Skip to main content

Five legal steps every business can take to strengthen its cyber security

A cyber incident can disrupt operations, expose confidential information and create significant legal and financial consequences. For business owners, directors and management teams, preparation includes understanding what information the business holds, who can access it and how the business will respond if something goes wrong.

October is Cyber Security Awareness Month, providing an opportunity to review your business’s cyber security practices. Technical protections are essential, but effective preparation also requires clear governance, appropriate contracts and a tested incident response plan.

The following five steps can help businesses manage cyber security risks and reduce the consequences of a data breach.

1. Know what data you hold and only keep what you need

Businesses can accumulate substantial amounts of personal information through customer accounts, employment records and everyday transactions. Keeping information indefinitely increases the amount that could be exposed in a cyber incident, including information the business no longer needs.

Start by identifying what personal and sensitive information your business collects, why it is needed, where it is stored and who can access it. Include information in email accounts, shared drives, archived records and systems operated by service providers.

For businesses subject to the Australian Privacy Principles (APPs), APP 11 generally requires reasonable steps to destroy or de-identify personal information once it is no longer needed for a permitted purpose. Exceptions include information in Commonwealth records and information that must be retained under Australian law or a court or tribunal order. Retention decisions should also account for relevant legal proceedings and document preservation requirements.

Practical tip: Establish a data retention schedule that identifies what must be kept, for how long and who is responsible for secure destruction or de-identification. Regularly review inactive accounts and older records rather than retaining them by default.

2. Make cyber security a governance responsibility

Cyber security decisions affect the whole business. Directors and management should understand the risks, ensure responsibilities are allocated and receive information that enables them to assess whether those risks are being managed.

APP 11 expressly recognises that reasonable steps to protect personal information include both technical and organisational measures. The appropriate measures depend on the circumstances, including the nature and sensitivity of the information held and the business’s size, resources and operations.

Policies, training and oversight should work alongside technical controls. Staff need to understand how to handle personal information, recognise phishing and impersonation attempts, and report concerns. Written policies have limited value if employees do not understand or follow them.

Practical tip: Include cyber risk in regular management and board discussions. Assign responsibility for policies, staff training and reviews, and document decisions and follow-up actions so the business can demonstrate how it manages those risks.

3. Manage cyber security risks across suppliers and customers

Your business’s exposure extends to information held by, or accessible to, third-party suppliers and customers. Cloud providers, payroll processors, external advisers and customers using shared portals can introduce risks through their own systems or access arrangements. A third party with inadequate controls can become the weakest link in your business’s cyber security.

Before sharing information or granting access, assess whether the third party has appropriate cyber security controls for the information and systems involved. Consider what access is necessary, whether subcontractors are involved and how compliance will be monitored over the life of the relationship.

Contracts should address security standards, permitted use and access, retention and secure destruction, prompt notification of suspected or actual incidents, and cooperation with investigations and incident response. Appropriate audit rights and clear responsibility for response costs and losses may also be relevant. These protections should reflect the relationship and the risks involved.

Outsourcing a function does not automatically remove your business’s legal obligations. Where a breach affects information held by multiple organisations, clarify who will investigate and notify, and ensure your business can obtain the information it needs to meet its own obligations.

Practical tip: Review supplier and relevant customer agreements alongside their access permissions. Confirm that contractual protections are supported by appropriate controls and workable arrangements for notifying, investigating and responding to an incident.

4. Prepare and test your data breach response plan

A cyber incident can require urgent decisions with incomplete information. A written response plan helps staff identify a suspected breach, escalate it promptly and coordinate the experts needed to contain and assess it.

The plan should identify who employees must contact, who leads the response and who has authority to make decisions. It should also explain how IT, forensic specialists, legal advisers and communications personnel will work together, including when insurers, suppliers and other stakeholders need to be contacted.

Businesses covered by the Notifiable Data Breaches scheme must promptly assess suspected eligible data breaches and take all reasonable steps to complete that assessment within 30 calendar days. Where there are reasonable grounds to believe an eligible data breach has occurred, notification to the Office of the Australian Information Commissioner and affected individuals is required as soon as practicable, unless an exception applies. The assessment period is not a reason to delay acting.

Practical tip: Test your plan using a realistic scenario, such as a compromised email account or a supplier breach. Check that staff know how to report concerns, contact details are current and the plan remains accessible if your usual systems are unavailable.

Early legal advice can help a business identify regulatory obligations, assess contractual exposure and coordinate notifications following a cyber incident. It can also help establish an appropriate structure for investigations where legal professional privilege is intended to apply.

Privilege is not automatic because a lawyer is involved, copied into correspondence or given an investigation report. Broadly, it protects confidential communications and documents created for the dominant purpose of obtaining legal advice or conducting existing or reasonably anticipated litigation. The purpose and management of an investigation therefore matter from the outset.

Businesses should seek advice before commissioning reports or making public statements about an investigation. Legal advisers can help define the scope and purpose, establish confidentiality arrangements and advise on disclosure that could affect a claim to privilege.

Practical tip: Build legal escalation into your incident response plan. Identify your legal advisers in advance and involve them promptly when an incident arises, alongside the specialists needed to contain it and restore operations.

Summary

Cyber Security Awareness Month is a useful prompt to review your arrangements, but cyber risk requires ongoing attention. Regular reviews of data holdings, governance, third-party arrangements and response plans can help your business identify gaps before an incident occurs.

DMAW Lawyers assists businesses with cyber security governance, privacy compliance, contractual protections and incident response. Our team can help you assess your legal obligations and put practical arrangements in place to manage cyber and information security risks.

Our cyber and information security experts

Related Insights