SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Australian businesses face AUD $37 billion AI cyber risk

Australian businesses face AUD $37 billion AI cyber risk

Fri, 9th Oct 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

Australian businesses could lose up to AUD $37 billion a year by 2030 from AI-driven cyber attacks, according to research commissioned by CyberCX. The estimate is based on a scenario in which organisations take no additional steps to strengthen their defences.

The report, produced by Mandala Partners, projects that the number of cyber incidents in Australia could rise ninefold, to 357,000 in 2030 from 38,000 in 2025, as AI increases the speed and scale of attacks. It also forecasts a 16% increase in the severity of cyber loss incidents.

The findings point to a sharp rise in financial exposure as attackers use AI tools to expand campaigns, identify vulnerabilities faster and intensify disruption. Under the report's model, large Australian businesses are expected to lose AUD $4.5 million per cyber incident by 2030.

Nearly half of projected cyber incident losses in 2030 are expected to come from business interruption, including systems being taken offline by ransomware, denial-of-service attacks and outages at third-party suppliers.

Other losses are expected to come from direct payments to threat actors, response and recovery costs, and external liabilities. The modelling suggests the economic burden would extend well beyond ransom demands or technical remediation, affecting operations and customer obligations.

The research also examines cyber spending. Australian businesses were estimated to spend 4.4% of their IT budgets on cyber security in 2025, below what it describes as a global industry standard of about 7% to 10%.

Defensive gap

That spending gap underpins the report's argument that many organisations remain exposed as AI reshapes the threat landscape. It estimates that foundational defensive measures could reduce annual losses by AUD $24 billion by 2030, cutting the projected total to AUD $13 billion.

Preventive steps such as multi-factor authentication, patching known vulnerabilities and securing AI deployments account for 75% of that reduction, or about AUD $18 billion. Responsive actions, including continuous monitoring that detects intrusions earlier, account for a further AUD $6 billion reduction.

John Paitaridis, Chief Executive Officer of CyberCX, said the headline figure should be seen as a warning about inaction rather than an unavoidable outcome.

"AI is transforming the Australian economy and will provide businesses with a wealth of benefits, unlocking growth and innovation. However, we're already seeing how threat actors can misuse this technology to devastating effect. This report says that what we see now may only be the tip of the iceberg as Australian businesses confront an advancing set of cyber risks over the next four years.

While $37 billion a year in loss would represent a significant and material impact to our economy, it's important to note that this estimate is modelled on a 'do nothing' scenario and assumes Australian businesses take no further steps to mitigate against AI-driven cyber threats. In reality, there are tangible actions that every business can take today to reduce the potential harm in the future.

The frontline of the fight against AI-driven cyber threats is to go back to basics and ensure we are implementing the core principles of cyber security. Preventative actions and foundational security measures like enforcing multi-factor authentication, identity and access management and patching known vulnerabilities could reduce annual losses to $13 billion by 2030 and even further over time," Paitaridis said.

Economic risk

Mandala Partners said the figures point to a broader economic issue, not just a technical or operational challenge for security teams. The research frames cyber resilience as a matter of investment discipline across Australian business.

"What we now see clearly is that a BAU approach on cyber security in an AI era would constitute a severe blow to the economy.

Australian businesses are already underinvesting relative to the rest of the world, with just 4.4 per cent of Australian IT budgets going toward cyber security, around half the global industry standard.

The heartening news is that we already know how to mitigate most of the damage. Preventive actions ranging from secure-by-design approaches and continuous threat exposure management to multi-factor authentication and patching known vulnerabilities can prevent some three-quarters of the projected economic loss by 2030. Responsive actions, like advanced monitoring that detects intrusions faster, can reduce most of the remainder," said Tom McMahon, Partner, Mandala Partners.

The report's emphasis on business interruption reflects how cyber incidents can spread through supply chains and third-party providers. For many organisations, the cost of suspended operations can exceed the direct loss from a single breach, especially when customer services, logistics or internal systems are halted.

By placing a monetary estimate on those effects, the research adds to a broader debate over whether Australian companies are investing enough in cyber controls as AI lowers the barrier to conducting attacks. It also suggests that the most effective steps remain familiar, with the biggest gains coming from routine security practices rather than highly specialised interventions.

Under that assessment, the difference between basic defensive action and inaction amounts to AUD $24 billion a year by 2030.