Australia’s notifiable data breach scheme has produced published statistics on a consistent basis since 2018. This file sets out what that provides that nothing else in this corpus does.
A Trend You Can Believe
The corpus holds four incompatible 2025 ransomware totals at 25-1210b, two leak-site counts disagreeing about 2024 at 25-1230, an 80% single-year swing attributable to methodology at 25-0423, and a 3,000% figure at 25-0821 that almost certainly measures new reporting.
Against that, an 8% annual change measured the same way for eight years is a different class of statement — and it is the reason this desk graded 25-1229b high while grading most sector totals low.
Causes, Not Just Counts
The register distinguishes malicious attack from human error and system fault, which is how 25-1230b established that around 40% of notifiable breaches involve no adversary — a fact this corpus could not otherwise have known.
Leak sites cannot produce that. Vendor telemetry cannot produce it. Only a register that requires notification regardless of cause can.
Sector Shares On A Common Basis
Because every sector notifies on the same test, the health finding at 25-0802b is comparable in a way the US healthcare register at 25-0630 is not — that one measures a sector against sectors with no obligation at all.
What It Still Cannot Do
It counts notifications meeting a statutory harm threshold, so smaller incidents fall outside — the size problem at 25-0613b. It publishes a mean and no median, per 25-0731b. It records exposure and not outcome, so the unbridged link at 25-1219 remains unbridged.
And it says nothing about availability. A council whose telephones fail at 25-1127b, a manufacturer that stops building at 25-0902, a distributor that cannot invoice at 25-0606 — none of that is a notifiable data breach in any regime this corpus has found.
The Corpus’s Recommendation, Stated Plainly
A universal mandatory register with cause classification and published aggregates is achievable — one country has run it for eight years. It answers questions this database has repeatedly been unable to answer.
It would not answer the availability question, the outcome question, or the small-organisation question. Graded medium: this is an argument from what one register produced, not a finding.
It assesses what a long-running national register provides, against the measurement problems recorded throughout this database. Corrections: corrections@forensicpost.com.