Add Think Technology as a trusted source The Real Cost of Cybercrime for Australian Businesses | TTA

The real cost of cybercrime for Australian businesses

Title graphic reading The Cost of Cybercrime

A Brisbane accounting firm we work with got hit by a ransomware attack on a Tuesday morning. By Thursday, they still couldn’t access their client files. The ransom demand was the headline cost, but the bigger bill came from three weeks of disrupted operations, emergency IT response, and a near-miss with the Notifiable Data Breaches scheme. That story is not unusual. It is the pattern we see across Queensland SMEs, and the numbers behind it keep getting worse.

The Australian Signals Directorate (ASD) released its Annual Cyber Threat Report for 2024-25 in October 2025. The findings are worth every business owner reading. Cybercrime is not slowing down, and the cost per incident is climbing sharply. Our IT security assessments consistently confirm what the report shows: most successful attacks exploit gaps that are fixable before an incident occurs.

How much is cybercrime costing Australian businesses right now?

The ASD’s 2024-25 report put the average self-reported cost of cybercrime across all businesses at $80,850 per incident, up 50% on the previous year. Small businesses reported an average loss of $56,600, a 14% rise. Medium businesses faced an average of $97,200, up 55%. Large organisations were hit hardest in dollar terms, averaging $202,700 per incident, representing a 219% increase year on year.

These are reported figures. ASD and independent researchers consistently note the real total is higher, because many incidents go unreported or are only partially captured. The $80,850 figure covers what businesses can quantify. Reputation damage, lost clients, and staff time rarely make it into a formal report.

Across 2024-25, ASD received over 84,700 cybercrime reports. That is one report every six minutes. The Australian Cyber Security Hotline answered more than 42,500 calls during the same period, a 16% increase on the prior year. ASD also responded to more than 1,200 cyber security incidents, up 11% from the previous year.

Ransomware remains the most disruptive threat

Ransomware appears in 11% of all incidents recorded by ASD, and in 34% of the most serious Category 3 or higher incidents affecting government, large organisations, and critical infrastructure. The Australian Government introduced mandatory ransomware payment reporting in May 2025, requiring businesses with annual turnover above $3 million to disclose payments made to ransomware groups. More than 75 Australian businesses have already disclosed payments since the regime began, and that is just the businesses above the reporting threshold.

Ransomware recovery is not just a technology cost. Businesses we have assisted after an incident typically face:

  • Days or weeks of lost access to systems and client data.
  • Emergency forensic and recovery costs on top of any ransom paid.
  • Regulatory exposure if personal data was accessed or exfiltrated.
  • Reputational damage that lingers well after systems are restored.

The fastest-growing attack type in 2024-25 was denial-of-service (DoS and DDoS). ASD responded to more than 200 such incidents, a rise of over 280% on the year before. These attacks don’t steal data, but they take systems offline and cost businesses in lost revenue and emergency response.

Small businesses are disproportionately targeted

Small businesses reported 92.6% of all business cybercrime incidents to ASD in 2024-25. That figure is striking. Larger organisations have more resources to invest in security, while smaller ones often run outdated systems, have fewer controls in place, and are less likely to detect intrusions quickly. Attackers know this and price their effort accordingly.

The most common attack types targeting businesses are email compromise, business email compromise (BEC) fraud, and online banking fraud. Together these account for more than half of all business cybercrime reports. Email security is the single most impactful first step most SMEs can take, and it is still under-invested in by a large share of businesses we meet.

Phishing has also become more sophisticated. The European Union Agency for Cybersecurity (ENISA) found that over 80% of phishing emails analyzed between late 2024 and early 2025 used AI to some degree, whether to personalise the message, improve the writing, or translate it into the target’s language. AI lowers the effort for attackers and makes scam emails harder to spot by eye alone.

What we see at TTA: the gap between perceived and actual risk

One pattern we see repeatedly with Queensland SMEs is the gap between how secure a business thinks it is and how secure it actually is. Businesses that have “always been fine” often have no idea whether an attacker has been inside their environment. ASD’s report found that 39% of ransomware incidents in 2024-25 were discovered by ASD contacting the affected organisation, not by the organisation itself. That figure should give any business owner pause.

Legacy systems are a major contributor. ASD’s report is explicit: outdated technology increases the likelihood of an incident and makes any incident significantly more damaging. We regularly find businesses running software that is years past end-of-support, with no patching process in place. Twenty-one percent of hacks occur within 48 hours of a vendor disclosing a vulnerability. That window is too short for a business without a managed patching process to respond in time.

The good news is that the most effective defences are also among the most practical to put in place. Multi-factor authentication (MFA), strong password management, email filtering, regular patching, and a tested backup are not exotic or expensive. They close the majority of the gaps attackers rely on. Our IT audits give businesses a clear picture of where those gaps are before an attacker finds them first.

The cost of protection versus the cost of recovery

Cyber security investment is often framed as an IT expense. We think of it differently: it is the cost of not having to spend $56,000 to $202,000 recovering from a single incident, plus the unquantified cost of reputation damage and client attrition. Prevention is cheaper, faster, and far less disruptive than recovery.

The ASD’s four priority actions for organisations right now are: implement best-practice event logging, replace legacy technology, choose secure-by-design products, and begin planning for post-quantum cryptography. For most SMEs, the first two are the place to start. Good logging means you know when something goes wrong. Replacing legacy systems removes the low-hanging attack surface that criminals look for first.

Businesses that carry cyber insurance should also check whether their current security posture actually meets their policy requirements. Insurers have tightened underwriting standards significantly since 2022, and a claim can be denied if basic controls like MFA and regular backups were not in place at the time of the incident.

For more on how to protect your business from the most common attack types, see our overview of cybersecurity for Australian businessesor our piece on building cyber resilience after an attack.

Frequently asked questions

How much does a cyberattack cost an Australian small business on average?

According to ASD’s Annual Cyber Threat Report 2024-25, the average self-reported cost of cybercrime for a small business in Australia is $56,600 per incident, up 14% on the previous year. Medium businesses average $97,200 and large businesses average $202,700. These figures cover reported costs only; reputation damage and lost revenue are typically not included.

How often is cybercrime reported in Australia?

ASD received over 84,700 cybercrime reports in the 2024-25 financial year, equivalent to one report every six minutes. More than 42,500 calls were made to the Australian Cyber Security Hotline in the same period, a 16% increase on the prior year. These are reported incidents only; actual cybercrime volumes are estimated to be significantly higher.

What types of cybercrime most affect Australian businesses?

Email compromise, business email compromise (BEC) fraud, and online banking fraud together make up more than half of all business cybercrime reports. Ransomware is the most disruptive single threat, appearing in 34% of the most serious incidents. Phishing is the most common entry point, increasingly aided by AI tools that make fraudulent emails harder to detect.

Do small businesses really need to worry about ransomware?

Yes. Small businesses account for 92.6% of all business cybercrime incidents reported to ASD in 2024-25. Attackers target smaller organisations because they typically have fewer defences, older systems, and less capacity to detect intrusions quickly. A ransomware attack on a 20-person business can be just as disabling as one on a larger organisation, often more so because there is less capacity to absorb the disruption.

What basic steps can an SME take to reduce cyber risk?

ASD recommends four priorities: implement best-practice event logging, replace legacy systems, choose secure-by-design products, and enable multi-factor authentication. For most SMEs, MFA on all accounts, a managed email filtering solution, regular patching, and a tested offsite backup cover the majority of attack pathways. An independent IT security assessment helps identify which gaps are most urgent to close.

When should a business contact an IT provider after a cyber incident?

Immediately. The first hours after a suspected incident determine how much damage is contained. An IT provider can isolate affected systems, preserve evidence for any insurance or regulatory claim, and begin recovery. Waiting to see whether the situation resolves itself almost always makes it worse. ASD’s Cyber Security Hotline (1300 CYBER1) is also available 24 hours a day for immediate guidance.

How do we get started?

If you are unsure where your business sits on the risk spectrum, an independent assessment is the best place to start. Think Technology Australia works with SMEs across South-East Queensland to identify vulnerabilities, put practical defences in place, and build a continuity plan for when things go wrong. Get in touch with our team to start a conversation about your current security posture.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.