Now in its fourth year, the HSF Kramer Cyber Risk Survey draws on the views of general counsel and senior legal counsel across Australia's leading organisations to examine how legal leaders perceive, prepare for and respond to cyber risk.

The defining story of 2026 is AI.  97% of respondents are aware of how AI is changing the threat landscape, yet only 20% report a detailed understanding of those risks.

Third-party risk remains the leading concern, with 62% experiencing a supply chain cyber incident in the past 12 months.

A reactive approach to governance persists, with 59% believing it would take a cyber incident to drive meaningful focus on data risk management.

Despite material improvements in board cyber maturity, significant gaps remain between awareness and readiness across data governance, people risk and incident preparedness.

Drawing on deep expertise across cyber incident response, regulatory compliance and data governance, this report offers a clear view of where Australian organisations stand today and what it will take to become genuinely cyber resilient.

The Report covers:

  • AI and the evolving threat landscape
  • People risk and the human element
  • Third-party and supply chain exposure
  • Board governance and cyber maturity
  • Data management practices
  • The regulatory environment
  • The outlook for cyber resilience

The cyber challenge is no longer awareness. It is ensuring organisations have the governance, controls and response capabilities needed to keep pace with a rapidly evolving threat environment."

Cameron Whittfield
Partner, Cyber, Data and Emerging Technologies

Survey at a glance

It is the convergence of AI with established threat categories that is reshaping how organisations must think about and resource their cyber risk programs.”

Magdalena Blanch-de Wilt
Executive Counsel

Six key themes

AI as the key cyber risk

the emergence of AI-driven threat vectors and the challenge of AI risk in existing cyber frameworks

 

The human element as a persistent vulnerability

People-related risk ranks as top-three concern, yet remains absent from top investment priorities, revealing a disconnect between risk recognition and directed action

 

Third-party risk entrenched at the top

Persistent supply chain exposure, with ‘fourth-party’ risk visibility emerging as the dominant pain point

 

Board maturity improving, but gaps remain

Increasing confidence in Board cyber maturity, yet simulation participation and ransom preparedness still fall short

 

Data risk management

While most respondent organisations have taken steps to review data management practices in the past 12 months, 59% of respondents believe it would take a cyber incident to meaningfully drive greater focus on data risk management

 

Legal teams as essential crisis responders

Deepening integration of legal functions into incident response, simulations and cyber incident response frameworks

 

Global expertise

See how our global Cyber team can help you

Cyber risk advisory

Key contacts

Stay in the know

Receive timely insights and briefings from HSF Kramer, tailored to keep you informed and ahead

Subscribe now
Australia Brisbane Sydney Perth Melbourne Technology, media and entertainment, and telecommunications Data protection and privacy Corporate governance Corporate Cyber risk advisory Financial services Mining Pharmaceuticals and healthcare Technology Manufacturing and industrials Government and public sector Energy Real estate Infrastructure Consumer Cyber Security Feature Cameron Whittfield Magdalena Blanch-de Wilt