This page collects published Australian figures relevant to technology procurement, cyber risk and third-party assurance. Every number is attributed to a named source with a publication date, and links to the original. CYBORIUM does not publish its own survey data, so nothing here is a CYBORIUM estimate.
How many cybercrime reports does Australia receive each year?
The Australian Signals Directorate received over 84,700 cybercrime reports in the 2024-25 financial year, an average of one report every six minutes. The figure comes from the ASD Annual Cyber Threat Report 2024-25, published in October 2025.
What does cybercrime cost an Australian business on average?
The average self-reported cost of cybercrime per report for businesses was $80,850 in 2024-25, an increase of 50 per cent on the previous year. For small business the average was $56,600, up 14 per cent. Source: ASD Annual Cyber Threat Report 2024-25.
Cost of cybercrime by reporting group, 2024-25
| Reporting group | Average self-reported cost per report | Change on prior year |
|---|---|---|
| Business, all sizes | $80,850 | Up 50 per cent |
| Small business | $56,600 | Up 14 per cent |
| Individuals | $33,000 | Up 8 per cent |
All figures from the ASD Annual Cyber Threat Report 2024-25, published October 2025. The report also records a 219 per cent rise in losses reported by large business. Figures are self-reported to ASD and represent reported losses, not total economic cost.
When did APRA CPS 230 take effect?
APRA Prudential Standard CPS 230 Operational Risk Management came into force on 1 July 2025. It applies to APRA-regulated entities including banks, insurers and superannuation trustees, and covers critical operations and the management of material service providers.
What are the Essential Eight maturity levels?
The Australian Signals Directorate assesses the Essential Eight against four maturity levels, numbered zero to three. Maturity Level Zero indicates weaknesses in an organisation overall cyber security posture. The levels are defined in the ASD Essential Eight Maturity Model.
Australian regulatory instruments that affect technology procurement
| Instrument | Applies to | Status |
|---|---|---|
| APRA CPS 230 Operational Risk Management | APRA-regulated banks, insurers, superannuation trustees | In force 1 July 2025 |
| APRA CPS 234 Information Security | APRA-regulated entities | In force since 1 July 2019 |
| Security of Critical Infrastructure Act 2018, including the CIRMP Rules | Responsible entities for critical infrastructure assets | In force, obligations phased |
| Privacy Act 1988 and the Australian Privacy Principles | Most Australian organisations above the turnover threshold | In force, under reform |
| ASD Essential Eight Maturity Model | Non-corporate Commonwealth entities, widely adopted elsewhere | Current model, periodically revised |
How to read these numbers in a procurement decision
Reported-loss averages describe what organisations told ASD after an incident. They are useful for sizing an argument, not for pricing a specific risk, because they exclude unreported incidents and say nothing about the distribution behind the average. In an evaluation, the more useful question is what a given provider does to reduce your exposure, and whether the provider can evidence it.
Related reading: APRA CPS 230 due diligence, vendor and supplier risk management, and guided vendor evaluations.
Comparisons: procurement as a service vs staff augmentation, vendor-neutral advisor vs reseller, in-house vs outsourced procurement.
Sources
- Australian Signals Directorate, Annual Cyber Threat Report 2024-25, published October 2025. cyber.gov.au
- Australian Prudential Regulation Authority, Prudential Standard CPS 230 Operational Risk Management, effective 1 July 2025. apra.gov.au
- Australian Signals Directorate, Essential Eight Maturity Model. cyber.gov.au
Figures on this page were last checked on 25 August 2026. If a source has since been revised, the source prevails.
Also relevant: where independent market scanning differs.