03/09/2026
One in two Australian businesses reported a cyber event in the past twelve months. Two thirds of those incidents involved a third party supplier.
Those figures come from a QBE survey of 400 Australian businesses. The supplier finding is one that can be easy to overlook. You can run your own systems properly and still end up inside somebody else's breach, through a supplier, a platform, a bookkeeper, a portal you log into once a fortnight.
Sixty per cent of the businesses that had an incident lost revenue over it. Eighteen per cent experienced business interruption lasting one day or more.
The costs sit in more places than the obvious one. The forensic investigator working out what was taken and whether they are still in there. The lawyer advising whether the breach is notifiable. The costs of notifying customers where required following a data breach. And the days you cannot invoice while all of it happens.
Cyber cover here generally splits two ways. First party responds to your own losses: incident response, business interruption, data restoration, extortion costs. Third party responds to what you owe other people, including penalties and compensation where personal information was not kept safe. What any policy picks up is set by its own terms, conditions, limits and exclusions, and those vary between insurers.
One more thing worth knowing. Cyber insurance rates across the region have been moving down: in the Pacific they decreased 6 per cent in the first quarter of 2026. That is not a statement about the risk.
Three things to check before the morning you need them. Whether you hold cyber cover at all. Whether it responds to business interruption or only to incident response. And how many days you could keep trading with the systems down.
Sources: QBE, One in four Australian businesses hit by AI enabled cyber attacks, 9 June 2026; Marsh, Pacific Insurance Market Rates, Q1 2026.