The Times Australia
The Times World News

.

Why do organisations still struggle to protect our data? We asked 50 professionals on the privacy front line

  • Written by Jane Andrew, Professor, Head of the Discipline of Accounting, Governance and Regulation, University of Sydney Business School, University of Sydney

More of our personal data is now collected and stored online than ever before in history. The rise of data breaches should unsettle us all.

At an individual level, data breaches can compromise our privacy, cause harm to our finances and mental health, and even enable identity theft.

For organisations, the repercussions can be equally severe, often resulting in major financial losses and brand damage.

Despite the increasing importance of protecting our personal information, doing so remains fraught with challenges.

As part of a comprehensive study[1] of data breach notification practices, we interviewed 50 senior personnel working in information security and privacy. Here’s what they told us about the multifaceted challenges they face.

Read more: The Australian government has introduced new cyber security laws. Here's what you need to know[2]

What does the law actually say?

Data breaches occur whenever personal information is accessed or disclosed without authorisation, or even lost altogether. Optus[3], Medibank[4] and Canva[5] have all experienced high-profile incidents in recent years.

Under Australia’s privacy laws[6], organisations aren’t allowed to sweep major cyber attacks under the rug.

People walking in front of an Optus store
Optus suffered a major data breach in 2022. Detail from Bianca De Marchi/AAP[7]

They have to notify both the regulator – the Office of the Australian Information Commissioner (OAIC) – and any affected individuals of breaches that are likely to result in “serious harm[8]”.

But according to the organisational leaders we interviewed, this poses a tricky question. How do you define serious harm?

Interpretations of what “serious harm” actually means – and how likely it is to occur – vary significantly. This inconsistency can make it impossible to predict the specific impact of a data breach on an individual.

Victims of domestic violence, for example, may be at increased risk when personal information is exposed, creating harms that are difficult to foresee or mitigate.

Enforcing the rules

Interviewees also had concerns about how well the regulator could provide guidance and enforce data protection measures.

Many expressed a belief the OAIC is underfunded and lacks the authority to impose and enforce fines properly. The consensus was that the challenge of protecting our data has now outgrown the power and resources of the regulator.

As one chief information security officer at a publicly listed company put it:

What’s the point of having speeding signs and cameras if you don’t give anyone a ticket?

A lack of enforcement can undermine the incentive for organisations to invest in robust data protection.

Only the tip of the iceberg

Data breaches are also underreported, particularly in the corporate sector.

One senior cybersecurity consultant from a major multinational company told us there is a strong incentive for companies to minimise or cover up breaches, to avoid embarrassment.

This culture means many breaches that should be reported simply aren’t. One senior public servant estimated only about 10% of reportable breaches end up actually being disclosed.

Without this basic transparency, the regulator and affected individuals can’t take necessary steps to protect themselves.

Closeup person holding credit card using laptop
Affected individuals can’t take steps to protect themselves if breaches aren’t reported. Yuri A/Shutterstock[9]

Third-party breaches

Sometimes, when we give our personal information to one organisation, it can end up in the hands of another one we might not expect. This is because key tasks – especially managing databases – are often outsourced to third parties.

Outsourcing tasks might be a more efficient option for an organisation, but it can make protecting personal data even more complicated.

Interviewees told us breaches were more likely when engaging third-party providers, because it limited the control they had over security measures.

Between July and December 2023 in Australia, there was an increase of more than 300%[10] in third-party data breaches compared to the six months prior.

There have been some highly publicised examples.

In May this year, many Clubs NSW customers had their personal information potentially breached[11] through an attack on third-party software provider Outabox.

Bunnings suffered a similar breach[12] in late 2021, via an attack on scheduling software provider FlexBooker.

Bunnings Warehouse carpark and signage
In 2021, Bunnings had outsourced some customer booking tasks to third-party provider Flexabooker. Dave Hunt/AAP[13]

Getting the basics right

Some organisations are still struggling with the basics. Our research found many data breaches occur because outdated or “legacy” data systems are still in use.

These systems are old or inactive databases, often containing huge amounts of personal information about all the individuals who’ve previously interacted with them.

Organisations tend to hold onto personal data longer than is legally required. This can come down to confusion about data-retention requirements, but also the high cost and complexity of safely decommissioning old systems.

One chief privacy officer of a large financial services institution told us:

In an organisation like ours where we have over 2,000 legacy systems […] the systems don’t speak to each other. They don’t come with big red delete buttons.

Other interviewees flagged that risky data testing practices are widespread.

Software developers and tech teams often use “production data” – real customer data – to test new products. This is often quicker and cheaper than creating test datasets.

However, this practice exposes real customer information to insecure testing environments, making it more vulnerable. A senior cybersecurity specialist told us:

I’ve seen it so much in every industry […] It’s literally live, real information going into systems that are not live and real and have low security.

What needs to be done?

Drawing insights from professionals at the coalface, our study highlights just how complex data protection has become in Australia, and how quickly the landscape is evolving.

Addressing these issues will require a multi-pronged approach, including clearer legislative guidelines, better enforcement, greater transparency and robust security practices for the use of third-party providers.

As the digital world continues to evolve, so too must our strategies for protecting ourselves and our data.

References

  1. ^ comprehensive study (www.doi.org)
  2. ^ The Australian government has introduced new cyber security laws. Here's what you need to know (theconversation.com)
  3. ^ Optus (www.abc.net.au)
  4. ^ Medibank (www.abc.net.au)
  5. ^ Canva (www.afr.com)
  6. ^ privacy laws (www8.austlii.edu.au)
  7. ^ Detail from Bianca De Marchi/AAP (photos.aap.com.au)
  8. ^ serious harm (www8.austlii.edu.au)
  9. ^ Yuri A/Shutterstock (www.shutterstock.com)
  10. ^ more than 300% (www.oaic.gov.au)
  11. ^ breached (www.rimpa.com.au)
  12. ^ similar breach (australiancybersecuritymagazine.com.au)
  13. ^ Dave Hunt/AAP (photos.aap.com.au)

Read more https://theconversation.com/why-do-organisations-still-struggle-to-protect-our-data-we-asked-50-professionals-on-the-privacy-front-line-236681

Times Magazine

When Touchscreens Turn Temperamental: What to Do Before You Panic

When your touchscreen starts acting up, ignoring taps, registering phantom touches, or freezing entirely, it can feel like your entire setup is falling apart. Before you rush to replace the device, it’s worth taking a deep breath and exploring what c...

Why Social Media Marketing Matters for Businesses in Australia

Today social media is a big part of daily life. All over Australia people use Facebook, Instagram, TikTok , LinkedIn and Twitter to stay connected, share updates and find new ideas. For businesses this means a great chance to reach new customers and...

Building an AI-First Culture in Your Company

AI isn't just something to think about anymore - it's becoming part of how we live and work, whether we like it or not. At the office, it definitely helps us move faster. But here's the thing: just using tools like ChatGPT or plugging AI into your wo...

Data Management Isn't Just About Tech—Here’s Why It’s a Human Problem Too

Photo by Kevin Kuby Manuel O. Diaz Jr.We live in a world drowning in data. Every click, swipe, medical scan, and financial transaction generates information, so much that managing it all has become one of the biggest challenges of our digital age. Bu...

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Decline of Hyper-Casual: How Mid-Core Mobile Games Took Over in 2025

In recent years, the mobile gaming landscape has undergone a significant transformation, with mid-core mobile games emerging as the dominant force in app stores by 2025. This shift is underpinned by changing user habits and evolving monetization tr...

The Times Features

How Businesses Turn Data into Actionable Insights

In today's digital landscape, businesses are drowning in data yet thirsting for meaningful direction. The challenge isn't collecting information—it's knowing how to turn data i...

Why Mobile Allied Therapy Services Are Essential in Post-Hospital Recovery

Mobile allied health services matter more than ever under recent NDIA travel funding cuts. A quiet but critical shift is unfolding in Australia’s healthcare landscape. Mobile all...

Sydney Fertility Specialist – Expert IVF Treatment for Your Parenthood Journey

Improving the world with the help of a new child is the most valuable dream of many couples. To the infertile, though, this process can be daunting. It is here that a Sydney Fertil...

Could we one day get vaccinated against the gastro bug norovirus? Here’s where scientists are at

Norovirus is the leading cause[1] of acute gastroenteritis outbreaks worldwide. It’s responsible for roughly one in every five cases[2] of gastro annually. Sometimes dubbed ...

Does running ruin your knees? And how old is too old to start?

You’ve probably heard that running is tough on your knees – and even that it can cause long-term damage. But is this true? Running is a relatively high-impact activity. Eve...

Jetstar announces first ever Brisbane to Rarotonga flights with launch fares from just $249^ one-way

Jetstar will start operating direct flights between Brisbane and Rarotonga, the stunning capital island of the Cook Islands, in May 2026, with launch sale fares available today...