The average self-reported cost of cybercrime for an Australian small business was $56,571 per report in 2024-25 — up 14% on the year before. Across all business sizes the average climbed to $80,850, a 50% jump in twelve months (ASD's Annual Cyber Threat Report 2024-25). For a team of five to fifty people, one bad cybercrime report now costs more than a full year of most IT budgets.
TL;DR
- Australian businesses averaged $80,850 per cybercrime report in 2024-25, up 50% year on year.
- Small business: $56,571 per report, up 14%. Medium: $97,166. Large: $202,691.
- ASD received 84,700 cybercrime reports in 2024-25 — one every 6 minutes.
- Email compromise drives 34% of all business reports: 19% with no financial loss, 15% fraud with loss.
- Every top-reported crime type starts with a human action that training addresses.
What does cybercrime cost an Australian small business in 2026?
The benchmark small businesses should size against is $56,571 per report — the average self-reported loss when an Australian small business lodges a cybercrime report with ReportCyber. The trend is the uncomfortable part: small business losses have risen from $45,965 in 2022-23 to $49,615 in 2023-24 to $56,571 in 2024-25, roughly 23% over two years, while the all-business average jumped 50% in a single year.
The three-year picture, straight from the ASD report:
| Business size | 2022-23 | 2023-24 | 2024-25 |
|---|---|---|---|
| Small business | $45,965 | $49,615 | $56,571 |
| Medium business | $97,203 | $62,870 | $97,166 |
| Large business | $71,598 | $63,202 | $202,691 |
Small business: $56,571 per report
Small business is the steady riser: three consecutive annual increases, each report now costing more than a full year of staff awareness training for a ten-person team. The risk is asymmetrical — a small business rarely has the cash buffer to absorb a $56,571 event, which is why prevention spending should be judged against that number, not against zero.
Medium business: $97,166 per report
Medium businesses jumped 55% in 2024-25 after falling the year before. More staff, more inboxes, more payment workflows — the same crimes, a larger blast radius.
Large business: $202,691 per report
Large business nearly tripled, up 219%. Fewer incidents, but far more severe ones. The lesson for smaller firms is that severity is rising everywhere in 2026, not only in the enterprise.
What small businesses actually report
ASD breaks the 2024-25 business cybercrime reports into three leading categories:
- Email compromise with no financial loss — 19%. Someone's mailbox or credentials were attacked; nothing was stolen yet.
- Business email compromise fraud with financial loss — 15%. A payment went out on the strength of a fake instruction.
- Identity fraud — 11%. Stolen personal details turned into accounts, loans or refunds.
Together the two email categories are 34% of all business reports — a third of Australia's reported business cybercrime starts in a mailbox. Phishing is the entry event for most of it, and phishing is the crime type staff training measurably changes; the phishing statistics for 2026 show what click and report rates look like across real programmes.
How to read these numbers honestly
Three limitations, stated plainly. The figures are self-reported — victims estimate their own losses. They are per report — an incident never reported never appears, so the true cost to Australian businesses is higher. And they are averages — a typical small business incident can be a few hundred dollars of lost time while the average is dragged up by multi-hundred-thousand-dollar payment fraud.
How to use the $56,571 benchmark
- Budget prevention against one bad day. Price your 2026 controls against a plausible $56,571 event, not against zero.
- Put money where the reports are. Email compromise dominates the list; mailbox-focused training and phishing simulations target 34% of the report mix directly.
- Collect evidence as you go. Completion logs and click-rate trends are what insurers and enterprise clients ask for after an incident — generate them now.
- Find your weakest controls first. A security gap assessment shows which of the Essential Eight-style controls need the budget before the next report.
A monthly phishing simulation plus short training modules costs a fraction of one average incident — the cheapest line in the 2026 risk budget.
FAQ
How much does cybercrime cost an Australian small business on average? $56,571 per report in 2024-25, up 14% from $49,615 in 2023-24, according to ASD's Annual Cyber Threat Report 2024-25.
What was the average cybercrime cost for all Australian businesses in 2024-25? $80,850 per report, a 50% increase on the previous year.
How many cybercrime reports did Australians lodge in 2024-25? 84,700 reports to ReportCyber — one every 6 minutes.
Are these figures the full cost of cybercrime in 2026? No. They are self-reported losses from reported incidents only; unreported incidents and unquantified costs sit outside them.
Which cybercrime type costs small business the most? Business email compromise fraud with financial loss — 15% of business reports and the category where a single event regularly reaches six figures.
Can training reduce this cost? Yes, indirectly. The top report types are email compromise and identity fraud — both begin with a clicked link or a shared credential, and both are the behaviours awareness training and phishing simulations target month after month.
One last thing
The number that matters most is not $56,571. It is 34% — the share of business cybercrime reports that start in a mailbox. Mailbox crime is the cheapest category of all to defend against with a trained team, which makes it the highest-leverage line in your 2026 budget.