MinterEllison's Perspectives on Cyber Risk 2026: The AI Edition highlights this changing landscape. Its research found that 64% of respondents had experienced a direct cyber incident in the previous 12 months, while 57% had experienced an incident through a supplier or vendor. At the same time, 98% had adopted AI within the previous 24 months, bringing new opportunities alongside new sources of cyber risk.
For security leaders, this raises a more important question than simply how much recovery will cost:
What is the total business impact when a cyber incident occurs?
AI has not created cyber risk, but it is changing its economics.
Threat actors can use AI to accelerate reconnaissance, develop more convincing social engineering campaigns and automate activities that previously required significant time and expertise. MinterEllison identifies AI-enabled threats as the second-leading cyber concern among respondents, behind ransomware, reflecting the growing recognition that AI could fundamentally change the threat landscape.
For defenders, greater speed creates greater pressure.
The Australian Signals Directorate's 2024–25 Annual Cyber Threat Report recorded more than 84,700 reports of cybercrime, while the average self-reported cost of cybercrime for Australian businesses increased to A$80,850, up 50% from the previous year. For large businesses, the average reported cost reached A$202,700, a 219% increase year-on-year.
These figures do not represent the cost of every cyber breach, but they demonstrate how quickly the financial impact of cybercrime can change.
And the costs can begin accumulating long before an organisation reaches the recovery stage.
When systems go offline, organisations can lose revenue, delay transactions, disrupt operations and redirect employees towards incident management. Customers may be unable to access services, while suppliers and other partners can experience knock-on effects.
The latest ASD report reinforces the importance of preparing for this disruption, urging Australian businesses to strengthen business continuity planning alongside measures such as logging, legacy technology replacement and third-party risk management.
For security leaders, this changes the question from “What will recovery cost?” to “How much will disruption cost us?”
That distinction matters. An organisation may eventually restore every affected system, but every hour spent operating at reduced capacity can add another layer to the financial impact of the incident.
And in an environment where AI is enabling faster and more scalable attacks, the ability to contain an incident quickly could become just as important to the bottom line as the ability to recover from one.
The source of a breach can also determine how far its consequences spread.
MinterEllison found that 57% of respondents had experienced a cyber incident through a supplier or vendor.
This highlights a growing challenge for CISOs: an organisation's cyber exposure increasingly extends beyond the systems it directly controls.
Cloud providers, managed service providers, technology vendors and other partners can all form part of the operational ecosystem. A vulnerability or compromise within one of those relationships can create consequences for multiple organisations at once.
AI adds another layer to this challenge.
As organisations increasingly embed AI into software and business processes, they may also inherit risks associated with the models, platforms and data environments supporting those services. Understanding where AI is being used across the supply chain, what information is being processed and what happens if a critical provider becomes unavailable will become increasingly important.
The Australian Signals Directorate has also identified third-party risk management as one of four priority areas for Australian organisations, alongside best-practice logging, replacing legacy technology and preparing for post-quantum cryptography.
Then there are the costs that are harder to quantify.
A significant cyber incident can trigger regulatory scrutiny, legal proceedings, customer notifications and additional compliance requirements. Australia's privacy environment has also become more consequential for organisations handling personal information, with the maximum penalty for serious or repeated privacy breaches significantly increased under recent reforms.
But financial penalties are only part of the equation.
A breach can also affect how customers, employees, investors and business partners perceive an organisation's ability to protect information and maintain reliable services.
That loss of confidence can take considerably longer to recover from than the systems affected by the original incident.
In this sense, recovery is not the same as resolution.
Getting systems operational again may mark the end of the technical incident, but the business consequences can continue for months or even years.
This makes organisational preparedness one of the most important factors in determining the eventual cost of a breach.
MinterEllison's research points to a growing need for organisations to test whether their incident response plans reflect the threats they are actually likely to face, rather than simply maintaining a plan for compliance purposes.
An organisation may have a documented response plan, but how quickly can it make decisions when systems are unavailable?
Who has authority to shut down affected operations?
How quickly can legal, security, communications and executive teams coordinate?
Which suppliers need to be contacted?
How will customers be informed?
And what happens when the incident involves an AI system or a third-party provider that the organisation does not fully control?
These questions can have a direct bearing on the financial impact of an incident.
A faster, more coordinated response can limit operational disruption, contain the spread of an attack and reduce the time needed to restore services.
Preparedness therefore becomes more than a cybersecurity capability.
It becomes a financial risk management strategy.
As cyber incidents become more frequent and AI continues to reshape the threat landscape, organisations may need to rethink how they quantify cyber risk.
The question is no longer simply:
How much will it cost to recover?
It is:
The organisations best positioned to manage cyber risk will not necessarily be those that can guarantee they will never experience a breach.
They will be those that understand what a breach could cost before one happens, identify where that cost could escalate, and build the resilience needed to contain it.
Because recovery is only the point at which the technical work begins.
The true cost of a cyber breach is measured in everything the organisation stands to lose while getting back to business.
Join us at CISO Critical Infrastructure Melbourne 2027 to learn more about the latest challenges and developments for infosec executives in the country. Reach out to Kashmira George to learn more.