Almost three in four Australian organisations have weathered a cyber incident in the past 12 months, a figure that lands as artificial intelligence quietly rewires both how attacks are launched and how they are defended against. The number comes from law firm MinterEllison’s latest Perspectives on Cyber Risk report, which surveyed senior leaders across the country and found that 71 per cent had reported an incident, a record rate that suggests the problem is no longer an edge case but a routine cost of doing business.
For anyone watching the sector, the headline figure is confronting without being surprising. Australian boards have spent the better part of five years absorbing the lessons of Optus, Medibank and a long tail of smaller breaches that never made the front page. What has shifted, according to the firm, is the character of the threat rather than simply its volume. Generative AI has lowered the barrier to entry for attackers while handing defenders new tools of their own, and the report frames this as a moment where organisations can no longer treat cyber security as a discrete IT function bolted onto the side of the business.
What the report actually says
The survey paints a picture of organisations that are more exposed and, in many cases, more aware of that exposure than they were a year ago. Beyond the topline 71 per cent, the research points to AI as a double-edged development. On one side, criminals are using large language models to craft more convincing phishing lures, to automate reconnaissance and to move faster once they are inside a network. On the other, the same technology is being folded into detection, triage and response, giving stretched security teams a way to keep pace with a rising tide of alerts.
MinterEllison’s framing is deliberately practical. The firm advises boards and executives on cyber risk as a legal and governance matter, not just a technical one, and the report leans into the regulatory reality that directors now face. Under Australian law, a serious data breach can trigger obligations to the Office of the Australian Information Commissioner, potential action under the Privacy Act, and uncomfortable questions from shareholders about whether the board discharged its duty of care. The message running through the research is that AI raises the stakes on both counts, because an incident can escalate faster and because regulators increasingly expect organisations to have thought about how the technology changes their risk profile.
Two ways to read the numbers
There are competing interpretations of a figure as high as 71 per cent, and both deserve airtime. The pessimistic reading is straightforward: Australian organisations are being overwhelmed, and the arrival of cheap, capable AI tooling has tilted the field decisively towards attackers who only need to succeed once. On this view, the record incident rate is a warning that current defences are not keeping up and that the gap will widen as offensive AI matures.
The more optimistic reading is that the number partly reflects better visibility. Organisations that have invested in monitoring, threat hunting and mandatory reporting simply see more of what is happening on their networks, and a high incident count can be a sign of maturity rather than failure. An organisation that reports zero incidents is often not safer, just blinder. Security professionals have long argued that the worst position is not knowing, and by that logic a rising detection rate is a feature of a system that is finally paying attention. The truth almost certainly sits between the two, but the distinction matters for how boards respond, because panic and complacency both produce bad decisions.
Why this matters for Australia
The Australian stakes here are unusually concrete. The federal government has staked a good deal of political capital on its 2023 to 2030 Cyber Security Strategy, which set the ambition of making the country a world leader in cyber resilience by the end of the decade. A report showing that most organisations are still being breached is a reality check on that timeline, and it arrives while Canberra is simultaneously trying to encourage AI adoption across the economy as a productivity lever. Those two goals sit in tension. Every business that rushes to deploy AI agents, copilots and automated workflows is also expanding its attack surface, and the MinterEllison findings are a reminder that the security conversation has to travel alongside the enthusiasm rather than trailing behind it.
There is a skills dimension as well. Australia has a well-documented shortage of experienced cyber security professionals, and the promise of AI-assisted defence is that it can stretch the people we do have further. If smaller organisations, councils, health providers and the mid-market can lean on AI to handle first-line triage, some of the pressure eases. If they cannot afford or govern those tools properly, the divide between well-resourced enterprises and everyone else grows wider. That gap has a national character, because supply chains connect the big end of town to thousands of small vendors, and attackers have shown a persistent appetite for the weakest link.
The regulatory backdrop sharpens the point further. The Security of Critical Infrastructure Act now captures a broad sweep of sectors, from energy and water to food, health and financial services, and it imposes reporting and risk-management obligations that assume boards understand their exposure. A report telling those same boards that AI is reshaping the threat landscape is, in effect, telling them that yesterday’s risk assessment may already be out of date.
What comes next
The practical question for Australian executives is not whether to adopt AI in their security operations but how to do so without introducing new vulnerabilities. Feeding sensitive data into third-party models, giving automated agents standing access to internal systems, and trusting AI-generated triage without human oversight all carry their own hazards. Expect the next wave of guidance from regulators and advisers to focus on exactly these governance questions, and expect insurers, who have grown far more selective about cyber cover, to start asking pointed questions about how AI is being used on both offence and defence.
For now, the MinterEllison research serves as a useful barometer. It confirms that incidents have become the norm rather than the exception, it names AI as the variable most likely to change the equation over the next few years, and it puts the responsibility squarely with boards to treat the issue as a matter of governance. Whether 71 per cent is a ceiling or a waypoint will depend on choices being made in Australian boardrooms right now.
Sources: Australian Cyber Security Magazine.



















































