Cybersecurity 2026

AUSTRALIA Trends and Developments Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

Nyman Gibson Miralis Level 9, 299 Elizabeth Street Sydney NSW 2000 Australia

Tel: +61 292 648 884 Email: dm@ngm.com Web: www.ngm.com.au

Introduction Since releasing the 2023-2030 Australian Cyber Security Strategy (the “CS Strategy”) on 22 Novem - ber 2023, the Australian government has pursued sweeping reforms to address the gaps in cybersecu - rity. The government aims to become “a world leader in cyber security by 2030”. The CS Strategy is aimed at strengthening Australia’s cyberdefences and sup - porting people and businesses to be resilient to and recover quickly from cyber-attacks. Grounded in the 2023-2030 Australian Cyber Security Strategy: Action Plan (the “Action Plan”), the CS Strategy is planned out across three “Horizons” targeting six “shields” or “layers of defence”. Although Australia has already entered Horizon 2 (“Expand our search”), the gov - ernment is still assessing progress under Horizon 1 and determining what the next stage truly looks like: ie, scaling cybermaturity across the whole economy, making investments, and growing a diverse cyber - workforce. The effectiveness of the actions imple - mented to date and of the reforms are also uncertain, as is expected when a country starts taking unprec - edented steps in an environment that demands con - sistent reassessment and a “set and forget” approach is not an option. Between 2024 and 2025, Australia introduced a range of leading reforms, from the Australian-first cyberse - curity legislation under the Cybersecurity Act package to the world-first social media ban via the Online Safe - ty Amendment (Social Media Minimum Age) Act 2024 (Cth). As the dust continues to settle, further reform is to be tabled and law enforcement approaches are evolving.

Threat Landscape Victim typologies

The Australian Signals Directorate (ASD) Annual Cyber Threat Report for 2024-25 (the “ASD 2024-25 Report”) indicates an 11% increase in incidents reported to ASD since the 2023-24 period. In terms of the top five sectors reporting cyberthreats, there was a shift from FY2023-24 (and the previous year). The top two remained the same, being federal government and state/local governments, however, financial and insurance services rose from eighth position (4%) to third (7%), usurping the three sectors previously tied for fourth, which still contained health - care and social assistance; professional, scientific and technical services (increased from 5% to 6%); as well as information media and telecommunications; with education and training maintaining its 5% share, but fell to a tie for seventh place. The ASD 2024-25 Report flagged that the ASD responded to 1,200 cybersecurity incidents and received over 84,700 cybercrime reports (a further 3% drop, compared to a 7% drop the previous year). The crime trends differ amongst targets, as outlined below. • For individuals, self-reported cybercrimes com - prised identify fraud (30%, up from 26%), online shopping fraud (13%, down from 15%) and online banking fraud (10%, down from 12%). • For businesses, the most common incidents were “email compromise resulting in no financial loss” (19%), “business email compromise fraud result - ing in financial loss” (15%, up from 13%), and identity fraud (11%). Online banking fraud (previ - ously, 13%) did not feature among the top reported incidents.

26 CHAMBERS.COM

Powered by