SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
AI cyber threats rise as Australian incidents surge

AI cyber threats rise as Australian incidents surge

Mon, 10th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

MinterEllison has released a cyber risk report showing that 71% of Australian organisations experienced a cyber incident in the past 12 months. For the first time, AI-enabled threats ranked as the second biggest cyber concern.

Based on a survey of 150 senior decision-makers at Australian organisations, the report points to rising costs, growing concern about AI-related attacks, and a gap between formal preparedness and the threats many businesses expect to face.

The average cost of a cybercrime incident for large Australian businesses rose 219% year on year to AUD $202,700. Meanwhile, 57% of organisations reported a breach involving a third-party supplier or vendor, up from 50% in the previous survey period.

Ransomware remained the leading cyber concern, cited by 30% of respondents, with AI-enabled threats close behind at 25%. Cybersecurity also overtook privacy as the top-ranked risk linked to AI adoption, with 41% of respondents identifying it as their main concern.

Preparedness gap

Many organisations reported established cyber controls and response processes. The survey found that 98% had benchmarked their cyber maturity against an established framework, 91% had an incident response plan, and 51% tested that plan at least quarterly.

Yet many of those plans still appear focused on established threats such as ransomware and business email compromise. Rehearsal exercises largely omitted scenarios involving deepfake-enabled fraud, prompt-injection attacks targeting enterprise AI tools, and autonomous offensive agents.

That mismatch was reflected in how respondents described AI cyber risk. According to the survey, 32% used anxiety-related terms including worried, anxious, alarmed, or overwhelmed, while only 8% used net-positive language.

Paul Kallenbach, Partner and National Legal Cyber Lead at MinterEllison, said: "The fact that 71% of organisations we surveyed experienced a cyber incident in the past 12 months, and that AI-enabled threats are now the second leading cyber concern, tells you everything about how rapidly the risk landscape is shifting. While organisations have made real progress on preparedness over the past decade, governance has not kept pace with the speed of AI adoption and boards cannot afford to treat AI governance as a compliance exercise. It needs to operate as a live discipline, and organisations that get this right will be far better placed when an incident occurs."

Regulatory pressure

The report linked the issue to a tougher regulatory environment for Australian organisations managing cyber risk and AI use. It pointed to scrutiny from APRA, the Office of the Australian Information Commissioner, and ASIC as regulators examine how companies assess, monitor, and test risks tied to new systems and digital operations.

The findings suggest the regulatory environment has become more demanding even as incident costs have risen and third-party exposure has grown. Together, those pressures leave organisations facing broader legal and financial consequences if a cyber event is handled poorly.

The report also highlighted legal developments that could raise the stakes after a breach or cyber attack. These include a statutory tort giving individuals a direct right to sue for serious invasions of privacy, the prospect of cyber incident-related class actions, and a narrower approach to legal professional privilege in post-incident reviews.

Those developments could affect how boards approach incident planning, record-keeping, and internal investigations after an attack. The findings suggest that while many organisations can point to documented plans and regular testing, the substance of those exercises may not yet reflect the changing threat environment created by wider AI adoption.

Board oversight

The survey results indicate that cyber governance is moving further into the remit of boards and executive teams. Formal plans alone may no longer be enough if testing cycles remain focused on the attack types that dominated previous years rather than emerging techniques that use AI tools or exploit AI systems.

For large businesses, the rise in average incident costs adds further pressure to improve response processes. Supply chain breaches were also a notable part of the picture, highlighting how cyber exposure can stem from vendors and service providers as well as an organisation's own systems.

The report argues that AI governance and cyber preparedness should be treated as an ongoing process rather than a one-off exercise. That means not only maintaining plans on paper, but also revising scenarios, rehearsing decision-making, and testing whether escalation procedures match the risks companies now say concern them most.

Kallenbach said: "Preparedness is not a static state. It is an ongoing process of testing, learning and adapting, and it has to be led from the boardroom. Organisations that have adopted AI at scale need to ask themselves whether their governance has kept pace, and whether their frameworks recorded on paper have been tested under pressure."