Two credible reports landed within days of each other this year, and they told almost opposite stories. One showed that Australia recorded more notifiable data breaches than ever before under the NDB scheme. The other suggested breaches were declining among the organisations surveyed. The gap between them is worth understanding briefly, but the more useful part of this story is who tends to get left out of both reports altogether, and what that means for the businesses that make up most of the Australian economy.
Two reports, two different pictures
On 6 July 2026, the Office of the Australian Information Commissioner (OAIC) reported that it received 1,205 data breach notifications in the 2025 calendar year, an 8% increase on 2024 and the highest annual total since Australia’s Notifiable Data Breaches scheme began in 2018. Around the same time, the RSM Australia 2026 Cyber Security Report, a survey of business and IT leaders across 155 medium and large organisations, found the opposite trend. According to reporting on the survey’s findings, the proportion reporting a breach fell from 42% in 2024 to 21% in 2026, though RSM itself notes the two survey samples weren’t identical.
The short explanation is that these reports measure different things. The OAIC figure is a mandatory reporting count covering eligible data breaches notified under Australia’s NDB scheme The RSM figure is a small, voluntary survey with a changed sample between rounds. Neither is wrong, they simply aren’t answering quite the same question, which is worth knowing before either statistic gets repeated as settled fact. It’s also worth noting that both figures, however they’re interpreted, describe a population skewed toward larger, more visible organisations, which is where the more interesting part of this story actually begins.
The gap that matters more
There’s a more consequential gap hiding in both reports, and it’s about who’s actually represented in them. RSM’s survey covered medium and large organisations only. The OAIC’s notification count, while broader, tends to surface the incidents large enough or visible enough to trigger a mandatory report. “RSM’s survey covers medium-to-large organisations only. The OAIC dataset is broader, but it captures eligible data breaches reported by entities covered by the NDB scheme rather than every cyber incident affecting Australian businesses. This means many small-business incidents will not necessarily appear in these statistics.
That’s a genuinely important gap, because the separate data that does exist on smaller businesses tells a clear story. According to the Australian Signals Directorate’s Annual Cyber Threat Report for the 2024 to 2025 financial year, the average self-reported cost of cybercrime to small businesses rose 14% to $56,600, while the cost to medium-sized businesses rose 55% to $97,200. Smaller organisations aren’t sitting outside this problem. They’re carrying a rising cost that simply doesn’t make it into the headline national breach statistics as clearly as it should.
Why awareness matters most at this end of the market
Larger organisations tend to have dedicated security teams, formal budgets and the internal capacity to absorb the cost of a serious incident. Small and moderate-sized entities usually don’t have that cushion. A single serious incident can represent a genuinely significant portion of a smaller business’s annual revenue, not just an inconvenient line item, and recovering from one often draws on time and attention that a smaller leadership team can’t easily spare from everything else it’s already managing.
This is precisely why basic cyber security awareness carries disproportionate weight for smaller organisations. Attackers generally don’t need a sophisticated technique to succeed against a business with no formal training, no tested response plan and no clear picture of its own risk. Simple, consistent habits, recognising a phishing attempt, using multi-factor authentication, knowing who to call when something looks wrong, tend to close off a large share of the incidents that smaller businesses actually face.
It’s also worth being clear about what awareness actually means in practice, since the word can sound vague. It isn’t a single training session delivered once and forgotten. It’s a consistent rhythm of exposure, short and regular rather than long and occasional, reinforced by leadership treating it as genuinely important rather than a box to tick. Businesses that build this rhythm tend to see it show up in small, unglamorous ways: a staff member who pauses before clicking an unexpected link, someone who double-checks an unusual payment request by phone rather than replying to the email that asked for it. None of these moments make headlines, but collectively they prevent a large share of the incidents that do.
The encouraging part of this is that awareness doesn’t require a large budget to build. A small or moderate-sized business can meaningfully improve its position through consistent staff awareness training, a current cyber security risk assessment sized to its actual operations, and a simple incident response plan that’s been talked through at least once, rather than left untouched in a drawer. None of this requires the scale of a large enterprise security program. It requires consistent attention from leadership, informed by sound cyber governance principles, applied at a scale that actually fits the business.
Building a clearer picture, regardless of the headlines
Whichever national statistic gets more attention in a given month, the more useful question for a small or moderate-sized business is a simpler one: does leadership have a current, accurate picture of its own risk, built from its own evidence, rather than borrowed from someone else’s survey? A cyber security dashboard that leadership can actually read, without needing a technical translator, tends to answer that question more reliably than any industry report ever will.
That clarity matters more for smaller organisations, not less. They’re the ones least likely to be captured cleanly in national statistics, and the ones with the least room to absorb a costly surprise. But there’s an upside worth naming too: genuine awareness isn’t just protection, it’s a real point of difference. In a market where many smaller competitors are still treating cyber security as an afterthought, a business that can speak confidently and honestly about its own risk stands out for reasons that have nothing to do with luck.
That difference tends to show up in very practical ways. Clients running due diligence before signing a contract, insurers weighing up renewal terms, and larger partners reviewing their own supply chains are all, in effect, asking the same question: can this business be trusted with what we’re handing it? A business that has built genuine cyber security awareness into how it operates can answer that question with confidence, while competitors are still working out what to say. That’s not a defensive win. It’s a commercial one, and it’s available to any business willing to build the habit, regardless of size or budget.
Get started with 4walls
You don’t need the resources of a large enterprise to build a genuinely clear picture of your own risk. You need consistent attention and a starting point that’s actually sized to your business.
If you want a quick read on where things stand, our 3 minute cyber starting point check is a reasonable place to begin. For a more considered look, our Board cyber check in walks through the same questions raised here, in the context of your own organisation. Either way, the goal is confidence you can actually stand behind, at 4walls.au.