This page collects published Australian figures relevant to technology procurement, cyber risk and third-party assurance. Every number is attributed to a named source with a publication date, and links to the original. CYBORIUM does not publish its own survey data, so nothing here is a CYBORIUM estimate.

How many cybercrime reports does Australia receive each year?

The Australian Signals Directorate received over 84,700 cybercrime reports in the 2024-25 financial year, an average of one report every six minutes. The figure comes from the ASD Annual Cyber Threat Report 2024-25, published in October 2025.

What does cybercrime cost an Australian business on average?

The average self-reported cost of cybercrime per report for businesses was $80,850 in 2024-25, an increase of 50 per cent on the previous year. For small business the average was $56,600, up 14 per cent. Source: ASD Annual Cyber Threat Report 2024-25.

Cost of cybercrime by reporting group, 2024-25

Reporting groupAverage self-reported cost per reportChange on prior year
Business, all sizes$80,850Up 50 per cent
Small business$56,600Up 14 per cent
Individuals$33,000Up 8 per cent

All figures from the ASD Annual Cyber Threat Report 2024-25, published October 2025. The report also records a 219 per cent rise in losses reported by large business. Figures are self-reported to ASD and represent reported losses, not total economic cost.

When did APRA CPS 230 take effect?

APRA Prudential Standard CPS 230 Operational Risk Management came into force on 1 July 2025. It applies to APRA-regulated entities including banks, insurers and superannuation trustees, and covers critical operations and the management of material service providers.

What are the Essential Eight maturity levels?

The Australian Signals Directorate assesses the Essential Eight against four maturity levels, numbered zero to three. Maturity Level Zero indicates weaknesses in an organisation overall cyber security posture. The levels are defined in the ASD Essential Eight Maturity Model.

Australian regulatory instruments that affect technology procurement

InstrumentApplies toStatus
APRA CPS 230 Operational Risk ManagementAPRA-regulated banks, insurers, superannuation trusteesIn force 1 July 2025
APRA CPS 234 Information SecurityAPRA-regulated entitiesIn force since 1 July 2019
Security of Critical Infrastructure Act 2018, including the CIRMP RulesResponsible entities for critical infrastructure assetsIn force, obligations phased
Privacy Act 1988 and the Australian Privacy PrinciplesMost Australian organisations above the turnover thresholdIn force, under reform
ASD Essential Eight Maturity ModelNon-corporate Commonwealth entities, widely adopted elsewhereCurrent model, periodically revised

How to read these numbers in a procurement decision

Reported-loss averages describe what organisations told ASD after an incident. They are useful for sizing an argument, not for pricing a specific risk, because they exclude unreported incidents and say nothing about the distribution behind the average. In an evaluation, the more useful question is what a given provider does to reduce your exposure, and whether the provider can evidence it.

Related reading: APRA CPS 230 due diligence, vendor and supplier risk management, and guided vendor evaluations.

Comparisons: procurement as a service vs staff augmentation, vendor-neutral advisor vs reseller, in-house vs outsourced procurement.

Sources

Figures on this page were last checked on 25 August 2026. If a source has since been revised, the source prevails.

Also relevant: where independent market scanning differs.