Australian organisations are experiencing cyber incidents at record rates, with 71% of surveyed organisations reporting an incident in the past 12 months, according to MinterEllison’s latest Perspectives on Cyber Risk report.
The 11th annual report, based on a survey of 150 senior decision makers, found AI-enabled threats have become the second-leading cyber concern for the first time in the survey’s history. It said 25% of respondents cited AI-enabled threats as a concern, behind ransomware at 30%.
The report also found cybersecurity has overtaken privacy as the top-ranked risk associated with AI adoption, cited by 41% of respondents.
MinterEllison reported sharply higher incident-related costs, with the average cybercrime incident costing large Australian businesses A$202,700—up 219% year-on-year. Supply chain exposure also increased, with 57% of surveyed organisations reporting a breach involving a third-party supplier or vendor, up from 50% in 2025.
Paul Kallenbach, Partner and National Legal Cyber Lead at MinterEllison, says:
“The fact that 71% of organisations we surveyed experienced a cyber incident in the past 12 months, and that AI-enabled threats are now the second leading cyber concern, tells you everything about how rapidly the risk landscape is shifting. While organisations have made real progress on preparedness over the past decade, governance has not kept pace with the speed of AI adoption and boards cannot afford to treat AI governance as a compliance exercise. It needs to operate as a live discipline, and organisations that get this right will be far better placed when an incident occurs.”
The report points to a gap between formal preparedness and readiness for emerging AI-era threats. It found 91% of organisations have an incident response plan and 51% test at least quarterly. However, it said most plans remain centred on ransomware and business email compromise, while scenarios such as deepfake-enabled fraud, prompt-injection attacks on enterprise AI tools, and autonomous offensive agents are largely absent from rehearsal cycles despite growing concern.
It also highlighted rising regulatory scrutiny, pointing to APRA’s April 2026 letter on assurance practices not keeping pace with the scale and complexity of AI, stepped-up enforcement by the Office of the Australian Information Commissioner involving AI-enabled technologies, and ASIC’s May 2026 call for regulated entities to strengthen cyber resilience as frontier AI intensifies the global threat environment.
The report said the consequences of an inadequate response have increased, citing the introduction of a statutory tort allowing individuals to sue for serious invasions of privacy, the risk of cyber incident-related class actions, and Federal Court decisions narrowing legal professional privilege in post-incident reviews.
Kallenbach concludes:
“Preparedness is not a static state. It is an ongoing process of testing, learning and adapting, and it has to be led from the boardroom. Organisations that have adopted AI at scale need to ask themselves whether their governance has kept pace, and whether their frameworks recorded on paper have been tested under pressure.”
You can read the full report here.

