signals Directorate within 72 hours. The obligation started on 30 May 2025 and the enforcement phase began on 1 January 2026. A decision many boards still treat as private is now a regulated event with a paper trail.
Regulated sectors carry their own clocks
APRA's CPS 230 on operational risk commenced on 1 July 2025, and from 1 July 2026 every material service provider contract held by a bank, insurer or superannuation fund must comply. The practical effect is that a breach at a supplier to a regulated entity becomes the regulated entity's incident, with the tolerance levels and notification duties that follow. Anyone selling into financial services has inherited that scrutiny whether or not they are regulated themselves.
The next round is already drafted
On 31 August 2026 the Attorney-General released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the second tranche of Privacy Act reform. It proposes around forty changes, including a fair and reasonable test for the handling of personal information, a controller and processor framework, a right to erasure for large platforms, and a positive duty to mitigate harm after any breach. Submissions closed on 18 September and the Government intends to introduce the Bill before the end of 2026. The Children's Online Privacy Code must be registered by 10 December 2026.
How breaches start
How data breaches happen in Australia: credentials, people and suppliers
The pattern in the Australian data has held for several years. In the OAIC's most recent detailed breakdown, 55 per cent of cyber incidents began with credentials, either phished (34 per cent) or stolen by unknown means (21 per cent). Ransomware accounted for a further quarter. The ASD found compromised accounts or credentials in 42 per cent of the more serious incidents it responded to. Human error, mostly misdirected email, caused 37 per cent of all notified breaches in the first half of 2025, up from 29 per cent.
The largest Australian incidents of the past eighteen months follow the same lines. Qantas lost 5.7 million customer records in June 2025 when an overseas third-party contact centre was socially engineered by phone; the OAIC closed its inquiries in July 2026 without further action, but the records were leaked publicly and a representative complaint is proceeding. In April 2025 credential stuffing hit AustralianSuper, Rest, Hostplus, Australian Retirement Trust and Insignia, with SMS two-factor authentication bypassed by SIM swap in some cases and four AustralianSuper members losing roughly $500,000 between them. Origin Energy confirmed in July 2026 that data on around 900,000 current and former customers had been accessed.
Third parties were involved in 48 per cent of breaches worldwide in 2025, up from 30 per cent the year before and 15 per cent the year before that.
Verizon Data Breach Investigations Report 2026
IBM's 2026 Australian data ranks the most expensive initial vectors as abuse of valid accounts ($4.87 million), social engineering and IT impersonation ($4.78 million) and phishing ($4.48 million). All three are failures of identity, verification and the controls around privileged access. Four of the eight Essential Eight strategies address them directly, which is why insurers have started asking for a maturity level rather than a list of products.
What changed in 2026
AI-enabled attacks, shadow AI and the cyber insurance market in 2026
AI-enabled attacks became ordinary
One in four malicious breaches in IBM's 2026 study was AI-enabled, a 56 per cent increase in a year, at an average cost of US$6 million. In Australia 32 per cent of malicious attacks involved AI-generated elements. The techniques are older ones made cheaper: voice phishing that sounds like the CFO, help-desk impersonation that passes the security questions, résumés and interview performances that belong to someone other than the person who turns up on day one. Recorded Future's research into North Korean operatives obtaining software engineering roles at Western companies through fabricated identities is the sharpest current example, and the subject of our executive briefing on 27 October.
Shadow AI became a data breach vector in its own right
Verizon's 2026 report found the share of employees using unapproved AI tools tripled in a year, from 15 to 45 per cent. IBM found that more than a fifth of organisations had suffered a breach involving their own AI models or applications, most often through compromised APIs and plug-ins or misconfigured cloud AI workloads, and that 92 per cent of those organisations had no AI access controls in place. Organisations using AI extensively in their security operations, by contrast, identified breaches 68 days faster and paid $1.75 million less per breach in Australia than those using none.
Cyber insurance is softer on price and harder on evidence
Australian cyber premiums fell five to ten per cent in the first half of 2026 according to Marsh, continuing a decline that ran through 2025, and global rates have fallen for twelve consecutive quarters. Capacity is up and the class has been profitable for insurers. Underwriting has tightened at the same time: MFA on all remote and privileged access, endpoint detection and response, tested backups and an evidenced Essential Eight maturity level are now standard questions, and healthcare in particular is under closer scrutiny. Coalition's 2026 claims data shows business email compromise and funds transfer fraud making up 58 per cent of claims, with the average funds transfer loss near $199,000. Take-up remains low: the Australian Institute of Criminology found only 3.7 per cent of respondents held cyber insurance in 2025, while a quarter of small business owners had been hit by cybercrime in the previous year.
Breaches are taking longer to find again
After years of improvement, the global average time to identify and contain a breach lengthened to 247 days in 2026. In Australia, breaches that ran past 200 days cost $5.17 million against $3.26 million for those contained sooner. Only 32 per cent of Australian organisations had encryption in place across sensitive data at rest and in transit at the time they were breached.
Where the money goes
The cost lines of a data breach
The first three lines below are what an incident budget covers. The remaining five are what the board will still be dealing with a year later.
| Cost line | What it covers | What drives it up or down |
|---|---|---|
| Detection and containment | Forensics, incident response, overtime, external counsel, recovery of systems | Days to detect. Whether logs, backups and a rehearsed response plan exist |
| Notification | OAIC assessment and notification, individual notices, call centre, credit monitoring | Number of records, quality of data inventory, 30-day assessment discipline |
| Lost business | Customer churn, delayed sales, contract terminations, share price | Sector trust sensitivity, transparency of the response, duration of outage |
| Regulatory | Civil penalties, enforceable undertakings, compliance programs, Commissioner determinations | Whether reasonable steps can be evidenced. Timeliness of assessment and notification |
| Litigation | Class actions, representative complaints, statutory tort claims, supplier disputes | Scale, sensitivity of data, what internal documents show was known and unfixed |
| Extortion | Ransom decision, negotiation, 72-hour reporting, sanctions screening | Backup integrity, data exfiltration, leverage the attacker holds |
| Contractual | Customer and regulated-entity notification duties, CPS 230 obligations, insurer conditions | What was promised in security schedules and questionnaires, and whether it was true |
| Remediation | The uplift that should have happened before, now done under pressure | Distance between current and required maturity. Done in a crisis, it costs more |
Every tender response, insurance proposal and customer security schedule an organisation has completed is a statement about its controls. When a breach shows those statements were aspirational, a failure to secure becomes a misrepresentation as well, and the internal record of what was known and left unfixed becomes discoverable. The Australian Clinical Labs penalty turned in large part on what the company was aware of before the breach and had not acted on.
What reduces the cost
How to reduce the cost of a data breach: five board decisions
Set an Essential Eight maturity target and have it independently assessed
The ASD names the Essential Eight the most effective set of mitigations available, and Maturity Level 2 is now the common floor in contracts, insurer questionnaires and government supply chains. A self-assessment carries little weight with any of them. An independent rating against the current maturity model, control by control, answers the regulator, the insurer and the customer with one document and turns a general obligation into a costed plan.
Treat identity as the perimeter
More than half of Australian cyber incidents start with a credential. Phishing-resistant MFA for all staff, with no SMS fallback for privileged or high-value accounts, restriction of administrative privilege, and conditional access that notices an impossible login are the controls that would have changed the outcome at the super funds and in most of the OAIC's ransomware notifications.
Know your suppliers' controls, not their brochures
Nearly half of breaches now involve a third party, and the Qantas incident shows the regulator will look at what the organisation did to verify its contact centre, its software vendors and its outsourced developers. For regulated entities CPS 230 makes this a hard deadline in 2026. For everyone else it is the difference between a supplier's breach and your own.
Govern AI before it governs your data
Nearly half of employees are using unapproved AI tools. Decide which tools are permitted, put access controls on the models and integrations the business builds, and treat prompts, connectors and plug-ins as the data flows they are. The organisations paying least for breaches are the ones using AI deliberately in their own security operations.
Rehearse the first 72 hours
The 30-day OAIC assessment clock, the 72-hour ransomware payment report and the contractual notification duties all begin before anyone fully understands what happened. A response plan that has been exercised at executive level, with legal, communications and forensics roles assigned, is most of the difference between the $3.26 million breach and the $5.17 million one. The Court's findings against Australian Clinical Labs turned partly on how slowly the company assessed and notified once it knew.
Most of this advice has been given before. Since 2025 the cost of ignoring it comes with a penalty schedule, a class action bar, an insurer's questionnaire and a 72-hour clock. The organisations that spend least on cyber risk over the next few years will be those that can prove, on request, what they have done.
Quick answers
Data breach costs in Australia: common questions
What is the average cost of a data breach in Australia?
$4.22 million in 2026, according to IBM's Cost of a Data Breach study, with financial services at $6.31 million and healthcare at $5.09 million. For smaller organisations the ASD's self-reported figures are a better guide: $56,600 per cybercrime report for small businesses, $97,200 for medium and $202,700 for large.
How many data breaches were reported in Australia in 2025?
1,205 notifications under the Notifiable Data Breaches scheme, up 8 per cent on 2024 and the highest annual total since the scheme began in 2018. Health providers made the most notifications, followed by finance and the Australian Government.
What are the penalties for a data breach under the Privacy Act?
For a serious or repeated interference with privacy, the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover. A mid-tier penalty of up to $3.3 million and infringement notices apply to lesser breaches. The first civil penalty, $5.8 million against Australian Clinical Labs, was ordered in October 2025. Individuals can also sue directly under the statutory tort in force since June 2025.
Do ransomware payments have to be reported in Australia?
Yes. Since 30 May 2025, businesses with turnover of $3 million or more must report any ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours under the Cyber Security Act 2024. Enforcement began on 1 January 2026.
What does cyber insurance require in 2026?
Premiums have fallen but underwriting questions have hardened. Insurers commonly require multi-factor authentication on remote and privileged access, endpoint detection and response, tested offline backups, and increasingly an evidenced Essential Eight maturity level. Healthcare organisations face closer scrutiny than most.
Sources
IBM, Cost of a Data Breach Report 2026, 29 July 2026, and Australian findings as reported by SecurityBrief Australia, 31 July 2026.
OAIC, Data breach notifications increase to all-time high in 2025, 6 July 2026; Notifiable data breach statistics January to June 2025; Notifiable Data Breaches Report July to December 2024.
Australian Signals Directorate, Annual Cyber Threat Report 2024-25, October 2025.
OAIC, Australian Clinical Labs ordered to pay penalties, October 2025; civil penalty action against Medibank; civil penalty action against Optus, August 2025; Qantas preliminary inquiries, July 2026.
OAIC, Statutory tort for serious invasions of privacy, in force 10 June 2025.
Verizon, 2026 Data Breach Investigations Report, May 2026.
Marsh, Australian Insurance Market Update, mid-year 2026; Marsh Global Insurance Market Index Q2 2026; Gallagher, Australia's 2026 cyber insurance outlook, March 2026; Coalition, 2026 Cyber Claims Report.
Insurance Business Australia, Cyber insurance uptake falls as online risks remain widespread, July 2026, reporting APRA and Australian Institute of Criminology data.
APRA, Prudential Standard CPS 230 Operational Risk Management; McCullough Robertson, CPS 230 compliance countdown, May 2026.
Attorney-General's Department, exposure draft Privacy Amendment (Personal Data Protection) Bill 2026, 31 August 2026, as analysed by Ashurst and Corrs Chambers Westgarth.
ABC News, How the super funds were hacked, April 2025; Bloomberg via Insurance Journal on Origin Energy, July 2026.
Figures are as published at 25 September 2026. The OAIC report for January to June 2026 and the ASD Cyber Threat Report 2025-26 had not been released at the time of writing; this page will be updated when they are.
Where to start
Know your maturity level before someone asks for it.
An independent Essential Eight assessment gives you the rating, the evidence and the costed plan in one document. Scoped in one call, fixed quote within one business day.