The Sentence a Statistic Cannot Support

The Sentence a Statistic Cannot Support

Every quarter a regulator publishes a number, a vendor builds a campaign around it, and it arrives at a board meeting inside a sentence it does not support.

The Australian breach figures are a good worked example, because they are well-collected, publicly documented, and almost universally misquoted. What follows is less about breaches than about how to interrogate any published risk number before acting on it.

The figures

For the 2025 calendar year, the Office of the Australian Information Commissioner recorded 1,205 notifiable data breaches — an all-time high, and 8% up on the 1,112 recorded in 2024. 716 of them, 59%, were attributed to malicious or criminal activity. The largest reporting sector was health services, with 225 notifications, or 19% of the total.

Those are the facts, and they are not this piece’s subject. What the 2025 release does and does not support for an Australian business is set out by Cloud Geeks in 1,205 Breaches, and the 59% That Were Attacks.

What follows is the general problem those figures happen to illustrate: the distance between a number and the sentence somebody puts it in. Here are three such sentences, none of which these figures support.

”There were 1,205 data breaches in Australia last year”

The number counts breaches notified under one scheme, by entities obliged to notify.

Organisations with turnover under $3 million are largely outside the Privacy Act, and therefore outside this statistic, unless they trade in personal information, provide a health service, hold a government contract, or — from 1 July 2026 — became a reporting entity under the second tranche of the anti-money-laundering regime.

So the figure is not a census of Australian breaches. It is a census of notified breaches among larger organisations. Whether the true number is two times or twenty times higher is genuinely unknown, and any vendor deck implying otherwise is reading a coverage statistic as a prevalence one.

The governance consequence is specific: if your organisation is below the threshold, this number tells you nothing about your own exposure, and the absence of your sector from the table is an artefact of who must report.

”Health is the most attacked sector”

Health is the largest reporting sector. Different claim.

Health providers are covered regardless of turnover, they hold sensitive information by definition, and the threshold at which a breach becomes likely to cause serious harm is reached more readily. Higher reporting can reflect a higher duty to report rather than a higher rate of being attacked.

This distinction matters because the sentence usually appears as an argument for sector-specific spending. The defensible version of that argument is different and better: health, finance, government, professional associations, education and legal and accounting practices lead the table because they hold other people’s sensitive information. That is a characteristic you can check yourself against in a minute, and it does not require believing anything about attacker preference.

”Attacks are rising, so human error is falling”

The release gives one breakdown — malicious or criminal activity at 59% — and does not publish human error and system fault figures alongside it.

A share tells you nothing about the movement of the other categories. If total notifications rose 8% and the attack share is 59%, the remaining 41% could have grown, shrunk or stayed flat. You need the half-yearly report for that, not the headline.

This is the most common statistical error in security reporting generally: treating a proportion as though it were a trend, because proportions are easier to say.

★ Insight ───────────────────────────────────── All three misreadings share a structure. The statistic measures something narrow and precisely defined — notifications, under one scheme, by obliged entities, in one category — and the sentence it ends up in is broad. Nobody lies; the qualifier is simply dropped somewhere between the release and the slide. Which means the single most useful governance habit is not scepticism about the number but insistence on the qualifier: measured how, of whom, over what period. ─────────────────────────────────────────────────

The comparison that is usually missing

One more habit, and it is the one that most often changes a decision.

When a risk figure is presented, ask what it should be compared against. Almost none arrive with a comparator, and without one a number cannot be large or small — it can only be a number.

1,205 notifications against what? Against 1,112 the year before, which is the comparison the release itself makes and which supports a modest upward trend. Against the number of organisations covered by the scheme, which would give an incidence rate and is not published. Against other categories of business loss, which would let a board weigh it against the risks it already manages.

The third is the one that belongs in a board pack and is almost never there. A risk presented in isolation always looks urgent, because there is nothing in the frame that is more urgent.

What the figures do support

Three conclusions worth carrying into a risk conversation.

The direction is up, among organisations that must report. An 8% rise on an all-time high is not noise. Whatever the composition, the trend in that population is not improving.

The majority of notified breaches involve deliberate action. 59% attributed to malicious or criminal activity means the modal notified breach is not a misdirected email. The controls that address that majority — multi-factor authentication, patching what faces the internet, restricting who can reach what — are unglamorous, well understood, and their absence is what these notifications keep describing.

Custody of third-party data is the common factor at the top of the table. Not size, not sector glamour. Whether you hold information about people who are not your staff.

Where the qualifier gets lost

It is worth tracing the path, because knowing where the loss happens tells you where to intervene.

The regulator’s own release is careful. It says notifications, it names the scheme, it gives the period. The qualifier is present and prominent.

The first summary — a trade publication, a vendor blog — keeps the number and shortens the qualifier to something like “Australian businesses”. Not wrong exactly, and the population has quietly widened.

The second summary, usually a slide, keeps the number and drops the qualifier entirely, because a slide has no room for a subordinate clause and the number is the point.

By the third retelling the sentence is “there were 1,205 breaches last year”, which is a different claim about a different population, and nobody involved did anything more culpable than compress.

The intervention that works is not asking people to be more careful. It is a rule: any external figure presented for a decision arrives with its source link. Not a citation in a footnote — a link somebody can follow in the meeting. The discipline is not that anyone checks; it is that the qualifier has to survive the trip, because it is still in the linked document.

Four questions for any published risk number

Worth having as a standing habit rather than a security-specific one, because the same errors arrive with market sizing, benchmark salaries and customer satisfaction indices.

  1. Who is in the denominator? Nearly every misreading is a population error. The figure describes some group; ask which, and whether you are in it.
  2. Is this a count, a rate or a share? Shares cannot carry trends. Counts cannot carry prevalence without a denominator. Rates need both.
  3. Does reporting effort vary across the categories being compared? If one group is obliged to report and another is not, the comparison measures obligation, not incidence.
  4. What would this number look like if the thing it measures had not changed at all? If a plausible answer is “much the same”, the number cannot support a claim about change.

The vendor version of the same number

Worth recognising on sight, because it arrives more often than the regulator’s own release.

A security vendor’s use of these figures follows a reliable shape. The count appears without its population. The attack share appears as a trend. The leading sector appears as evidence of targeting. And a fourth move is added that the regulator never makes: an implied causal link between the trend and the product being sold.

None of that is dishonest in a way you could point at. Each sentence is individually arguable. The composite is a claim that the published data does not support, assembled from parts that individually do.

The defence is not cynicism about vendors, most of whom are selling something useful. It is a single question, asked out loud in the meeting: which of these numbers is about organisations like us? In our experience that question ends the statistics section and starts a more useful conversation about your own systems, which is where the meeting should have begun.

The uncomfortable conclusion for boards

A board that receives a well-sourced figure with the qualifier intact often finds it says less than expected — and that is the correct outcome, not a failure of the reporting.

The instinct at that point is to ask for a better external number. Usually there isn’t one, and the better move is inward: the questions that actually bear on your exposure are answerable from your own systems in an afternoon. Which systems hold data about other people. Who can reach each one. When a backup was last restored. Whether multi-factor authentication is on, not available.

None of those require a national statistic, and all of them change the outcome of an incident. The published figure is useful for establishing that the risk is real and rising. It was never capable of telling you where you stand, and it is usually deployed as though it were.


Risk governance and the reading of the numbers that drive it is part of the advisory work we do through Ganda Tech Services, with security operations through Cloud Geeks.

Source: OAIC, data breach notifications increase to all-time high in 2025.

Free Roadmap · 2026

Digital Transformation Roadmap 2026

A 12-month framework for Australian SMBs ready to modernise — phases, tools, and milestones.

We email a confirmation link first. No spam. Unsubscribe any time.