Reasonable Steps: Australia's First Privacy Penalty and the One-Hour Firewall Log

Published Category: Security 32 min read 6,278 words by James Nicholson

It is the week before Christmas, and you have just bought a house. Not a new one. A lovely old place with character, which is estate-agent language for "the previous owners did things their own way". You have a plan. By the end of June, you will change every lock, rewire the alarm and move your things into the rooms that matter. It is on a spreadsheet. The spreadsheet has colours.

Until June, though, you live with what came with the house. The back door latch does not quite catch. The security camera keeps exactly one hour of footage, then records over it, like a goldfish with a hard drive. The alarm panel is a model the manufacturer stopped supporting two years ago. The spare key is under the mat, where the spare key has always been, because that is where the last owners' children could find it.

In February, somebody gets in. They leave a note that says they have taken your filing cabinet and will post its contents on the internet unless you pay. You call the security company you already use. Their investigator comes over, looks around three of the house's 127 rooms, checks one hour of the camera's footage (the only hour there is), and tells you that the note is "merely a scare tactic". You feel relief. You tell your family nothing is missing.

In June, your filing cabinet appears on the internet. All of it: the medical letters, the bank statements, the kids' school reports. A government agency rings to tell you. It had already rung once, in March. It takes you another three and a half weeks to write to the one office that must be told.

Put the deadbolt catalogue down for a moment. Nobody is going to ask you to turn your house into a bank vault. The law does not ask for perfect locks. What it asks for is harder to fake: that the steps you took were reasonable, given what you kept in the house and what you knew about the neighbourhood.

On 8 October 2025, the Federal Court said what that word means, for the first time. Australian Clinical Labs (ACL), one of the largest private hospital pathology businesses in Australia, must pay $5.8 million in penalties over a 2022 cyberattack on Medlab Pathology, a business it had bought two months before. These are the first civil penalties ever ordered under the Privacy Act 1988. The house above is Medlab, with the details changed only a little. The one-hour camera is real. So are the three computers, and the scare tactic.

So we are going to start with the lock on your own front door and work down: what "reasonable steps" means in plain life, what Australian Privacy Principle 11 asks for, how a penalty gets from one breach to 223,000 contraventions, the two clocks of the data breach scheme, and then exactly what the court found wrong at Medlab. Then a (made-up) security lead shows how the first 30 days should go, and you get a list to check your own house this week.

Let's get into it.

Part 1: The Lock You Already Choose Without Thinking

You make security judgements every day, and you are rather good at them. When you go to the shops, you lock the front door. You do not board up the windows. If you own a shed full of garden tools, it gets a padlock. If you keep your grandmother's jewellery in the house, it may get a small safe. If you ran a jewellery shop, you would expect steel shutters, a monitored alarm and an insurer who asks awkward questions. Nobody gave you a rule for any of this. You scaled the protection to three things: what you are protecting, how bad it would be to lose it, and what you can reasonably do about it.

Now imagine you do not lock the front door, and you get burgled. Your friends will not ask whether you had the best lock money can buy. They will ask whether a sensible person in your position, with your things in the house, in your street, would have done more than you did.

That judgement has a name in law: the reasonable person standard. It is objective. It does not ask what you believed, or whether you tried hard. It asks what a sensible person, standing in your shoes and knowing what you knew, would have done. And it moves with the circumstances. The lock that is fine for a garden shed in Cygnet is negligent for a jeweller in Collins Street.1

Everything that follows is that same judgement, done by a Federal Court judge, with a statute in one hand and a statement of agreed facts in the other.

Part 2: What APP 11.1 Actually Asks For

A crowded Flemish locksmith's workshop where a locksmith adds a bolt to a balance scale that weighs a chest of sealed letters and a physician's flask against a heap of locks, while a peasant with a turnip and a jeweller with a strongbox wait, and a small server blinks on a shelf.
Fig. 1 — The heavier the chest, the more bolts it needs, generated by OpenAI GPT Image.

The Privacy Act has 13 Australian Privacy Principles, or APPs. They apply to "APP entities": most Australian Government agencies, and private organisations with an annual turnover above $3 million, plus some smaller ones such as health service providers.2 APP 11 is the security principle. In the OAIC's one-line summary, an entity "must take reasonable steps to protect personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure".

The ACL case turned on one part of it, APP 11.1(b). The exact words matter, so here they are as Justice Halley put them: an entity that holds personal information must take "such steps as are reasonable in the circumstances" to protect it from "unauthorised access, modification or disclosure". And here is the part that makes this judgment worth reading: APP 11.1(b) "has not been the subject of any previous judicial consideration". The principle has been in force since 2014, and a great many privacy policies promise to take reasonable steps. Until October 2025, no court had said what that meant.

The circumstances

The standard is objective, and the scope of the steps "must be informed by the circumstances", which he said should be read broadly. He listed what they could be expected to include:

  • the sensitivity of the personal information;
  • the potential harm to people if it was accessed or disclosed;
  • the size and sophistication of the entity;
  • the cybersecurity environment it operates in;
  • any previous threats or cyberattacks against it.

It is the garden shed and the jewellery shop, written by a lawyer. The OAIC has said much the same thing since its Guide to securing personal information in 2018. The guide names five circumstances: the nature of your entity, the amount and sensitivity of what you hold, the possible harm to a person if it leaks, the practical cost of a measure, and whether the measure is itself privacy invasive. The guide says that "generally, as the amount and/or sensitivity of personal information that is held increases, so too will the steps that it is reasonable to take to protect it".

On cost, the guide is careful. The time and cost of a step matter. But "you are not excused from taking specific steps to protect information just because it would be inconvenient, time-consuming or costly to do so". A step is unreasonable only when "the burden is excessive in the specific circumstances". A pathology company with nearly a billion dollars of revenue will struggle to argue that keeping more than an hour of firewall logs was an excessive burden.

Six things "reasonable steps" is, and is not

The Privacy Act had never been tested, but "reasonable steps" appears in other laws, especially the Corporations Act, where courts have worked on it for years. The judge borrowed six principles from those cases. For anyone who signs off on security, this is the most useful list in the judgment. The obligation:

  1. Differs with the complexity of the entity's business and its procedures.
  2. Cannot be discharged "simply by delegating it to another entity and doing nothing more".
  3. Needs a "wholistic analysis" of the entity's full framework of systems, policies and procedures.
  4. Does not require the optimal steps.
  5. Does not require all reasonable steps, or the "one true path". The question is whether the steps taken, "in their totality", were reasonable.
  6. Is assessed objectively, against what a reasonable person in the entity's position would do.

Numbers 4 and 5 are the good news. Perfection is not the standard. A clever expert with hindsight will always think of a better control; the test is the whole picture.

Number 2 is the bad news, and it is the one that sank ACL. You can hire someone to do the work, but not to own the obligation. If your contractor looks at three computers and says all is well, the question a court asks is not "what did the contractor say?" It is "was it reasonable for you to accept that?"

The OAIC guide says the same thing about outsourcing: if you still "hold" the information (possession or control of the record), APP 11 still applies to you, and so does the data breach scheme, "even if it is the third party who suffers the eligible data breach". The contractor is your locksmith. It is still your house.

And the rule got a little more specific in December 2024

One more change sits on top of all this. In the 2024 amendments to the Privacy Act, Parliament added APP 11.3, which says "reasonable steps" include "technical and organisational measures". As of October 2025, the OAIC's guide carries a banner that says so, and that it is being revised. The new clause applies to information held after 11 December 2024. I wrote about this idea when it was only a proposal in Unpacking the Review of Australia's Privacy Act Updates, and about what the reforms meant for marketers in Breaking Down Australia's Privacy Law Overhaul. It is now law, and the ACL judgment shows what the two halves look like. Technical: logs, MFA, encryption, antivirus that works. Organisational: playbooks, training, somebody with authority who knows what to do at 10.48 pm.

Part 3: How One Breach Became 223,000 Contraventions

This is the machinery that turns a data breach into a number with a lot of zeroes.

From a broken principle to a penalty

The chain has four links, and each one is a separate section of the Act:

  1. Breach an APP. ACL did not take reasonable steps, so it breached APP 11.1(b).
  2. That is an interference with privacy. Section 13 says an act that breaches an APP "in relation to personal information about the individual" is an interference with that individual's privacy.
  3. If it is serious, it is a civil penalty contravention. At the time, section 13G said an entity contravenes the Act if it does an act that is "a serious interference with the privacy of an individual". The Act does not define "serious". The court borrowed again from corporate law: "grave or significant", judged by how far the conduct departed from the standard. Sensitive health data, the list of deficiencies and the reliance on a contractor put it over that line.
  4. Count the individuals. This is the link that matters most. The Act protects individuals, so the court found (and ACL agreed) that there was a separate contravention for each person whose information sat on the Medlab systems. That is more than 223,000 contraventions, all from one course of conduct.

The arithmetic of the maximum

During the period in question, section 13G carried a maximum of 2,000 penalty units. A penalty unit was worth $222. And a body corporate can be penalised up to five times the base amount. So:

2,000 units × $222 × 5 = $2.22 million per contravention.

Multiply that by 223,000 individuals, and the judgment itself gives the theoretical maximum for the APP 11 breaches: $495,060,000,000. That is not a typing error. It is about 497 years of ACL's revenue in its best year.3

The agreed penalty for the APP 11 part was $4.2 million. That works out at about $18.83 per person. I would like to say that is the price of a nice lunch, but in Hobart that is the price of a toasted sandwich and a pot of tea, if you do not look at the cake cabinet.

Why so low, and why it is still a big deal

The judge was frank about it. Looking only at the bad factors (the scale, the sensitivity, the dark web, the involvement of the most senior management), he said the matters "would suggest that a penalty of $5.8 million was manifestly inadequate". Then he weighed the other side. ACL made no financial gain. It had no previous findings against it. There was no suggestion the conduct was deliberate. Its board had approved a cybersecurity uplift program in July 2021, before the attack, and it later appointed a full-time Chief Information Security Officer. It cooperated with the OAIC's investigation, opened in December 2022, produced some 12,000 documents, admitted the contraventions, and apologised. The parties agreed the penalty, and courts generally accept an agreed penalty if it falls in the permissible range.

So $5.8 million was the price of a company that confessed, cooperated and had already started fixing things. The next company may not do any of those.

And the next company will face a different maximum. From 13 December 2022, the maximum for a serious interference is the greater of $50 million, three times the benefit obtained, or (if the benefit cannot be worked out) 30% of adjusted turnover over the breach period. As of October 2025, the Commissioner also has civil penalty proceedings running against Medibank (9.7 million people) and Optus (about 9.5 million), both under the old $2.22 million maximum. In the Optus case, the Commissioner alleges one contravention per person. The Privacy Commissioner, Carly Kind, called the ACL result "an important turning point in the enforcement of privacy law in Australia". I think she is right, but not because of the size of the fine. It is because a court has now written down the test.

Part 4: The Second Clock, and the First One

APP 11 is about the lock. The data breach scheme is about what you do when you find the door open. It is in Part IIIC of the Privacy Act, it is called the Notifiable Data Breaches (NDB) scheme, and it has applied to breaches since 22 February 2018. ACL was penalised under it twice, for two different failures, and the difference between them is the most useful lesson in the case.

What counts as an "eligible data breach"

Under section 26WE, a breach is "eligible" when there is unauthorised access to, or disclosure of, personal information (or it is lost in a way that makes that likely), and a reasonable person would conclude that it "would be likely to result in serious harm" to any of the people it relates to. The Act lists things to weigh: the kind and sensitivity of the information, whether security measures protect it, who has it or could get it, and the nature of the harm. Health data, card numbers and Medicare numbers, taken by a ransomware group that publishes stolen files, is not a close call.

Two states of mind, two duties

The scheme hangs on the difference between two words: suspect and believe.

Suspect. When an entity is aware of reasonable grounds to suspect there may have been an eligible data breach, section 26WH(2) says it must "carry out a reasonable and expeditious assessment" of whether there are reasonable grounds to believe it happened, and take all reasonable steps to finish that assessment within 30 days. The OAIC's guidance says the Commissioner expects entities to treat 30 days "as a maximum time limit" and to aim for "a much shorter timeframe, as the risk of serious harm to individuals often increases with time". It also warns against waiting "until its CEO or board is aware".

Believe. Once an entity is aware of reasonable grounds to believe there has been an eligible data breach, section 26WK(2) says it must prepare a statement for the Commissioner, and give it to her "as soon as practicable". The statement is short: who you are, what happened, what kinds of information were involved, and what people should do. (It must also tell the affected people, under a separate section.)

Think of it as two clocks. The first starts at suspicion and measures the quality of your investigation as well as its speed. The second starts at belief and measures only speed. The two clocks measure different things.

A vertical timeline. 19 December 2021: ACL buys Medlab's assets. 25 February 2022: Quantum ransomware attack; the contractor calls the leak threat a scare tactic. 2 March 2022, green: the contractor's report; the court says suspicion exists and the 30-day assessment clock starts. 21 March 2022, green: ACL decides it is not an eligible breach, inside 30 days but not a reasonable assessment. 25 March 2022: first ACSC warning. 16 June 2022, green: 86 GB on the dark web; ACL now believes, and the statement clock starts. 10 July 2022, green: statement to the Commissioner, 24 days later, when 2 to 3 days was practicable. 27 October 2022: public announcement. 8 October 2025: $5.8 million in penalties.
Fig. 2 — Two clocks, two failures. Drawn from Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224, 8 October 2025, orders and paragraphs 14 to 39, 74 to 90.

ACL beat the first clock and still failed it

Here is the detail that is easy to miss. The court found that ACL had reasonable grounds to suspect a breach by 2 March 2022, the day its contractor delivered its incident report. ACL decided the attack was not an eligible data breach by 21 March. That is 19 days: comfortably inside the 30.

And the court still found a contravention of section 26WH(2), with an $800,000 penalty. The word that failed was not "expeditious". It was "reasonable". A quick assessment that looks in the wrong places is not an assessment the Act accepts. Nineteen days of looking at three rooms is not better than thirty days of looking at all of them.

ACL then missed the second clock

On 16 June 2022, the Australian Cyber Security Centre told ACL that "potentially 80gb" of Medlab data had been published. That afternoon, ACL's Head of Technical Services wrote that he was satisfied the data, including full card details, had been taken, and that ACL was likely obliged to notify. The court found that belief existed "by at least" that date. ACL admitted that it was practicable to prepare the statement "within two to three days". It gave the statement to the Commissioner on 10 July, 24 days later. That was the second $800,000.

So: the 30 days is a ceiling on a reasonable assessment, not a grace period. And the moment you believe, the 30 days stop mattering.

A Flemish-style townhouse where a proud merchant turns a new key in the front door while, behind him, the old back door hangs open on one hinge and a hooded figure carries a sack of letters out, with an hourglass and a glowing laptop on the windowsill.
Fig. 3 — New key, old back door, generated by OpenAI GPT Image.

Part 5: What the Court Found at Medlab

A Bosch-style cross-section of a many-roomed house where an inspector with a lantern checks three rooms and signals all clear to the owner, while in the unchecked rooms rat-headed clerks pass sacks of papers out of a window to a cart, and an empty hourglass stands in the hall.
Fig. 4 — Three rooms checked, all clear, generated by OpenAI GPT Image.

Now the house inspection. Everything here comes from the facts ACL agreed, as the judge summarised them. It is unusually specific.

The house, as bought

On 19 December 2021, ACL bought the assets of Medlab Pathology, a private pathology business in New South Wales and Queensland. Its tests included prenatal genetic testing, fertility assessments and testing for sexually transmitted diseases. Few kinds of health information are more sensitive. Medlab held health, contact and card information about more than 223,000 people. ACL "did not identify certain relevant vulnerabilities" in Medlab's systems before the purchase.

In January 2022, ACL set up a steering committee to bring Medlab's systems into ACL's core environment by 30 June 2022, or shut them down. It was a serious committee: the CEO, the Chief Operating Officer, the Chief Financial Officer and the CIO were on it. Until the work was done, the court found, Medlab's systems had these deficiencies:

  • antivirus that could not stop certain malicious files from being written or run;
  • weak authentication;
  • firewalls that could log only one hour of activity before the logs were deleted;
  • no file encryption;
  • a server running a legacy version of Windows that Microsoft had stopped supporting on 14 January 2020;
  • antivirus on the server that did not prevent or detect a threat actor uploading data to the internet.

None of these is exotic. There is no zero-day, no nation-state, no genius hacker. It is the spare key under the mat. The judge also found that ACL knew these deficiencies exposed the systems to attack during the six months of integration. The spreadsheet had colours, and the back door still did not latch.

This is the part I would pin above the desk of anyone doing a merger. From the day of settlement, ACL "owned and controlled" Medlab's IT. The six-month integration plan did not pause APP 11. The obligation started on day one, and so did the attackers' interest.

The response, as it happened

The Quantum Group, a ransomware operation, attacked on or just before 25 February 2022. At 1.32 pm that day, ACL asked its existing cybersecurity provider, StickmanCyber, to investigate. The Medlab IT Team Leader first put in charge of the response "had received no training in how to respond to a cyberattack". She was given ACL's playbooks once the attack was known. Those playbooks, the court found, did not clearly define roles, said little about containment or stopping data from leaving, and recommended steps for technologies Medlab did not use.

At 10.48 pm, StickmanCyber passed on what the ransom note said: that in 48 hours the attackers would post the data. Then it gave its view:

…I don't feel that this will happen and it is merely a scare tactic, however, to err on the side of caution I would suggest that you prepare a statement stating that there was a malware incident but no data has been exfiltrated nor lost and the incident is being controlled...

That sentence is the case in miniature. On the first night, nine hours into the engagement, the advice was to prepare a statement that no data had been taken.

The investigation that followed was, in the court's words, "inadequate", because it:

  • monitored only 3 of the at least 127 computers the ransomware was deployed to;
  • did not investigate the Quantum Group or its attack traits to work out whether data was likely to have been taken;
  • based its review on only one of the firewall logs, which it did not access until about four hours after the ransom demand was first downloaded (set that next to a log that keeps one hour);
  • only did a limited check of whether the attackers had left a way back in.

StickmanCyber stopped looking for exfiltration on 1 March, with a last dark web scan that day. Its report on 2 March summarised 44.5 hours of work. It closed the investigation on 11 March, and on 15 March it emailed ACL about the NDB scheme and said that, when it ended its engagement, it "would have to say" no individual had been harmed. By 21 March, ACL had decided there was no eligible data breach.

On 25 March, at 5.28 am, the ACSC told ACL it had intelligence that Medlab might have been a ransomware victim, and reminded ACL it might need to notify. That afternoon, the CIO replied that ACL did not believe any data had been taken. On 29 March, the board was told that "no exfiltration of data was detected out of the network". Then June arrived, and 86 GB of Medlab data was on the dark web.4

"No exfiltration detected" is not "no exfiltration"

The Medlab ransom note threatened to post the data. That threat only works if the data was copied out first. Security people call this double extortion: copy the data, then encrypt it, then threaten to publish the copy if you do not pay for the key. The copying is the quiet part. It can ride out over the same channels the attacker already uses to control the machines. A ransom note that says "we have your data" is a claim to test, not a bluff to dismiss.

In April 2022, two months after the Medlab attack, The DFIR Report published an analysis of a different Quantum intrusion. The attackers came in through IcedID malware hidden in an ISO file sent by email, and went from first access to ransomware across the whole domain in 3 hours and 44 minutes. The ransom note there claimed data had been stolen, too. The analysts wrote that they "did not observe any overt exfiltration of data", and then, in the same sentence, that it was "possible that the threat actors used IcedID or Cobalt Strike to transmit sensitive data". That is what a careful investigator says when the evidence is thin: we did not see it, not it did not happen.

Now put that next to Medlab. Attackers can move across a network in hours. The firewall remembers one hour. The investigator arrives at the one log about four hours after the ransom note. The absence of evidence is guaranteed before anyone looks. Australia's own cyber agency says, in its logging guidance, that "default log retention periods are often insufficient", that in some cases it can take up to 18 months to discover an incident, and that some malware dwells for 70 to 200 days before it does visible harm. Medlab's firewall kept 60 minutes.

The ten missing things

The court also listed what ACL could not do by itself to detect and respond. I have kept the court's order, because the list reads like the contents page of a security program:

  1. Playbooks without clear roles, with thin containment and exfiltration steps, written for the wrong technology.
  2. Inadequate testing of incident management after the acquisition.
  3. No Data Loss Prevention (tools that watch for data leaving) on Medlab's systems.
  4. No behavioural analysis tools to catch what antivirus misses.
  5. No application whitelisting, so unknown programs could run.
  6. Only limited communications plans.
  7. A team leader with no incident response training, who had not seen the playbooks.
  8. Firewall logs kept for one hour, so almost no monitoring.
  9. No specific data recovery plans.
  10. No multi-factor authentication on the Medlab VPN.

Most items on that list match a question in the OAIC's 2018 guide, which asks, among other things, "How long are the audit logs kept for?", whether multi-factor authentication is used for remote access, whether whitelisting is in place, and, about the breach response plan, "Is the plan regularly tested?" MFA and application control are two of the ASD's Essential Eight, the country's baseline list of controls. So is patching operating systems, which an unsupported server cannot receive.5 None of this was new in 2022. That, in the end, is what "reasonable" means. Not the newest control. The well-known one, that a company of your size, holding what you hold, should already have.

Part 6: Nadia's Thirty Days

A Flemish counting house at dusk where a calm woman writes in a ledger beneath a wall calendar of thirty squares, while three clerks bring her a letter, a knotted rope and a map of rooms, with a cup of tea and an open laptop on her desk.
Fig. 5 — Day four, still writing it down, generated by OpenAI GPT Image.

Lists do not teach a process, so let me build a person. Nadia is not real, and neither is her company. She is the security lead at a mid-sized Australian allied health group, which bought a small physiotherapy chain in Launceston four months ago. The chain's systems are still being integrated. It is a Thursday evening, and a clinic manager rings to say every screen at the front desk shows a ransom note.

Here is what a reasonable first 30 days looks like, set against what the court found at Medlab. I have followed the OAIC's suggested three stages: initiate, investigate, evaluate.

Day 0, Thursday evening: initiate. Nadia opens an incident record and writes the time. She treats the ransom note as grounds to suspect an eligible data breach, because the chain holds health information and the note claims data was taken. The 30-day clock starts tonight, not when the CEO hears about it. She names who owns the assessment (herself, with the privacy officer), and she calls the incident response firm on the group's retainer. She also rings the CEO, because the board will want to know, and because the OAIC guidance says not to wait for them. Medlab: the Team Leader in charge had no incident response training and had not seen the playbooks.

Day 0, later that night: contain and preserve. Nadia's first instruction to the response firm is not "tell us it's fine". It is "preserve everything, then tell us what left". Firewall, VPN, endpoint and cloud logs are exported before they roll over. (The group changed the chain's firewall retention to 12 months in week two after the purchase, because it was on the acquisition checklist.)6 Medlab: one hour of logs, reached about four hours after the ransom demand.

Days 1 to 3: investigate the whole house. The firm's scope, in writing, covers every machine the ransomware touched, not a sample. It includes a specific question: was data taken, and how would we know? The firm looks for large outbound transfers, for tools that can carry data out, and for any way back in the attackers left. Someone researches the ransomware group: does it usually steal data before it encrypts? Does it publish? Medlab: 3 of at least 127 computers; no research on the Quantum Group; a limited check for persistence.

Day 4: the contractor's first view. The firm says it has no evidence of exfiltration yet. Nadia writes down exactly what that statement rests on: which logs, which machines, which gaps. She does not turn it into "no data was taken" in any email to the board. Medlab: "merely a scare tactic", and a board told "no exfiltration of data was detected out of the network".

Days 5 to 14: evaluate, and keep looking. The group subscribes to dark web monitoring for the chain's domains and the ransomware group's leak site. Nadia asks the firm to close the gaps it listed on day 4. She considers the serious harm factors in section 26WG one by one: health data, card data, a group known to publish. She writes her reasoning in the incident record each day, including the days nothing changes. Medlab: exfiltration work stopped on 1 March, and the investigation closed on 11 March.

Day 15: an outside signal. Suppose the ACSC calls, as it called ACL, to say it has intelligence the chain may be a ransomware victim. Nadia reopens any conclusion she has drawn and records why. Medlab: the CIO told the ACSC the same afternoon that ACL did not believe data had been taken.

Day 20: decision. Either the evidence now gives reasonable grounds to believe there was an eligible breach, or a documented assessment shows why not. If the work cannot honestly be finished in 30 days, the OAIC says to record why, and to be able to show that all reasonable steps were taken and the assessment was still reasonable and expeditious. What Nadia does not do is reach a clean answer early by looking in fewer places.

The moment of belief: the second clock. Suppose on day 20 the leak site lists the chain. Nadia now believes. The statement to the Commissioner has four required parts, and she has a template for it. It goes within two days, while the detailed forensic work goes on. The notices to patients follow on the same basis. Medlab: believed on 16 June, statement on 10 July, when two to three days was practicable.

What does the system record? Every decision, with a time, a name and the evidence behind it. The preserved logs sit in write-once storage. The firm's scope and each report are attached, with Nadia's notes on what each one did not cover. If the OAIC asks, a year from now, whether the assessment was reasonable, Nadia can show it.

The difference is not a bigger budget or a cleverer contractor. Nadia never let someone else's reassurance stand in for her own assessment.

Part 7: Checking Your Own Locks This Week

You do not need to have been breached to use this judgment. Here is where I would start.

  1. List what you hold, and how sensitive it is. The standard scales with it. If you do not know where your most sensitive records live, start there.
  2. Check every system you inherited. Acquisitions, old subsidiaries, the clinic or store chain that "runs its own IT". Give each one a named owner and a short gap list against your own baseline, with dates. Treat the day of settlement as the day APP 11 starts.
  3. Find out how long your logs last. Firewall, VPN, identity provider, endpoint and cloud audit logs. Ask the OAIC's question literally: "How long are the audit logs kept for?" If the answer is measured in hours or days, fix it this week. The ASD's guidance on 18 months to discovery is a good starting point for the conversation.
  4. Turn on MFA for every remote access path. The VPN, the remote desktop gateway, the admin portals. If MFA is on but the helpdesk can reset it on a phone call, read my post on helpdesk resets before you relax.
  5. Find anything unsupported. Operating systems and applications past their end of support go on a register with a plan and a date.
  6. Test your incident playbooks against your real technology. Run a tabletop exercise with the people who would actually be on call, including anyone in an acquired business.
  7. Rewrite your incident response contract. Make sure the scope covers every affected system and an explicit exfiltration question. Keep the decision on whether a breach is eligible with you, in writing. Principle 2 says you cannot delegate it.
  8. Keep an NDB decision log. For every suspected breach: when you became aware, who owns the assessment, what you looked at, what you did not, and why you decided what you decided.
  9. Draft the Commissioner statement now. It has four required parts. Write a template while nobody is under pressure, so that "as soon as practicable" can mean two days.
  10. Watch for data leaving. Egress monitoring or Data Loss Prevention on the systems that hold the most sensitive data. The Medlab server's antivirus did not notice 86 GB leaving.
  11. Close the easy entry points. The Quantum intrusion The DFIR Report analysed started with a file in an email. Sender authentication will not stop a malicious attachment by itself, but it makes impersonating your domain much harder; my introduction to email security covers SPF, DKIM and DMARC.
  12. Tell the board what "reasonable" now means. The judge found that ACL's most senior management were involved in the integration and response decisions, and weighed that against ACL. Your board is part of the circumstances. Give them this judgment, not a summary of it.

If you work in health, move this list up your queue. In the OAIC's report for July to December 2024, health service providers made 121 breach notifications, 20% of the total and more than any other sector. The judge said the penalty should send a deterrent signal "to participants in the healthcare system", and Carly Kind called it "a vivid reminder" to healthcare providers.

Final Thoughts

Go back to the old house with character. The spreadsheet with colours was a good plan. The problem was the months before it finished, with the back door that did not latch and the camera that remembered one hour. And then the problem was the night of the break-in, when the relief of hearing "it's a scare tactic" beat the harder work of checking all 127 rooms.

Keep one idea. "Reasonable steps" is not a list of products, and it is not perfection. It is the steps a sensible organisation, holding what you hold, knowing what you know, would already have taken, judged as a whole. You can hire people to help. You cannot hire them to be reasonable on your behalf. And when something goes wrong, the law has two clocks: one that asks whether you looked properly, and one that asks whether you told the Commissioner quickly once you knew.

So this week, pick one system you inherited and ask one question about it: how long does it keep its logs? If the answer makes you wince, you have found your first reasonable step.

As for me, I am off to find out how long my home router keeps its logs. I suspect the answer is less than an hour, and I suspect I will not enjoy it. But first, if you'll excuse me, I think my tea is ready.

Notes

  1. Cygnet is a small town in the Huon Valley, south of Hobart. Its sheds, as far as I know, are perfectly secure. I have simply never heard anyone call the Cygnet garden shed a high-value target. ↩

  2. The small business exemption is a long story. Most businesses with an annual turnover of $3 million or less are outside the Act, but a business that provides a health service and holds health information is covered whatever its size. That puts nearly every clinic, pathology lab and allied health practice in Australia inside APP 11. ↩

  3. ACL's revenue was $995.6 million in the financial year to June 2022, its highest in the judgment. $495.06 billion divided by that is about 497 years. The maximum is the sum of 223,000 separate maximums, so nobody expected anything near it; the judge still had to set the agreed penalty against it. ↩

  4. ACL's own figures, published in October 2022 and reported by iTnews, broke the data down further: 17,539 records linked to a pathology test, 28,286 credit card numbers with names (about 15,700 of them expired, and 3,375 with a CVV), and 128,608 Medicare numbers with names. The judgment itself gives only the total of more than 223,000 people. ↩

  5. The judgment calls it "multifactor identification". It means the same thing as multi-factor authentication: a second factor, such as an app prompt or a security key, on top of the password. ↩

  6. The 12-month log retention in Nadia's example is my choice, not a legal rule. The ASD's logging guidance does not set one number. It says retention should follow a risk assessment, and that default settings are often too short. ↩

end of article · 6,278 words · 14 October 2025

James Nicholson, smiling, in round tortoiseshell glasses and a white T-shirt.

James Nicholson

James is a technology consultant in Hobart, Tasmania, and runs NEOBADGER. He works where technology, regulation and the people organisations serve meet: AI harnesses, development, data and compliance.

The story

Further reading

3 more articles on Security.