Australian data breaches 2025 reached a record level. The Office of the Australian Information Commissioner received 1,205 notifications during the calendar year, up 8% from 1,112 in 2024.
The number matters, but the operational lesson matters more. Australian organisations need stronger identity controls, clearer data ownership, tested recovery and an incident process that works before staff are under pressure.
By the Compuloop Editorial Team | Australian business cybersecurity analysis | Source review completed 4 August 2026
What the OAIC's record figure actually tells us
The OAIC published the 2025 figures on 6 July 2026. Of the 1,205 notifications, 716 were attributed to malicious or criminal activity. That is about 59% of the reported total. The OAIC identified cyber hacking as the primary cause of reported breaches.
Health service providers recorded the highest volume, followed by financial services and Australian Government agencies. Professional organisations, education providers, legal firms, accountants and management services also appear prominently. These are sectors that routinely hold identity, health, financial, employment or commercially sensitive information.
| Sector | 2025 notifications | Share or position |
|---|---|---|
| Health service providers | 225 | 19% of all notifications; highest-volume sector |
| Financial services | 157 | Second-highest volume |
| Australian Government | 118 | Third-highest volume |
| Business and professional associations | 103 | Fourth-highest volume |
| Education | 81 | Equal fifth-highest volume |
| Legal, accounting and management services | 81 | Equal fifth-highest volume |
A notification is not the same as every cyber incident
The 1,205 figure should be interpreted carefully. It counts notifications received under the Notifiable Data Breaches scheme. It is not a count of every phishing email, lost device, malware alert or unsuccessful attack in Australia.
Under the OAIC quick-reference guide, an eligible data breach generally involves unauthorised access, unauthorised disclosure or loss of personal information that is likely to result in serious harm, where remedial action has not removed that likely risk. Some small businesses are covered even when annual turnover is below $3 million, depending on their activities and the information they handle.
Six changes Australian businesses should make in 2026
The response should not be another broad policy document that nobody uses. Each change below can be assigned to an owner, tested and evidenced. Together, they reduce the chance that a single stolen account, exposed device or supplier failure becomes a business-wide data event.
1. Treat identity as the front door
Email and cloud accounts hold customer information, invoices and reset links. A password alone is not a sufficient control.
- Require strong MFA for staff and administrators
- Separate daily and privileged accounts
- Review dormant users, recovery methods and external access
2. Know which data deserves protection
A business cannot secure or notify accurately when nobody knows what information it keeps, where it lives or who can reach it.
- Map customer, staff and financial information
- Set owners and retention periods
- Remove data that no longer has a business or legal purpose
3. Configure Microsoft 365 deliberately
Buying Microsoft 365 licences does not automatically configure Entra ID, Defender, device policies, sharing controls or audit visibility.
- Review MFA and Conditional Access
- Check admin roles and application consent
- Inspect mailbox rules, external sharing and device compliance
4. Prove that recovery works
A successful backup job is not the same as a successful recovery. Test a real restore before an incident forces the question.
- Define recovery time and recovery point expectations
- Include cloud email and files in the plan
- Record restore time, gaps and responsible owners
5. Prepare the NDB decision path
The OAIC guide sets out containment, assessment, notification and review. The technical team, management and privacy or legal advisers need a shared process.
- Keep an offline incident contact list
- Preserve logs and evidence
- Know who assesses serious harm and approves communications
6. Test suppliers and support ownership
Cloud providers, software vendors and managed services can be part of the response. Contracts do not replace operational clarity.
- Document who monitors and who responds
- Confirm access removal and escalation paths
- Test how suppliers provide logs, backups and incident updates
The Microsoft 365 gap: licences are not a security outcome
Microsoft 365 is often where Australian SMEs store email, identity, shared files, calendars and business conversations. The platform can support strong controls, but settings, licences and operational ownership still need to be reviewed.
A practical assessment should look at Entra ID sign-ins, MFA registration, legacy authentication, administrator roles, conditional access, risky application consent, Defender coverage, Intune enrolment, mailbox forwarding and SharePoint or OneDrive sharing. It should also ask how quickly a leaver loses access and whether a compromised account can be isolated without disabling the whole business.
The ASD Australian Cyber Security Centre recommends that small businesses start with MFA, software updates and backups. It also recommends an emergency plan and testing that plan. Those basics map directly to the weaknesses that turn a routine support issue into a damaging incident.
Backups should be tested as a business process
Recovery is not only a storage question. A business may need to restore email, cloud files, server data, application settings, identity records and the documentation required to reconnect systems safely.
A useful recovery drill selects representative data, sets an expected recovery time, performs the restore and records what happened. It should identify missing data, slow transfers, inaccessible credentials, unclear ownership and any dependency that would delay staff returning to work.
The result is evidence: what was restored, from which backup, by whom, how long it took and what must improve. That evidence is more valuable than a dashboard showing only that last night’s job finished without an error.
A 30-day data breach readiness plan
The OAIC response model has four broad steps: contain the breach, assess the facts and risks, notify affected individuals and the OAIC when required, then review the incident. Organisations that only begin assigning these roles after an alert arrives lose valuable time. The ACSC incident-response guidance also recommends maintaining and testing a formal response plan.
Turn the statistics into one measurable next step
Not every business needs the same project. A 15-person professional firm may need an identity and Microsoft 365 review. A business with servers and line-of-business applications may get more value from a recovery drill. A growing organisation may need ongoing ownership across users, devices, patching, security alerts and suppliers.
Cybersecurity review
Check identity, endpoints, email, firewalls and incident ownership, then rank the work by real business risk.
Review cybersecurity postureMicrosoft 365 assessment
Review Entra ID, MFA, administrator roles, Defender, external sharing and device-management settings.
Assess Microsoft 365Backup recovery drill
Restore representative Microsoft 365, server or business data and document recovery time, gaps and next actions.
Plan a recovery testManaged IT consultation
Connect security work to onboarding, offboarding, devices, support tickets, patching and normal business operations.
Discuss the next practical stepStart with evidence, not assumptions
Compuloop can review the controls already in place, identify the highest-priority gaps and document a practical improvement path for an Australian business environment.
Book a data breach readiness reviewCall 1300 007 613Sources and editorial notes
- OAIC: Data breach notifications increase to all-time high in 2025, published 6 July 2026.
- OAIC: Quick reference guide for responding to data breaches, published 29 June 2026.
- ASD ACSC: Small business cyber security guidance.
- ASD ACSC: Cyber security incident response planning, practitioner guidance.
Editorial note: This article reports and explains official statistics. It does not claim that a notification proves a particular organisation had weak security, and the photographs do not depict breaches counted in the OAIC data. This is general technical information, not legal advice. Organisations should obtain legal or privacy advice for their specific obligations. AI-assisted tools were used during page production; statistics, links, captions and conclusions were checked against the cited primary sources before publication.





