AUTOFYEDGE mark AUTOFYEDGE

AI-Driven Cyber Audit Automation / Regulatory Case

Regulatory Case Study · Cyber Risk in Australia

The regulatory case for continuous cyber assurance

A new mandatory ransomware-reporting regime, a record year for data breach notifications, and a cybercrime report every six minutes. Here's what Australia's cyber regulatory stack now actually requires — and why point-in-time pen tests can't keep up with it.

59% of breaches are malicious or criminal attacks, not error

OAIC Notifiable Data Breaches, Jan–Jun 2025. See sources.

Cybercrime reports, FY2024–25

84,700

One report roughly every six minutes, per ASD's Annual Cyber Threat Report.

Ransomware incidents, FY2024–25

138

Healthcare-sector ransomware incidents doubled year-on-year.

Data breaches notified, 2025

1,205

Record high to the OAIC — up 8% on 2024.

Average cost per incident

$80,850

Up 50% year-on-year, per ASD's cybercrime cost modelling.

The Regulators

Who actually regulates cyber risk

Four bodies, four different levers — technical authority, privacy enforcement, critical-infrastructure obligations, and sector-specific rules.

ASD / ACSC

Technical authority

The Australian Signals Directorate's Cyber Security Centre issues the Essential Eight, coordinates incident response, and publishes the Annual Cyber Threat Report.

OAIC

Privacy enforcement

The Office of the Australian Information Commissioner runs the Notifiable Data Breaches scheme and enforces the Privacy Act, including the new doxxing offences and civil penalties.

Home Affairs / CISC

Critical infrastructure

The Cyber and Infrastructure Security Centre administers the SOCI Act and the Cyber Security Act 2024's mandatory ransomware-payment reporting regime.

Sector regulators

Layered obligations

Bodies like APRA (CPS 234, for financial services) add sector-specific cyber and operational-resilience requirements on top of the national baseline.

Interactive · State & Territory

State government cyber policy, by jurisdiction

Commonwealth law sets the floor everywhere; several states layer their own information-security policy on top for their own agencies. Select a state to see how.

Select a state

National baseline

Every entity in Australia sits under the Commonwealth baseline: the Privacy Act, the SOCI Act (if critical infrastructure), and the Cyber Security Act 2024's ransomware-reporting regime. States can layer additional policy on top for their own agencies.

Shows state government information-security policy for state agencies, not a private-sector obligation. See sources.

The Stack

Australia's cyber regulatory stack, 2024–2026

Five instruments now do most of the work — four commenced or tightened within the last 18 months.

What it requires
Applies to
Status
Privacy Act 1988 (2024 amendment)
What it requiresStatutory tort for serious invasions of privacy; criminal doxxing offences; mid-tier civil penalties (2,000 / 10,000 penalty units).
Applies toAll APP entities
StatusIn force since Dec 2024 / Jun 2025
Notifiable Data Breaches scheme
What it requiresMandatory notification to OAIC and affected individuals for eligible data breaches.
Applies toAll APP entities
StatusOngoing — record 1,205 notifications in 2025
SOCI Act
What it requiresAsset registration, risk-management program, mandatory incident reporting across 11 critical-infrastructure sectors.
Applies toCritical infrastructure entities
StatusIn force, rules updated 2024–25
Cyber Security Act 2024
What it requiresMandatory ransomware/extortion payment reporting within 72 hours to the CISC; smart-device security standards.
Applies toTurnover ≥$3M, or any critical infrastructure entity
StatusRansomware reporting live since 30 May 2025
Essential Eight (ASD)
What it requiresEight mitigation strategies scored across four maturity levels (ML0–ML3).
Applies toVoluntary baseline, referenced across govt & industry
StatusLiving standard, ongoing guidance

Source: Cyber Security Act 2024, SOCI Act, Privacy and Other Legislation Amendment Act 2024, ASD Essential Eight guidance. See sources.

FY2023–24 → FY2024–25

Threat activity is climbing fast

Prior-year figures derived from ASD's reported year-on-year percentage change.

Incidents ACSC
responded to

~1,080 prior year1,200+  +11%

Malicious-activity
notifications issued

~930 prior year1,700+  +83%

Attacks on critical
infrastructure

indexed prior year+111% YoY

FY2023–24   FY2024–25

OAIC, Calendar Year 2025

Data breaches by sector

Top 5 of 1,205 total notifications. Legal, accounting & management services also reported 81, tying with education.

Health services

225 · 19%

Financial services

157

Australian Government

118

Business & professional

103

Education

81

ASD Essential Eight

Recommended maturity target, by organisation type

Federal government entities

Maturity Level 3

Critical infrastructure operators

Maturity Level 2 (minimum)

Commercial organisations

ML1 baseline · ML2 recommended

Recent Regulatory Developments

A timeline of Australia's cyber regulatory shift

Curated and updated periodically from ASD, OAIC and Home Affairs reporting — not a live feed. Last reviewed 22 July 2026.

29 November 2024

Cyber Security Act 2024 receives Royal Assent

Australia's first standalone Commonwealth cyber security law — introduces smart-device standards and the ransomware payment reporting regime.

10 December 2024

Privacy Act doxxing reforms pass

The Privacy and Other Legislation Amendment Act 2024 receives Royal Assent, criminalising doxxing and adding a mid-tier civil penalty tier ahead of a statutory tort taking effect by June 2025.

30 May 2025

Mandatory ransomware reporting goes live

Entities with turnover ≥$3M, or responsible for critical infrastructure, must report ransomware/extortion payments to the CISC within 72 hours.

30 June 2025

Qantas contact-centre breach

A social-engineering attack on a third-party contact-centre platform exposed data on 5.7 million customers — a reminder that human-layer controls matter as much as technical ones.

14 October 2025

ASD releases the Annual Cyber Threat Report 2024–25

84,700 cybercrime reports, 138 ransomware incidents, and a 111% rise in attacks on critical infrastructure.

July 2026

OAIC confirms an all-time-high breach year

1,205 notifications for calendar 2025, the highest since the scheme began. Separately, OAIC's preliminary inquiries into the Qantas incident conclude without a formal privacy investigation.

What This Means For You

An annual pen test can't cover a 72-hour reporting clock

When ransomware payments must be reported within 72 hours and breach volumes are at record highs, security posture needs to be continuously evidenced, not reconstructed after an incident. That's the problem AI-Driven Cyber Audit Automation exists to solve.

Get your risk snapshot

Sources

This page is independent research summarised for context and is not legal or compliance advice. Figures are the most recent publicly reported at time of writing (22 July 2026) and may have moved since.

Evidence your security posture continuously, not once a year.