Data breach victims are staying silent, leaving insurers with less visibility
Widespread non-reporting is creating a gap between the cyber incidents businesses experience and the risks insurers can see
Data breach victims are staying silent, leaving insurers with less visibility
CYBER
By Roxanne Libatique
24 Sep 2026

More than half of Australian data breach victims do not report their incident to anyone – not to their insurer, not to the regulator, not to the police.

That finding, from a survey of 2,003 Australian adults published on September 24 by cybersecurity firm Sekuro and Women in Digital, has a direct consequence for every broker with a cyber client: the loss data underwriting those policies is built on what gets reported. If 51% of data breach victims say nothing, the models informing coverage recommendations are working from an incomplete picture.

The scale of the silence

Across all cybercrime categories, 44% of victims in the Sekuro and Women in Digital survey did not report through any channel. Data breaches had the highest non-reporting rate at 51%.

The victimisation figures are substantial. Some 42% of respondents said they had been exposed to cybercrime in the past five years, and 27% said they had been direct victims. Among those who had been hacked, 40% said they had been targeted more than once.

Financial scams were the top concern for 29% of respondents, followed by hacking at 27% and data breaches at 24%. Anxiety about the threat is rising: 71% said they were worried about cybercrime affecting themselves or their family, and 59% said they were more worried than two years ago.

Holly Hunt, chief executive officer and founder of Women in Digital, said shame is a central driver of silence among victims. “Shame can also play a powerful role in keeping victims silent. Fear of judgement, further exposure, or being blamed can stop people from reporting, creating cybercrime that sits outside official statistics and leaving some of the most harmful forms of offending largely unseen,” Hunt said.

Noel Allnutt, chief executive officer of Sekuro, said the burden should not sit with individuals alone. “We know most Australians are already taking steps to protect themselves online. However, cyber hygiene is becoming increasingly overwhelming, and preventing cybercrime can’t rest on individuals alone. We need systems, workplaces, and technologies that recognise how criminals target people, and make it easier for victims to know where to turn and get help when they need it,” Allnutt said.

Read next: Biological weapons researchers were using AI. Insurers should know

A market with a distribution problem

The non-reporting finding sits against a market where cyber insurance take-up is falling despite a growing threat.

The Australian Institute of Criminology’s (AIC) Cybercrime in Australia 2025 report, released in June 2026 and drawing on a survey of more than 10,000 Australians, found one in four SMEs reported being a cybercrime victim in the past year. The proportion reporting legal and staffing consequences nearly doubled in 12 months. Yet cyber insurance uptake fell for the second consecutive year – from 4.6% of respondents in 2024 to 3.7% in 2025.

The Insurance Council of Australia (ICA) puts cyber insurance penetration at around one in five SMEs. Australian Prudential Regulation Authority (APRA) data shows the cyber class wrote 6,000 risks in the March 2026 quarter, against 4.78 million for domestic motor. Gross written premium has never exceeded $73 million in a single quarter and sits at less than 0.2% of total industry premium – despite three consecutive profitable quarters.

Premiums fell approximately 10% through 2025. Lower prices have not moved volumes.

Trent Nihill, general manager of Coalition Australia, said the friction for brokers sits before the premium conversation even starts. “The challenge often is not necessarily the price of selling it, it’s actually getting the quote in the first place,” Nihill said, citing broker feedback that SME owners acknowledge cyber risk but lack the time and technical knowledge to work through lengthy proposal forms.

What the law now requires

Two reforms already in force change the stakes for uninsured or underinsured business clients.

Under the Cyber Security Act 2024, mandatory reporting of ransomware payments commenced on May 30, 2025, for businesses with annual turnover above $3 million. A 72-hour clock runs from the moment a payment is made.

Separately, Privacy Act amendments introduced a statutory tort for serious invasions of privacy on June 10, 2025. Individuals can now pursue civil claims of up to $478,550 in damages against organisations for serious privacy breaches, independently of any regulatory action by the Office of the Australian Information Commissioner (OAIC).

Those two changes mean incidents that were once absorbed quietly now carry concurrent regulatory and litigation exposure. A client who has not reported a past breach – and the research suggests many have not – may not have considered what the current framework requires going forward.

AI and the risk window

The Sekuro and Women in Digital survey found 84% of Australians believe AI will increase cybercrime, and 80% said they were concerned it would make them personally more vulnerable to cyberattacks. Some 74% already use AI, with 45% using it at least weekly.

On the same date, the Australian Signals Directorate (ASD) issued an advisory confirming it had observed AI agents independently identifying vulnerabilities in public-facing systems and acting on them without human authorisation – shortening the gap between exposure and exploitation.

A Herbert Smith Freehills Kramer survey of general counsel, also published on September 24, found only 20% of Australian organisations had a detailed understanding of AI cyber risks, even as the category ranked in their top three areas of cyber investment.

Read next: Medicare AI breach tests how cyber wordings define unauthorised access

What is coming

APRA confirmed in July 2026 that it will proceed with a refreshed publication of the National Claims and Policies Database (NCPD) that breaks out cyber insurance as a standalone category for the first time. An initial publication covering data to December 31, 2024, is planned, with 2025 figures undergoing validation and due later in 2026.

When that data is published, it will give brokers, underwriters, and regulators the clearest view yet of the cyber class – claims frequency, premium volume, and risk concentration – at a time when the Sekuro and Women in Digital research confirms that reported incident data already understates the true scale of loss.

For brokers with SME clients operating without cover, or with policies not reviewed against the current regulatory environment, the APRA release will put numbers to a gap the research shows already exists. The time to have that client conversation is before the data makes it unavoidable.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.