The inaugural State of the Industry 2024 report provides the first national benchmark of its kind, built on open data, a transparent methodology and over 30 datasets, to inform policy, investment and workforce development across the country.
The report reveals a sector that’s growing fast, fuelling jobs and attracting record investment, yet still under resourced and dangerously overlooked at a national level.
It finds Australia’s cyber industry contributes $9.99 billion in GVA, supports over 137,000 jobs and attracted $348 million in investment in 2024.
However, it also confirms that 69 per cent of businesses experienced a ransomware attack and that Australia now ranks 4th globally for cyber attacks on critical infrastructure.
“This report sets the baseline. It tells us where we are and what’s at stake. We support the government’s Cyber Security Strategy,” said Jason Murrell, Chair of ACN.
“But the threat is outpacing the implementation. This is not just an industry issue. It’s a national security issue that demands national leadership.” he said.
The release follows a series of serious cyber incidents, including recent attacks on the NSW Law Courts, AustralianSuper, universities and Australian IVF provider Genea. Yet, cyber security has been absent from national policy debates during the federal election cycle.
“This silence is a risk in itself,” Mr Murrell said. “Cyber is a strategic domain. It affects trust in government, the safety of citizens and the viability of supply chains. We have got the strategy, now we need the urgency, action and visible political priority”
The State of the Industry 2025 report draws on more than 30 datasets across workforce, investment, business structure and threat surface mapping.
It has been developed in collaboration with government, industry and research partners to provide an open, repeatable and shared view of the sector’s shape and direction.
Among its key findings:
- Cyber security revenue reached $6.13 billion in 2024 – up 9.66%
- $348 million raised by cyber start-ups – more than triple the year prior
- 137,453 Australians employed – forecast to grow 41% by 2029
- More than 302 cyber companies, with 97% Australian-owned
- 69% of businesses hit by ransomware in 2024
- 25% female participation in the workforce – higher than previously recorded
- New workforce tracking enabled via updated national job classifications (ANZSCO)
With ACN’s advocacy work, the Australian Bureau of Statistics introduced five new cyber specific job codes into the national ANZSCO framework. The changes allow for, for the first time, a true understanding of the cyber workforce’s size, growth trajectory and diversity profile.
The report also challenges assumptions about gender participation in cyber security. Previous studies undercounted women due to narrow definitions of technical roles. New methods adopted in this report show that one in four cyber professionals identify as women.
“It’s encouraging to see progress in gender diversity within the cyber workforce, with women now representing 25% – up from 17% in 2021,” said Professor Ryan Ko, Chair and Director of the Cyber Research Centre at the University of Queensland.
“This reflects both the collective efforts of our industry and the robust methodology behind this study. More importantly, this report gives us, for the first time, a complete and evidence based view of Australia’s cyber workforce,” said Ko
“For too long, we’ve relied on fragmented datasets and inconsistent job definitions. This is the first national baseline built on real methodology,”
“It allows us to track not just how many people are in cyber but who they are, where they work and how that’s changing over time,”
“That clarity is essential if we want to design inclusive pathways, identify systemic gaps and build the workforce Australia actually needs.” he said.
Cyber lawyer and ACN Board Member Annie Haggar said recent legislative reforms, such as the Cyber Security Act 2024 represent important progress but noted that cultural change is still lagging.
“Companies must take reasonable steps to secure their systems. The question is, how many are actually doing it? Not enough is the answer, not just from the numbers of breaches being reported but also from recent action by Australia’s regulators in the space,” said Haggar
“This report shows that 69 per cent of Australian businesses were hit by ransomware last year. That’s not just a worrying statistic, it’s a signal that the current approach isn’t working. We still see fear, silence and legal risk driving decisions after incidents,”
“If we want to build national resilience, we have to normalise transparency and treat cyber as a shared responsibility, not a private embarrassment,”
“The new limited use protections in the Cyber Security Act are designed to foster a culture of disclosure which will ultimately help us all to understand and address cyber risk as a nation.” she said.
Jason Murrell, Chair of the Australian Cyber Network said, “Australia has the talent, tech and tenacity to lead in cyber,”
“But leadership doesn’t come from capability alone. It comes from action. This report is the evidence. The question now is whether government and industry act on it,” Murrell said
“If we don’t respond with urgency, coordination and long-term thinking, we won’t fall behind gradually. We’ll fall behind suddenly. The window to secure Australia’s digital future is open now. It won’t stay open forever.” he said.
The State of the Industry 2024 was sponsored by UQ Cyber Research Centre, University of Queensland and Recorded Future and supported by ACN’s Foundation Member Tesserent | Cyber Solutions by Thales

