Cyber Security for Australian Midsize Businesses

The Australian Threat Landscape in 2026
For an Australian midsize business, cyber security has moved from an IT line item to a board-level operational risk. Customer contracts, insurer questionnaires, government tender prequalification, and APRA-regulated supply chains all require evidence of specific controls. The question is no longer "should we invest" but "which framework, to what depth, on what timeline, and how do we prove it".
The Australian Signals Directorate's Annual Cyber Threat Report 2024-25 records a cyber incident reported to ASD on average every six minutes, with self-reported losses averaging around $49,600 for small business, $62,800 for medium business, and $63,600 for large business. The OAIC received 1,113 Notifiable Data Breaches notifications in 2024, the highest since the scheme commenced in 2018. The leading cause was malicious or criminal attack, with health, finance, and Australian government the top reporting sectors.
This article is written for executives and IT leaders at Australian organisations of roughly 50 to 500 employees and $10m to $500m revenue. The frameworks below are the ones that show up on procurement questionnaires and insurance applications.
What this guide covers
- The frameworks that matter in Australia: Essential Eight, ISO 27001, NIST CSF, APRA CPS 234 and CPS 230, SOCI Act
- 2024-25 regulatory changes: Privacy Act reforms, Cyber Security Act 2024 ransomware reporting
- Notifiable Data Breaches: when it applies, how to respond, what to notify
- A 12-week realistic path to Essential Eight Maturity Level 1
- Governance, third-party risk, and cyber insurance considerations
Why Frameworks Matter More Than Tools
A common failure pattern in midsize organisations is buying tools without a framework. Endpoint detection, email security, identity governance, backup, and SIEM are all valuable, but on their own they do not answer the question a customer, auditor, or insurer is actually asking: "what is your security baseline, who owns it, and how do you evidence it".
A framework gives you four things: a defined scope, a measurable maturity bar, a control list to allocate to owners, and an audit trail you can produce on demand. For Australian midsize organisations, four frameworks recur:
Frameworks Australian Midsize Businesses Encounter
| Metric | Framework | When It Applies |
|---|---|---|
| ASD Essential Eight | Australian baseline, ASD-published | Default starting point for any AU organisation; required for many federal contracts |
| ISO/IEC 27001:2022 | International ISMS standard | Often required in B2B procurement, global customers, or large enterprise supply chains |
| NIST CSF 2.0 | US-origin risk framework | Common in US-headquartered customers; complements Essential Eight |
| APRA CPS 234 + CPS 230 | APRA-regulated entities and their material service providers | Mandatory if you are an APRA entity; flow-down obligations if you serve banks, insurers, or super funds |
| SOCI Act (2018, as amended) | Critical infrastructure sectors | Mandatory if you operate assets in one of the 11 declared critical sectors |
The framework you adopt is rarely a free choice. It is driven by who you sell to, who regulates you, and what your insurer requires.
The Essential Eight: The Australian Default
The ASD Essential Eight (published at cyber.gov.au) is the Australian baseline. It is eight prioritised mitigation strategies, evaluated against four maturity levels (Level 0 through Level 3). For Commonwealth non-corporate entities the target is Maturity Level 2 under the Protective Security Policy Framework. For a midsize business in the private sector, Maturity Level 1 is the practical entry point, with Level 2 a defensible goal within 18 to 24 months if you sell into government or APRA-adjacent supply chains.
The eight strategies, grouped by objective:
- Prevent malware delivery and execution: application control, patch applications, configure Microsoft Office macro settings, user application hardening
- Limit the extent of incidents: restrict administrative privileges, patch operating systems, multi-factor authentication
- Recover data and system availability: regular backups
Maturity Levels in Plain English
ASD describes the maturity levels in terms of the threat actor sophistication each level is designed to mitigate against. Translated for a board audience:
Essential Eight Maturity Levels 1, 2, and 3
| Metric | Maturity Level | What Changes at This Level | Improvement |
|---|---|---|---|
| Level 1 | Opportunistic adversary using widely-available tradecraft | Internet-facing patches within 2 weeks (48 hours if exploited in the wild), MFA on internet-facing services, daily backups, macros blocked from the internet, basic admin separation | |
| Level 2 | Adversary investing more time and capability in a specific target | Phishing-resistant MFA, centralised event logging, admin tasks from privileged access workstations, application control on workstations and servers, immutable backups, OS patches within 2 weeks (48 hours critical) | |
| Level 3 | Adaptive adversary willing to invest substantial effort and resources | Continuous validation of controls, advanced credential hardening, integrity-verified backups tested at scale, application control across user profiles and servers, executable signature validation, full audit logging with retention | Designed for high-value targets and critical infrastructure operators |
For most Australian midsize businesses, Maturity Level 1 across all eight strategies is a more credible starting position than Level 2 on three and Level 0 on the other five. Even or no maturity at all is the correct measure for procurement questionnaires.
Full Maturity Level 1 specifications are published in the ASD Essential Eight Maturity Model. The honest reality is that even Level 1 across all eight strategies requires deliberate programme work, typically 8 to 16 weeks of focused effort for a 100-person organisation with a competent internal IT function or external partner.
When You Need More Than Essential Eight
Essential Eight is a baseline, not a ceiling. Several scenarios push midsize organisations into adjacent or additional frameworks:
Which Framework Should We Adopt?
ISO/IEC 27001:2022 and NIST CSF 2.0
ISO 27001 is a management system standard rather than a control list. It requires a defined scope, risk assessment, controls selected from Annex A (93 controls in the 2022 revision), and demonstrated continual improvement. First certification typically takes 9 to 18 months for a midsize business. It is the most-requested credential in enterprise B2B procurement.
NIST CSF 2.0, released in 2024, organises cybersecurity around six functions: Govern, Identify, Protect, Detect, Respond, Recover. It is risk-based and outcome-focused. Many Australian organisations use NIST CSF as the overarching narrative for board reporting and map Essential Eight controls into it.
APRA CPS 234 and CPS 230
APRA CPS 234 (Information Security) applies to APRA-regulated entities (banks, insurers, super funds) and extends to information assets managed by related parties or third parties. If your midsize business processes data for an APRA-regulated entity, CPS 234 flows down through your contract. Obligations include defined roles, control commensurate with criticality, notification to APRA within 72 hours of a material incident, and annual control testing.
CPS 230 (Operational Risk Management) took effect on 1 July 2025. It tightens third-party risk management, requiring service provider registers, business continuity testing with critical providers, and APRA notification of material service provider arrangements. Midsize firms in the APRA supply chain should expect more rigorous due diligence and contractual operational resilience obligations.
SOCI Act and Critical Infrastructure
The Security of Critical Infrastructure Act 2018, as amended, applies to assets in 11 declared critical sectors: communications; financial services and markets; data storage or processing; defence industry; higher education and research; energy; food and grocery; health care and medical; space technology; transport; and water and sewerage.
Responsible entities must register critical assets, maintain a Critical Infrastructure Risk Management Program (CIRMP), and report incidents to ASD within 12 hours (significant) or 72 hours (relevant). If your business operates a data centre, a managed services platform processing business-critical data for others, or assets in any declared sector, seek legal advice on whether you are a responsible entity.
IRAP and the ISM
The Information Security Manual (ISM) is ASD's detailed control catalogue. To sell PROTECTED-level services to the Commonwealth, you need an Information Security Registered Assessors Program (IRAP) assessment against the ISM. This is a significant uplift from Essential Eight and is typically pursued only by organisations with a clear government revenue strategy.
The 2024-25 Regulatory Changes That Actually Matter
Three pieces of legislation have changed the obligation landscape for midsize businesses in the last 18 months.
Privacy Act Reforms
The Privacy and Other Legislation Amendment Act 2024 received assent in December 2024. The most significant changes for midsize businesses are a new statutory tort for serious invasions of privacy (a private right of action where the invasion is intentional or reckless), tiered civil penalties sitting beneath the existing maximum (greater of $50 million, three times benefit obtained, or 30% adjusted turnover), expanded OAIC enforcement powers including infringement notices, new transparency obligations for automated decision-making that affects individuals (staged commencement), and a developing Children's Online Privacy Code. Midsize businesses above $3m turnover have always been APP entities and should treat the reforms as raising the cost of a privacy failure substantially.
Notifiable Data Breaches Scheme
The Notifiable Data Breaches scheme (Part IIIC of the Privacy Act) requires APP entities to notify the OAIC and affected individuals as soon as practicable after becoming aware of an eligible data breach. An eligible breach has three elements: unauthorised access, disclosure, or loss of personal information; likely to result in serious harm; and remedial action has not prevented that risk. A suspected eligible breach triggers a 30-day assessment obligation; if confirmed, notification follows as soon as practicable.
Eligible Data Breach Incident Response Flow
Cyber Security Act 2024 Ransomware Reporting
The Cyber Security Act 2024 commenced in stages from late 2024. The provision most relevant to midsize businesses is mandatory ransomware payment reporting.
If your business has an annual turnover above $3 million and you (or someone on your behalf) make a payment, or provide a benefit, to a cyber extortion actor in response to a cyber security incident, you must report the payment to the Department of Home Affairs within 72 hours. Failure to report is a civil penalty offence.
The Act also establishes the National Cyber Security Coordinator role, creates a Cyber Incident Review Board, and introduces a "limited use" obligation on government to limit how voluntarily-shared incident information can be used against the disclosing entity. Practically, the law means every midsize business needs a documented decision process for whether to pay a ransom, who has authority, and how reporting will be lodged in time.
Practical Implementation: Who Owns This?
Frameworks fail when ownership is ambiguous. A defensible midsize operating model assigns the board responsibility for risk appetite and quarterly oversight, the CEO accountability for cyber resilience and material incident steering, the CIO or fractional CISO ownership of the control environment and maturity roadmap, and a designated Privacy Officer (typically Legal or COO) ownership of Privacy Act compliance and NDB notifications. External assurance partners provide independent annual assessment, penetration testing, and IRAP or ISO audit support.
Midsize businesses rarely justify a full-time CISO. A fractional CISO or a security partner with a defined deliverables list typically delivers better outcomes for the budget than a single internal hire trying to cover strategy, operations, and incident response.
A Realistic 12-Week Path to Essential Eight Maturity Level 1
A defensible Maturity Level 1 across all eight strategies for a 100-person organisation, on a typical Microsoft 365 stack, is achievable in roughly 12 weeks with focused effort. The sequence below front-loads the controls that materially reduce risk fastest.
12-Week Essential Eight Maturity Level 1 Roadmap
The honest caveat: this schedule assumes a single-site organisation on cloud-first infrastructure with no legacy on-premise dependencies. Add 4 to 8 weeks if you have an on-premise Active Directory legacy, a major ERP, or operational technology in scope.
Budget Reality for a Midsize Business
Vendor pricing varies more than is useful to quote, but for a 100-user midsize organisation in 2026, baseline annual operating ranges run roughly: identity and MFA from included in M365 to $20,000; endpoint protection and EDR $15,000 to $40,000; email security $8,000 to $25,000; patch and configuration management $10,000 to $30,000; backup and recovery $15,000 to $50,000; security awareness $5,000 to $15,000; SIEM or managed detection and response $30,000 to $120,000; external assessment and penetration testing $25,000 to $80,000; cyber insurance $10,000 to $60,000.
These are baseline operating costs. First-year implementation typically adds 30% to 60% on top, largely in professional services and internal time. Sectoral requirements (CPS 234, SOCI, IRAP) materially increase the upper bound.
Cost of Prevention vs. Cost of an Incident
The argument for the programme is not the loss-event arithmetic alone. It is the compounding cost of failed insurance applications, lost customer contracts because you cannot answer a security questionnaire, and the operational distraction of unstructured incident response.
Where AI Changes the Picture
Offensive AI is now industrialised. Generative AI has materially reduced the cost and skill required to produce convincing phishing, business email compromise lures, deepfake voice for executive impersonation, and tailored social engineering. ASD continues to flag BEC as one of the highest-loss attack types. The defensive implications: phishing-resistant MFA (FIDO2 or passkeys, not SMS), out-of-band verification protocols for financial instructions, and executive deepfake drills.
Defensive AI is becoming standard. EDR, email security, and SIEM products now integrate AI for anomaly detection, alert triage, and incident summarisation. The gain is tier-1 SOC analyst productivity and faster mean time to detect. The risk is over-reliance on opaque vendor models without governance: who validates the model, what data is sent to which jurisdiction, and what happens when the model misclassifies?
The DISR Voluntary AI Safety Standard provides a governance scaffold for any AI use in your environment, including AI-powered security tools. See our AI Agent Governance guide for a more detailed treatment.
Governance and Reporting: What the Board Should See
A defensible quarterly board cyber report covers seven areas: threat landscape and regulatory change, current Essential Eight maturity by strategy with target trajectory, the top five cyber risks against appetite with named owners, material incidents (including any ransomware payment decisions and NDB assessments), third-party risk status across critical service providers, the cyber insurance position with coverage and exclusions, and year-to-date programme delivery against the annual cyber roadmap. The OAIC's annual NDB reports are a useful external benchmark for context.
Third-Party Risk Management
If you serve APRA-regulated customers, CPS 230 effectively raises the bar on every material service provider in your tech stack. Even outside APRA, treat critical providers (cloud, MSP, payroll, finance) as if CPS 230 applied: register them, classify them by criticality, run annual due diligence, get evidence of their controls (ISO 27001, SOC 2 Type II, IRAP letter where relevant), and include incident notification and audit rights in contracts.
For more on data residency obligations, see our Data Sovereignty Australia guide and our comparison of Privacy Act and GDPR.
Cyber Insurance
Cyber insurance is harder and more expensive than three years ago. Insurers now typically require MFA on all external and privileged access, EDR, tested backups with offline or immutable copies, security awareness training, and a documented incident response plan; many ask for Essential Eight self-assessment results. Treat the application as a free external audit: the gaps insurers flag are the gaps a procurement team will flag six months later.
Where to Start This Quarter
For a midsize business CEO or CIO reading this and wondering where to begin:
- This week: run an Essential Eight self-assessment against Maturity Level 1. Use the ASD self-assessment guide. Estimate the gap in two pages, not twenty.
- This month: nominate the accountable executive. Approve a 12 to 16-week uplift programme to Maturity Level 1. Confirm whether you sit inside any regulated regime (APRA, SOCI, government supplier) that demands more.
- This quarter: deliver the uplift. Run a tabletop incident response exercise that includes a ransomware payment decision and an NDB notification scenario. Refresh your cyber insurance application using the evidence pack from the uplift.
- This year: decide whether ISO 27001, NIST CSF, or IRAP are commercially worth pursuing. Document third-party risk management. Build the board reporting cadence.
The Australian organisations that handle cyber best are not the ones with the largest tooling spend. They are the ones with a named accountable executive, a maturity bar they can articulate, an audit trail they can produce on demand, and a rehearsed response plan.
For practical execution help, our Managed AI Services practice supports midsize Australian businesses on the operational side of security uplift, and our AI Strategy work covers the governance scaffolding for AI tools that touch sensitive data. For a fast view of your public-facing exposure, the Solve8 Security Scanner provides a free starting point on website-level controls.
Related Reading
- AI Security Checklist: 50 Essential Points for Australian Businesses - Detailed control list for organisations deploying AI alongside their security programme
- Financial Services AI Compliance: APRA and ASIC Requirements - Deep dive on CPS 234, CPS 230, and ASIC expectations for AFSL holders
- Privacy Act vs GDPR for Australian Business - Where Australian privacy law converges with and diverges from GDPR, including the 2024-25 reforms
- AI Government Contracts and Compliance Requirements - Sourcing into Commonwealth and state government, IRAP, and assurance expectations
- AI Agent Governance, Data Access, Privacy and Human Override - Governance scaffolding for AI tools that touch regulated data
Sources:
Australian Signals Directorate, Annual Cyber Threat Report 2024-25; ASD, Essential Eight Maturity Model; ASD, Information Security Manual; OAIC, Notifiable Data Breaches Reports; OAIC, guidance on the Privacy and Other Legislation Amendment Act 2024; APRA, Prudential Standard CPS 234 and CPS 230 Operational Risk Management; Department of Home Affairs, Cyber Security Legislative Package 2024 and Security of Critical Infrastructure Act 2018; NIST, Cybersecurity Framework 2.0; Department of Industry, Science and Resources, Voluntary AI Safety Standard.