Escalating Cyber Threats in Australia: In-House Legal Teams Must Act

Australian organisations are increasingly vulnerable to complex cyber threats, with far-reaching consequences for their regulatory, financial, and reputational standing. In-house legal teams play a pivotal role in bolstering their organisation's cyber resilience and mitigating significant regulatory exposure. This article outlines critical cyber risk areas, including poor data governance, third-party and supply chain risk, and lack of employee training and awareness.

Key Takeaways:

  • In-house legal teams must ensure data governance by mapping critical data assets, understanding data retention regulatory landscapes, and enforcing data minimisation.
  • Review and strengthen contracts with third-party vendors to include binding privacy and security obligations, as well as provisions for independent third-party reports on cyber resilience.
  • Legal teams should lead training on legal risk, including targeted real-world examples of AI-generated phishing attacks, and highlight the legal consequences of poor security practices.
  • Mandate multi-factor authentication (MFA) across all systems handling sensitive data and prepare incident response plans that identify relevant legal obligations.
  • Legal professional privilege should be applied appropriately in the context of cyber breaches.
  • Update fraud protocols to require multi-channel verification for high-value or unusual payment requests, especially those initiated via voice or video.

Statistics:

  • Approximately 4 million former Optus customers' personal information were compromised due to unclear data retention requirements.
  • The 2022 Optus data breach led to the retainage of billing records for up to six years, illustrating the risks of unclear data retention requirements.
  • Regulators and courts hold organisations responsible for security breaches affecting the data they control, regardless of where it resides or which vendor manages it.
  • Generative AI has created a new risk: sophisticated deepfakes, which can enable targeted attacks on organisations and executives.
  • Deepfakes can bypass traditional controls and cause breaches, resulting in practicable reputational harm, and further necessitating authoritative policies in order-to overcome these.

Sources:

  • Optus data breach
  • Australian Privacy Principle 11
  • Privacy Act 1988 (Cth)
  • Security of Critical Infrastructure Act 2019 (Cth)
  • Click Here for related articles (c) Mondaq Ltd, 2025 - Tel. +44 (0)20 8544 8300 - http://www.mondaq.com

This article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.