Escalating Cyber Threats in Australia: In-House Legal Teams Must Act
Australian organisations are increasingly vulnerable to complex cyber threats, with far-reaching consequences for their regulatory, financial, and reputational standing. In-house legal teams play a pivotal role in bolstering their organisation's cyber resilience and mitigating significant regulatory exposure. This article outlines critical cyber risk areas, including poor data governance, third-party and supply chain risk, and lack of employee training and awareness.
Key Takeaways:
- In-house legal teams must ensure data governance by mapping critical data assets, understanding data retention regulatory landscapes, and enforcing data minimisation.
- Review and strengthen contracts with third-party vendors to include binding privacy and security obligations, as well as provisions for independent third-party reports on cyber resilience.
- Legal teams should lead training on legal risk, including targeted real-world examples of AI-generated phishing attacks, and highlight the legal consequences of poor security practices.
- Mandate multi-factor authentication (MFA) across all systems handling sensitive data and prepare incident response plans that identify relevant legal obligations.
- Legal professional privilege should be applied appropriately in the context of cyber breaches.
- Update fraud protocols to require multi-channel verification for high-value or unusual payment requests, especially those initiated via voice or video.
Statistics:
- Approximately 4 million former Optus customers' personal information were compromised due to unclear data retention requirements.
- The 2022 Optus data breach led to the retainage of billing records for up to six years, illustrating the risks of unclear data retention requirements.
- Regulators and courts hold organisations responsible for security breaches affecting the data they control, regardless of where it resides or which vendor manages it.
- Generative AI has created a new risk: sophisticated deepfakes, which can enable targeted attacks on organisations and executives.
- Deepfakes can bypass traditional controls and cause breaches, resulting in practicable reputational harm, and further necessitating authoritative policies in order-to overcome these.
Sources:
- Optus data breach
- Australian Privacy Principle 11
- Privacy Act 1988 (Cth)
- Security of Critical Infrastructure Act 2019 (Cth)
- Click Here for related articles (c) Mondaq Ltd, 2025 - Tel. +44 (0)20 8544 8300 - http://www.mondaq.com
This article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.