# Queensland Audit Office Flags Supplier Cyber Gaps

A Queensland government department reported an A$809,000 loss after attackers accessed a telecommunications provider’s systems in July 2025; the department said no government data or sensitive information was compromised. A Queensland Audit Office review found weaknesses in third-party cyber controls: only two of 36 contracts examined required suppliers to report cyber incidents or vulnerabilities. For procurement teams, the findings highlight a gap in supplier oversight and the need to assess how contract clauses and cyber insurance address third-party incidents.

- Procurement professionals can review supplier contracts for explicit incident and vulnerability reporting clauses, noting that only 2 of the 36 reviewed contracts included them.
- The reported loss underscores the financial exposure that can arise through a supplier’s systems, even when government data is not reported as compromised.
- Contractors and service providers should be prepared to address customers’ expectations for cyber incident disclosure and clarify how their cyber insurance covers third-party events.

**Jurisdictions:** sled
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 30, 2026

### Government Entities
- Queensland Audit Office (QAO)
- Department of Customer Services, Open Data and Small and Family Business (CDSB)

### Sources
- [A government cyber loss – and the policy question it leaves unanswered | Insurance Business](https://www.insurancebusinessmag.com/au/news/cyber/a-government-cyber-loss--and-the-policy-question-it-leaves-unanswered-591745.aspx) - Insurance Business