Australian organisations could be required to notify the Information Commissioner within 72 hours of becoming aware of an eligible data breach under proposed changes to the Privacy Act, as announced yesterday by Australia’s Attorney-General, Michelle Rowland.
The current rule requires organisations to report breaches “as soon as practicable”. The proposed fixed deadline would align Australia’s privacy rules with other cyber incident reporting requirements.
Organisations would still have 30 days to assess whether a suspected breach is eligible for notification. If they cannot provide all the required information within 72 hours, they could submit an incomplete report and explain what is missing and why.
Failing to report within 72 hours could result in penalties or a compliance notice.
According to Andrew Kay, APJ director of systems engineering at Illumio, the proposed changes expose a pair of security issues that may demand a rethink.
“First, replacing the vague ‘as soon as practicable’ requirement with a 72-hour deadline is important, but the real question is whether organisations have the visibility to detect a breach in the first place,” Kay told Cyber Daily.
“A company cannot protect Australians’ personal information if it does not know where that information sits, who is accessing it or be able to detect suspicious activity surrounding it. Real-time visibility across the IT estate is now a basic requirement, not a luxury.”
The second issue Kay foresees is that while speedier reporting may bring greater clarity, simply identifying a breach is not the same as containing it.
“Illumio’s recent research found a critical gap between detection and containment, with 95 per cent of organisations confident they can detect cyber attacks, but half struggling to stop them,” Kay said.
“This is where the real danger lies, as nefarious actors are able to live inside networks longer, moving through systems to access and eventually compromise critical operations and data. Frontier AI models are also automating and accelerating reconnaissance, exploitation and other stages of attacks, shrinking the time between an initial compromise and serious damage even more rapidly.
“The proposed rule is ultimately a test of whether Australian organisations are prepared for these realities. The 72-hour clock may start when a breach is identified, but in practice, the clock starts much earlier – when attackers first get inside.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.