Australian Cybersecurity Landscape Faces Record Incidents and AI-Driven Threats
Australian organizations are grappling with unprecedented cyber risks, with 71% of surveyed entities reporting a cyber incident in the past 12 months, according to MinterEllison’s Perspectives on Cyber Risk report. The 11th annual study, based on responses from 150 senior decision-makers, reveals a rapidly evolving threat landscape where AI-enabled attacks have surged to become the second-leading concern (25%), trailing only ransomware (30%).
Cybersecurity has now overtaken privacy as the top risk associated with AI adoption, cited by 41% of respondents. The financial toll of breaches has also escalated, with the average cost of a cybercrime incident for large businesses reaching A$202,700 a 219% year-on-year increase. Supply chain vulnerabilities are worsening, with 57% of organizations reporting a third-party breach, up from 50% in 2025.
Despite high preparedness on paper 91% of organizations have an incident response plan and 51% test it quarterly most plans remain focused on traditional threats like ransomware and business email compromise. Emerging AI-driven risks, such as deepfake fraud, prompt-injection attacks on enterprise AI tools, and autonomous offensive agents, are largely absent from rehearsal scenarios.
Regulatory pressure is intensifying, with APRA, the Office of the Australian Information Commissioner (OAIC), and ASIC all signaling heightened scrutiny. Key developments include:
- APRA’s April 2026 warning that assurance practices are lagging behind AI’s complexity.
- OAIC’s stepped-up enforcement targeting AI-enabled technologies.
- ASIC’s May 2026 call for regulated entities to bolster cyber resilience amid rising global threats.
Legal consequences are also expanding, with new risks including:
- A statutory tort allowing lawsuits for serious privacy invasions.
- Increased potential for cyber incident-related class actions.
- Federal Court rulings narrowing legal professional privilege in post-incident reviews.
MinterEllison’s Paul Kallenbach emphasized that AI governance must evolve beyond compliance, warning that boards risk falling behind if they treat preparedness as a static exercise. The report underscores the need for dynamic, board-led cybersecurity strategies to address the gap between formal plans and real-world AI-era threats.
AustCyber cybersecurity rating report: https://www.rankiteo.com/company/australian-cyber-security-growth-network-ltd
"id": "AUS1786335842",
"linkid": "australian-cyber-security-growth-network-ltd",
"type": "Cyber Attack",
"date": "8/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'Australia',
'size': 'large businesses',
'type': 'organizations'}],
'attack_vector': ['AI-driven threats',
'deepfake fraud',
'prompt-injection attacks',
'autonomous offensive agents'],
'description': 'Australian organizations are grappling with unprecedented '
'cyber risks, with 71% of surveyed entities reporting a cyber '
'incident in the past 12 months. The threat landscape includes '
'AI-enabled attacks (25%) and ransomware (30%), with '
'cybersecurity now the top risk associated with AI adoption '
'(41%). Financial tolls have escalated, with the average cost '
'of a cybercrime incident for large businesses reaching '
'A$202,700 (a 219% year-on-year increase). Supply chain '
'vulnerabilities are worsening, with 57% of organizations '
'reporting a third-party breach. Despite high preparedness, '
'most incident response plans remain focused on traditional '
'threats, leaving gaps for emerging AI-driven risks like '
'deepfake fraud and prompt-injection attacks.',
'impact': {'financial_loss': 'A$202,700 (average for large businesses, 219% '
'YoY increase)',
'legal_liabilities': ['statutory tort for serious privacy '
'invasions',
'cyber incident-related class actions']},
'lessons_learned': 'AI governance must evolve beyond compliance, and boards '
'risk falling behind if they treat preparedness as a '
'static exercise. Dynamic, board-led cybersecurity '
'strategies are needed to address the gap between formal '
'plans and real-world AI-era threats.',
'post_incident_analysis': {'corrective_actions': ['Dynamic cybersecurity '
'strategies',
'Board-led AI governance',
'Inclusion of AI-driven '
'threats in incident '
'response plans'],
'root_causes': ['AI-enabled attacks',
'supply chain vulnerabilities',
'inadequate AI governance']},
'recommendations': 'Organizations should update incident response plans to '
'include AI-driven threats like deepfake fraud and '
'prompt-injection attacks, and ensure regulatory '
'compliance with APRA, OAIC, and ASIC guidelines.',
'references': [{'source': 'MinterEllison’s Perspectives on Cyber Risk report '
'(11th annual study)'}],
'regulatory_compliance': {'legal_actions': ['APRA scrutiny',
'OAIC enforcement',
'ASIC calls for cyber resilience'],
'regulatory_notifications': ['APRA’s April 2026 '
'warning on AI '
'assurance practices',
'OAIC’s stepped-up '
'enforcement targeting '
'AI-enabled '
'technologies',
'ASIC’s May 2026 call '
'for regulated '
'entities to bolster '
'cyber resilience']},
'response': {'incident_response_plan_activated': '91% of organizations have '
'an incident response plan'},
'title': 'Australian Cybersecurity Landscape Faces Record Incidents and '
'AI-Driven Threats',
'type': ['ransomware',
'AI-enabled attacks',
'supply chain breach',
'data breach']}