Cyber Breach Notification Guide for Australian Businesses

IT Admin 14 July 2026
Cyber Breach Notification Guide for Australian Businesses

A suspicious login alert, a lost laptop or an email sent to the wrong recipient can become far more than an IT problem. If personal information has been accessed, disclosed or lost, a business may face urgent obligations to assess the incident and, in some cases, notify affected people and the Office of the Australian Information Commissioner (OAIC). This cyber breach notification guide explains the practical and legal steps Australian businesses should take when time matters.

The right response protects people whose information is at risk, preserves evidence and gives your business the best chance to manage legal, financial and reputational consequences. The facts of each incident matter, so early legal advice can be particularly valuable where the breach involves sensitive information, a ransomware demand, employee misconduct or a third-party supplier.

What is a notifiable data breach?

Under Australia’s Notifiable Data Breaches scheme, an organisation covered by the Privacy Act 1988 may need to notify if an eligible data breach has occurred. Broadly, this involves unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to one or more individuals.

Personal information can include names, contact details, dates of birth, bank account information, Medicare details, passport information, customer records and employee files. Sensitive information, such as health information, criminal history, biometric data or religious beliefs, may create a higher risk of serious harm if exposed.

Not every cyber incident is notifiable. A phishing email received by an employee, for example, is not automatically a reportable breach. The key questions are whether personal information was actually compromised, whether the risk of serious harm is likely, and whether remedial action has removed that risk before serious harm occurs.

Many private-sector organisations with an annual turnover above $3 million are covered by the Privacy Act. However, some smaller businesses are also covered, including health service providers and businesses that trade in personal information. Other legal and contractual duties may apply even where the Notifiable Data Breaches scheme does not. This is why relying on turnover alone can be risky.

Cyber breach notification guide: the first 24 hours

A rushed public statement can create problems, but delay can be equally damaging. The first day should focus on containment, preservation of evidence and a clear assessment process.

Start by taking reasonable steps to stop further unauthorised access. This may mean disabling compromised accounts, resetting passwords, isolating affected systems, revoking remote access or asking an IT provider to secure backups. Avoid deleting emails, logs or devices that may help establish what happened, who was affected and whether data was taken.

Your internal response team should then identify the incident lead and bring together the people who need to act. Depending on the business, this may include a director, IT provider, privacy officer, insurer, HR representative and legal adviser. Communications should be carefully managed. Staff should know how to escalate enquiries, but should not speculate about the cause, scope or affected individuals.

At this stage, record the known facts and the actions taken. A contemporaneous incident log can be vital later if regulators, customers, insurers or other parties ask how the business responded.

Where a breach may involve criminal activity, such as hacking, identity theft, fraud or extortion, consider whether a report to the Australian Cyber Security Centre or police is appropriate. A ransomware incident raises additional issues. Paying a demand does not guarantee that data will be returned or deleted, and it may not remove notification obligations. Specialist legal and cyber security advice should be obtained before making decisions that could affect the business or its customers.

Assessing whether serious harm is likely

If there are reasonable grounds to suspect an eligible data breach, an assessment must generally be completed within 30 days. That does not mean a business should wait 30 days before acting. The assessment should begin promptly and be conducted efficiently.

The likelihood of serious harm depends on the context. Consider the type and sensitivity of the information, whether it was protected by effective encryption, who may have accessed it, the likely intention of that person, and whether the information can be used for identity theft, financial fraud, physical harm, humiliation or discrimination.

For example, an encrypted device that is lost but cannot be accessed may present a very different risk from an unencrypted spreadsheet containing customer names, addresses, licence details and payment information sent to an unknown recipient. Similarly, a misdirected email to a trusted professional who confirms permanent deletion may be capable of remediation. A database accessed by an unknown attacker may require a more cautious approach.

The analysis should be evidence-based, not based on assumptions or a desire to avoid difficult customer conversations. If you cannot establish that the risk has been removed, notification may be required.

When and how to notify affected people

Where an eligible data breach is confirmed, organisations must notify the OAIC and affected individuals as soon as practicable. The notice should clearly describe the breach, identify the information involved and set out practical recommendations for people to reduce their risk.

For an individual whose identity documents or banking details may be exposed, useful recommendations may include changing passwords, contacting their financial institution, monitoring accounts and being alert to scams. If health or highly personal information is involved, communications should be respectful, direct and tailored to the nature of the potential harm.

The notice must not minimise the incident or make promises the business cannot keep. At the same time, it should avoid unnecessary technical detail that confuses recipients or creates further security risks. Clear language is usually best: what happened, what information may be involved, what you have done, what the person can do, and how they can contact the business.

Direct notification is generally expected where it is practicable to contact affected individuals. If that is not practicable, substitute notification may be used, such as publishing a statement on the business website and taking reasonable steps to publicise it. Whether direct contact is practical will depend on the size of the incident, the quality of contact records and the urgency of the risk.

Common mistakes that make a breach worse

Businesses under pressure often make avoidable errors. Treating the issue as only an IT outage is one of them. A breach can involve privacy law, contracts, employment obligations, insurance requirements, consumer expectations and potential disputes with suppliers.

Another common mistake is failing to check contractual notification clauses. A client agreement, software contract or managed services agreement may require notice within a particular timeframe, even if the legal threshold for a notifiable data breach has not been met. Delayed notice can create a separate contractual risk.

It is also unwise to send a broad all-staff or all-customer email before the facts are known. Premature communications can cause unnecessary alarm, compromise an investigation or contain inaccurate information. A controlled response does not mean hiding the issue. It means communicating honestly once the business has a sound factual basis and a plan to support those affected.

Finally, do not assume a vendor is solely responsible because its platform was involved. If your business collected or controls the personal information, your own obligations may remain. Review the supplier’s role, security commitments, reporting duties and cooperation obligations without delay.

Build a response plan before an incident

The strongest breach response begins before a breach occurs. A written incident response plan should identify decision-makers, emergency contacts, external IT support, legal advisers, insurer notification requirements and the process for documenting assessments and notifications.

Staff training also matters. Many breaches begin with a fraudulent email, compromised password or a simple mistake in handling information. Training should be practical and repeated, not a one-off exercise. Employees need to know how to recognise suspicious activity and report it immediately without fear of blame.

Businesses should also review what personal information they collect, where it is stored, who can access it and how long it is retained. Holding less unnecessary information can reduce the impact of a future incident. Security measures should match the sensitivity of the data and the realistic threats faced by the business.

A cyber breach is stressful, particularly for small and medium-sized businesses without a dedicated privacy or security team. Prompt action, careful assessment and honest communication can make a meaningful difference. If your business has experienced a suspected breach or needs help preparing a response plan, SDC Lawyers can provide practical legal guidance tailored to the circumstances.