Free HR Services from our Employee Relations Experts. Find out more.

You have one free articles for this month. Sign up for a CCIWA Membership for unlimited access.

Preparing for a cyber breach: lessons from the Qantas incident

By Cassandra Wright

No business is immune from a cyber attack.
From small operators to major national brands, any business that collects customer, employee or supplier information faces the risk of a data breach.

While cyber risk can never be eliminated entirely, businesses that invest in strong governance, clear processes and regular testing are better placed to minimise the impact when an incident occurs.

The Qantas cyber incident provides a timely reminder of why preparation matters.

The 2025 breach, linked to a third-party customer service platform, was reported by Qantas to the Office of the Australian Information Commissioner (OAIC) under Australia's Notifiable Data Breaches scheme.

In July 2026, the Privacy Commissioner found insufficient evidence that Qantas had breached its privacy obligations and took no further regulatory action.

Key points for businesses

A lack of regulatory action should not be taken as proof that a business' governance was adequate.

Each case is different. Therefore, it is important for businesses to prepare before a breach occurs.

A professional using a laptop with digital document icons, representing cyber attack safety and business compliance.

In short:

  • The Qantas cyber incident highlights why businesses should prepare for a cyber attack or data breach before one occurs.
  • Strong cyber governance includes knowing what data you hold, managing third-party risks and maintaining a tested incident response plan.
  • If a breach occurs, businesses should act quickly to contain it, assess notification obligations, communicate appropriately and document their response.

Good governance is more than a policy document

Having a Privacy Policy and Cyber Incident Response Plan is a good start, but effective cyber governance requires more than documents on a shelf.

Businesses need clear processes to identify what data they hold, where it is stored and who can access it, supported by data retention policies, incident registers and breach response procedures.

Strong governance also includes access controls, multi-factor authentication, supplier due diligence and business continuity planning.

Just as importantly, policies must be tested, followed and documented. In the event of a regulatory review, records of training, decision-making and compliance activities may carry more weight than policies that exist only on paper.

Steps businesses can take today

Preparation is critical.

Businesses should know what data they hold, securely destroy information they no longer need, review third-party contracts, maintain tested incident response plans and ensure adequate cyber insurance cover.

What happens when a breach occurs?

When a cyber incident occurs, businesses need to act quickly to contain the incident, assess risks, meet any notification obligations and ensure timely and accurate communications to customers, employees, service providers and regulators as required.

Decisions should be documented, with records kept to support any future regulatory review.

Once the incident has been resolved, businesses should identify the cause, implement remedial actions and update policies, systems and training to prevent a recurrence.

How Business Law WA can help

Business Law WA can assist with: 

  • Privacy policies and privacy compliance reviews 
  • Data retention and protection policies 
  • Data breach and cyber incident response plans 
  • Incident registers, assessment forms and response checklists 
  • Supplier and cloud-service agreements 
  • Privacy, cybersecurity and data destruction clauses 
  • Privacy Act and Notifiable Data Breaches compliance advice 
  • Communications to affected individuals and regulators 
  • Post-incident legal and governance reviews 
  • Executive and board-level breach response exercises 

Businesses can also access templates and resources through CCIWA Toolkits & Guides. For tailored advice, contact Business Law WA at [email protected] or call 08 9365 7560. 

Cass Wright – Legal Director, Business Law WA

Cass has practiced as a lawyer for more than 20 years. She has assisted a large number of SMEs and businesses to put in place protections against cyber attacks and make sure businesses better protect their data assets.

Cass is well known for her easy-to-talk-to nature, proactive advice and clarity.

Make a time to chat to her and discuss your needs: [email protected] or call 08 9365 7746.

This article is authorised by Business Law WA, an incorporated legal practice and wholly owned subsidiary of CCIWA. The content of this article is general in nature and is not legal or professional advice and should not be relied upon as such.

No business is immune from a cyber attack.
From small operators to major national brands, any business that collects customer, employee or supplier information faces the risk of a data breach.
While cyber risk can never be eliminated entirely, businesses that invest in strong governance, clear processes and regular testing are better placed to minimise the impact when an incident occurs.

The Qantas cyber incident provides a timely reminder of why preparation matters.

The 2025 breach, linked to a third-party customer service platform, was reported by Qantas to the Office of the Australian Information Commissioner (OAIC) under Australia's Notifiable Data Breaches scheme.

In July 2026, the Privacy Commissioner found insufficient evidence that Qantas had breached its privacy obligations and took no further regulatory action.

Tagged under: