Majority of businesses believe risk and security issues will worsen over the next 12 months

Business Risk

Most Australian business leaders (89 percent) believe risk and security issues will escalate in severity over the next 12 months – up from 58 percent in 2023 – according to a new report from McGrathNicol Advisory.

Cyber security ranks as the number one concern for businesses, followed by financial, legal and regulatory risks.

The specialist advisory firm conducted a study of 300+ C-Suite executives and board-level directors to learn about the perceptions and attitudes of Australian business leaders towards risk.

Respondents were quizzed on geopolitical threats, insider risks, cyber security, issues in the supply chain, and financial, legal and regulatory concerns.

For more than a third of Australian organisations (37 percent) trade issues are a concern, but only nine percent believe that the outcome of the upcoming US presidential election will pose a significant challenge to their business.

Matt Fehon, Head of Advisory, McGrathNicol Advisory, said many Australian organisations will be required to submit Risk Management Programs – addressing areas like cyber, geopolitical, regulatory and supply chain risks – for the first time as the SOCI reporting deadline approaches.

“Following a data breach, a cyber incident can rapidly escalate throughout the supply chain to customers and employees, becoming a regulatory issue with severe financial and reputational consequences,” he said.

“Too often, we see organisations react only once a risk event has occurred. But this can be costly due to the interconnected nature of risk areas. We would prefer to arm businesses with the tools to face the changing landscape of business risk head on.”

In August, new cyber security obligations were introduced under the Security of Critical Infrastructure Act 2018 (SOCI Act), meaning Australian organisations operating in certain sectors – such as communications, defence, higher education and research, financial services, healthcare, energy and transport – may need to submit a Critical Infrastructure Risk Management Program by 28 September.

Key findings of the research include:

  • Businesses are underestimating the secondary impacts of geopolitics: Australian businesses are struggling to identify the link between geopolitics and other enterprise risks such as cyber, insider and supply chain threats, despite the Russian invasion of Ukraine and the Israel-Hamas war illustrating how geopolitical events can create significant disruption. If re-elected, a second Trump administration has proposed the introduction of new tariffs targeting Chinese-made goods of between 60-100 percent. This would almost certainly reinvigorate trade disputes and directly impact Australian businesses
  • Cyber concerns grow as supply chains become increasingly targeted: Cyber security is a significant concern for Australian businesses, with 68 percent of organisations placing cyber risk within their top five concerns for 2024, meaning it is the highest of any risk category. Despite this, 71 percent of organisations do not conduct due diligence on their key suppliers’ cyber security practices and more than three quarters (77 percent) do not require mandatory reporting of any cyber or data breaches affecting their suppliers
  • Insider risk is a ‘human’ problem: While 87 percent of surveyed organisations were confident that their business has a comprehensive insider risk management program in place, less than a third have implemented fundamental insider risk controls. Only 28 percent are using a risk-based vetting and due diligence framework for employees and suppliers or contractors. 27 percent have education and awareness programs in place, while just 18 percent have appointed an authority that is accountable for insider risk
  • Practical testing of supply chains is required: Most enterprise risk management programs (80 percent) now include supply chain risk as a core pillar. Similar to last year’s results, most organisations (74 percent) acknowledge internal issues in addressing supply chain challenges due to a shortage of expertise, insufficient data and visibility tools, budgetary constraints and competing priorities
  • Data management adds new layers of legal and regulatory complexity: Regulatory bodies have shifted focus from market education and awareness to enforcement, and in the past few years, new legislation has been introduced with regards to payment times reporting, wage underpayments, changes to the Privacy Act and the SOCI Act. As a result of this, more than half of respondents (55 percent) see legal and regulatory risk as a top concern for their organisation, with 27 percent expecting these risks to continue increasing in severity
  • Multiple risk factors fuel financial pressure: High inflation, wage increases, interest rate rises and higher energy costs are leading to CFOs being tasked with identifying areas where costs can be cut. This trend is expected to continue into 2025. While cyber risk was the highest-ranking risk among organisations, financial risk ranked second with 66 percent acknowledging it as a top five concern.