Two numbers get quoted whenever the cost of a data breach comes up in Australia. The first is AUD $4.26 million, the average cost of a data breach that IBM calculates and that the Office of the Australian Information Commissioner (OAIC) cites in its own reporting. The second is $56,571, the average amount a small business told the Australian Signals Directorate (ASD) it lost to cybercrime in the 2024-25 financial year.
Both numbers are real. Both come from credible, named sources. And neither is the number a genuine Australian SME should use to budget for its own risk.
Here is why, and here is what the real number is closer to.
Two Numbers, Two Different Businesses
IBM’s Cost of a Data Breach Report is built from enterprise incident data: an organisation experiences a breach, and researchers cost out detection, containment, notification, lost business, and post-breach response across its full scale. The 2025 global edition puts the average cost at USD $4.4 million, itself a 9% fall on the prior year. The AUD $4.26 million figure that gets quoted for Australia, including by the OAIC in its own November 2025 commentary on the Notifiable Data Breaches (NDB) scheme, traces back to IBM’s earlier Australia-specific analysis. I have not been able to confirm whether IBM’s 2025 report includes a freshly updated Australia country figure, so treat $4.26 million as the most recent verified Australia number rather than a 2025 refresh, and verify the current figure against IBM’s own report before quoting it in a board pack.
Either way, that figure describes organisations with the IT estate, legal exposure, and customer base to generate a multi-million-dollar incident. A ten-person accounting firm or a regional aged care provider is not that organisation, and the $4.26 million figure was never trying to describe it.
The more useful comparison sits inside ASD’s own Annual Cyber Threat Report 2024-25. Businesses that self-reported a financial loss from cybercrime through ReportCyber lost, on average:
| Business size | 2022-23 | 2023-24 | 2024-25 |
|---|---|---|---|
| Small | $45,965 | $49,615 | $56,571 |
| Medium | $97,203 | $62,870 | $97,166 |
| Large | $71,598 | $63,202 | $202,691 |
Source: ASD Annual Cyber Threat Report 2024-25, self-reported average cybercrime loss by business size.
Small business losses have climbed in both of the last two years, up 14% in 2024-25 alone and roughly 23% across the two-year run. Medium and large business figures move around more sharply year to year, which most likely reflects a smaller pool of reported incidents at that scale rather than a genuine reversal and recovery. I would treat the medium and large rows as directionally useful rather than precise, and I have not seen ASD publish whether these are means or medians. That distinction is worth knowing, since a mean can be pulled a long way by a single large incident in a small reported sample, where a median would not move as much.
What the $56,571 Figure Measures
That figure is a self-reported, voluntary number. A business experiences a cybercrime incident, decides to report it to ReportCyber, and states a financial loss. It is a genuinely useful, primary-sourced figure, and it is the closest thing Australia has to an SME-specific benchmark. It is also, almost certainly, an undercount of the true cost to the business, for three reasons.
First, ReportCyber captures what a business chooses to report as a loss, which in practice tends to be direct, quantifiable costs: money stolen, invoices paid to a scammer, ransom demanded. It does not naturally capture the owner’s own time spent on containment and recovery, which the Australian Institute of Criminology’s 2024 Australian Cybercrime Survey found SME owners bear more of than other victims when they are affected. That survey also found 22% of SME owner respondents said their business was impacted by cybercrime in 2024, and that when SME owners were affected, they lost larger amounts than other respondent groups.
Second, it does not capture lost billable hours, the week a professional services firm spends restoring systems instead of serving clients, or the client relationships that end quietly rather than being logged as a cost.
Third, cybercrime loss reported to ASD is a different measure again from a data breach reported to the OAIC under the NDB scheme, and the two datasets do not overlap cleanly. In the January-June 2025 reporting period, the OAIC received 532 NDB notifications, 59% attributed to malicious or criminal attack and 37% to human error, itself up from 29% in the previous period. Cyber incidents in that period affected an average of just over 10,000 individuals each. None of that maps directly onto ASD’s cybercrime loss figures; they are measuring different things, from different reporting pathways, for different purposes. Anyone quoting a single “cost of a breach in Australia” figure is almost certainly blending sources that were never designed to be added together.
Best Practice - This is the way
You do not need a $56,571 incident to know roughly what a breach would cost your business. You need four things, none of which require a security budget.
- Cost your own incident, on paper, before you have one. Estimate the billable hours you would lose, the cost of an IT forensics call-out, and what it would cost to notify your actual client list. That number, not a national average, is the one to plan against.
- Check what your cyber insurance actually covers, if you have a policy at all. A meaningful share of Australian SMEs carry no cyber cover, and many that do have never checked the sub-limits against the estimate above.
- Fix the two controls that show up in almost every incident. Multi-factor authentication and tested backups remain the cheapest, highest-return controls against the most common causes of loss in every sector this series has covered.
- Get a professional assessment before you need one. An independent cyber health check gives you an evidenced number for your own business, rather than a borrowed one from an IBM survey or an ASD dashboard.
Sources
- IBM, Cost of a Data Breach Report 2025 — global figure, USD $4.4 million average, a 9% year-on-year decrease. ibm.com/reports/data-breach
- Office of the Australian Information Commissioner, “Latest Notifiable Data Breach statistics for January to June 2025,” published 4 November 2025 — cites IBM’s AUD $4.26 million figure; 532 NDB notifications, 59% malicious/criminal, 37% human error, roughly 10,000 individuals affected on average per cyber incident. oaic.gov.au
- Australian Signals Directorate, Annual Cyber Threat Report 2024-25, published 14 October 2025 — self-reported average cybercrime cost by business size, FY2022-23 to FY2024-25. cyber.gov.au
- Australian Institute of Criminology, Australian Cybercrime Survey 2024 — 22% of SME owner respondents reported business impact in 2024; SME owners reported disproportionately higher losses when affected. As cited in ASD’s Annual Cyber Threat Report 2024-25.