ANZ cyber losses average $2m per incident, Claroty report finds
Operational technology attacks cost ANZ organisations almost double the global average, raising questions about cyber insurance adequacy
ANZ cyber losses average $2m per incident, Claroty report finds
CYBER
By Roxanne Libatique
09 Oct 2026

New research has put a dollar figure on the cost of cyberattacks targeting operational environments across Australia and New Zealand. Average losses reached $2.04 million per incident, almost double the global average of $1.04 million.

The findings come from a global survey of 2,000 business and technology leaders across more than 40 countries, conducted by cyber-physical systems firm Claroty. The survey found that 80% of ANZ organisations experienced a cyberattack on their operational environments in the past 12 months.

For brokers, the data points to a growing gap between the financial exposure clients face from operational technology (OT) attacks and the cyber insurance coverage many of them carry. The Australian Prudential Regulation Authority’s (APRA) quarterly general insurance statistics show cyber gross written premium has never exceeded $73 million in a single quarter and accounted for under 0.2% of total industry premium as of March 2026, even as losses from OT incidents run into the millions.

Read next: Data breach victims are staying silent, leaving insurers with less visibility

Downtime figures carry business interruption implications

When asked to identify the most significant consequences of attacks on their operational environments, 41% of respondents cited operational downtime, 37% pointed to safety incidents or hazards, and 32% identified reputational damage.

On average, organisations experienced approximately two hours of downtime from their most significant cyber incident. However, 18% reported operational downtime lasting more than three days.

That three-day-plus figure matters for brokers assessing business interruption coverage, where waiting periods in Australian cyber policies commonly sit at between eight and 12 hours.

The $2.04 million average loss figure sits within a broader pattern of rising cybercrime costs in Australia. The Australian Signals Directorate’s (ASD) Annual Cyber Threat Report 2024-25 found the average self-reported cost of cybercrime for Australian businesses rose 50% year-on-year to approximately $80,850 per report. For large businesses, the figure reached approximately $202,700, up 219%.

The ASD also reported it notified critical infrastructure entities of potential malicious cyber activity more than 190 times during the year, up 111%.

Third-party access and the coverage gap

The Claroty report found that 88% of ANZ organisations experienced at least one cybersecurity incident originating from third-party access in the past 12 months, with organisations reporting an average of more than three such incidents.

More than half (52%) said they had only partial or no monitoring of third-party connections into their cyber-physical systems or OT environments.

For brokers, third-party incidents that cascade into operational disruption may trigger policy responses across multiple coverage lines, including cyber liability, business interruption, and potentially professional indemnity depending on the nature of the downstream impact.

Yet uptake remains low. An Australian Institute of Criminology (AIC) survey published in June 2026 found the share of respondents holding cyber insurance fell from 4.6% in 2024 to 3.7% in 2025, the second consecutive annual decline.

Jeffrey Gonlin, chief underwriter at Emergence Insurance, told Insurance Business that the disconnect is difficult to explain. “It’s a real mystery. When people get animated about businesses not being insured for some natural peril, somehow when it comes to cyber, because it’s less concrete, it seems less real, there’s just no sense of urgency,” Gonlin said.

Jason Pearce, field chief technology officer, Asia Pacific and Japan at Claroty, said: “In operational environments, uptime isn’t simply a metric – it is directly connected to business continuity, productivity, profitability, customer trust and, in many critical environments, safety. Even a relatively short disruption to physical operations can create significant downstream consequences across production, supply chains and essential services.”

Pearce added: “The ANZ findings are particularly significant because organisations across Australia and New Zealand are experiencing an average financial impact from cyber incidents that is almost twice the global average. That reinforces why operational resilience needs to be treated as a business priority, not simply a cybersecurity objective.”

Regulatory pressure is building around operational environments

The survey found that while 74% of ANZ organisations said they take a proactive or structured approach to cybersecurity compliance, barriers remain. Thirty-one percent cited a lack of IT/OT alignment as their biggest obstacle to full compliance, followed by limited visibility (23%) and third-party risk (23%).

These compliance gaps carry weight given Australia’s evolving regulatory settings. The Security of Critical Infrastructure Act 2018 (SOCI Act) is undergoing further reform, with proposed enhanced CIRMP rules set to introduce mandatory cyber maturity requirements, supply chain mapping obligations, and network segregation standards for operators across sectors including energy, water, and transport, according to a legal analysis by LK Law.

Separately, APRA’s prudential standard CPS 234 requires regulated entities to maintain information security capabilities proportionate to the threats they face, while CPS 230, which took effect in July 2025, strengthened operational risk management and business continuity requirements.

Since May 30, 2025, businesses with turnover of $3 million or more, and critical infrastructure entities, must report ransomware and cyber extortion payments to the ASD within 72 hours under the Cyber Security Act 2024.

For brokers advising clients in critical infrastructure or APRA-regulated sectors, these overlapping obligations create both risk and opportunity. Clients who cannot demonstrate compliance may face coverage restrictions at renewal, while those investing in OT security may present stronger risk profiles.

Read next: Falling cyber alerts may not mean lower risk at renewal

AI adoption adds new exposure

The report found that 83% of ANZ organisations are already using AI in their operational environments. While 49% said AI has improved efficiency and 46% said it has improved decision-making, 45% also said the technology has introduced new cybersecurity and compliance risks.

When asked to identify the biggest threats facing their operational environments, 32% pointed to AI-powered cyberattacks, followed by vulnerable legacy OT systems at 30%.

Pearce said: “As organisations continue to digitise and connect their operational environments, cybersecurity also needs to move beyond tick-box compliance. Compliance provides an important baseline, but ultimately resilience is measured by whether critical operations can withstand disruption, maintain safety and recover effectively.”

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.