Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
    • ISO 13485 Medical Devices
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

The Patch Directive Went Out the Same Day. Not Every School Applied It.

The Department of Education’s directive to patch went to every Victorian government school technician six and a half hours after the Australian Signals Directorate issued a critical alert. That part worked. What the Department could not do was tell whether the schools had acted on it, and at least one had not. An attacker got into that school’s IT system and took the names, schools, year levels, school email addresses and encrypted passwords of every government school student in the state, plus hundreds of thousands of former students.

Tilt-shift miniature of a school campus with an open comms cabinet in one classroom block and a patch notice pinned to its door
ASD’s alert went out at 10am on 27 October 2025. The Department’s directive reached every school technician by 4.32pm. OVIC found patching “did not occur at the school level”.

That is the finding of the Office of the Victorian Information Commissioner’s investigation report, published this week. It is worth reading for anyone who runs IT across more than one site, because the failure it describes is not a missing control. It is a control that stopped at “sent”.

Short answer

OVIC found the Department breached Information Privacy Principles 4.1 (security) and 4.2 (destroying or de-identifying information no longer needed). The Department had a patching policy and issued the right instruction on the right day. It had no process to verify or monitor whether schools carried it out. OVIC made seven recommendations, all due by 31 December 2026, including a “feedback loop” so the Department knows schools have acted on future security advisories. The lesson for any multi-site organisation is that an instruction is the start of a control, not the control.

What happened, and when

The timeline comes from the OVIC report.

Date and timeWhat happened
27 October 2025, 10.00amASD releases a critical alert
27 October 2025, 10.01amThe Department of Government Services alerts the Department of Education
27 October 2025, 4.32pmThe Department sends a directive to all school technicians
6 November 2025Earliest evidence of malicious activity. OVIC has high confidence exploitation happened before this
2 December 2025, about 5.30pmThe Department’s vendor reports detecting significant threats through routine monitoring
3 December 2025The Department activates its cyber security incident response plan
4 December 2025The Department re-sends the advisory to school technicians
23 December 2025Forensic analysis confirms data was exfiltrated
7 January 2026The Department notifies OVIC

Two details stand out. The school whose system was compromised did not know its network and servers had been breached until it was told. And the advisory had to be sent a second time, five weeks later, after the attack had been found.

Why the directive was not enough

Victorian government schools run on a devolved model. The Department sets policy and schools implement it, supported by more than 750 specialist technicians through the Technical Support to Schools Program. The Department’s policy expects technicians to carry out “risk-prioritised patching”.

On 27 October the Department told the program to notify schools, and it did, the same day. OVIC’s report records that “not all schools followed the advice”, and that “timely and effective patching did not occur at the school level”. OVIC described the Department’s governance of the support program as “inadequate”, because there was no process to check whether schools had acted on a directive. It also found the Department’s vulnerability management program did not cover every school and did not see every critical vulnerability remediated, and said exposure of unpatched internet-facing servers after a critical alert “should have warranted greater attention by the Department”.

None of that is unusual. Most organisations with branches, franchisees, clinics, depots or schools work this way: the centre writes the policy, the sites do the work, and the centre assumes that what it sent was done.

The control is the check, not the email

Read this as an auditor and the gap is precise. ISO 27001 control A.8.8, management of technical vulnerabilities, asks you to obtain information about vulnerabilities, evaluate your exposure and take appropriate measures. Getting an advisory and passing it on covers the first part. It does not show the exposure was evaluated or that anything was done about it.

The evidence an auditor would ask for is the return leg:

  • Confirmation per site. Which sites have applied the patch, by when, and who confirmed it.
  • Independent verification. A scan or report from a central tool, not just a reply saying “done”.
  • Follow-up for the gaps. What happens to a site that has not confirmed by the deadline, and who chases it.
  • Escalation. At what point an unpatched internet-facing system stops being a site’s problem and becomes the organisation’s.

That return leg is what OVIC’s second recommendation describes as a feedback loop. In ISO 27001 terms it is also A.5.36, compliance with policies, rules and standards for information security, which asks you to regularly review whether your own policy is being followed. A policy that expects risk-prioritised patching, with nobody checking whether it happens, is a policy the organisation has written for itself and then not tested.

Your own policy is auditable too

This is the part internal audit tends to miss. Clause 9.2 asks two questions: does the management system meet the standard, and does it meet the organisation’s own requirements? The second one is a trap for anyone who has written more into their system than they do in practice.

If your patching procedure says critical vulnerabilities are applied within 48 hours at every site, that is now an auditable requirement, whether or not ISO 27001 asked for 48 hours. An internal audit should sample it: pick an advisory from the last quarter, pick three sites, and trace it from receipt to confirmed remediation. If the trail stops at the email, that is a nonconformity against your own procedure, and it is far better found by your internal auditor than by a regulator.

The Department has told OVIC it will run an internal audit in 2027 to review how well its vulnerability management for schools works. That is the right instrument. The difficulty is timing: OVIC noted the Department’s plan to move schools to centrally provided technology by the end of 2028 leaves a long lead time, with risk to manage in the meantime.

Old credentials are a data risk too

The second finding is less about patching and more about what was there to steal. The Department kept credentials for past students so that a new student would not be given an email address that had already been used, and with it access to a former student’s records. OVIC accepted the business need but found keeping the credentials themselves was “not a proportionate response” to it, and that the practice breached IPP 4.2.

The equivalent ISO 27001 control is A.8.10, information deletion. Ask what personal information you are holding for people who left years ago, and whether you need the information itself or only a record that the identifier was used. Under the Commonwealth Privacy Act the same thinking sits in APP 11.2, and we covered the reasonable-steps side of it in securing personal information under APP 11.3. The Department has said it plans an archive policy for inactive student records by December 2026, but will need extra funding to deliver it.

Where this sits next to the other recent cases

This is the reverse of the problem in one breach, 21 GP practices, where a single compromised head office exposed every site. Here the centre did its part and one site did not. Both come back to the same question of scope: if your ISMS covers many locations, the controls have to reach every one of them, and you need evidence that they do.

It is also a cousin of the Mathspace case, where a patch was published on 6 August, the breach happened on the 10th and the patch was applied on the 29th. In a single organisation the gap is between the advisory and the patch. Across many sites there is a second gap, between the instruction and the confirmation, and it is easier to miss because the centre believes it has already acted.

What to do this month

If you run IT across more than one site, five things are worth doing now:

  1. Pick last quarter’s most serious advisory and trace it to every site. Record who confirmed, when, and how you know.
  2. Add a confirmation step to your vulnerability procedure, with a deadline and a named owner who chases the gaps.
  3. Get central visibility of internet-facing systems at every site, so verification does not depend on a reply.
  4. Put the trace in your internal audit programme under clause 9.2 and A.5.36, sampled against your own stated timeframes.
  5. Review what you keep about former customers, students, members or staff, and whether you need the record itself or only a note that it existed.

Frequently asked questions

What did OVIC find about the Department of Education breach?

OVIC found the Department breached IPP 4.1 because its security controls were not adequate, and IPP 4.2 because it kept past students’ credentials when that was not proportionate to the business need. It made seven recommendations, all due by 31 December 2026, which the Department accepted.

Was the Department told about the vulnerability in time?

Yes. ASD issued a critical alert at 10am on 27 October 2025, the Department was alerted a minute later, and it directed all school technicians to act at 4.32pm the same day. OVIC’s concern was what happened after the directive, not before it.

What is a feedback loop in vulnerability management?

It is the return path that confirms each site, team or system owner has acted on a security advisory, with evidence and a follow-up for anyone who has not. Without it, the centre knows what it asked for but not what was done.

Does ISO 27001 require patches within a set time?

No. A.8.8 asks for timely, appropriate action based on your evaluation of the exposure. The timeframe is yours to set, but once your procedure states one, internal audit should test it.

Does this apply to private businesses?

The report applies Victorian public sector privacy law, but the failure is common to any organisation with sites, branches or franchisees managing their own IT. Private businesses covered by the Commonwealth Privacy Act face the equivalent test under APP 11.

Closing the loop

The Department did the hard part on the first day and still lost the data, because nobody could see whether the instruction had landed. That is a governance gap, and it is exactly what an independent audit is designed to find before an attacker does.

Streamline builds ISO 27001 information security management systems for Australian organisations, and you deal directly with a practising ISO Lead Auditor. An independent internal audit will trace your last critical advisory to every site, a gap analysis will show where your vulnerability process stops short, and ISO mentoring suits organisations that want their own people to build it. If your patching ends at “sent”, get in touch.

Sources

  • Office of the Victorian Information Commissioner, Investigation into the data breach of student information at the Department of Education, report dated 5 October 2026, page updated 7 October 2026 (PDF)
  • ISO/IEC 27001:2022, clause 9.2 and Annex A controls A.5.36, A.8.8 and A.8.10

Facts in this article are current as at 8 October 2026 and are drawn from the OVIC report. This article is general information from an auditing and management system perspective and is not legal advice.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • Tilt-shift miniature of a darkened open-plan office at night, one desk lit by two monitors showing a wall of server log lines and an email client with a single unread message, the chair pushed back and empty, and a wall calendar with weeks crossed off in red
    The Patch Was Published on 6 August. Mathspace…
  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Tilt-shift miniature of an electricity substation at dusk, with the cable running to the adjacent building visibly cut
    ASD Wants Critical Infrastructure Isolated for 3…
  • Tilt-shift miniature of a darkened data centre at night, a single figure standing at a plain control desk with three monitors showing abstract graphs, rows of equipment racks with green and amber indicator lights receding into the distance and cable trays overhead
    What You Govern Is the Harness, Not the Model
  • Tilt-shift miniature of a server room where technicians tag and log every cable and certificate into a ledger, beneath a calendar turned to December 2026, while a faded 2030 banner hangs ignored at the back
    Everyone Heard 2030. The First Post-Quantum…
  • Tilt-shift miniature of a government mailroom with an unopened flagged envelope in the public enquiries tray and a small robot leaving a server room.
    OpenAI's Medicare Breach: What It Means for…
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Miniature network operations room with staff at monitoring screens and an incident list on a whiteboard, and a server rack room beyond glass with one cabinet door standing open
    The ACSC Just Handed Your IT Provider a Question. Do…
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring

Filed Under: Articles Tagged With: #informationsecurity, #iso27001

Quick Contact Form

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Citation Certification ISO 9001 certification mark, the JAS-ANZ accreditation symbol and the ASQ logo

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Trust Centre · Privacy Policy · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire