Back to News
Cyber Security August 19, 2026 · 5 min read

A Cyber Incident Now Costs 219% More Than Last Year

A new industry report puts the average cost of a cyber incident at over $200,000 for large businesses — up 219% in a single year. The businesses surveyed had security budgets, legal teams and cyber insurance. Most Melbourne SMBs have none of those. Here's why that gap matters.

DS

Denis Stevcic

Founder & Director, InfuzeIT

Rising cost of a cyber incident illustrated as a sharply climbing graph over a keyboard

MinterEllison's 11th annual Perspectives on Cyber Risk report landed this month, and the headline number is stark: the average cost of a cyber incident for a large business has jumped 219% year-on-year. Read past the headline, though, and the report is really a warning aimed at businesses with far less cushion than the ones it surveyed.

What the Report Found

MinterEllison surveyed 150 senior decision-makers for the report. The key figures:

As Paul Kallenbach, MinterEllison's national legal cyber lead, put it: "The fact that 71 per cent of organisations we surveyed experienced a cyber incident in the past 12 months, and that AI-enabled threats are now the second-leading cyber concern, tells you everything about how rapidly the risk landscape is shifting." He added that preparedness "is not a static state. It is an ongoing process of testing, learning, and adapting, and it has to be led from the boardroom."

The Number That Should Actually Worry Small Businesses

Here's the context missing from most coverage of this report: the organisations surveyed are large businesses — the kind with dedicated security teams, legal counsel on retainer, and in most cases, cyber insurance. Their average cost still jumped 219% in a single year. That's the cost with a safety net.

A Melbourne SMB facing the same category of incident — ransomware, a business email compromise, a data breach — is absorbing a proportionally much bigger hit, without the infrastructure large businesses use to soften it. There's no in-house legal team to manage notification obligations. No dedicated PR function to manage the fallout with local clients who talk to each other. And for a lot of small businesses, no cyber insurance at all, or a policy they've never actually read closely enough to know what it excludes. We've written before about how most businesses that lose their data permanently close within six months — this report is the same story from a different angle: the businesses least equipped to absorb a six-figure hit are the ones most likely to take one relative to their size.

Why Costs Are Climbing So Fast: AI

The report points squarely at accessible AI tools as a driver of both the volume and severity of incidents. Phishing emails no longer have the typos and clumsy phrasing that used to give them away. Voice cloning makes a "call from the CEO" authorising an urgent transfer far more convincing than it should be. And the report flags that most businesses' response plans are built for traditional threats like ransomware and email compromise — not for deepfakes, AI prompt injection, or scams run by autonomous AI agents. The threat is evolving faster than the average incident response plan.

What Actually Moves the Needle for a Business Your Size

1

Put an Incident Response Plan on Paper

"We'll figure it out if it happens" is not a plan. Know in advance who you call first, who has authority to make decisions, and what your notification obligations actually are.

2

Actually Read Your Cyber Insurance Policy

Plenty of business owners assume they're covered and find out otherwise at the worst possible moment. Check what's excluded — social engineering and payment fraud are commonly carved out unless specifically added.

3

Update Your Defences for AI-Era Threats

If your phishing training still teaches staff to look for typos, it's out of date. Modern filtering and staff training both need to account for AI-generated phishing and voice-cloned "urgent" requests.

4

Get an Outside View, Regularly

Security isn't a set-and-forget project. A periodic external assessment catches the gaps that become invisible to a team working inside the same systems every day.

5

Make It an Ownership-Level Priority

Kallenbach's point about preparedness being "led from the boardroom" applies just as much at small business scale — it means the owner treats security as a standing item, not something delegated entirely and never revisited.

A 219% jump in average incident cost is a wake-up call for businesses with the resources to absorb it. For a Melbourne SMB, it's a preview of a bill you almost certainly can't absorb the same way — which makes proactive monitoring and a real security baseline a lot cheaper than it looks, once you compare it to the alternative.

What would an incident actually cost you?

Our security team offers a free cyber security assessment for Melbourne businesses — a plain-English look at where you're exposed and what it would take to close the gaps, before you're the one calculating the cost.

Book a Free Security Assessment

More articles