Cybersecurity Compliance
Cybersecurity compliance is handed to IT, and a good share of the actual obligations are not technical at all.
Where personal information is involved, privacy law requires reasonable steps to protect it and, where an eligible data breach is suspected, an assessment and notification within defined timeframes. Those are business obligations with a clock attached, not server configuration.
Records obligations sit alongside them. Employee and customer records have to be retained and produced, which means a ransomware event is a compliance problem as well as an operational one.
Third parties are the third piece. Where a supplier holds your data, their breach can become your notification.
Any of that requires the business to know which systems hold personal information, which is rarely written down.
The Office of the Australian Information Commissioner publishes the breach scheme. This is general information rather than legal advice, and obligations vary by state and territory.
See Sentrient’s cyber security training course and privacy training course.
2026 Compliance Risks In Australia: All You Need To Know
Quick Answer: The compliance risks in Australia that changed in 2026 are led by two that both commenced on 1 July 2026: Payday Super, which requires employers to pay superannuation at the same time as salary and wages, and AML/CTF Tranche 2, which brings lawyers, accountants, conveyancers, real estate professionals and precious metals dealers under […]
