Who investigates a data breach in Australia?
Regulators take the reports. The organisation that was breached has to find out what happened.
After a breach, several government bodies may need to hear from you, and some have deadlines. None of them will examine your systems to find out how the attacker got in or whose information they reached. The organisation engages a forensic investigator for that work, and the answers go into the notifications. This page sets out who does what.
Who does what
The bodies involved after a breach
Which ones apply depends on your sector, your size and what happened. This is general information, not legal advice.
Office of the Australian Information Commissioner (OAIC)
Runs the Notifiable Data Breaches scheme under the Privacy Act 1988. If you suspect an eligible data breach, you must take reasonable steps to assess it within 30 days. If it is likely to cause serious harm, you notify the OAIC and the people affected. The OAIC can investigate how you handled the breach, but it does not investigate the breach for you.
Australian Signals Directorate’s ACSC
Takes cyber incident reports through ReportCyber and on 1300 CYBER1 (1300 292 371), and gives technical advice. Some organisations must also report a ransomware or cyber extortion payment to ASD within 72 hours of paying. That applies to businesses with turnover of $3 million or more, and to critical infrastructure entities.
Police
Investigate the crime. A cybercrime report made through ReportCyber goes to police. They pursue the offender, and that work runs to its own timeline. It will not produce answers in time for your notifications.
Sector regulators
Some sectors carry their own reporting duty. APRA-regulated entities notify APRA of a material information security incident within 72 hours. Critical infrastructure entities under the SOCI Act report to ASD. A critical incident is due within 12 hours and other incidents within 72 hours.
Your side of it
What a forensic investigation answers
A notification, your insurer and your board will all ask these questions.
How they got in
The entry point, the date it was first used, and whether the attacker still has access.
What they accessed or took
Which systems, mailboxes and files were reached, and whether data left the network, from logs and forensic images.
Whose information was involved
Which people’s personal information was in the affected data, and what kind. That list decides who gets notified. How we sorted 85,000 documents after a healthcare incident.
Whether it was a breach at all
Some suspected breaches turn out not to be eligible data breaches. A documented assessment shows why, if the OAIC asks later.
If it has just happened
The first day
Contain it without wiping it
Disconnect affected machines and reset compromised accounts, but do not reinstall or delete anything. The evidence of what happened is on those systems.
Write down when you found out
Note when you first had grounds to suspect a breach. The 30-day assessment runs from that point. The APRA and SOCI deadlines run from when you became aware of the incident.
Call your insurer and your lawyer
Many cyber policies set out who you must call first. Organisations often engage the forensic investigator through their lawyer.
Engage an investigator
We preserve the evidence first, then work out what happened. All analysis is done in Australia, and you get a fixed-price scope before any work begins.
Suspect a breach? Call us.
We have handled more than 100 engagements since 2021. Retainer clients are triaged within 4 business hours, and everyone else hears on the call whether we can start. Related: departing employee data theft and published case studies.
