The augmented attacker:
The growing AI-driven cyber threat to Australian businesses
The augmented attacker: the growing AI-driven cyber threat to Australian businesses report, conducted by Mandala Partners and commissioned by CyberCX, part of Accenture, anticipates that cyber incidents in Australia will increase nine-fold from 38,000 in 2025 to 357,000 in 2030, largely driven by rapid improvements in AI cyber capabilities. The report also expects a 16% increase in the severity of cyber loss incidents as AI increases the speed with which threat actors can attack Australian organisations.
AI is changing what an attacker can do, making cyber incidents both more frequent and more severe
Australian businesses would face losses reaching $37 billion a year by 2030 as AI-driven threats grow
Businesses can avoid most of the losses by investing in foundational cyber defences

CyberCX CEO, John Paitaridis
“AI is transforming the Australian economy and will provide businesses with a wealth of benefits, unlocking growth and innovation. However, we’re already seeing how threat actors can misuse this technology to devastating effect. This report says that what we see now may only be the tip of the iceberg as Australian businesses confront an advancing set of cyber risks over the next four years.”

Mandala Partners Partner, Tom McMahon
“What we now see clearly is that a BAU approach on cyber security in an AI-era would constitute a severe blow to the economy.
“Australian businesses are already underinvesting relative to the rest of the world, with just 4.4 per cent of Australian IT budgets going toward cyber security around half the global industry standard.”
Download report
The augmented attacker: the growing AI-driven cyber threat to Australian businesses
Nearly half of the cyber incident losses in 2030 are expected to be due to business interruptions. This includes the cost of systems being taken offline by ransomware, denial-of-service-attacks or a third-party supplier outage. Other drivers include losses to the threat actor directly, losses due to response and recovery, and loss due to external liabilities.
Preventive actions like MFA, patching known vulnerabilities, and securing AI deployments account for 75% – or $18 billion – of the reduction in economic loss by 2030 if Australian businesses adopt foundational defensive actions. Responsive actions, like continuous monitoring that detects intrusions earlier and limits the damage of each incident, accounts for a further $6 billion reduction.
The report highlights the need for increased cyber security investment across the economy, with Australian businesses in total spending 4.4 per cent of their IT budgets on cyber security in 2025, trailing the global industry standard of around 7-10 per cent.
