Vendor & Industry News

AI cyber threats rise as Australian incidents surge

A new cyber risk report from law firm MinterEllison should give every facilities manager, IT lead and board member pause: 71% of Australian organisations experienced a cyber incident in the past 12 months, and for the first time, AI-enabled threats have climbed to the second-biggest cyber concern nationally. The report, based on a survey of 150 senior decision-makers, paints a picture of rising costs and a widening gap between what organisations say they’re prepared for and what they’re actually rehearsing.

The numbers behind the headline

The average cost of a cybercrime incident for large Australian businesses rose 219% year-on-year to AUD $202,700. More than half of respondents — 57% — reported a breach involving a third-party supplier or vendor, up from 50% in the previous survey period. Ransomware remains the top-cited concern at 30%, but AI-enabled threats are close behind at 25%, and cybersecurity has now overtaken privacy as the leading risk organisations associate with AI adoption.

  • 71% of organisations experienced a cyber incident in the past 12 months
  • Average incident cost for large businesses: AUD $202,700 (up 219% YoY)
  • 57% reported a third-party or vendor-related breach
  • 25% cite AI-enabled threats as a top concern, second only to ransomware at 30%

What’s notable is the preparedness paradox the report highlights. Nearly all respondents (98%) had benchmarked their cyber maturity against a recognised framework, 91% had a documented incident response plan, and 51% tested that plan at least quarterly. On paper, that looks solid. But the report found those rehearsal exercises largely still focus on established threats — ransomware, business email compromise — while omitting scenarios involving deepfake-enabled fraud, prompt-injection attacks against enterprise AI tools, or autonomous offensive agents. In other words, many organisations are drilling for yesterday’s attack while a newer category of risk goes unrehearsed.

Operational implications for facilities and building operators

This isn’t just a head-office IT problem. Building management systems, access control platforms, and networked CCTV infrastructure are increasingly part of the same converged network as corporate IT — and third-party/vendor exposure was cited by well over half of survey respondents. Any integrator, cloud VMS provider, or remote monitoring service sitting on your network is a potential entry point, and boards are now expected to treat that exposure as seriously as their own internal systems.

The report also flags a tougher regulatory backdrop, with APRA, the OAIC and ASIC all increasing scrutiny of how organisations assess, monitor and test risk around new digital systems, including AI tools. Legal developments cited in the report — a statutory tort for serious invasions of privacy, the prospect of cyber-related class actions, and a narrower approach to legal professional privilege in post-incident reviews — all raise the stakes for how incidents are documented, investigated and disclosed. For strata committees, club operators and building owners running networked security and BMS infrastructure, this reinforces the value of maintaining an accurate, current device register and network topology map well before an incident occurs, not after.

Paul Kallenbach, Partner and National Legal Cyber Lead at MinterEllison, summed up the governance gap: “Preparedness is not a static state. It is an ongoing process of testing, learning and adapting, and it has to be led from the boardroom. Organisations that have adopted AI at scale need to ask themselves whether their governance has kept pace, and whether their frameworks recorded on paper have been tested under pressure.”

Mallen’s take

For the sites we support — strata buildings, clubs, and commercial facilities running converged security and BMS networks — this report is a useful prompt rather than an alarm bell. Most of our clients aren’t running enterprise AI tools that face prompt-injection risk directly, but the broader lesson applies: documented plans mean little if they’re not tested against the risks that actually matter for your environment, and third-party/vendor access to your network deserves the same scrutiny as your own systems.

A practical starting point is knowing exactly what’s on your network, who has access to it, and how that’s documented. This is precisely what the Mallen site audit is designed to establish — a clear device register and topology map that becomes the foundation for any sensible incident response conversation, and something your insurer or auditor will increasingly expect to see. If your organisation is also grappling with AI governance at the IT strategy level, that’s a conversation better had proactively than reactively — an area where fractional CTO consulting can help bridge the gap between board-level policy and what’s actually deployed on the ground.

Original source: https://securitybrief.com.au/story/ai-cyber-threats-rise-as-australian-incidents-surge