OAIC data breach trends: impact and outlook for the insurance market
15 September 2026
Australia’s data breach environment hit a milestone in 2025 - the Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications, the highest annual total since the Notifiable Data Breaches (NDB) scheme commenced in 2018 and an 8% increase over the 1,112 notifications logged in the year before. While we do not yet have the OAIC’s official statistics for this year, current data suggests numbers will continue to rise. Notably, the OAIC’s Australian Community Attitudes to Privacy Survey 2026 reveals that concern over data breaches has increased from 74% in 2023 to 82%. Latest OAIC NDB data reveals that major breaches and resulting consumer claims primarily stem from key institutional sectors, ranked in order below:
- The healthcare sector remains a primary target for data breaches, largely due to third-party tracking pixel errors and vulnerabilities in digital records.
- Finance and Insurance ranked next, driven primarily by phishing, social engineering, and fraudulent credential stuffing.
- Finally, government bodies, that are navigating the complex intersection of data breach vulnerabilities and public pressure regarding freedom of information.
What is more concerning is that data breaches in Australia now cost businesses an average of AUD $4.22 million each, a sharp 38% jump from 2019 levels. Per IBM’s 2026 Cost of a Data Breach Report, the average breach cost continues to increase given organisations are taking over 200 days to manage an incident which no doubt affects mitigation costs and highlighting the basis for why insurers are now deciding to impose a penalty on insureds with substandard response capability.
How is the insurance market responding: key takeaways
Overall, Australian insurers, underwriters, and brokers are moving from passive claims payers to active risk partners; they achieve this by demanding better security, detailed proposals, and continuous threat monitoring.
Underwriters
For underwriters, the most critical takeaway is clear: the factors that separate expensive data breaches from the manageable breaches map directly to the controls evaluated during the application process. Accordingly, underwriters are now mandating baseline cyber hygiene before quoting a policy. Required controls typically include multi-factor authentication, endpoint detection and response, regular data backups, and structured incident response plans.
Insurers
As a matter of prudence, rather than relying on traditional tick-box applications, insurers have started utilising third-party scanning and telemetry tools to directly verify an applicant's digital defences. Further, top insurer carriers now embed dark web monitoring and worldwide incident response into policy packages.
Brokers
As the primary point of contact for insureds, brokers play a critical role in placing and executing insurance policies. These days, cyber insurance applications have grown increasingly stringent, with major brokers reporting that questionnaires now span over 20 pages. These forms require highly granular control attestations. Because of this rigorous vetting process, brokers warn that misrepresentations on applications have become a leading cause of claim disputes.
Further, to address emerging threats, brokers are actively updating coverage designs. They are advising clients to secure contingent business interruption for third-party IT failures and are closely reviewing cybercrime and social engineering sub-limits.
Finally, with reports that just 10% of SMEs ($100M revenue) hold active cyber insurance, brokers are ramping up education on the true financial impact of ransomware and the strict mandatory reporting laws affecting SMEs.
