Australia’s data breach environment reached a new threshold in 2025. The Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications – the highest annual total since the Notifiable Data Breaches (NDB) scheme commenced in 2018, an 8% increase over 2024’s 1,112 notifications. New research from IBM puts the average cost of each Australian breach at $4.22 million, up 38% from 2019. For underwriters, the more consequential finding is what separates expensive breaches from manageable ones – and it maps directly to controls already assessed at application.
IBM’s 2026 Cost of a Data Breach Report, based on 602 organisations globally between March 2025 and February 2026 and conducted by the Ponemon Institute, identifies a $1.75 million cost differential between organisations with and without AI-driven security tools. Companies using AI tools extensively reported average breach costs of $3.46 million; those without faced $5.21 million. AI-equipped organisations also identified breaches 68 days faster – a metric the report links directly to lower financial losses.
Response time compounds the effect. Organisations taking more than 200 days to contain a breach faced average costs of $5.17 million, compared with $3.26 million for those resolving incidents within 200 days. The IBM report found that 67% of Australian organisations plan to increase security investment, with 51% citing skilled security specialists and 41% naming AI security and governance tools as priorities. If those planned investments translate into implemented controls, the cost differential associated with AI-enabled security may narrow over time. Whether that ultimately influences cyber claims severity is likely to be closely watched by insurers. Nick Flood, managing director of IBM ANZ, said the threat environment is shifting faster than many organisations have adapted. “With breach costs rising 38% over seven years and AI-generated attacks comprising nearly one-third of incidents, the imperative for advanced security measures has never been greater,” Flood said, as reported by IT Brief Australia.
Financial services recorded the highest average breach cost at $6.31 million per incident, ahead of technology at $5.51 million and healthcare at $5.09 million. That figure sits above what many businesses currently carry. Typical 2026 policy aggregates for Australian small and mid-market businesses run from $500,000 to $5 million. For financial services clients – where the IBM average exceeds the top of that common range – limit adequacy warrants direct attention at renewal.
The regulatory exposure compounding that financial risk has grown measurably in the past 12 months. In February 2026, the Federal Court ordered FIIG Securities to pay $2.5 million in penalties after the Australian Securities and Investments Commission (ASIC) brought proceedings for cyber security failures spanning more than four years, marking the first time the Federal Court imposed civil penalties for cyber security failures under general AFS licensee obligations.
The Australian Prudential Regulation Authority’s (APRA) Prudential Standard CPS 230, which came into effect on July 1, 2025, requires all APRA-regulated entities – including banks, insurers, and superannuation trustees – to maintain critical operations during disruptions including cyberattacks. A further layer of third-party liability arrived on June 10, 2025, when changes to the Privacy Act commenced introducing a statutory tort for serious invasions of privacy, giving individuals a direct cause of action in court for privacy harms for the first time.
The IBM report found that only 32% of breached organisations had encryption deployed across sensitive data at rest and in transit, and that valid account abuse was the costliest attack vector at $4.87 million per incident – reinforcing the underwriting logic behind multi-factor authentication (MFA) and encryption as baseline conditions rather than differentiators. IBM’s Chris Hockings noted that organisations treating security tools as foundational investments rather than afterthoughts were recovering faster and at lower cost – a finding the data bears out across both the AI adoption and response-time variables.
The IBM findings arrive as Australian market participants are managing a structural tension: the underwriting economics for cyber are sound, but the product is reaching a fraction of the businesses exposed to the risk the IBM data quantifies. Claud Bilbao, Cowbell’s VP of underwriting and distribution for the UK and Australia, said SME cyber penetration in Australia sits at between 5% and 20%, describing it as “definitely an existing protection gap.” Emergence Insurance chief underwriting officer Jeff Gonlin updated the insurer’s Cyber Event Protection policy wording in early 2026 to keep it aligned with claims experience and broker feedback, saying: “Cyber risk doesn’t stand still, so our policy wording can’t either.”
APRA data shows the cyber class posted a positive insurance service result in each of the three most recent quarters – $17 million in September 2025, $10 million in December 2025, and $10 million in March 2026 – yet cyber GWP has never exceeded $73 million in a single quarter. Swiss Re estimates that only around 10% of businesses with annual revenue below US$100 million carry cyber insurance, highlighting the protection gap facing SMEs even as breach costs and regulatory obligations continue to increase.
With three new regulatory obligations now active – APRA CPS 230, mandatory ransomware reporting, and the Privacy Act statutory tort – and IBM’s sector data placing financial services breach costs above common SME policy limits, the businesses least likely to carry cyber insurance are increasingly also those least positioned to absorb the consequences of going without it.