29 February 2024

Managing Cyber security risks


GILES RAFFERTY, Corporate Communication and Media Advisor


Cybersecurity is back at the top of the news agenda. The Albanese Government is seeking to tackle ‘Doxing’, which is publicly revealing identifying material about someone without their consent; the AFP has helped to smash global ransomware gang Lockbit and the hacker claimed to behind the massive Medibank data breach in October 2022 has been detained in Russia. Likely of more interest to listed companies is the release of the ‘Notifiable Data Breaches Report: July to December 2023’ by Office of the Australian Information Commissioner (OAIC).

The Federal Government’s Notifiable Data Breach (NDB) scheme is 5 years old, and the expectation is the companies that sit under the scheme will fully understand their obligations. Every private or public company with annual turnover of $3 million or more must report cyber breaches that are likely to result in harm to individuals whose personal data is compromised to the OAIC as soon as they become aware of a breach. Companies covered by the NDB must also notify the individuals affected by a breach and offer recommendations to them about how best to protect themselves.

More than 5000 Data Breach Notifications

While Optus and MediBank have the unenviable position of being the Australian poster children for data breaches, the information stolen from them in 2022 covered nearly half the population of Australia, the OAIC has received over 5000 data breach notifications in the 5 years since the NDB was launched.

The trend in the most recent NDB report for the July to December 2023 period was for a 19% increase in the number of notifications to 483, (see figure 1), which follows a decline of 16% in notifications to 407 in the January to June 2023 period. This pattern of a greater number of breaches being reported in the second half of the calendar year has persisted since the inception of the NDB in 2018.


Figure 1


Interestingly, despite the strong upward trend in monthly reporting over the final 6 months of 2023, the total number of data breaches reported under the NDA for the year was unchanged from the 890 reported in 2022 and the 900 notifications in 2021 but was belowthe 1,051 notifications in 2020, the largest number of notifications in a 12 month period since the NDB was launched.

Multi-Party Breaches Highlight Supply Chain Risk

The risk from outsourcing personal information handling to third parties was brought into focus in the second half of 2023 when the OAIC received 121 secondary data breach notifications compared to 29 in the first half. A secondary notification is when the OAIC receives a report from additional entities affected by a breach that has already been reported. The sharp increase in secondary notifications may be linked to an increase in the level of multi-party breaches, most of which result from a breach of a cloud or software provider.

The OAIC Commissioner has identified multi-party breaches as a key contributor to the increase in complexity, scale and impact of data breaches and stated the OAIC will look to escalate regulatory actions, including the option of initiating Federal Court proceedings.

“Organisations need to proactively address privacy risks in contractual agreements with third-party service providers.
“This includes having clear processes and policies in place for handling personal information and a data breach response plan that assigns roles and responsibilities for managing an incident and meeting regulatory reporting obligations.”
Australian Information Commissioner, Angelene Falk

Civil Penalty Proceedings

Companies may face legal action if they fail to have processes in place to ensure they have a considered and up‑to‑date data breach response plan, as was the case with Australian Clinical Labs Limited (ACL).

On 3 November 2023, the Commissioner announced the commencement of civil penalty proceedings in the Federal Court against ACL following a February 2022 data breach that resulted in sensitive information being published on the dark web.

Commissioner alleges that ACL:

    • failed to conduct a reasonable and expeditious assessment,
    • failed to notify the Commissioner as soon as practicable.

The Federal Court can impose a civil penalty of up to $2,220,000 for each contravention.

Healthcare Services top the table for breaches

In the 5 years that reporting data breaches has been mandatory Healthcare Services have consistently accounted for the greatest number of reports. In the July to December 2023 period Healthcare Service providers reported 104, (see figure 2), up from 63 in the first half of CY 2023.  The Financial Services sector, including superannuation, has consistently reported the second most breaches, 49 in the second half of CY2023, although this was down from 54 in the first half.

Aside from Healthcare and Finance, other industries have made periodic appearances in the top 5 sectors include the Insurance sector in 2023, 2022 and 2020, Education between 2018 and 2021; the Australian Government in 2023 and 2021; retail in 2023; Recruitment in 2022; Personal Services in 2019 and Business and Professional Services in 2018.


Figure 2


Sources of Data Breaches

Malicious or criminal attacks remain the leading cause of data breaches (see figure 3). Between July and December 2023 there were 322 malicious or criminal attacks reported, (310 in1H23). The increase in breaches relating to human error (+36%) and system fault (+21%) were both material.


Figure 3


Of the 144 human error incidents reported, 46% related to personal information being sent to the wrong e-mail recipient, 20% to the unintended release or publication of data and 10% to personal information being sent to the wrong recipient via traditional mail.

65% of breaches in the second half of CY 2023 affected 100 people or less (63% in 1H23).

Cyber security incidents accounted for 44% of data breach notifications (211) between July and December 2023 (see figure 4). This is consistent with the first half of 2023 (42%) and 2022 (43% of notifications).

The following chart highlights the most common types of cyber incident over the past year. Phishing attacks were the most common reported incidents in 2H23 taking over from Ransomware attacks, which dominated in the first half of 2023.


Figure 4


Strengthening enforcement

Following the publication of the Attorney-General’s Privacy Act Review in February 2023 the Australian Government committed to progressing work on privacy protections for individuals and ensure Australian businesses have clarity about how to best protect this information. In September 2023, the government agreed in principle to proposals to strengthen the NDB and is currently conducting targeted consultations to support the development of reforms.

The government is looking to sharpen the OAIC’s teeth and after 5 years of the NDB scheme there is an expectation that organisations will understand and comply with their obligations or potentially face legal action.

For listed companies this makes it more important than ever that a cyber-incident response plan is put in place and regularly tested, built on the advice of external advisers and incorporating a well thought out communication strategy. Bringing in advisers with experience in crisis communication to support the internal team is strongly recommended. There is only one opportunity to get the response right so using it as an exercise to test whether or not the team can cope almost guarantees a disappointing outcome.


28 February 2023

CEOs need to drive social change to build trust


GILES RAFFERTY, Corporate Communications and Media The findings of 2023 Edelman Trust Barometer were revealed at Davos in January, with the Australian cut of the data made public at the start of February. The Edelman global survey highlights concern around “severe polarisation” among respondents, which the PR firm interprets as people believing their society is […]

Read More
12 December 2022

Travelling at the speed of change, 2022 in review


GILES RAFFERTY, Corporate Communications and Media US founding father, Benjamin Franklin, said “nothing is certain except death and taxes”. Had he been in a more expansive mood he may have included ‘change’ as another certainty. 2022 has been a year of change. We welcomed Queen Elizabeth’s Platinum Jubilee and mourned her passing. We celebrated the […]

Read More
30 August 2022

Accessing new media opportunities


GILES RAFFERTY, Corporate Communications and Media Adviser It is well understood that the media industry has been experiencing significant technological disruption with the emergence of digital, online and social media platforms. The recent 2022 Digital News Report, by the Reuters Institute and the University of Oxford, indicates the various shocks of the last few years, […]

Read More
28 February 2022

Distrust threatens societal stability


GILES RAFFERTY, Corporate Communications and Media Adviser One of the findings from the annual Edelman Trust Barometer survey is a cycle of distrust that is threatening societal stability both here in Australia and globally. The survey results were published on February 16th, a little over a week before Russia invaded the Ukraine. Australia trapped in […]

Read More
4 March 2021

Locking in the Trust premium


GILES RAFFERTY, Corporate Communication and Media Advisor Trust in Australian Institutions has surged during the Coronavirus pandemic to reach all-time highs.  This resurgence of trust means, in Australia,  the institutions of Business, Government, Media and NGO’s are all now viewed as competent where just 12 months ago only Business was seen to be so. Two institutions, […]

Read More
6 November 2017

Communicating in a Crisis


Geoff Michels, Senior Corporate Communications Adviser A crisis is an event or a series of events that adversely affects the health or well-being of employees, the environment, a community or the wider public, the integrity of a product or the reputation of an organisation.  A crisis can be operational (fire, an accident) or non-operational (workplace discrimination, […]

Read More
10 April 2017

Presentation Techniques for Senior Executives


Geoff Michels, Senior Adviser – Corporate Communications At FIRST Advisers we are frequently asked to coach senior business executives or managers on presentation techniques.  Generally it’s about coming across well at an AGM, or at a roadshow event or in presenting to audiences large and small.  There is also a significant demand for advice and […]

Read More
5 July 2016

Short Attacks: The new wolf pack


VICTORIA GEDDES, ECECUTIVE DIRECTOR Those who have been on the receiving end of a short attack describe the process as akin to being at war, or being pursued by a pack of wolves, with the company’s very destruction their opponent’s goal. A short or bear attack, to make the distinction clear, is not the same […]

Read More
12 November 2015

Why someone on the outside should draft that press release


FIRST Advisers Corporate Communications Some see it as axiomatic that the people within a company are best placed to draft a press release or other piece of external communication. After all, who better to write the news than those on the inside: the people who were responsible for it, were there from the beginning and […]

Read More

Archives