CFOtech Australia - Technology news for CFOs & financial decision-makers
Australia
Australia breach costs hit AUD $4.22 million, IBM says

Australia breach costs hit AUD $4.22 million, IBM says

Fri, 31st Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

The average cost of a data breach in Australia has risen to AUD $4.22 million, up 38% from 2019, according to IBM's latest study.

The research found that 32% of malicious attacks in Australia now involve AI-generated elements, signalling a shift in attackers' methods as cyber security costs climb.

Financial services recorded the highest average breach cost at AUD $6.31 million per incident, ahead of the technology sector at AUD $5.51 million and healthcare at AUD $5.09 million.

Across all sectors, the average incident involved 22,400 compromised records, with a per-record cost of AUD $167. The findings come from IBM's 2026 Cost of a Data Breach Report.

AI divide

The study found a clear gap between organisations that had widely adopted AI in security operations and those that had not. Companies with extensive AI use reported average breach costs of AUD $3.46 million, while organisations with no AI security tools faced average costs of AUD $5.21 million.

Organisations using AI extensively identified breaches 68 days faster than those without such tools. The report linked faster detection and containment with lower financial losses.

Response speed was another major factor in overall cost. Australian organisations that took more than 200 days to identify and contain a breach faced average costs of AUD $5.17 million, compared with AUD $3.26 million for those that responded in under 200 days.

The most expensive initial attack vector was the abuse of valid accounts, associated with average costs of AUD $4.87 million. Social engineering and IT impersonation followed at AUD $4.78 million, while phishing attacks were tied to average costs of AUD $4.48 million.

Security spending

The data suggests many organisations are preparing to increase spending. Some 67% said they plan to lift security investment, mainly by hiring skilled security specialists and buying AI security and governance tools.

Hiring security specialists was cited as a priority by 51% of respondents, while 41% named AI security and governance tools.

The report also highlighted a gap in encryption use. Only 32% of organisations had encryption deployed across sensitive data at rest and in transit at the time of breach.

Nick Flood, Managing Director, IBM ANZ, said the figures show a growing cost burden for Australian organisations dealing with more advanced attacks.

"With breach costs rising 38% over seven years and AI-generated attacks comprising nearly one-third of incidents, the imperative for advanced security measures has never been greater," Flood said.

He said the threat environment was changing quickly as attackers used AI to increase both scale and speed.

"Australian organisations are operating in an environment where AI is accelerating both the scale and speed of cyberattacks, particularly across sectors that provide essential services and handle sensitive customer data," Flood said.

Chris Hockings, an IBM cyber security expert, said the difference between organisations that adopt AI-based security and those that do not is likely to become more pronounced.

"The gap between organisations that have embraced AI-powered security and those that haven't is only going to widen," Hockings said. "Encryption remains one of the most effective and most under-utilised controls available to organisations. Combined with AI-driven detection and response, it helps form the backbone of a strong security strategy. The data shows that organisations that treat these tools as foundational investments, rather than afterthoughts, are recovering faster and at a fraction of the cost."

The report was conducted by Ponemon Institute and sponsored and analysed by IBM. It was based on breaches experienced by 602 organisations globally between March 2025 and February 2026, with a follow-on study involving 456 of those organisations.

Among organisations that took part in the follow-on study, 78% said they were aware of recent reports about highly advanced frontier models such as Mythos.