29 February 2024

Managing Cyber security risks


GILES RAFFERTY, Corporate Communication and Media Advisor


Cybersecurity is back at the top of the news agenda. The Albanese Government is seeking to tackle ‘Doxing’, which is publicly revealing identifying material about someone without their consent; the AFP has helped to smash global ransomware gang Lockbit and the hacker claimed to behind the massive Medibank data breach in October 2022 has been detained in Russia. Likely of more interest to listed companies is the release of the ‘Notifiable Data Breaches Report: July to December 2023’ by Office of the Australian Information Commissioner (OAIC).

The Federal Government’s Notifiable Data Breach (NDB) scheme is 5 years old, and the expectation is the companies that sit under the scheme will fully understand their obligations. Every private or public company with annual turnover of $3 million or more must report cyber breaches that are likely to result in harm to individuals whose personal data is compromised to the OAIC as soon as they become aware of a breach. Companies covered by the NDB must also notify the individuals affected by a breach and offer recommendations to them about how best to protect themselves.

More than 5000 Data Breach Notifications

While Optus and MediBank have the unenviable position of being the Australian poster children for data breaches, the information stolen from them in 2022 covered nearly half the population of Australia, the OAIC has received over 5000 data breach notifications in the 5 years since the NDB was launched.

The trend in the most recent NDB report for the July to December 2023 period was for a 19% increase in the number of notifications to 483, (see figure 1), which follows a decline of 16% in notifications to 407 in the January to June 2023 period. This pattern of a greater number of breaches being reported in the second half of the calendar year has persisted since the inception of the NDB in 2018.


Figure 1


Interestingly, despite the strong upward trend in monthly reporting over the final 6 months of 2023, the total number of data breaches reported under the NDA for the year was unchanged from the 890 reported in 2022 and the 900 notifications in 2021 but was belowthe 1,051 notifications in 2020, the largest number of notifications in a 12 month period since the NDB was launched.

Multi-Party Breaches Highlight Supply Chain Risk

The risk from outsourcing personal information handling to third parties was brought into focus in the second half of 2023 when the OAIC received 121 secondary data breach notifications compared to 29 in the first half. A secondary notification is when the OAIC receives a report from additional entities affected by a breach that has already been reported. The sharp increase in secondary notifications may be linked to an increase in the level of multi-party breaches, most of which result from a breach of a cloud or software provider.

The OAIC Commissioner has identified multi-party breaches as a key contributor to the increase in complexity, scale and impact of data breaches and stated the OAIC will look to escalate regulatory actions, including the option of initiating Federal Court proceedings.

“Organisations need to proactively address privacy risks in contractual agreements with third-party service providers.
“This includes having clear processes and policies in place for handling personal information and a data breach response plan that assigns roles and responsibilities for managing an incident and meeting regulatory reporting obligations.”
Australian Information Commissioner, Angelene Falk

Civil Penalty Proceedings

Companies may face legal action if they fail to have processes in place to ensure they have a considered and up‑to‑date data breach response plan, as was the case with Australian Clinical Labs Limited (ACL).

On 3 November 2023, the Commissioner announced the commencement of civil penalty proceedings in the Federal Court against ACL following a February 2022 data breach that resulted in sensitive information being published on the dark web.

Commissioner alleges that ACL:

    • failed to conduct a reasonable and expeditious assessment,
    • failed to notify the Commissioner as soon as practicable.

The Federal Court can impose a civil penalty of up to $2,220,000 for each contravention.

Healthcare Services top the table for breaches

In the 5 years that reporting data breaches has been mandatory Healthcare Services have consistently accounted for the greatest number of reports. In the July to December 2023 period Healthcare Service providers reported 104, (see figure 2), up from 63 in the first half of CY 2023.  The Financial Services sector, including superannuation, has consistently reported the second most breaches, 49 in the second half of CY2023, although this was down from 54 in the first half.

Aside from Healthcare and Finance, other industries have made periodic appearances in the top 5 sectors include the Insurance sector in 2023, 2022 and 2020, Education between 2018 and 2021; the Australian Government in 2023 and 2021; retail in 2023; Recruitment in 2022; Personal Services in 2019 and Business and Professional Services in 2018.


Figure 2


Sources of Data Breaches

Malicious or criminal attacks remain the leading cause of data breaches (see figure 3). Between July and December 2023 there were 322 malicious or criminal attacks reported, (310 in1H23). The increase in breaches relating to human error (+36%) and system fault (+21%) were both material.


Figure 3


Of the 144 human error incidents reported, 46% related to personal information being sent to the wrong e-mail recipient, 20% to the unintended release or publication of data and 10% to personal information being sent to the wrong recipient via traditional mail.

65% of breaches in the second half of CY 2023 affected 100 people or less (63% in 1H23).

Cyber security incidents accounted for 44% of data breach notifications (211) between July and December 2023 (see figure 4). This is consistent with the first half of 2023 (42%) and 2022 (43% of notifications).

The following chart highlights the most common types of cyber incident over the past year. Phishing attacks were the most common reported incidents in 2H23 taking over from Ransomware attacks, which dominated in the first half of 2023.


Figure 4


Strengthening enforcement

Following the publication of the Attorney-General’s Privacy Act Review in February 2023 the Australian Government committed to progressing work on privacy protections for individuals and ensure Australian businesses have clarity about how to best protect this information. In September 2023, the government agreed in principle to proposals to strengthen the NDB and is currently conducting targeted consultations to support the development of reforms.

The government is looking to sharpen the OAIC’s teeth and after 5 years of the NDB scheme there is an expectation that organisations will understand and comply with their obligations or potentially face legal action.

For listed companies this makes it more important than ever that a cyber-incident response plan is put in place and regularly tested, built on the advice of external advisers and incorporating a well thought out communication strategy. Bringing in advisers with experience in crisis communication to support the internal team is strongly recommended. There is only one opportunity to get the response right so using it as an exercise to test whether or not the team can cope almost guarantees a disappointing outcome.


28 February 2024

Key Issues for Proxy Advisors in 2024


GILES RAFFERTY, Corporate Communication and Media Advisor An analysis of data collected by Proxy Advisory firm Glass Lewis on voting outcomes during the 2023 Australian AGM season reveals a record number of companies received strikes against their remuneration reports, there was a significant increase in the number and severity of dissenting votes against Directors and […]

Read More
29 November 2023

Winds of change – AASB draft climate standards


GILES RAFFERTY, Corporate Communications and Media Advisor “The biggest change to corporate reporting in a generation.”, is how the Australian Institute of Company Directors has described the Australian Governments ambitions to make climate-related disclosures mandatory for large businesses and financial institutions. Civil penalties planned to ensure climate reporting compliance The Government’s target is to have […]

Read More
29 November 2023

2023 a year of headwinds, inflation, and continued rate hikes


GILES RAFFERTY, Corporate Communications and Media Advisor It was in early May of 2023 that the World health organization announced Covid-19 was no longer a global health emergency. We are, however, still working through the economic disruption caused by COVID, compounded by other significant geo-political events, such as the ongoing war in Ukraine, which has helped to […]

Read More
28 February 2023

CEOs need to drive social change to build trust


GILES RAFFERTY, Corporate Communications and Media The findings of 2023 Edelman Trust Barometer were revealed at Davos in January, with the Australian cut of the data made public at the start of February. The Edelman global survey highlights concern around “severe polarisation” among respondents, which the PR firm interprets as people believing their society is […]

Read More
12 December 2022

Travelling at the speed of change, 2022 in review


GILES RAFFERTY, Corporate Communications and Media US founding father, Benjamin Franklin, said “nothing is certain except death and taxes”. Had he been in a more expansive mood he may have included ‘change’ as another certainty. 2022 has been a year of change. We welcomed Queen Elizabeth’s Platinum Jubilee and mourned her passing. We celebrated the […]

Read More
30 August 2022

Corporate access in the new norm


GILES RAFFERTY, Corporate Communications and Media Adviser The COVID-19 pandemic effectively eliminated in person Investor Relations (IR) meetings and events and accelerated the adoption and refinement of virtual interactions between companies and the investment community. Now, with travel restrictions removed or significantly eased and the WHO reporting global COVID cases falling 9% and deaths 15%, […]

Read More
30 August 2022

Accessing new media opportunities


GILES RAFFERTY, Corporate Communications and Media Adviser It is well understood that the media industry has been experiencing significant technological disruption with the emergence of digital, online and social media platforms. The recent 2022 Digital News Report, by the Reuters Institute and the University of Oxford, indicates the various shocks of the last few years, […]

Read More
28 February 2022

Distrust threatens societal stability


GILES RAFFERTY, Corporate Communications and Media Adviser One of the findings from the annual Edelman Trust Barometer survey is a cycle of distrust that is threatening societal stability both here in Australia and globally. The survey results were published on February 16th, a little over a week before Russia invaded the Ukraine. Australia trapped in […]

Read More
28 February 2022

Proxy advice – if it ain’t, broke don’t try to fix it


GILES RAFFERTY, Corporate Communications and Media Adviser The dust has settled following the short-lived federal regulations designed to impose new licensing and independence requirements on the Proxy Adviser industry. The now defunct rules were introduced as regulations by Federal Treasure Josh Frydenberg, just before Christmas last year, rather than as legislation that could have been […]

Read More
30 November 2021

FIRST Edition in 2021


GILES RAFFERTY, Corporate Communication and Media Adviser. 2021 is drawing to a close with a sense of COVID-19 déjà vu. In late 2020 a new COVID variant, labelled Delta, was first identified in India. The Delta variant is characterised by mutations to the ‘spike protein’ which make it highly transmissible. The Delta variant is thought […]

Read More
30 September 2021

Virtual AGMs


GILES RAFFERTY, Corporate Communication and Media Advisor Talking the talk at virtual AGMs As AGM season looms large, the Australian Federal Government has given clarity around what will be required to hold a virtual Annual General Meeting during the latter part of 2021. A key change, compared to the COVID-19 inspired temporary arrangements introduced in 2020, […]

Read More
31 May 2021

ESG at the Vanguard of proxy voting


GILES RAFFERTY, Corporate Communication and Media Advisor. The financial markets adage is if Wall Street sneezes other markets catch cold. So it is worth keeping an eye on what’s happening in US financial markets as trends there tend to inform decision making elsewhere. In this context we have been interested to note how Vanguard, one of […]

Read More
30 April 2021

Proxy Advisors in a time of COVID


GILES RAFFERTY, Corporate Communication and Media Advisor The Coronavirus pandemic continues to ravage the world, we canvassed the three main Proxy Advisory firms operating in Australia Ownership Matters, CGI Glass Lewis and ISS to get a sense of what impact corporate and government responses to the pandemic has had on governance and their voting recommendations. Widening […]

Read More
4 March 2021

Locking in the Trust premium


GILES RAFFERTY, Corporate Communication and Media Advisor Trust in Australian Institutions has surged during the Coronavirus pandemic to reach all-time highs.  This resurgence of trust means, in Australia,  the institutions of Business, Government, Media and NGO’s are all now viewed as competent where just 12 months ago only Business was seen to be so. Two institutions, […]

Read More
31 January 2021

Fink doubles down on climate


GILES RAFFERTY, Corporate Communication and Media Advisor Restating that climate risk is investment risk, Larry Fink, the Founder, Chairman and CEO of Blackrock, the world’s biggest and arguably most powerful investor, is calling for companies to share their plans for the transition to a net zero economy in his annual letter to CEOs. Mr Fink […]

Read More
30 October 2020

Video with vim and vigour


GILES RAFFERTY, Corporate Communications and Media Advisor The camera never lies! A broad statement that still holds true despite the incredible advances in software to manipulate digital imagery. The cameras built into smartphones and laptops are amazingly sophisticated but are no guarantee that a video presentation will look good or be engaging. If you don’t […]

Read More
28 July 2020

Corporate Purpose during the Coronavirus pandemic


GILES RAFFERTY, Corporate Communications and Media Advisor, writing for the Winter 2020 Issue of Listed@ASX. What does the Coronavirus pandemic and the ‘new normal’, that is expected to emerge in its wake, mean for a Company’s purpose? As the pandemic surges across the globe many senior corporate leaders will, rightly, view the immediate purpose of […]

Read More
30 June 2020

A new number 3 share registry


GILES RAFFERTY, Corporate Communications. An interview with Ben Kay, Executive Director, Automic At FIRST Advisers our shareholder analytics team works with all registries in the delivery of beneficial ownership analysis reports to our clients. We have watched the increasing penetration of Automic Group as a new player in the registry market in recent years and […]

Read More
28 May 2020

Designs on Annual Reporting


GILES RAFFERTY, Corporate Communications. It is time to think about Annual Reports and then to think again. While an Annual Report must include content required by the Corporations Act and the ASX listing rules,that doesn’t mean we should limit our thinking to just meeting that objective. It is right and proper for the compulsory materials, […]

Read More
28 February 2020

Australian CEOs need to take a stand


GILES RAFFERTY, Corporate Communications and Media Advisor Australian’s don’t trust business. This is a key finding of the Edelman Trust Barometer, published on 19 February, which has been measuring levels of trust in business, Government, the media and NGOs for the past 20 years. It will be little comfort to Australian business leaders to know […]

Read More
30 January 2020

Time to confront climate change


GILES RAFFERTY, Corporate Communications and Media Advisor Every Government, company and shareholder must confront climate change according to Larry Fink, CEO and Chairman of BlackRock, the world’s largest asset manager. In his annual letter to CEO’s, Mr Fink says a rapidly growing awareness amongst investment market participants of the risks climate change poses to economic […]

Read More
29 November 2019

CORPORATE PURPOSE


GILES RAFFERTY, Corporate Communications and Media Advisor ‘The more things change, the more they stay the same’ is an adage that could easily be applied to the re-prioritising of a company’s Purpose as the underpinning of its culture and long term, sustainable growth. Only last August, The Business Roundtable (BRT) an American association whose members […]

Read More
28 November 2019

Acclimatising to a new normal? – 2019 in review


GILES RAFFERTY, Corporate Communications and Media Advisor 2019 is bookended by environmental challenges. The year began with massive fish mortalities in the Murray Darling and is ending with a devastating, early bushfire season that has impacted every state in the country. In between, on the global stage, climate activist Greta Thunberg made an impassioned speech […]

Read More
30 October 2019

ASX tightens listing rules


GILES RAFFERTY, Corporate Communications and Media Advisor “It’s important that ASX keeps evolving the listing rules so they remain contemporary, address emerging compliance issues, and continue to serve the interests of issuers, investors, and the Australian economy.” Kevin Lewis, ASX Chief Compliance Officer. A range of changes to the ASX listing rules will come into […]

Read More
30 September 2019

Five ways to improve an IR website


An Investor Relations website is the critical channel through which to communicate educate and engage with investors. It should be more than a demonstration of compliance with the Corporations Act 2001 and a listed company’s disclosure obligations. It is a gateway through which to tell a company’s investment story so it is equally well understood […]

Read More
29 June 2019

Leading with Purpose


GILES RAFFERTY, Corporate Communications and Media Advisor We are fast approaching the first reporting season under the 4thedition of the ASX Corporate Governance Principles and Recommendations. An aspect of the new Principles and Recommendations, which we wrote about in our March 28th ‘Purpose for the Board’ blog, is the elevation of responsibility for linking a company’s […]

Read More
4 June 2019

Time for Proxy Advisors


GILES RAFFERTY, Corporate Communications and Media Advisor AGM season may seem a long way off for many ASX listed companies but June and July are prime time for engaging with proxy advisors in advance of the peak months of proxy season, between August and October. Proxy advisors play a vital role in helping inform investment […]

Read More
1 May 2019

The importance of good design


GOOD DESIGN is the difference between telling someone and showing them. It can be the difference between informing your audience or convincing them. A carefully composed image, an effectively executed graphic concept or a thoughtfully constructed layout can convert worthy content into memorable messages. We sat down with Campbell van Venrooy, a graphic designer with […]

Read More
28 March 2019

Purpose for the Board


GILES RAFFERTY, Corporate Communications and Media Advisor A listed company’s Purpose is now, very much, a matter for Board consideration. The latest edition of the ASX’s Corporate Governance Principles and Recommendations makes it clear the Board is responsible for linking a company’s Purpose to its strategic goals. Principle 3 states a listed entity should instil a […]

Read More
4 March 2019

Cybersecurity: reported data breaches surge almost 700% in 2018


As we mark the one-year anniversary of the introduction of the Federal Government’s Notifiable Data Breach (NDB) scheme, the headlines focused on cybersecurity breaches seem to be coming thick and fast. The attack in early February 2019 on the Australian Federal Parliament’s computer network, has been identified by Prime Minister Scott Morrison as the work […]

Read More
31 January 2019

The importance of being purposeful


A well understood and expressed corporate purpose drives long term value. This is why purpose, as a driver of profitability, was a central theme of the 2019 letter from Larry Fink, CEO of Blackrock, the world’s largest investment manager, to the Board’s and senior managers of companies Blackrock has holdings in. It has also been the […]

Read More
29 May 2018

ASX to make purpose key to good governance


Giles Rafferty, Corporate Communications and Media Advisor The Financial Services Royal Commission is shining a light on governance failures at some of Australia’s largest businesses. It has also revealed a clear need to restore trust in Australian listed companies. The ASX Corporate Governance Council is seeking to address the trust deficit by updating the Principles and Recommendations […]

Read More
30 April 2018

Annual reports – bring it all together


Giles Rafferty, Corporate Communications and Media Adviser The world of investor relations is getting faster, busier and noisier. As soon as news hits the ASX announcements platform it is time to update the company website; amplify the news with tweets and social posts; push out the media release; set up interviews; live stream webcasts; monitor […]

Read More
5 April 2018

Engaging Retail investors – work smarter not harder


It is generally accepted, at least in the Australian equity market, that Retail Investors play an important role in the construction of a balanced shareholder register. The characteristics that make them attractive are that they generally invest for the long term, are volatility averse and focus on a company’s fundamentals. However these traits can also […]

Read More
28 February 2018

Doing it on Purpose


Giles Rafferty, Corporate Communications Doing it on Purpose Having a Corporate Purpose must be one of the oldest, latest things. There is good degree of noise around the concept of ‘Corporate Purpose’ and it may feel like it has become a buzz word, but it is much more than that and always has been. A […]

Read More

Archives