Why do we need another cyber article? Because breaches in Australia average one every six minutes and my virtual audit file keeps getting thicker. While everyone talks about breaches, as an auditor I would like to talk to you about what happens after the breach and why no company should treat security as “just an IT thing” anymore.
Some statistics:
- Total number of cybercrime reports for 2023/2024 financial year: 87,400 (and these are just those who admitted).
- Calls to Cybersecurity hotline: 36,700 – 4 every hour on a 24/7 basis
- Ransomware: featured in 11% of incidents reported by Australian Signals Directorate (ASD), while January 2025 saw 16 attacks
(i.e., it is not something exotic anymore – it’s daily bread and butter of digital underworld masterminds)
What auditors see post-breach:
Financial knock-ons: revised risk premiums by insurers and material provisions for litigations and customer remediation. Medibank, for example, have already spent $86.2M in relation to their October 2022 breach, when thousands of personal customer data was stolen and published on the dark web. Directly associated expenditure is expected to continue well into 2025. Australian Prudential Regulation Authority (APRA) requested additional equity requirement of $250M. On top of this, Medibank faces a civil suit action, consumer class action AND shareholder class action.
Red flags for Going concern: ransomware downtime can wipe out quarterly EBIT. Latitude lost $76M in “pre-tax costs” during the 6 weeks it was paralysed when they refused to pay the cyber attackers in March 2023.
Related disclosures and impairments:
- Woolworths Group (MyDeal): flags $45M non‑cash impairment plus $90–100M cash closure costs to shutter the MyDeal marketplace after the 2022 breach
- Singtel/Optus: Singtel’s FY 2024 Annual Report revealed a S$2 billion non‑cash goodwill impairment tied largely to the 2022 Optus data breach and network assets
- IPH Limited: FY 2023 results detailed a $4.4M March revenue shortfall and $2.8 million remediation spend directly attributed to its March 2023 cyber incident
Control deficiencies: your auditors will start raising significant findings about access logging, passwords, privilege sprawl, data confidentiality of your employees, vendors and customers. The Australian cases I was mentioning before illustrate this point:
-
Optus’ internal review uncovered unauthenticated API points and missing firewall logs after its 2022 breach;
-
Latitude Financial’s investigation showed attackers leveraged stolen vendor credentials to establish remote access, resulting in the March 2023 compromise; and
-
In case of Medibank, it was as simple as hackers getting the username and a password that belonged to an outside IT contractor.
Spotlight on Directors – Consequences are no longer hypothetical:
ASIC’s Key Issues Outlook 2025 places cyber governance squarely on directors’ duty‑of‑care radar. The regulator has flagged ongoing investigations and personal liability where boards ignore credible risk signals and recent media releases demonstrate that:
-
In case of FIIG Securities (March 2025) ASIC found 4 years of weak firewalls and no staff training, which lead to 385GB of sensitive client data stolen. ASIC is seeking civil penalties with the case hearing listed for 2 February 2026.
-
It is alleged that Directors of Fortnum Private Wealth (July 2025) breached its obligations when they failed to implement adequate policies and procedures. As a result: ASIC has commenced court action against the company demanding penalties.
Raise your hand if you use Copilot
Until Microsoft patched Copilot in June 2025, a booby‑trapped email could quietly order Copilot to ship whatever you were working on—draft contracts, payroll spreadsheets, even board papers—to a thief’s server. No clicks, no pop‑ups, no antivirus alert.
Note to self: Treat AI helpers like privileged users – patch the moment Microsoft tells you, turn Copilot off on sensitive mailboxes, and keep an eye on outbound traffic logs.
Conclusion
Cyber talk is everywhere, and the advantage belongs to those who listen and prepare.
From an auditor’s seat: breaches translate into journal entries, adverse findings, and sleepless nights for directors. For a complementary global lens, read InCorp Global’s When Cyber Risk Hits Home (Jul 2025)—then compare where your controls stack up.
We're here to help
Get in touch for more insights or direct support - we are here to help. You can also find news, webinars and resources online, and contact us on (02) 8999 1199 for all your tax, accounting and advisory needs.