10.4 Cybersecurity, Privacy Principles (APPs), and Critical Infrastructure

Key Takeaways

  • Cybersecurity is a critical enterprise risk and board-level fiduciary responsibility, not merely an operational IT function, as established in the landmark Federal Court decision ASIC v RI Advice Group Pty Ltd [2022].
  • The Privacy Act 1988 (Cth) governs the handling of personal and sensitive information through 13 Australian Privacy Principles (APPs), with APP 11 mandating 'reasonable steps' to protect data and destroy/de-identify it when no longer required.
  • Under the Notifiable Data Breaches (NDB) Scheme (Part IIIC), an entity must conduct an assessment within 30 days of suspecting an eligible data breach and notify both the OAIC and affected individuals if unauthorized access/disclosure is likely to result in serious harm.
  • The Security of Critical Infrastructure Act 2018 (SOCI Act) imposes mandatory incident reporting to the ACSC/ASD within 12 hours for critical cyber incidents and 72 hours for other incidents across 11 vital infrastructure sectors.
  • Professional accountants play an indispensable governance role in data asset valuation under AASB 138, privacy impact assessments, general IT control (GITC) audits, and quantifying cyber risk exposures for board risk committees.
Last updated: September 2026

10.4 Cybersecurity, Privacy Principles (APPs), and Critical Infrastructure

Core Principle: In an increasingly digitized global economy, corporate data assets represent both immense strategic value and catastrophic financial, regulatory, and reputational liability. Australian corporate law and prudential standards firmly establish that cybersecurity is a core governance and fiduciary responsibility of the board of directors and executive management, not an operational issue delegated solely to technical IT staff. Boards must implement robust cyber resilience frameworks, comply with the 13 Australian Privacy Principles (APPs) under the Privacy Act 1988, manage mandatory reporting under the Notifiable Data Breaches (NDB) Scheme, and adhere to strict notification rules under the Security of Critical Infrastructure Act 2018 (SOCI Act).


1. Board and Executive Governance of Cyber Risk

The Shift from Operational IT to Strategic Fiduciary Risk

Historically, corporate boards treated information technology and digital security as operational support functions relegated to Chief Information Officers (CIOs) or external vendors. A succession of catastrophic global and Australian cyber breaches—compromising millions of customer identity records and disrupting essential services—has dismantled this obsolete paradigm.

Today, cyber risk encompasses:

  • Systemic Business Disruption: Ransomware attacks paralyzing production, supply chains, and transaction clearing;
  • Financial and Capital Destruction: Direct extortion, forensic remediation costs, regulatory fines, and equity value impairment;
  • Litigation and Class Action Exposure: Representative shareholder and consumer class actions alleging negligence and breach of privacy;
  • Reputational and Brand Erosion: Loss of consumer trust and commercial counterparty confidence.

Under Principle 7 of the ASX Corporate Governance Principles and Recommendations, listed entities must recognize and manage material operational, non-financial, and technology-related risks. Boards that fail to maintain continuous cyber risk oversight violate their fundamental duty of care and diligence under Section 180(1) of the Corporations Act 2001.

+-------------------------------------------------------------------------------------------------+
|                            THE THREE PILLARS OF CYBER GOVERNANCE                                |
+-------------------------------------------------------------------------------------------------+
| 1. BOARD OVERSIGHT & CULTURE        | 2. ENTERPRISE DEFENCE ARCHITECTURE                        |
| Cyber risk appetite, continuous     | Implementation of technical standards (Essential Eight,   |
| reporting, simulated crisis drills, | zero-trust, MFA, encryption), continuous vulnerability    |
| and independent third-line audits.  | scanning, and supply chain vendor due diligence.          |
+-------------------------------------+-----------------------------------------------------------+
| 3. STATUTORY COMPLIANCE & INCIDENT RESPONSE (NDB, APPs, SOCI Act, APRA CPS 234)                 |
| Pre-established breach playbooks, legal retainers, forensic partnerships, and 12h/72h reporting.|
+-------------------------------------------------------------------------------------------------+

Landmark Legal Precedent: ASIC v RI Advice Group Pty Ltd [2022] FCA 496

The legal milestone defining Australian cyber governance occurred in May 2022, when the Federal Court delivered its judgment in ASIC v RI Advice Group Pty Ltd.

  • Factual Background: RI Advice Group, an Australian Financial Services Licensee (AFSL) and subsidiary of a major financial institution, oversaw a network of corporate authorized representative (CAR) financial practices. Over a six-year period (2014–2020), multiple CAR practices suffered significant cybersecurity incidents, including brute-force ransomware attacks, compromised email accounts, and unauthorized access to thousands of clients' sensitive personal and financial data.
  • Regulatory Action: ASIC initiated civil penalty proceedings, arguing that RI Advice breached Section 912A(1)(a) and (h) of the Corporations Act 2001, which mandates that an AFSL must do all things necessary to ensure financial services are provided "efficiently, honestly, and fairly," and have adequate risk management systems.
  • The Federal Court's Ruling: The Federal Court held that RI Advice had breached its statutory obligations. Justice Rofe established that cyber risk management is not optional; financial services licensees (and by extension, corporate directors) must have adequate, up-to-date, and operational cybersecurity documentation, controls, and risk management systems across their operations and distributed networks.
  • Key Takeaway for Directors and Accountants: The court affirmed that an entity cannot avoid liability by claiming it relied on decentralized representatives or third-party contractors. The board retains an ultimate, non-delegable duty to implement and enforce minimum cybersecurity baseline standards.

Prudential Standard CPS 234 (Information Security)

For APRA-regulated institutions (banks, insurers, superannuation funds), Prudential Standard CPS 234 establishes strict statutory mandates:

  • Ultimate Board Accountability: The governing board is explicitly responsible for ensuring the information security of the entire regulated institution;
  • Information Security Capability: Must maintain cyber defenses commensurate with the size and extent of threats to information assets;
  • Third-Party Service Providers: Must evaluate and monitor the cyber controls of all external supply chain and cloud service vendors;
  • 72-Hour APRA Notification: Must notify APRA within 72 hours of becoming aware of an information security incident that has material potential to impact the interests of depositors, policyholders, or beneficiaries.

1. The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)

The federal privacy framework is codified in the Privacy Act 1988 (Cth), which applies to APP entities: private sector businesses and non-profits with an annual turnover exceeding $3 million, all private health service providers, credit reporting bodies, and Commonwealth government agencies.

Personal Information vs. Sensitive Information

Understanding the distinction between these two statutory classifications is vital for risk assessment and compliance:

+-------------------------------------------------------------------------------------------------+
|                       PERSONAL INFORMATION VS. SENSITIVE INFORMATION                            |
+---------------------------------------+---------------------------------------------------------+
| PERSONAL INFORMATION (Section 6)      | SENSITIVE INFORMATION (Section 6 - Higher Tier)         |
+---------------------------------------+---------------------------------------------------------+
| Information or an opinion about an    | A subset of personal information carrying heightened    |
| identified individual, or an          | risk of harm, discrimination, or distress:              |
| individual who is reasonably          | * Health, medical, and biometric information            |
| identifiable, whether true or not,    | * Racial or ethnic origin                               |
| and whether recorded in material form.| * Political opinions and association memberships        |
|                                       | * Religious beliefs or philosophical affiliations       |
| * Examples: Full name, home address,  | * Professional or trade union memberships               |
|   email, date of birth, driver's      | * Criminal history and sexual orientation               |
|   license, tax file number (TFN).     | RULE: Requires EXPLICIT CONSENT to collect (APP 3) and  |
|                                       | attracts heightened security controls under APP 11.     |
+---------------------------------------+---------------------------------------------------------+

Core Australian Privacy Principles Relevant to Governance and Accounting

The Privacy Act contains 13 Australian Privacy Principles (APPs) set out in Schedule 1. The following principles represent primary areas of regulatory enforcement:

PrincipleStatutory RequirementGovernance & Accounting Focus
APP 1: Open and Transparent ManagementMust have an up-to-date, publicly available Privacy Policy and establish internal governance practices to ensure compliance.Documented data flows, privacy officer appointment, and staff compliance training.
APP 3: Collection of Personal InformationCan only collect personal information that is reasonably necessary for an entity's commercial functions.Anti-data-hoarding principle. Do not collect superfluous personal data from customers.
APP 5: Notification of CollectionMust notify individuals at or before collection of the entity's identity, collection purposes, and consequences of non-collection.Clear, unambiguous privacy collection notices at all digital and physical entry points.
APP 6: Use or DisclosurePersonal information collected for a primary purpose must not be used/disclosed for a secondary purpose without consent.Prohibits selling or sharing customer data with third-party advertisers or data brokers without explicit opt-in consent.
APP 8: Cross-Border DisclosuresMust take reasonable steps to ensure overseas recipients do not breach the APPs before disclosing personal data overseas.Cloud hosting contracts (AWS, Microsoft Azure, Google Cloud). Entity remains vicariously liable for overseas breaches.
APP 11: Security of Personal InformationMust take reasonable steps to protect information from misuse, interference, loss, unauthorized access, modification, or disclosure.<br/>APP 11.2: Must destroy or de-identify data when no longer needed for any lawful purpose.Critical corporate vulnerability: failure to purge historical customer records (driver's licenses, passports) after commercial retention requirements expire.

Massive Escalation of Privacy Penalties

Following catastrophic corporate data breaches in 2022, the Australian Parliament enacted the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022, dramatically increasing the maximum civil penalties for serious or repeated privacy breaches under Section 13G.

For corporations, the maximum penalty is now the GREATER of:

  1. $50,000,000;
  2. Three times the value of the benefit obtained directly or indirectly from the contravention; or
  3. If the court cannot determine the benefit, 30% of the entity's adjusted turnover during the breach turnover period (minimum 12 months).

1. The Notifiable Data Breaches (NDB) Scheme (Part IIIC)

Established under Part IIIC of the Privacy Act 1988, the Notifiable Data Breaches (NDB) Scheme mandates that APP entities notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when an eligible data breach occurs.

Definition of an Eligible Data Breach (Section 26WE)

An eligible data breach occurs when three cumulative conditions are met:

  1. Unauthorized Access, Disclosure, or Loss: There is unauthorized access to, or unauthorized disclosure of, personal information held by an entity (or information is lost in circumstances where unauthorized access or disclosure is likely to occur);
  2. Likelihood of Serious Harm: A reasonable person would conclude that the access or disclosure is likely to result in serious harm to any of the individuals to whom the information relates; and
  3. Failure of Remedial Action: The entity has not been able to prevent the likely risk of serious harm with prompt remedial action.
+-------------------------------------------------------------------------------------------------+
|                        WHAT CONSTITUTES 'SERIOUS HARM' UNDER SECTION 26WG?                      |
+-------------------------------------------------------------------------------------------------+
| Serious harm is evaluated objectively and encompasses:                                          |
|                                                                                                 |
|   * Severe Financial Loss: Identity theft, credit card fraud, unauthorized loan creation.        |
|   * Psychological & Physical Harm: Stalking, extortion, harassment, domestic violence threats.  |
|   * Severe Reputational Damage: Exposure of sensitive medical conditions, sexual orientation,  |
|     or disciplinary records.                                                                    |
+-------------------------------------------------------------------------------------------------+

The Remedial Action Safe Harbour (Sections 26WF and 26WG)

If an entity takes immediate remedial action that neutralizes the potential harm before any individual suffers serious consequences, the breach is deemed NOT an eligible data breach, and mandatory notification is not required.

  • Example: An employee accidentally emails an unencrypted customer spreadsheet containing 500 tax file numbers to an external third party. Within 15 minutes, IT contacts the recipient, confirms the email was not opened, executes a remote wipe/retraction, and obtains a signed confirmation of deletion. Because immediate remedial action eliminated the likelihood of serious harm, the NDB reporting requirement is not triggered (though internal logging is required).

The 30-Day Mandatory Assessment Requirement (Section 26WH)

Where an entity has reasonable grounds to suspect (but does not yet know) that an eligible data breach has occurred, it cannot delay. Under Section 26WH, the entity must:

  1. Carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe the incident is an eligible data breach; and
  2. Take all reasonable steps to ensure the assessment is completed within 30 calendar days after the entity first suspected the breach.

Mandatory Notification Obligations (Section 26WK & 26WL)

Once an entity forms reasonable grounds to believe an eligible data breach has occurred, it must:

  1. Notify the OAIC: Prepare an official statement in the prescribed form and submit it to the Information Commissioner as soon as practicable;
  2. Notify Affected Individuals: Notify the affected individuals directly (via email, SMS, or letter) detailing:
    • The identity and contact details of the entity;
    • A description of the eligible data breach;
    • The specific kinds of personal information accessed or disclosed; and
    • Actionable recommendations regarding the steps individuals should take to mitigate potential harm (e.g., placing fraud alerts on credit files, replacing compromised driver's licenses, changing passwords).

1. The Security of Critical Infrastructure Act 2018 (SOCI Act)

Recognizing that cyber warfare, state-sponsored cyber espionage, and ransomware cartels threaten national sovereignty and essential utility networks, Australia significantly reformed the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act).

Scope: The 11 Critical Infrastructure Sectors

The SOCI Act applies to "responsible entities" operating assets across 11 vital national sectors:

  1. Energy (electricity, gas, liquid fuels)
  2. Communications (telecommunications, internet infrastructure)
  3. Financial Services and Markets (banking, superannuation, stock exchanges)
  4. Data Storage and Processing (major cloud data centers)
  5. Healthcare and Medical (major hospitals, pharmaceutical supply)
  6. Higher Education and Research
  7. Food and Grocery (major national distribution hubs)
  8. Transport (ports, aviation, freight rail)
  9. Water and Sewerage
  10. Space Technology
  11. Defence Industry
+-------------------------------------------------------------------------------------------------+
|                            SOCI ACT MANDATORY CYBER INCIDENT REPORTING                          |
+-----------------------------------+-------------------------------------------------------------+
| INCIDENT SEVERITY LEVEL           | STATUTORY DEADLINE & REPORTING CHANNEL                      |
+-----------------------------------+-------------------------------------------------------------+
| CRITICAL CYBER SECURITY INCIDENT  | MANDATORY REPORTING WITHIN 12 HOURS                         |
| An incident that has occurred or  | Must notify the Australian Cyber Security Centre (ACSC)     |
| is occurring that has a 'critical | within the Australian Signals Directorate (ASD).            |
| impact' on the availability,      |                                                             |
| integrity, or reliability of an   | Initial oral report within 12 hours, followed by written    |
| asset (e.g., grid blackout,       | submission within 84 hours.                                 |
| hospital IT shutdown).            |                                                             |
+-----------------------------------+-------------------------------------------------------------+
| OTHER CYBER SECURITY INCIDENTS    | MANDATORY REPORTING WITHIN 72 HOURS                         |
| An incident that has an impact on | Must notify the ACSC / ASD within 72 hours of becoming     |
| the asset that is significant,    | aware of the incident.                                      |
| but does not meet the 'critical'  |                                                             |
| threshold.                        |                                                             |
+-----------------------------------+-------------------------------------------------------------+

Critical Infrastructure Risk Management Program (CIRMP)

Responsible entities must develop, maintain, and comply with a written Critical Infrastructure Risk Management Program (CIRMP). The CIRMP must identify material operational risks across four hazard domains: cyber and information security, personnel hazards, physical and natural hazards, and supply chain vulnerabilities. The board must submit an annual report to the relevant regulator certifying compliance.

1. The Professional Accountant's Role in Data Governance and Cyber Risk

Professional accountants, both in financial reporting and internal audit roles, play an indispensable part in cyber and data governance:

1. Data Asset Valuation vs. Unquantified Liabilities (AASB 138)

Under AASB 138 / IAS 38 (Intangible Assets), internally generated customer lists and user data are prohibited from being capitalized on balance sheets, yet data is often described as an organization's "most valuable intangible asset." Conversely, in the post-breach environment, data hoarding is a massive unrecorded liability. Accountants must evaluate whether legacy datasets stored without commercial justification violate APP 11.2, exposing the entity to multi-million-dollar fines and remediation liabilities.

2. General IT Controls (GITCs) and Internal Audit Testing

Accountants in internal audit (Third Line) evaluate the operational efficacy of General IT Controls (GITCs) across four domains:

  • Access Security: User access provisioning, timely de-provisioning upon employee departure, privileged access management (PAM), and mandatory multi-factor authentication (MFA);
  • Change Management: Formal segregation of duties between software developers and production environments;
  • System Operations: Backup redundancy, immutable cloud backups, and disaster recovery testing;
  • Patch and Vulnerability Management: Rigorous monitoring of known vulnerabilities and system patching cadences.

3. Cyber Due Diligence in Mergers and Acquisitions (M&A)

When an entity acquires a target business, it acquires its cyber liabilities and dormant network intrusions. Accountants leading due diligence must audit the target's data inventory, review historical NDB logs, inspect compliance with APPs, and price in necessary post-acquisition remediation capital expenditure.


2. Comparative Compliance Matrix: Cyber and Privacy Frameworks

Governance DimensionPrivacy Act 1988 (APPs)NDB Scheme (Part IIIC)SOCI Act 2018APRA CPS 234
Primary RegulatorOAICOAICACSC / Home AffairsAPRA
Application ScopeEntities with turnover > $3M, health providers, credit bureaus.Same as Privacy Act (APP entities).Responsible entities across 11 critical sectors.Banks, general/life insurers, superannuation trustees.
Core ObligationComply with 13 APPs; protect and purge data (APP 11).Assess breach within 30 days; notify OAIC & individuals of serious harm.Maintain CIRMP; notify critical cyber incidents.Board oversight; ensure security capabilities of third parties.
Incident Reporting DeadlineOngoing compliance reporting."As soon as practicable" after 30-day assessment.12 hours (Critical) / 72 hours (Other).72 hours to APRA.
Maximum Financial PenaltiesGreater of $50M, 3x benefit, or 30% adjusted turnover.Subsumed under Privacy Act civil penalties.Significant civil penalties; direct government intervention.Enforceable undertakings, license conditions, capital add-ons.

3. Critical Distinctions and Exam Traps

⚠️ Exam Alert: Common Cyber and Privacy Pitfalls

  • Trap 1: Assuming IT Has Sole Legal Responsibility. Directors cannot defend themselves against ASIC or APRA enforcement by claiming they are not software engineers. The RI Advice Federal Court ruling confirms that boards have an affirmative legal duty under Section 180(1) and Section 912A to understand, resource, and critically monitor cyber risk.
  • Trap 2: Believing Every Lost Device Triggers an NDB Notification. Under Section 26WE, an eligible data breach requires that unauthorized access or disclosure is likely to result in serious harm. If an encrypted, password-protected laptop is lost and remotely wiped before access can occur, or if the lost file contains only publicly accessible marketing brochures, no serious harm is likely, and an NDB notification is not legally required.
  • Trap 3: Overlooking the APP 11.2 Purge Mandate. Organizations frequently breach APP 11 not by failing to install firewalls, but by hoarding historical customer identification data for years after the transaction closed. APP 11.2 legally mandates the destruction or de-identification of personal information once it is no longer required for any lawful purpose.
  • Trap 4: Confusing SOCI Act Timeframes with NDB Timeframes. The SOCI Act requires mandatory cyber notification within 12 hours for critical incidents and 72 hours for other incidents to the ACSC. In contrast, the NDB scheme provides up to 30 calendar days to assess an incident before issuing notifications to the OAIC and affected individuals.
Loading diagram...
Notifiable Data Breaches (NDB) Assessment and Escalation Workflow
Test Your Knowledge

In the landmark Federal Court case ASIC v RI Advice Group Pty Ltd [2022] FCA 496, what fundamental legal principle was established regarding the corporate governance of cybersecurity?

A
B
C
D
Test Your Knowledge

An employee at an Australian financial planning firm accidentally emails an unencrypted spreadsheet containing the tax file numbers, dates of birth, and bank account details of 400 high-net-worth clients to an external public mailing list. Within 20 minutes, the firm's IT security team detects the transmission, initiates a remote purge, verifies that the email server did not deliver the message to any external inbox, and confirms that no third party accessed the file. How does the Notifiable Data Breaches (NDB) Scheme under Part IIIC of the Privacy Act 1988 apply to this event?

A
B
C
D
Test Your Knowledge

A major Australian electricity transmission network operator discovers at 2:00 AM on a Saturday that malicious ransomware has infected its operational SCADA control systems, causing an active blackout across half a capital city. Which of the following correctly outlines the entity's statutory cyber incident reporting obligation under the Security of Critical Infrastructure Act 2018 (SOCI Act)?

A
B
C
D