National Audit Office worried about Census Cyber Security

Australia's biggest data collection is 11 weeks away — and the national auditor has just found its cyber defences weren't built right.

Family completing census form at kitchen table with shadowy figure visible through window
Family completing census form at kitchen table with shadowy figure visible through window

Every five years, Australia asks every household in the country to sit down and hand over some of its most personal information: names, ages, relationships, religion, income, health conditions, languages spoken at home. The Australian Bureau of Statistics then compiles it into the most detailed portrait of the nation that exists, and governments at every level use it to decide where to build hospitals, how to fund schools, and where to draw electoral boundaries. On 11 August 2026, roughly 27 million Australians will do it again, with 85 per cent of them expected to submit their answers online.

Bottom LineA performance audit by the Australian National Audit Office has found that the Australian Bureau of Statistics has not adequately prepared the cyber security arrangements for the 2026 Census, identifying unresolved vulnerabilities, gaps in risk management, and planning shortcomings that leave Australia's largest data collection exercise exposed before Census night. If the systems are breached, the consequences are not just personal for the Australians whose data is compromised — they flow directly into the policy decisions that shape public spending and infrastructure for the next five years.

Late security design is a pattern, not an exception

The Australian National Audit Office published its findings on 27 May 2026. Its conclusion was measured but pointed: the ABS must address key remaining cyber security vulnerabilities before Census night, and some of those vulnerabilities exist because the ABS did not consider cyber security risks holistically across its full ICT environment early enough. The result was delayed identification of problems, which meant the remediation effort has required significantly more expert resources, for longer, than originally planned.

That is a familiar pattern in government IT. Cyber security that is bolted on late in a project costs more to fix and tends to miss things that would have been caught had it been designed in from the start. The ANAO noted that risk reviews were neither complete nor timely, and that security architecture documentation had not been adequately prepared, approved, or reviewed. Four formal recommendations followed. The ABS has agreed to all of them.

Cyber security that is bolted on late in a project costs more to fix and tends to miss things that would have been caught had it been designed in from the start.

This is not the first time the ABS has been here. The 2021 Census drew about one billion attempted cyber attacks, by the ABS's own account. A previous Auditor-General review of the planning for that Census found that cyber security measures were only partly appropriate, and recommended they be strengthened. The 2026 audit is, in a meaningful sense, a test of whether those lessons were absorbed. The ANAO's findings suggest they were absorbed imperfectly, and not early enough.

The 2016 Census provides the sharpest illustration of what the stakes look like in practice. On Census night that year, the online form was taken down after a series of distributed denial-of-service attacks and was not restored for 40 hours. The public loss of confidence was significant. The data loss, while disputed, created gaps in that year's collection. Entire categories of policy planning depend on continuity and completeness in Census data. A compromise that distorts the responses, or that causes a significant share of households to abandon the form, does not just create a privacy problem. It corrupts the evidence base that underpins public investment decisions for the next half-decade.

$726 million is on the line — and so is the data quality

The budget for the 2026 Census is $726 million. That is a significant public investment in data that is supposed to be both secure and accurate. The ANAO's finding that holistic planning for cyber security across the ABS ICT environment was insufficient does not mean that investment has been wasted, but it does mean that some portion of it has been spent fixing problems that earlier planning might have avoided.

The ANAO was careful to acknowledge that the ABS responded quickly once vulnerabilities were identified, and that the assurance programme is on schedule, with testing focused on the attack vectors most likely to be used. That matters. The audit was designed to be published before Census night precisely so there was time to act. The ANAO is not sounding a post-mortem; it is sounding a warning with enough lead time for the warning to be useful.

This is one front in a broader government cyber security failure

This sits within a broader pattern worth noting. An ANAO audit earlier this year found that Parliament House's own IT infrastructure carries serious cyber security vulnerabilities, affecting nearly 5,000 users across the building. A separate audit of IP Australia flagged gaps in cyber security management in the use of AI for patent examination. The government's capacity to protect sensitive data it holds on behalf of citizens is being tested across multiple fronts at once.

For the Census specifically, the question between now and 11 August is whether the ABS can close the remaining vulnerabilities in time. The ANAO says it can, if the critical activities are completed. That is a conditional assurance, not a clean one. Australians filling in the form in August will be trusting that the conditional has been met. Given what the data is used for, and how long it shapes the decisions made in its name, that trust needs to be earned rather than assumed.


Sources

Australian National Audit Office — Cyber Security Readiness for the 2026 Census

Frequently Asked Questions

What did the ANAO find wrong with the ABS's cyber security for the 2026 Census?
The ANAO found that the ABS did not consider cyber security risks across its full ICT environment early enough, leading to delayed identification of vulnerabilities and a remediation effort that has required more expert resources for longer than planned. Risk reviews were neither complete nor timely, and security architecture documentation was not adequately prepared or approved.

Has the Census been hacked before?
The 2016 Census online form was taken offline for 40 hours after distributed denial-of-service attacks on Census night, creating gaps in that year's data collection. The 2021 Census faced approximately one billion attempted cyber attacks, according to the ABS's own account.

Is it safe to fill in the 2026 Census online?
The ANAO says the ABS can close remaining vulnerabilities in time, but only if critical remediation activities are completed before 11 August 2026 — a conditional assurance rather than a clean one. The ABS has agreed to all four of the ANAO's formal recommendations and its assurance programme is reported to be on schedule.

Why does Census cyber security matter beyond personal privacy?
Census data directly shapes government decisions on hospital locations, school funding, and electoral boundaries for the five years following each Census. A successful attack that distorts responses or drives households to abandon the form corrupts the evidence base underpinning public investment decisions — not just the privacy of individuals whose data is exposed.

How much is the Australian government spending on the 2026 Census?
The budget for the 2026 Census is $726 million. The ANAO's finding that cyber security planning was insufficient means a portion of that investment has been spent remedying problems that earlier security-by-design planning might have avoided.