Story image

As NDB takes hold, expect to see more breach reports come to light

14 Jun 18

In light of Australia’s Notifiable Data Breaches legislation that rolled out in February, one Australian technology integrator says we can expect to see many reports surfacing over the coming years.

RBC Group says that ‘dozens’ of corporate data security breaches have been reported as part of the new legislation. Businesses with an annual turnover of more than $3 million must now notify the Australian Information Commissioner and customers in the event of a data breach.

The Notifiable Data Breaches Quarterly Statistics Report (January-March 2018) report detailed 63 breach notifications, of which the largest proportion came from the healthcare industry.

RBC Group notes that the legal accounting and management services sector who reported 10 breaches – equating to 16% of notices.

Further statistics from the report show that in 78% of cases, private contact information was exposed or accessed and in 30% of cases, financial details of businesses and customers were breached. Health information and identity information was also exposed 33% and 24% respectively.

RBC Group believes that there are increasing fears about the safety of classified corporate information, particularly with growing numbers of employees that work remotely.

“With more and more employees taking devices home or using them in public away from a corporate office, it’s no wonder we’re seeing such high numbers of corporate data breaches,” comments RBC Group managing director David Wheeler.

“I would expect these figures will continue to rise each quarter, so businesses need to start taking more responsibility in educating their workforce. This is particularly in regards to maintaining data security and ensuring that they audit the security of their entire network regularly.”

RBC Group cites further statistics from the report that reveal in 28 cases, the breach was the result of malicious or criminal attacks on the data. Malicious or criminal attacks usually involve the theft of personal information, or cyber security incidents resulting from unauthorised access to an entity’s systems.

“73% of data breaches involved the personal information of under 100 individuals, however in 3 cases, between 10,000 and 99,999 people were affected and in a further 3 cases more than 1000 people were affected,” the company states.

“Data breaches weren’t all the result of malicious or criminal attacks, however, with 32 cases a result of human error, with information inadvertently disclosed by sending a document to the wrong person.”

RBC Group is one of Australia’s largest independent and privately owned technology integrators. It was formed in 1975.

Disruption in the supply chain: Why IT resilience is a collective responsibility
"A truly resilient organisation will invest in building strong relationships while the sun shines so they can draw on goodwill when it rains."
Businesses too slow on attack detection – CrowdStrike
The 2018 CrowdStrike Services Cyber Intrusion Casebook reveals IR strategies, lessons learned, and trends derived from more than 200 cases.
What disaster recovery will look like in 2019
“With nearly half of all businesses experiencing an unrecoverable data event in the last three years, current backup solutions are no longer fit for purpose."
Proofpoint launches feature to identify most targeted users
“One of the largest security industry misconceptions is that most cyberattacks target top executives and management.”
McAfee named Leader in Magic Quadrant an eighth time
The company has been once again named as a Leader in the Gartner Magic Quadrant for Security Information and Event Management.
Symantec and Fortinet partner for integration
The partnership will deliver essential security controls across endpoint, network, and cloud environments.
Is Supermicro innocent? 3rd party test finds no malicious hardware
One of the larger scandals within IT circles took place this year with Bloomberg firing shots at Supermicro - now Supermicro is firing back.
25% of malicious emails still make it through to recipients
Popular email security programmes may fail to detect as much as 25% of all emails with malicious or dangerous attachments, a study from Mimecast says.