Australia’s 38% improvement in cyber recovery times has made us realize a harsh truth about corporate behavior. Companies won’t invest in cybersecurity until they’re legally forced to.
The shift comes in the wake of high-profile data breaches at Optus and Medibank, which exposed sensitive customer data and shattered confidence in voluntary compliance frameworks.
Despite the improvement in response times—now 17 days faster than the previous year—more than half of Australian companies still lack basic awareness of where their data resides or how their systems are interconnected.
Commvault Asia-Pacific VP Martin Creighan says he puts it down to the fact that the regulators are being more stringent and more strict on what their requirements are.
“Cybersecurity was no longer confined to company tech departments and he had seen a rise in requests to brief boards on cyber resilience ‘because they’re worried about the regulation landscape,” Creighan said
Fear of regulation makes decision making faster than years of technical arguments
When cybersecurity discussions moved from IT departments to executive suites, the entire power dynamic shifted. CISOs who previously begged for a budget are now briefing boards because directors finally understand that they face personal liability.
Australia’s 28-day recovery time is still behind the global 24-day average and this exposes a big flaw in security reforms that come during the crisis.
Countries with better recovery times built their cybersecurity capabilities over decades and not after they heard breaches were hot in the headlines. Australia is playing catch up with reactive measures while competitors operate from mature and relatively proactive security foundations.
The market opportunity here is massive but misunderstood. Everyone’s investing in breach detection and incident response tools but the real money is in solving the foundational problem. What’s the foundation problem, you may ask. Data visibility and infrastructure mapping.

