Insight

5 Key Actions Your Business Can Take to Manage Data Breach Risk

Data breach incidents are an unfortunate reality of 21st century life. A recent study of data breach incidents in Australia found that, on average, a cyber breach costs business $2.82 million to rectify.

PL

Written by Philip Catania & Tim Lee

Published: August 2, 2015

Data breach incidents are an unfortunate reality of 21st century life. A recent study of data breach incidents in Australia found that, on average, a cyber breach costs business $2.82 million to rectify.

Apart from the financial costs, there are other compelling reasons why businesses should take data breach management seriously. Not to mention that the Federal Government has just released a draft bill that would require businesses to notify the Federal Privacy Commissioner and affected individuals of serious data breaches involving personal information.

You can take steps to protect your business from data breaches and reduce their impact if they occur.

In this article we outline five actions to better data breach management. Following these steps will also help your business comply with the Privacy Commissioner’s voluntary guidelines on data breach notification, and prepare for the potential introduction of mandatory notification requirements in Australia.

ACTION 1: TAKE STOCK OF WHAT DATA YOUR BUSINESS HOLDS

It is essential the decision makers in your business understand (and monitor) the types and amount of personal information that the business holds, and how/where that information is stored.

Under the Privacy Act, entities are responsible for the security of any records containing personal information (whether physical or electronic) that are in the entity’s possession or control. This can include information that is processed or stored by external service providers (including cloud storage providers). Particular care should also be taken to identify and manage archived and backup copies of data.

Your business’ risk and compliance governance procedures should incorporate regular reporting on information security and data storage issues so that management has appropriate visibility of any risks and can take a co-ordinated approach to manage them. These matters should be reported on at the most senior levels of governance in an organisation.

ACTION 2: REVIEW YOUR CONTRACT TERMS WITH SERVICE PROVIDERS

Your business should have appropriate operational procedures (and contractual rights) in place so that you can promptly and accurately identify and assess any security breaches affecting your data, regardless of whether the breach is suffered by you or your service provider.

Ideally, contracts should include a clause requiring the service provider to immediately notify the customer of any security breaches affecting the customer’s data, and to co-operate with the customer in connection with the management of the breach.

You should also seek to ensure that the contractual trigger for notification operates on an objective basis, and is not subject to an assessment of severity by the service provider.

The cost of managing data breaches should also be addressed in the contract. The contract should include appropriate liability positions, indemnity obligations and insurance requirements.

ACTION 3: ENCRYPT YOUR DATA AND REVIEW YOUR INFORMATION SECURITY PRACTICES

The Privacy Commissioner recognises that it is not possible (nor required under the Privacy Act) for businesses to design completely impenetrable security systems. Rather, organisations are required to implement information security measures that are “reasonable” in the circumstances (based on factors such as the nature of the business and the amount and sensitivity the personal information held).

The Privacy Commissioner says that determining whether a reasonable security measure has been put in place should not be judged solely by reference to the expense of the implementation.

A good information security program should incorporate both proactive and reactive risk management – it should:

help you to prevent unauthorised access/disclosure or loss of data (e.g. firewalls, network security, malware detection and prevention software); and

reduce the risk posed to affected individuals when breaches do occur (e.g. passwords, data encryption and database segregation techniques, which make it more difficult for hackers to use data extracted from your systems).

Implementing sufficiently strong reactive security measures (such as an adequate level of data encryption) could potentially save you from having to notify, as the proposed Australian data breach notification regime would allow businesses to consider factors such as “whether the information is in a form that is intelligible to an ordinary person” and “whether the information is protected by security measures” when determining whether a data breach is “serious” (thereby triggering the notification requirement).

ACTION 4: IMPROVE YOUR BREACH DETECTION PROCESSES

It’s critical to identify data breach incidents quickly so that remedial steps and notifications can be performed in a timely manner. The notification requirements under the proposed mandatory data breach notification regime will apply to any serious data breaches that the organisation “ought reasonably to be aware of”.

Businesses can consider breach detection measures such as:

network security tools, which act as a “security alarm” for your IT systems (e.g. intrusion detection software to monitor unauthorised access, and data loss prevention software to scan outbound e-mails sent by staff);

regular security testing to identify potential weak spots – this could include technical testing (such as network penetration testing) and operational readiness testing (such as training exercises for staff that simulate phishing attacks); and

training for staff to identify and report errors in handling personal information.

ACTION 5: HAVE A DATA BREACH MANAGEMENT RESPONSE PLAN IN PLACE

Your business should have a clear data breach plan in place that sets out a strategy for identifying and remedying the source of a data breach. The plan should also identify key responsible personnel, and set out the procedures for determining whether notice should be given of the breach.

A good starting point in designing the plan would be to refer to the Government’s draft bill on the proposed mandatory data breach notification regime. The Privacy Commissioner has also published a range of guidance materials on data breach management, and is currently in the process of public consultation on a draft Guide to Developing a Data Breach Response Plan (although it should be noted that the consultation draft of the Guide was released prior to the draft bill, and so does not currently reflect the proposed mandatory data breach notification regime).

Businesses should also consider having a list of “go-to” subject matter experts that can be engaged at short notice to assess the severity of the breach, advise on steps on containment and risk mitigation and determine whether notification is required.

Search the Best Lawyers legal directory to connect with experienced lawyers in your area.

Trending Articles

What AI Visibility Means for Lawyers


by Bryan Driscoll and Josh Rupall

AI tools increasingly interpret lawyers public information. Clear, consistent and credible sources help ensure they describe legal expertise accurately.

AI dashboard visualizing a lawyer's online profile, reputation, and practice information across mult

Recognizing Legal Leaders: The 2027 Best Lawyers Awards in Australia, Japan and Singapore


by Jamilla Tabbara

Market drivers, diversity trends and the elite practitioners shaping the legal landscape.

Illustrated maps of Australia, Japan and Singapore displayed with their national flags, representing

The Best Lawyers in Canada 2027: Recognizing the Nation's Top Legal Talent


by Jamilla Tabbara

Honoring established leaders and rising practitioners across Canada's legal profession.

3D model of Canada textured with the Canadian flag.

2027 Best Lawyers Awards: Honoring Excellence in the Legal Profession


by Jamilla Tabbara

Recognizing the outstanding attorneys leading top practice areas nationwide.

United States with American flag representing The Best Lawyers in America 2027 awards

Musk v. Altman: The Lawyers Behind the Case


by Jamilla Tabbara

Meet the Trial Lawyers Shaping One of AI's Biggest Legal Disputes.

Portrait photos of Elon Musk and Sam Altman positioned in front of the OpenAI logo.

Announcing the 2027 Best Lawyers Awards: Austria, Germany and Switzerland


by Jamilla Tabbara

Celebrating the legal professionals throughout Central Europe.

Graphic displaying three-dimensional map cutouts of Austria, Germany and Switzerland.

The Legal Teams Behind the Blake Lively–Justin Baldoni Settlement


by Grace Greer

A closer look at the legal teams and attorneys involved in the Blake Lively–Justin Baldoni litigation and its resolution.

Split-screen image of Blake Lively and Justin Baldoni

The Best Lawyers in France 2027: Peer-Reviewed Excellence


by Jamilla Tabbara

Seventeen editions of peer trust, a growing profession and a dynamic legal market.

3D Map of France with National Flag Graphic

New England's Climate Litigation Surge


by Bryan Driscoll

What law firms need to know

New England's Climate Litigation Surge: What Firms Must Know headline

What Is a Quitclaim Deed? Uses, Risks and When to Get Help


by Bryan Driscoll

A quitclaim deed can be one of the fastest ways to transfer property but knowing when it's the right tool and when it isn't, can save you from serious legal and financial headaches down the road.

One hand holding a wooden house model and another holding house keys.

An Employee's Guide to Non-Disclosure Agreements (NDA)


by Bryan Driscoll

Before you sign anything, here's what you need to know about non-disclosure agreements.

Figure stands before an open giant book, holding a large key, facing a keyhole on the inner page.

Rules on Gifting Money to Family: What to Know


by Bryan Driscoll

Generosity often runs ahead of paperwork. Here's how to give to loved ones without surprising the IRS, your estate plan or your relationships.

An open gift box filled with US $100 bills next to a lid tied with a red bow.

How to Optimize Your Best Lawyers Profile for AI Search


by Everett Sizemore

Learn how a complete, well-structured Best Lawyers profile can strengthen your visibility and accuracy across AI search platforms.

A laptop screen displaying the Best Lawyers profile dashboard showing customizable sections.

Best Lawyers Launches ChatGPT App


by Jennifer Verta

Expanding Trusted Legal Guidance Into AI-Driven Search

A glowing digital network overlay on a person typing on a laptop, representing AI in legal search.

Turn Client Questions Into Content That AI Search Can Find


by Bryan Driscoll and Manny Candal

Client questions are becoming search inputs. Your firm’s content should answer them clearly.

Pile of question marks with a single bright yellow question mark in the center, representing search.

Who Can Override a Power of Attorney?


by Bryan Driscoll

A power of attorney carries real legal authority, but it isn't absolute. Here's who can step in to revoke, restrict or set it aside.

Close-up of a power of attorney document, symbolizing legal authority, revocation rights, guardiansh
Smithy AI Tap to expand

Welcome to Smithy AI the Best Lawyers Assistant

I can help you find attorneys, compare firms, explore practice areas, and surface rankings curated from the Best Lawyers methodology.

Not legal advice This assistant provides general information only. For guidance on your specific situation, please consult a licensed attorney.
Learn about Best Lawyers Research Process
Suggested prompts
Chat limit reached
You've reached the message limit for this chat. To keep exploring, browse Best Lawyers directly or come back later to start a fresh conversation.
Browse Best Lawyers