Can you prevent a hack?

Erin Robertson • November 16, 2022

In the wake of the Optus data leak, legislation before Parliament will lift the maximum fine for serious or repeated breaches of the Privacy Act from $2.2m to up to $50m. But there are no guarantees that even the strongest safety measures will prevent an attack. So, what does that mean for business and their customers?

Legislation before Parliament will lift penalties for serious or repeated privacy breaches, provide new powers to the Australian Information Commissioner, require entities to provide detailed data to the Information Commissioner to assess public risk, and give the regulator greater information sharing powers. In a statement, Attorney General Mark Dreyfus said, “When Australians are asked to hand over their personal data they have a right to expect it will be protected.” But the question is, can any business claim that customer data will be protected from hackers?


If a customer needs to disclose their personal information to your business to work with you, at the point the data is collected, your business is the custodian of that data. A duty of care exists from the moment the data is collected to the point the information is no longer required and destroyed.

 

The Privacy Act requires organisations to take “reasonable steps” to protect the data collected. ‘Reasonable’ steps “requires the existence of facts which are sufficient to [persuade] a reasonable person.” That is, in the event of a data breach, the business will need to prove the steps they have taken to protect client data.

Lessons from RI Advice

Australian Competition and Consumer Commission v RI Advice Group Pty Ltd was a landmark case. While specific to the obligations of an Australian Financial Services License (AFSL), it demonstrates that ASIC are willing to pursue not just companies that breach their duty of care but the directors and officers involved.


RI advice is a financial services company that, through its AFSL, authorised representatives to provide financial services. As you would expect, as part of providing financial services, the authorised representatives received, stored and accessed confidential and sensitive personal information. Between June 2014 and May 2020, nine cybersecurity incidents occurred at practices of RI Advice’s Authorised Representatives. Enquiries following the incidents revealed:

  • Computer systems which did not have up-to-date antivirus software installed and operating
  • No filtering or quarantining of emails
  • No backup systems or back-ups being performed; and
  • Poor password practices including sharing of passwords between employees, use of default passwords, passwords and other security details being held in easily accessible places or being known by third parties.


RI Advice took steps to manage their cybersecurity introducing a cyber resilience program, controls and risk management measures for its representatives including training, incident reporting, and contractual professional standard terms, but by its own admission, it took too long to implement.


RI Advice was ordered to pay $750,000 towards ASIC's costs. Handing down the decision Justice Rofe said, “It is not possible to reduce cybersecurity risk to zero, but it is possible to materially reduce cybersecurity risk through adequate cybersecurity documentation and controls to an acceptable level.”


February 16, 2026
When clients sell a long-held family home, they may be able to channel part of the proceeds into superannuation by using the downsizer contribution rules.
February 16, 2026
As a business owner or investor, time is always tight...
February 16, 2026
Electric vehicles (EVs) are no longer a niche choice...
February 10, 2026
For many Australians, a holiday home does double duty...
By Erin Robertson December 4, 2025
For years, businesses have been moving away from cash – and for good reason.
By Erin Robertson December 3, 2025
The ATO’s rules on self-education expenses are strict, and the line between “deductible” and “non-deductible” can be thin. Getting it right could mean thousands back in your pocket; getting it wrong could mean an ATO adjustment, plus interest and penalties.
By Erin Robertson December 2, 2025
Running, or deciding to set up a self-managed super fund (SMSF) gives you control, but it also brings legal responsibilities.
By Erin Robertson December 1, 2025
If you run a business, you already know the juggling act that comes with managing the payroll process — paying staff on time, managing cash flow, and staying compliant.
By Erin Robertson November 11, 2025
Many businesses hold critical data that poses significant risk to both businesses and their customers if the data they hold is not safeguarded from cybersecurity threats.
By Erin Robertson November 11, 2025
A new Bill before Parliament – the Treasury Laws Amendment (Strengthening Financial Systems and Other Measures) Bill 2025 – proposes several key changes that could affect small businesses, listed companies, and the not-for-profit sector.
Show More