Select Page

Australian Cyber Aware Audit Report Listing

This register provides a collection of publicly available audit reports from Australian Auditors-General, regulators, and oversight bodies. It helps organisations understand emerging risks, recurring audit findings, governance challenges, and best-practice recommendations.

By learning from real-world audits and reviews, boards, executives, business owners, and risk professionals can identify opportunities to strengthen governance, cyber security, privacy, compliance, and risk management practices.

August 2026

12-Aug-26 AU NSW
AONSW Multiple Agencies
Internal controls and governance 2026: grants, consultants, purchasing cards and technology
Less than half of agencies reported compliance with requirements to protect and govern their risk exposure. Some agencies did not assess risks from legacy systems that cannot be patched, increasing their exposure to cyber-attack.

Audit Tasmania12-Aug-26 AU TAS
AuditTas Finance Multiple Agencies
Auditor-General’s Report on the Financial Statements of State Entities 2025-26, Volume 1
Our audits continue to identify recurring weaknesses in core control disciplines. These issues have been reported repeatedly over several years and should no longer be regarded as emerging challenges. They are known risks requiring sustained management attention. This includes matters on cyber security and information technology. However, due to the sensitive nature of these matters, only limited detail has been included in the report to avoid identifying potential security vulnerabilities.

 

 


July 2026

Northen Territory Auditor Generals Office22-Jul-26 AU NT
NTAGO Multiple Agencies
Results of Financial Audits – 30 June and 31 December 2025
Key finding: Strong audit outcomes for the public tertiary sector; however, timeliness and control weaknesses require continued attention. Recurring weaknesses in information technology user access controls remain a common theme.

 


June 2026

29-Jun-26 AU FED
ANAO IP Australia
Artificial Intelligence Use in IP Australia
“Artificial intelligence (AI) is increasingly becoming a part of the Australian Public Service. AI offers the promise of better services, enhanced productivity and efficiency — but has the potential for increased risk and unintended consequences.
The ANAO made two recommendations to IP Australia aimed at improving management of cyber security risks and improving strategic oversight of AI implementation. “

29-Jun-26 AU NSW
AONSW, Education
Security and privacy of student information
This audit assessed how effectively the NSW Department of Education (the department) and NSW public schools (schools) protect the security and privacy of student information. The audit made recommendations for the department to review the allocation of responsibilities to principals, improve the guidance and supports for schools, and strengthen the controls for managing the access to and use of student information.

24-Jun-26 AU FED
ANAO Department of the Treasury’s
Department of the Treasury’s Readiness to Implement the Scams Prevention Framework
Treasury has largely appropriate implementation and monitoring arrangements to support its readiness to implement the SPF, up to the point where the SPF becomes operational. To position Treasury to provide impactful, informed and influential advice about the SPF in operation, it will need to develop monitoring, reporting and evaluation arrangements.

18-Jun-26 AU QLD
QAO, Education
Education 2025
Weaknesses in the security of information systems at universities continue to account for most of the deficiencies we identified. Despite this, we have been able to rely on the systems and processes they used to prepare financial statements. This year, we identified 25 deficiencies – including one significant deficiency – relating to weaknesses in information systems controls at universities. Of the 48 deficiencies we identified last year, 14 remain unresolved as at 31 December 2025

16-Jun-26 AU SA
AOSA Government
Review of legacy ICT systems
We found weaknesses in how some agencies manage legacy system risks, including incomplete asset inventories, limited formal risk assessments, gaps in risk register documents and inconsistent reporting to governance bodies. These gaps reduce visibility of risks and can delay action to remediate or replace systems.

11-Jun-26 AU FED
ANAO, Department of Parliamentary Services, Government
Management of Cyber Security in the Department of Parliamentary Services
The ANAO audit assessed whether the Department of Parliamentary Services (DPS) had an effective baseline of cyber security controls, focusing on its assessment of cyber risks, implementation of the Essential Eight mitigation strategies, and assurance over control effectiveness in alignment with the Protective Security Policy Framework (PSPF) and Information Security Manual (ISM). It found that while governance structures existed, the overall cyber security posture was only partly effective due to gaps in risk assessment, incomplete implementation of controls, reliance on compensating measures, and weaknesses in asset inventories, policy frameworks, and assurance processes.

11-Jun-26 AU NSW
AONSW Education
Universities 2025
“Control deficiencies were most common in IT/cyber security, governance and payroll
There were 94 reported audit findings and most related to poor monitoring of IT/cyber security risks, inadequate governance oversight and deficiencies in payroll management. One university has no processes to manage IT legacy systems, and 6 universities have not formally assessed legacy system risks.
Three universities still do not have a formalised AI policy. Only 2 universities had procurement guidance in place for AI-related procurement.”

04-Jun-26 AU VIC
VAGO, Higher Education
Results of 2025 Audits: TAFEs and Universities
Weaknesses in IT controls continue to require attention in both sectors. Issues with their management and monitoring of system access increase the risk that errors or fraud occur and go undetected.

 


May 2026

27-May-26 AU WA
WAOAG Higher Education
Universities and TAFEs 2025 – Financial Audit Results
This year we reported 73 control weaknesses compared to 883 last year. Despite a slight reduction, the proportion of significant and moderate weaknesses increased, and most of the weaknesses (64%) remained unresolved from prior years. Three per cent of weaknesses were rated significant, 74% moderate and 23% minor. Although the majority of weaknesses were moderate, entities should promptly address them to reduce their overall exposure to cyber and other information system threats.

27-May-26 AU FED
ANAO Australian Bureau of Statistics
Cyber Security Readiness for the 2026 Census
“There were four recommendations to the ABS regarding: Census risk management arrangements; early establishment of cyber security advisory arrangements; preparation, approval and review of security architecture documentation; and addressing risks stemming from the broader ABS ICT environment. The ABS agreed to the recommendations.”

22-May-26 AU WA
WAOAG Higher Education
Universities and TAFEs 2025 – Information Systems Audit Results
Information and cyber security controls is the most significant area of concern, accounting for 82% of all weaknesses identified. These controls are critical to protecting sensitive information and maintaining the integrity and availability of key systems.

11-May-26 AU NSW
AONSW NSW Police Force
Upgrades to core policing technology
While essential technology infrastructure and the forensics and exhibits system have been upgraded, other core systems identified in the original business case remain dependent on legacy platforms. This requires ongoing funding, increases technology risk and reduces operational effectiveness. In the 2025 updated business case, the NSW Police Force noted escalating risks to service continuity, cyber security and public safety.

 


April 2026

15-Apr-26 AU WA
WAOAG Local Government
Local Government 2025 – Financial Audit Results
For the 2025 financial year, we reported 333 general computer control weaknesses to 68 entities, compared to 360 control findings to 89 entities in 2024. Over half of these weaknesses (60%) were unaddressed prior year issues. Nine percent of findings were rated significant, 69% moderate and 22% minor.

 


March 2026

30-Mar-26 AU VIC
VAGO Local Government
Results of 2024–25 Audits: Local Government
Councils can strengthen their internal controls to better support the preparation of reliable reporting. Each year, we continue to identify weaknesses in financial reporting controls, IT controls and asset management and valuation. A large number of high and moderate‑risk issues identified in past audits also remain unresolved.

26-Mar-26 AU QLD
QAO Multiple
Managing third-party cyber security risks
“While the entities had implemented some policies, processes, and controls to identify and manage third party cyber security risks, gaps remained. In isolation, many of the gaps or issues may seem relatively minor. However, collectively they created vulnerabilities that unnecessarily exposed the entities to third party cyber attack – compromising their systems, data, and sensitive information.
The Department of Customer Services, Open Data and Small and Family Business (CDSB) and the Department of Housing and Public Works (DHPW) are not effectively building capability across the public sector to manage third-party cyber security risks.”

25-Mar-26 AU WA
WAOAG Local Government
Local Government 2025 – Information Systems Audit Results
Our 2025 audits highlight ongoing challenges for entities to strengthen their IT governance and security. While it was positive to see the number of entities that had control weaknesses reduce to 68 this year (89 in the prior year), 60% of our findings were unresolved issues from prior years. Entities need to address these persistent control weaknesses to safeguard their important systems, information and service delivery.

19-Mar-26 AU QLD
QAO Local Government
Local government 2025
This report summarises the audit results of Queensland’s 77 local government entities (councils) and the entities they control. In 2024–25, there were 263 significant internal control deficiencies that were either new or unresolved – the highest number of high risk matters we have found in the sector in the last 5 financial years.
This year, we identified 98 new information systems weaknesses across 49 councils (2023–24: 77 new weaknesses across 49 councils).

06-Mar-26 AU WA
WAOAG Multiple
Microsoft 365 Security Controls – State Entities
The audit found weaknesses in governance, identity and access management, information protection, logging and monitoring, and threat protection controls. These weaknesses heighten the risk of cyber incidents, data breaches and operational disruptions.

 


January 2026

28-Jan-26 AU NSW
AONSW Local Government
Local government 2025
“This report presents key findings and recommendations from financial audits of local councils, joint organisations and county councils for the year ended 30 June 2025. It also comments on the sector’s financial sustainability, internal controls and governance, major capital projects, artificial intelligence (AI) and cyber security.
Councils are in the early stages of adopting AI. Fewer than half have a strategy or governance framework, limiting oversight and opportunities to leverage benefits and mitigate AI risks.
Deficiencies in internal controls and governance were identified at most councils, mainly associated with asset management, information technology (IT) and fraud control.
Councils have critical weaknesses in managing supply chain risks. Policies and processes for assessing the cyber security exposure of technology assets are inadequate, and monitoring of cyber security investments and their associated benefits is limited.”

20-Jan-26 AU QLD
QAO Queensland Health
Health 2025
Health sector entities’ financial statements are reliable and their internal controls are also generally effective. However, we continue to find deficiencies in information technology (IT) access and security controls. Health entities are considered attractive targets by cyber criminals, due to the personal information they hold and the potential for profit. We therefore consider these access control deficiencies as significant. While management is working to address these complex issues, they need to take more timely action to resolve the deficiencies.

 

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

OpenAI bots breach NSW government websites twice | 7NEWS

OpenAI has admitted its AI bots were responsible for a second breach of NSW government websites, accessing non-public historic wildfire data from the National Parks and Wildlife Services app in [...]

Anthropic says AI agents didn’t breach Australian government websites

During a joint parliamentary hearing on artificial intelligence, Anthropic’s head of safeguards, Dave Orr, says that investigations of hundreds of millions of transcripts reveal no unauthorised interactions with Australian government [...]

Home affairs orders review over ‘unacceptable risk’ of AI

The federal government has ordered its departments and agencies to review their aging IT systems in a bid to combat the growing risks posed by artificial intelligence. The crackdown targeting [...]

Australian Information Commission launches smart glasses probe

A major probe has been launched into the privacy measures of the Chinese firm behind smart glasses recently on sale in Australia. The Office of the … [...]

ANZ releases advice on AI scams and fraud

Major bank ANZ has issued a warning regarding AI and increased levels of scams and fraud, highlighting that the technology is enabling threat actors … [...]

Trusted government data can help counter AI misinformation, says OAIC

The Office of the Australian Information Commissioner has warned that proactive access to trusted government information is increasingly important as … [...]

Report: Aussie government lags behind private sector in breach discovery

The average data breach in Australia takes three days to discover – but government breaches take more than 100. • Tue, 29 Sep 2026 • … [...]

Australian government to invest $3.5m to combat technology-facilitated abuse

The Albanese government to stand up 12 new “innovative” projects as part of its National Plan to End Violence Against Women and Children. • Wed, 30 … [...]

Op-Ed: The rogue agent breach of Medicare highlights the importance of AI literacy and fluency for lawyers

The newsfeed has reached a fever pitch about the dangers of artificial intelligence and “AI slop” in legal practice, with most of it focused on … [...]

NSW National Parks web app accessed by OpenAI agent

Key points An OpenAI agent is under investigation after a "misalignment" incident on a National Parks and Wildlife Service web app in June. • Current … [...]

Jobseekers exploited by recruitment scammers on LinkedIn

Tony Young is one of many Australians who have applied for work using websites like LinkedIn, only to realise afterwards it was a scam. The former … [...]

Small business delivers e-safety wishlist as risks grow

Small business owners need help - not regulation - to battle growing cyber threats, industry groups say. Business representatives addressed a … [...]

Shares
Share This