Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Report: Cost of a cyber incident rises by 219% year on year

More than two-thirds of respondents to a recent MinterEllison survey said their business was the target of a cyber incident as the cost of malicious activity rises to staggering new levels.

Tue, 18 Aug 2026
Report: Cost of a cyber incident rises by 219% year on year

The rise of affordable AI technology is driving an alarming increase in cyber incidents impacting businesses, according to new research by one of Australia’s top law firms.

MinterEllison’s 11th annual Perspectives on Cyber Risk report, published last week, polled 150 senior decision-makers to understand the current state of the threat landscape, with 71 per cent of respondents saying they had suffered some form of cyber security incident in the last 12 months.

“The fact that 71 per cent of organisations we surveyed experienced a cyber incident in the past 12 months, and that AI-enabled threats are now the second-leading cyber concern, tells you everything about how rapidly the risk landscape is shifting,” Paul Kallenbach, partner and national legal cyber lead at MinterEllison, said in a statement.

 
 

“While organisations have made real progress on preparedness over the past decade, governance has not kept pace with the speed of AI adoption, and boards cannot afford to treat AI governance as a compliance exercise. It needs to operate as a live discipline, and organisations that get this right will be far better placed when an incident occurs.”

However, while AI may be driving attacks – and ever more effective ones – the cost of those attacks is also rising. The average incident now costs large businesses in the realm of $202,700, an increase of 219 per cent year on year.

At the same time, supply chain exposure has grown to impact 57 per cent of respondents, an increase of 50 per cent compared to the previous year.

MinterEllison’s survey also found that while the vast majority of organisations have response plans in place and regularly test them, those plans are not keeping pace with the nature of modern threats. Business email compromise and ransomware incidents are what many companies expect, but many are failing to prepare to tackle deepfake-based fraud, AI prompt injection, and the threat of autonomous AI agents going on the offensive.

And with the capacity for events to go sideways beyond what organisations train for, the spectre of class actions related to data breaches and other legal and regulatory impacts are compounding the impact of poorly managed cyber incidents.

“Preparedness is not a static state. It is an ongoing process of testing, learning, and adapting, and it has to be led from the boardroom,” Kallenbach said.

“Organisations that have adopted AI at scale need to ask themselves whether their governance has kept pace, and whether their frameworks recorded on paper have been tested under pressure.”

You can read the full report here.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: