A decade of Perspectives on Cyber Risk

6 minute read  11.06.2025 Paul Kallenbach, Shannon Sedgwick

Our Perspectives on Cyber Risk 2025 report explores changes in privacy, data protection and cyber security laws over the last 10 years.

Between February and March 2025, we conducted our 10th annual Perspectives on Cyber Risk survey. More than 150 participants — including Australian business leaders, senior executives, directors, legal counsel, and risk professionals — shared their views on the evolving threat landscape. Drawing on a decade of survey data, this year’s report tracks how organisational perspectives have shifted alongside changes in cyber threats, defences, and regulatory expectations.

Over the past ten years, one constant has emerged:

awareness of cyber risk is rising, but readiness continues to lag behind.

Organisations are increasingly aware of the strategic importance of cybersecurity, yet persistent capability gaps remain — particularly in data governance, incident response, and Board-level oversight.

Icon block

76% of organisations now rank cyber risk among their top five priorities — up from 56% just two years ago.

Icon block

Only 36% of respondents are very confident their organisation knows what data it holds, where it is stored, or how it is secured.

Icon block

52% report low or partial confidence in meeting post-breach regulatory obligations.

Icon block

While 91% of organisations have a cybersecurity incident response plan, only 70% test or rehearse it at least annually.

These results highlight a critical need for uplift in governance, strategy, and accountability. Without stronger capability at Board and executive levels, organisations risk overestimating their resilience, underinvesting in uplift, and misjudging their regulatory exposure.

Reflecting on past lessons and considering future threats and opportunities, one thing is clear: cybersecurity is more than just a defensive imperative. It is a shared, strategic responsibility that must be embedded across governance, risk, technology and culture – and is critical to the resilience and success of every organisation in today’s digital age.” 
Shannon Sedgwick, Partner, Technology & Consulting

Download Perspectives on Cyber Risk 2025

Evolution of AI and cyber risks

Organisations are becoming increasingly ready to adopt AI — and rapidly so. In our 2025 survey, 70% of respondents said they are at least somewhat confident in their organisation’s preparedness to adopt Generative AI (GenAI) platforms. This marks a significant shift from 2018, when fewer than 15% reported any active use of AI solutions.

However, alongside this growing confidence is a sharp awareness of risk. 84% of respondents cite privacy risks, particularly data compromise, as their top concern when it comes to AI adoption.

As GenAI moves from experimentation to enterprise integration, the security, privacy, and governance implications are becoming increasingly complex — and increasingly urgent.

“Organisations must continuously evolve and adapt their security strategy to an increasingly complex environment – especially in the face of AI and its benefits and risks.

This means continuously investing in the fundamentals: timely patching, comprehensive asset and data visibility, rehearsed incident response, supply chain assurance, robust access controls, user awareness training, and reliable backup procedures.

Cyber considerations must be embedded into strategic planning and boardroom dialogue, not just compliance checklists.”

Paul Kallenbach, Partner, Technology, Digital & Data

To mark the release of the 10th Anniversary Edition of the Cyber Risk Report, we sat down for a ‘fireside’ chat with Carly Kind, Privacy Commissioner, Office of the Australian Information Commissioner, and Paul Kallenbach, MinterEllison’s National Legal Cyber Leader, to discuss the rapidly evolving cyber risk and regulatory environment.

Watch on demand - Launch of the Perspectives on Cyber Risk Report 2025

AVAILABLE NOW

60 Minutes Recorded June 11, 2025

Download Perspectives on Cyber Risk 2025

Contact

Tags

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJuYW1laWQiOiI1Y2EyMmJiOS0xYzhkLTRlYmItYWIwNy00NzQ2MjkyOWE3NmMiLCJyb2xlIjoiQXBpVXNlciIsIm5iZiI6MTc0OTgwNTE4NCwiZXhwIjoxNzQ5ODA2Mzg0LCJpYXQiOjE3NDk4MDUxODQsImlzcyI6Imh0dHBzOi8vd3d3Lm1pbnRlcmVsbGlzb24uY29tL2FydGljbGVzL2EtZGVjYWRlLW9mLXBlcnNwZWN0aXZlcy1vbi1jeWJlci1yaXNrIiwiYXVkIjoiaHR0cHM6Ly93d3cubWludGVyZWxsaXNvbi5jb20vYXJ0aWNsZXMvYS1kZWNhZGUtb2YtcGVyc3BlY3RpdmVzLW9uLWN5YmVyLXJpc2sifQ.aCNFAj3ZCQJ2_z7GN9hl-NoyoGRN8NTMwcloREKwJYY
https://www.minterellison.com/articles/a-decade-of-perspectives-on-cyber-risk