In February 2018, new legislation for mandatory data breach notifications will be introduced as an amendment to the Australian Privacy Act. This amendment will apply to all organisations required to comply with the Australian Privacy Act 1988 and could result in penalties for non-compliance of up to $1.7M for organisations and $300,000 for Directors.
The recent data breach at US credit reporting firm Equifax provides a valuable lesson.
Does your organisation have up to date well documented ICT security policies?
Does your organisation have up to date well documented procedures for ICT security (like patching, which is the vulnerability exploited in the WannaCry hack)?
Opinion piece published by CSO online concerning updates to documentation.