Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

The OAIC Just Cleared Qantas Over a 5.7 Million Record Breach: What “Reasonable Steps” Means

Tilt-shift miniature of a disaster-recovery control room with operators at screens, representing incident response and reasonable steps under APP 11
The OAIC cleared Qantas over its 2025 breach of about 5.7 million records, finding it had taken reasonable steps under APP 11 despite the attack.

When a regulator investigates the loss of millions of customer records and then decides to walk away, the reasons it gives are worth reading closely. On 16 July 2026 the Office of the Australian Information Commissioner did exactly that with Qantas, and in the process it published the clearest picture yet of what “reasonable steps” to protect personal information actually looks like.

The OAIC released its report of preliminary inquiries into the 2025 Qantas data breach and closed them without opening a commissioner-initiated investigation and without taking any regulatory action. The June 2025 incident exposed around 5.7 million customer records (the OAIC put the number of affected Australians at roughly 5 million) after a voice-phishing attack, or vishing, on an overseas contact-centre provider Qantas had contracted. An attacker posing as Qantas IT support talked a contact-centre agent into granting access. No penalty, no enforceable undertaking, no full investigation.

Australian Privacy Commissioner Carly Kind was blunt about why. “I do not consider that the evidence supports the likelihood that a breach of privacy law occurred,” she said. “As a result, it would not be appropriate for the OAIC, a proportionate and risk-based regulator, to commence a full investigation or take further action at this stage.”

“Reasonable steps” is the phrase that matters

Under Australian Privacy Principle 11, an organisation must take reasonable steps to protect the personal information it holds. The word doing the work is “reasonable”. It does not mean perfect, and it does not mean breach-proof. The OAIC’s decision turns on a distinction every auditor lives with: being breached is not the same as failing to take reasonable steps. Qantas was breached, and the regulator still found no likely contravention, because the evidence showed the airline had done the work beforehand and could prove it.

That is the part worth sitting with if you run a smaller business. The regulator did not ask “were you breached?” It asked “can you show what you had in place, and was it reasonable for an organisation like you?” The OAIC pointed to specific, documented measures Qantas had taken before the incident: it had audited its overseas third-party contact-centre provider, it ran cyber and data-protection training for the agents handling customer data, it had processes to destroy and de-identify personal information once it was no longer needed, and it used role-based access controls to limit who could reach what. None of that stopped the breach. All of it is why Qantas kept its regulatory record clean.

The breach came through a supplier, and that is where most businesses are exposed

Look at where the attack landed. Not Qantas’s own systems, but an overseas contact centre it had outsourced to. The OAIC did not just look at Qantas’s internal controls. It also examined whether Qantas had taken reasonable steps to ensure that third-party provider handled the data properly, which is squarely the territory of Australian Privacy Principle 8 on cross-border disclosure. The airline passed that test because it could show it had assessed and audited the supplier.

Most small and mid-sized businesses could not. They use offshore support, cloud tools, bookkeepers, marketing agencies and IT providers, and if you asked them to produce evidence that they had assessed how each of those suppliers protects data, the honest answer would be a shrug. Your data does not stop being your responsibility when it sits on someone else’s system. The Qantas outcome is a preview of the standard you will be held to when your own “we trusted our provider” moment arrives.

This is exactly what an ISO 27001 system is built to produce

Read the list of things that saved Qantas again: a documented view of what data it held and where, assessed and audited suppliers, trained staff, controlled access, and an incident response it could evidence. That is not a coincidental collection of good habits. It is the standard content of an ISO 27001 information security management system.

ISO 27001 asks you to identify your information assets and the risks to them, then treat those risks with controls you can point to. Its Annex A includes controls for supplier relationships (assessing and monitoring the third parties who touch your data), for information security awareness and training, for access control, and for managing security incidents when they happen. In other words, the framework produces exactly the evidence trail the OAIC went looking for at Qantas. A certified business can answer “show me your reasonable steps” with a register, an audit record and a training log, in minutes rather than weeks. An uncertified one is relying on memory, and memory does not survive contact with a regulator.

You do not have to be certified to comply with the Privacy Act. But the system that gets you certified is the same system that lets you prove you took reasonable steps, and that is a far better reason to build one than a logo for a tender.

The Commissioner’s warning: the bar is about to rise

Kind did not treat the Qantas outcome as a reason to relax. She used it to look forward. “Agentic and advanced AI will only increase the cyber-security risks that businesses face,” she said, “and it is critical that all organisations continuously review and enhance their security to protect against this growing threat.”

Two things follow from that. First, “reasonable steps” is a moving target. What counted as reasonable last year will not necessarily count next year, which is why ISO 27001 is built around continual improvement rather than a one-off tick. Second, as AI works its way into your operations, governing it becomes part of protecting data, which is where ISO 42001 AI management starts to sit alongside your security work rather than apart from it.

What to do before it is your turn

  • Map where your data actually lives. List the suppliers, tools and offshore services that hold or handle personal information. You cannot protect what you have not written down.
  • Get evidence on your suppliers. For each one that touches customer data, can you show you assessed how they protect it? If not, that is your Qantas-style exposure, and it is the first gap to close.
  • Check your training and access records. The Qantas attack worked on a person, not a firewall. Documented awareness training and role-based access are the controls the OAIC actually credited.
  • Start with an honest gap analysis. An independent gap analysis against ISO 27001 tells you where your “reasonable steps” story is strong and where it falls apart, before a breach forces the question.

Frequently asked questions

Does getting breached mean I failed to take reasonable steps?

No, and the Qantas outcome makes that clear. The OAIC found no likely breach of privacy law despite millions of records being exposed, because Qantas could show it had reasonable controls in place beforehand. Under APP 11 you are judged on the steps you took, not on whether an attacker got through anyway.

What counts as “reasonable steps” under APP 11?

It depends on your size, the sensitivity of the data and the risks you face, but the OAIC’s assessment of Qantas is a strong guide: assessing and auditing the suppliers who handle your data, training the people who touch it, controlling access, disposing of data you no longer need, and having an incident response you can evidence. The common thread is that each step is documented and can be shown.

How does ISO 27001 help me prove reasonable steps?

ISO 27001 gives you the exact machinery the OAIC looked for: a register of your information assets and risks, documented supplier controls, awareness training records, access controls and incident management, all kept current through a required audit cycle. It turns “we take security seriously” into something you can put in front of a regulator.

Speak with an experienced ISO auditor

If the Qantas findings have you wondering whether you could evidence your own reasonable steps, we can help you find out. Whether that is an independent gap analysis, a full ISO 27001 certification project, practical cyber and information security advisory, or ISO mentoring if your team wants to build it themselves, you deal directly with an experienced ISO auditor. Email hello@streamline.business or call us.

  • Brisbane 07 3667 8280
  • Sydney 02 8315 7780
  • Melbourne 03 9034 3990

Related reading

  • 1,205 data breaches: what Australia’s worst year on record tells you
  • ISO 27001 certification cost and timeline in Australia
  • The uninvited guest: why you should never let bots into your meetings
General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • Miniature industrial yard with a mobile crane on outriggers and timber packing inside a taped exclusion zone, and a worker in hi-vis at a table with a lift plan
    Your Plant Risk Assessment Is a Document. Is It a Control?

Filed Under: Articles Tagged With: #informationsecurity, #iso27001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire