Metbridge METBRIDGE CYBER

CYBER NEWS & INSIGHTS

Developments shaping cyber risk in Australia.

Selected threat, regulatory and technology updates for business leaders and security professionals, with practical context from Metbridge Cyber.

Last reviewed 4 September 2026

LATEST SELECTED UPDATES

What security leaders should know.

Our summaries highlight why each development matters. Follow the source link for the complete announcement and guidance.

AUSTRALIAN DATA BREACH PICTURE

Notifications reached a record high in 2025.

The latest full-year OAIC figures show both the scale of reported breaches and the continuing role of malicious activity.

YEAR-ON-YEAR Notifiable data breaches

+8% from 2024

PRIMARY CAUSE Malicious or criminal activity
MOST-AFFECTED SECTORS Notifications by reporting sector

Source: Office of the Australian Information Commissioner, published 6 July 2026. View source data

24 July 2026 Artificial intelligence

AUSTRALIAN SIGNALS DIRECTORATE

Careful adoption of agentic AI in cyber defence

ASD highlights both the defensive opportunities and the emerging risks of autonomous AI systems, recommending constrained permissions, human oversight, monitoring and progressive deployment.

Why it matters: AI governance must cover what agents can access, decide and change—not only the models they use.

Read the ASD guidance
16 July 2026 Data breach

OAIC

Privacy Commissioner reports on the Qantas data incident

The OAIC concluded its preliminary inquiries into the 2025 breach involving an overseas third-party contact centre and published its findings to explain the regulator's response.

Why it matters: Third-party assurance, workforce controls and rehearsed incident response remain central to protecting customer information.

Read the OAIC report summary
6 July 2026 Privacy

OAIC

Australian data breach notifications reach an all-time high

The OAIC received 1,205 notifications during 2025—an eight per cent increase on 2024—with malicious or criminal activity responsible for most reported breaches.

Why it matters: Organisations need clear breach assessment, escalation and notification procedures before an incident puts teams under pressure.

Read the OAIC statistics
15 June 2026 Security frameworks

AUSTRALIAN SIGNALS DIRECTORATE

ASD outlines the evolution of the Essential Eight

ASD consulted industry and government on an expanded Essentials series intended to provide prioritised, threat-informed mitigations across contemporary technology environments.

Why it matters: Organisations should keep maturity plans flexible as national guidance evolves beyond traditional enterprise IT environments.

Read the ASD announcement
8 May 2026 Education sector

OAIC

Regulators respond to the Instructure Canvas cyber incident

The OAIC acknowledged a global incident affecting the Canvas learning platform and Australian education providers, while the National Office of Cyber Security coordinated the response.

Why it matters: Cloud concentration and supplier incidents can create broad operational and privacy consequences across an entire sector.

Read the OAIC statement

EDITORIAL NOTE

Selected for practical relevance.

Metbridge Cyber curates public information from authoritative sources. Summaries are general information, not security or legal advice, and may not reflect later source updates.

Explore trusted resources →

What do these developments mean for your organisation?

Metbridge Cyber can help translate emerging threats and regulatory expectations into practical priorities.

Talk to Metbridge Cyber