A data breach costs an Australian small business an average of $56,600, according to self-reported figures in the Australian Signals Directorate's Annual Cyber Threat Report 2024-25 — up 14% from $49,615 the previous financial year. Medium businesses reported $97,200 on average and large businesses $202,700. The average has climbed every year since 2022-23, when the small business figure was $45,965.
TL;DR
- The average self-reported cost of cybercrime for Australian small business was $56,600 in 2024-25, up 14% year on year (ASD Annual Cyber Threat Report).
- IBM puts the global average cost of a data breach at USD 4.44 million in 2025; Australian small businesses lose less in dollars, but far more relative to revenue.
- Verizon's 2026 Data Breach Investigations Report found 62% of breaches involve a human element.
- Short, monthly training and phishing practice cost a fraction of the average loss.
What the reported numbers look like
| Business size | 2022-23 | 2023-24 | 2024-25 |
|---|---|---|---|
| Small business | $45,965 | $49,615 | $56,600 |
| Medium business | $97,203 | $62,870 | $97,200 |
| Large business | $71,598 | $63,202 | $202,700 |
These are averages of self-reported financial losses per cybercrime report, not audited totals. The ASD received 84,700 cybercrime reports in 2024-25 — roughly one every six minutes — and small businesses file a large share of them. Averages also swing on outliers: the 219% jump in large-business costs in 2024-25 was driven partly by a small number of very large business email compromise losses. Treat $56,600 as an order of magnitude, not an invoice.
Note that a cybercrime report is broader than a breach — it also covers scams and fraud where no data was taken. A full data breach, where customer or business data is exposed, usually costs more again once response, notification and downtime are counted.
How the Australian figure compares globally
IBM's 2025 Cost of a Data Breach Report put the global average at USD 4.44 million — the first decline in five years, down 9% from 2024. The two numbers measure different things: IBM surveys large enterprises on full incident response costs, while the ASD figures are self-reported cybercrime losses from reports like the one above. Both point the same way: an incident costs multiples of what prevention costs.
What the money actually pays for
- Stolen money. Invoice fraud and business email compromise — a fake supplier bank-detail change or a convincing fake-CEO email redirects a real payment.
- Response and recovery. External IT help, account lockouts, credential resets, device rebuilds and the staff hours lost dealing with all of it.
- Compromised data. Customer records or commercial information taken from a breached mailbox, which brings its own obligations.
The self-reported averages mostly capture the first item. They under-capture the second and third, which is why the real total often lands higher than the report suggests.
The costs the average misses
- Downtime. Days without email, payments or job management tools while accounts are secured.
- The 30-day clock. Organisations covered by the Privacy Act must assess a suspected data breach within 30 days under the Notifiable Data Breaches scheme, and notify affected people and the regulator when serious harm is likely. That assessment, notification and advice costs time and money.
- Trust. Customers whose details leaked from your systems come back slower, if at all.
- Insurance. Renewal premiums reflect the incident for years.
Why the cost keeps rising: the human element
Verizon's 2026 Data Breach Investigations Report found 62% of breaches involve a human element — a click, a misdirected email, a manipulated phone call. Attackers target people because people are cheaper to attack than systems are to defeat. For a small business with no security team, that makes training the handful of people who click the highest-leverage spend on the list.
What actually reduces the loss
- Train briefly and often. Short story-driven lessons on a monthly cadence beat one annual session — Cyber Aware's awareness training runs 120+ modules built exactly that way.
- Practise phishing in a safe place. Monthly phishing simulations let staff fail where it costs nothing; Cyber Aware reports an average 80% reduction in risk within the first eight months.
- Find the gaps before attackers do. A cyber security gap assessment mapped to Essential 8 and ISO 27001 shows which basics are missing while they are still cheap to fix.
- Measure and follow up. Human risk reporting turns overdue courses and phishing clicks into one score per learner, so follow-up reaches the two people who need it instead of the whole team.
FAQ
How much does a data breach cost a small business in Australia? The average self-reported cost was $56,600 in 2024-25, up 14% from $49,615 in 2023-24, per the ASD Annual Cyber Threat Report. It reflects reported cybercrime losses, not the full cost of downtime and lost trust.
Was the small business average lower in earlier years? Yes — $45,965 in 2022-23 and $49,615 in 2023-24. The average has risen for three consecutive financial years.
How quickly must an Australian business report a breach? Under the Notifiable Data Breaches scheme, organisations covered by the Privacy Act must assess a suspected eligible breach within 30 days and notify affected individuals and the Office of the Australian Information Commissioner when serious harm is likely.
Do small businesses really get targeted, or only big companies? The ASD received 84,700 cybercrime reports in 2024-25 — one roughly every six minutes — and small businesses file a large share of them. Attacks are automated, so headcount is not protection.
Which control gives the biggest reduction for the money? Monthly phishing simulations paired with short training modules. They address the 62% human element Verizon identifies, and they cost a fraction of the $56,600 average loss.
One last thing
Compare $56,600 to your own revenue, not to a bank's. For a five-person business turning over $500,000 a year, one average incident erases more than a tenth of a year's income — which is why the cheapest line item in the budget (training) protects the biggest one (the business itself).