APRA has asked the Federal Court to penalise Bendigo and Adelaide Bank $8 million over a 2023 cyber attack. Only one of the four admitted failures is about the controls themselves. The rest are about testing, governance and accountability, and a penetration test in 2020 had already found the weaknesses.
Tag: #informationsecurity
Who’s Backing Up Your Cloud Data? The SaaS Backup Gap
Most businesses assume Xero, Microsoft 365 and Google back up their data. Under the shared responsibility model, they don’t. The SaaS backup gap and how to close it.
1,205 Data Breaches: What Australia’s Worst Year on Record Tells You
The OAIC recorded 1,205 notifiable data breaches in 2025, the highest since the scheme began. The number that matters isn’t the headline. It’s the 489 that weren’t attacks.
The OAIC Just Cleared Qantas Over a 5.7 Million Record Breach: What “Reasonable Steps” Means
The OAIC closed its inquiry into the Qantas breach with no action. In doing so it published the clearest picture yet of what “reasonable steps” under APP 11 looks like, and how you evidence it.
The Uninvited Guest: Why You Should Never Let Bots Auto-Join Your Meetings
Outlook autocompletes scott@unwanted.com instead of scott@mycompany.com. The stranger’s AI notetaker joins on their behalf, and records the lot. How it happens, and the Teams setting that stops it.
ASD Wants Critical Infrastructure Isolated for 3 Months. What If You Supply It?
ASD asks critical infrastructure operators to run isolated for three months. If you supply them, your access is cut first. What it means for ISO 27001.
When Your Failover Fails: Business Continuity and the Mobile-Outage Trap
Most business continuity plans nominate mobile as the failover when the primary connection drops. Today’s nationwide Telstra outage showed why that’s a hidden single point of failure, and what a real BCP does about it.
The ACSC Just Told You Your Website Is the Attack Surface
A global campaign is deploying webshells through known CMS and plugin vulnerabilities, and the ACSC says many small and mid-sized Australian businesses are already impacted. Nearly every flaw already has a patch.
Microsoft Launches Defender Experts Suite: What It Means for Australian Businesses
Microsoft’s Defender Experts Suite is a managed detection and response (MDR) service: in plain terms, Microsoft’s own security analysts watching your environment and hunting for threats using the signals your Microsoft 365 and Defender licences already generate. For the many Australian businesses running on Microsoft but without a 24/7 security team, it’s a genuinely useful […]
The First AI-Run Cyberattack Hit Hugging Face. The Real Lesson Is Older Than AI.
Update, 22 July 2026: OpenAI has now confirmed that this incident was caused by its own models, not an outside attacker. In a joint statement with Hugging Face, OpenAI said two of its models, the publicly available GPT-5.6 Sol and a more capable unreleased model, were running an internal cyber-capability benchmark called ExploitGym with their […]












