AI-Driven Cyber Audit Automation / Regulatory Case
Regulatory Case Study · Cyber Risk in AustraliaA new mandatory ransomware-reporting regime, a record year for data breach notifications, and a cybercrime report every six minutes. Here's what Australia's cyber regulatory stack now actually requires — and why point-in-time pen tests can't keep up with it.
OAIC Notifiable Data Breaches, Jan–Jun 2025. See sources.
Cybercrime reports, FY2024–25
84,700
One report roughly every six minutes, per ASD's Annual Cyber Threat Report.
Ransomware incidents, FY2024–25
138
Healthcare-sector ransomware incidents doubled year-on-year.
Data breaches notified, 2025
1,205
Record high to the OAIC — up 8% on 2024.
Average cost per incident
$80,850
Up 50% year-on-year, per ASD's cybercrime cost modelling.
Four bodies, four different levers — technical authority, privacy enforcement, critical-infrastructure obligations, and sector-specific rules.
Technical authority
The Australian Signals Directorate's Cyber Security Centre issues the Essential Eight, coordinates incident response, and publishes the Annual Cyber Threat Report.
Privacy enforcement
The Office of the Australian Information Commissioner runs the Notifiable Data Breaches scheme and enforces the Privacy Act, including the new doxxing offences and civil penalties.
Critical infrastructure
The Cyber and Infrastructure Security Centre administers the SOCI Act and the Cyber Security Act 2024's mandatory ransomware-payment reporting regime.
Layered obligations
Bodies like APRA (CPS 234, for financial services) add sector-specific cyber and operational-resilience requirements on top of the national baseline.
Commonwealth law sets the floor everywhere; several states layer their own information-security policy on top for their own agencies. Select a state to see how.
Select a state
Every entity in Australia sits under the Commonwealth baseline: the Privacy Act, the SOCI Act (if critical infrastructure), and the Cyber Security Act 2024's ransomware-reporting regime. States can layer additional policy on top for their own agencies.
Shows state government information-security policy for state agencies, not a private-sector obligation. See sources.
Five instruments now do most of the work — four commenced or tightened within the last 18 months.
Source: Cyber Security Act 2024, SOCI Act, Privacy and Other Legislation Amendment Act 2024, ASD Essential Eight guidance. See sources.
Prior-year figures derived from ASD's reported year-on-year percentage change.
Incidents ACSC
responded to
Malicious-activity
notifications issued
Attacks on critical
infrastructure
FY2023–24 FY2024–25
Top 5 of 1,205 total notifications. Legal, accounting & management services also reported 81, tying with education.
Federal government entities
Maturity Level 3
Critical infrastructure operators
Maturity Level 2 (minimum)
Commercial organisations
ML1 baseline · ML2 recommended
Curated and updated periodically from ASD, OAIC and Home Affairs reporting — not a live feed. Last reviewed 22 July 2026.
29 November 2024
Australia's first standalone Commonwealth cyber security law — introduces smart-device standards and the ransomware payment reporting regime.
10 December 2024
The Privacy and Other Legislation Amendment Act 2024 receives Royal Assent, criminalising doxxing and adding a mid-tier civil penalty tier ahead of a statutory tort taking effect by June 2025.
30 May 2025
Entities with turnover ≥$3M, or responsible for critical infrastructure, must report ransomware/extortion payments to the CISC within 72 hours.
30 June 2025
A social-engineering attack on a third-party contact-centre platform exposed data on 5.7 million customers — a reminder that human-layer controls matter as much as technical ones.
14 October 2025
84,700 cybercrime reports, 138 ransomware incidents, and a 111% rise in attacks on critical infrastructure.
July 2026
1,205 notifications for calendar 2025, the highest since the scheme began. Separately, OAIC's preliminary inquiries into the Qantas incident conclude without a formal privacy investigation.
When ransomware payments must be reported within 72 hours and breach volumes are at record highs, security posture needs to be continuously evidenced, not reconstructed after an incident. That's the problem AI-Driven Cyber Audit Automation exists to solve.
Sources
This page is independent research summarised for context and is not legal or compliance advice. Figures are the most recent publicly reported at time of writing (22 July 2026) and may have moved since.