Free market enthusiasts have long argued that private industry does things more efficiently than government. New research into data breach notifications in Australia provides a stark illustration.
When an Australian Government agency is breached, it takes a median 108 days to notice. Organisations in every other sector take three.
That is the headline finding of Breach reporting in the AI era, by software and AI services firm Adaca. It analyses 4,769 notifications made to the Office of the Australian Information Commissioner (OAIC) between January 2022 and 2 July 2026.
Put another way, an intruder in a government system typically has more than three months before anyone notices. In a typical business, they are found within days.
"The Medicare breach has sent shockwaves through Australian public sector, but we have to be glad that it was OpenAI, not a malicious actor who wanted to cause genuine harm," said Adaca founder Lambros Photios.
"A real attacker would have held that data for ransom, sold it on the dark web, or used it for financial gain. And this is definitely happening too."
Slow to spot, slow to tell
The detection gap is not confined to the median. Some 60.0% of government breaches took more than a month simply to identify, against 20.5% elsewhere.
Once a breach is found, the regulator does not hear about it quickly either. Only 7.0% of government breaches since 2022 were reported to the OAIC within ten days of discovery, compared with 34.1% for non-government entities.
More than half, 56.9%, took longer than 30 days. Under the Notifiable Data Breaches scheme, an entity that suspects an eligible breach has 30 days to assess it. It must then notify as soon as practicable.
Government is also being breached more often. Australian Government notifications rose from 37 in 2022 to 118 in 2025, a 219% increase, after peaking at 161 in 2024.
Across the period, government is the third most-breached category in the register, with 399 notifications. Only health and finance recorded more.
The 108-day figure is based on 166 government notifications with a usable detection date. The three-day comparison draws on 1,746 notifications and excludes government at all levels.
Adaca built its dataset from two OAIC freedom of information releases. The first, FOIREQ24/00556, provides monthly aggregates to October 2024. The second, FOIREQ26/00195, holds 2,063 individual records from November 2024 to July 2026.
Not all business is quick
The private sector is not uniformly fast. Insurers reported just 10.6% of breaches within ten days, recruitment agencies 15.0% and finance, including superannuation, 22.0%.
At the other end, personal services reported 54.4% of breaches within ten days and education 46.6%.
Health service providers lodge more notifications than any other sector, with 914 since 2022. They are also among the quickest to report, with 43.8% notified within ten days.
Across all sectors, 31.7% of breaches reached the OAIC within ten days and 25.4% took more than 30.
Attackers change tactics
Overall volumes have stepped up sharply. Notifications were almost flat in 2022 and 2023, at 884 and 893, before climbing to 1,108 in 2024 and 1,205 in 2025.
The first half of 2026 averaged 111.7 a month. Comparing January to June in each year, 2026 produced 69% more notifications than 2022.
The methods are shifting too. Hacking nearly tripled, from 2.4 notifications a month to 7.0, and its share of cyber incidents rose from 7.6% to 15.8%.
Ransomware is still growing in number, but it now makes up a smaller share of attacks. Meanwhile, 13% of cyber incidents are now recorded as "other / not specified", meaning victims either do not know the cause or say it fits no listed category.
Not every breach is an attack. Roughly a third of all notifications stem from human error or system faults.
A rare bright spot
There is some good news. In 2022 and 2023, just 28.0% of breaches were notified within ten days, the worst result since the scheme began in 2018.
So far in 2026, 38.4% have been reported within ten days and only 18.6% have taken more than 30 days. Adaca says both are the best figures on record.
The report suggests organisations may be using AI to automate incident response. It also suggests many choose to hold off reporting until close to the deadline.
Adaca cautions that missing data may flatter the improvement. Notifications with no detection date rose from 1.0% in 2022 to 7.2% in 2026.
Photios warned that the gap between attackers and slow defenders is widening.
"It's scary how quickly an attacker can move now, at literally superhuman speed. AI makes it a lot easier to find vulnerabilities or exploit zero days," he said.
"Using AI tools, they can navigate through a company's most valuable assets and steal them before the target knows they've been hit. For a sector that typically only discovers a breach after 100 days, it is severely outmatched."