A Board-Level Framework for Prevention, Response, Evidence and Organisational Resilience
By Navid Sobbi, Founder and CEO, NSI Global
ORIGINAL PUBLICATION: 13 December 2023 RESEARCH CUT-OFF: 1 September 2026 (AEST)
This paper provides general risk-management and technical information. It is not legal advice. Notification, regulatory and contractual obligations should be assessed for the organisation and incident.
Table of Contents
This white paper moves from the Australian risk and legal context to a practical readiness model, response thresholds, implementation roadmap and service alignment.
- Executive Summary
- Purpose, Scope and Definitions
- Australia’s Data Breach Risk Has Changed
- Why Apparently Prepared Organisations Still Fail
- The NSI Global Data Breach Readiness Framework
- Decision Thresholds for Suspected Breaches
- The First 24 Hours
- Measuring Whether the Organisation Is Ready
- How NSI Global Services Support Breach Readiness
- A Three Phase Implementation Roadmap
- Questions Boards and Executives Should Ask
- In Sum
- Frequently Asked Questions
- Sources and Further Reading
Executive Summary
A data breach is not only a cyber event. It is a test of governance, decision authority, evidence quality, privacy assessment, communications, business continuity and executive judgement. An organisation can deploy strong security technology and still fail if it cannot determine what happened, which information was affected, whether the threat remains active, who is authorised to decide, or what must be communicated.
Australia’s breach environment remains persistently elevated. The Office of the Australian Information Commissioner (OAIC) received 532 notifications under the Notifiable Data Breaches scheme from January to June 2025. Malicious or criminal attacks accounted for 59 per cent, but human error and system faults remained material causes. These are self-reported notifications under a legal scheme, not a complete count of every security incident or exposed record.
The operational picture is broader still. The Australian Signals Directorate’s Australian Cyber Security Centre responded to more than 1,200 cyber security incidents in the 2024-25 financial year, an 11 per cent increase from the previous year. The figures describe different populations and should not be combined, but together they reinforce the same board-level conclusion: breach response capability must be designed before an incident.
This paper establishes a seven-domain readiness framework:
- Governance, authority and legal coordination
- Data knowledge and exposure reduction
- Preventive control assurance
- Detection and forensic visibility
- Response orchestration and evidence preservation
- Harm assessment, notification and communications
- Recovery, learning and resilience
These domains are not sequential. During an incident, containment, fact-finding, legal assessment, evidence preservation and business recovery often occur in parallel. The organisation must be able to act quickly without destroying the information needed to understand the breach.
The central finding is that preparedness should be measured by decision capability under pressure, not by the existence of policies or tools. A credible program can identify material sources, activate accountable leaders, preserve evidence, contain proportionately, assess likely harm, meet applicable obligations and restore operations without relying on improvisation.
Purpose, Scope and Definitions
This white paper is intended for boards, executives, legal counsel, chief information security officers, privacy officers, risk leaders, insurers and incident-response teams responsible for organisational preparedness in Australia.
A data breach occurs when information is lost or subjected to unauthorised access or disclosure. A cyber security incident is broader and may include attempted access, disruption, malicious code, compromised credentials or suspicious activity even where exposure has not yet been established. A cyber incident may become a data breach, but the terms are not interchangeable.
An eligible data breach under Australia’s Notifiable Data Breaches (NDB) scheme is a legal classification. In general terms, notification obligations arise for covered entities where unauthorised access to, disclosure of, or loss of personal information is likely to result in serious harm and remedial action has not prevented that likely harm. Whether an incident is notifiable depends on the facts and applicable law, not on the attacker’s label or the organisation’s preferred description.
Forensic readiness means that systems, contracts, processes and personnel are prepared to preserve and produce reliable information about an incident. It includes logging, time synchronisation, retention, access, chain of custody, acquisition pathways and reporting. It does not mean indiscriminate surveillance or collecting all available data.
1. Australia’s Data Breach Risk Has Changed
The original 2023 article was framed around several highly publicised Australian breaches and a claimed long-term increase in notifications. That framing is now too narrow. Current preparedness must account for changes in the threat environment, privacy enforcement, supply-chain dependence, cloud architecture and the speed at which stolen information can be exploited.
1.1 Notification Volumes Remain High
The OAIC recorded 532 NDB notifications in January-June 2025, 10 per cent fewer than the preceding six months but still at a high level. Health service providers accounted for 18 per cent of notifications, finance for 14 per cent and Australian Government agencies for 13 per cent. Malicious or criminal attacks were the largest source.
Notification data has limits. It reflects incidents reported by entities covered by the scheme, using information available at the time. It does not measure every cyber event, every data loss, undetected compromise or incidents outside the scheme. Boards should use it as an indicator of persistent exposure rather than as a probability forecast for their organisation.
1.2 The Legal and Regulatory Context Has Tightened
The NDB scheme has required covered entities to notify eligible breaches since 2018. The original article’s suggestion that Australia might need to introduce mandatory notification similar to overseas regimes was therefore inaccurate. The relevant issue is whether an organisation can rapidly assess the statutory threshold and meet its obligations.
Maximum penalties for serious or repeated interferences with privacy were substantially increased in 2022. Changes passed in 2024 expanded aspects of Australia’s privacy framework, and a statutory tort for serious invasions of privacy commenced on 10 June 2025. Legal exposure remains incident-specific, but breach handling now sits within a more consequential privacy environment.
1.3 Data Is Distributed Across Organisational Boundaries
Sensitive information may be held across cloud platforms, managed service providers, payroll systems, customer applications, collaboration tools, backups, endpoints, archives and third-party integrations. A breach involving one supplier may affect several controllers or custodians. Contractual access to logs, preservation, technical assistance and notification information can determine whether the organisation can establish the facts.
1.4 Identity and Legitimate Tools Complicate Detection
Many incidents do not begin with obvious malware. Attackers can use stolen credentials, session tokens, remote-management tools and legitimate cloud functions. Activity may resemble authorised work until context is applied. Prevention must therefore be supported by identity monitoring, meaningful logging and the ability to investigate behaviour across systems.
2. Why Apparently Prepared Organisations Still Fail
Preparedness often exists on paper but not as an integrated operating capability. The following failure modes repeatedly weaken breach response.
2.1 The Organisation Does Not Know What It Holds
An incident team cannot assess harm if it cannot identify the information involved, its sensitivity, affected individuals, storage locations, retention status or responsible business owner. Asset registers without data context are insufficient. Data mapping, classification and retention decisions reduce both the likelihood and consequence of a breach.
2.2 Response Authority Is Ambiguous
Containment can affect revenue, safety, evidence, customer access and contractual commitments. If the authority to isolate systems, suspend accounts, engage specialists or communicate externally is unclear, decisions are delayed or made informally. The response plan should identify decision rights, deputies and escalation thresholds before the incident.
2.3 Containment Destroys Evidence
Reimaging devices, deleting attacker accounts, rotating logs, restarting systems or changing cloud configurations may be necessary, but each action can alter evidence. The issue is not to delay containment; it is to coordinate containment with preservation. ASD guidance recommends that incident-response planning include processes for collecting, preserving, handling and storing evidence.
2.4 Logs Exist but Cannot Answer the Question
Logging is not the same as forensic visibility. Useful records require appropriate coverage, retention, time synchronisation, integrity, access and tested retrieval. Logs may be missing from identity providers, endpoints, email, cloud control planes, applications, data stores, network devices or third parties. A plan that assumes records exist without testing them creates false confidence.
2.5 Notification Drives the Investigation Instead of Evidence
Pressure to communicate can cause the organisation to state conclusions before scope, persistence and affected data are understood. Conversely, waiting for perfect certainty can delay action. Legal, privacy, forensic and communications teams should work from a shared incident record that separates confirmed facts, reasonable assessments, unresolved questions and decisions.
2.6 Recovery Is Treated as Restoration Alone
Restoring systems does not establish that the threat has been removed, credentials are trustworthy, vulnerabilities are corrected or affected information is understood. Recovery criteria should cover security, evidence, business operations and stakeholder harm.
3. The NSI Global Data Breach Readiness Framework
The following seven domains provide a practical structure for assessing readiness. They are an editorial synthesis of recognised Australian guidance and NSI Global’s service disciplines; they are not a certification scheme.
Domain 1: Governance, Authority and Legal Coordination
Define what constitutes a reportable internal event, who receives the first report, who leads technical response and who decides material business actions. Identify legal counsel, privacy decision-makers, communications leads, insurers, external specialists and relevant regulators. Establish protected workstreams where legal advice or anticipated proceedings require them.
Required evidence of readiness includes an approved response plan, current contact paths, delegated authorities, supplier escalation routes and records of exercises. The plan should account for incidents outside business hours and the unavailability of a primary decision-maker.
Domain 2: Data Knowledge and Exposure Reduction
Map high-value and regulated information to systems, owners, locations, custodians, suppliers and retention requirements. Prioritise information that could cause serious physical, psychological, emotional, financial or reputational harm if exposed. Reduce unnecessary collection, duplication and retention.
The goal is not a perfect enterprise-wide catalogue before any action can occur. Begin with material business services and sensitive datasets, then extend coverage. Validate the map against technical reality rather than relying only on questionnaires.
Domain 3: Preventive Control Assurance
Test whether controls address the organisation’s actual threat paths. Relevant measures may include phishing-resistant authentication for high-risk access, privileged-access management, secure configuration, vulnerability remediation, segmentation, protected backups, email-domain controls, encryption, supplier controls and workforce procedures.
Control assurance should distinguish design from operation. A policy requiring multi-factor authentication does not establish that every material account, legacy protocol, recovery path and service account is protected. NSI Global’s cyber security consultation and audit services can support risk-based assessment, vulnerability testing and remediation planning.
Domain 4: Detection and Forensic Visibility
Identify which records are needed to investigate likely scenarios. Test whether the organisation can retrieve identity, endpoint, email, network, cloud, application and data-access records within required timeframes. Confirm retention, timestamps, integrity, administrative access and provider limitations.
Detection should be tied to response. An alert that no authorised person owns or understands is not an effective control. High-impact detections should have an accountable recipient, triage procedure, severity threshold and escalation route.
Domain 5: Response Orchestration and Evidence Preservation
Prepare scenario-based actions for ransomware, business email compromise, cloud compromise, data exfiltration, insider activity, lost devices and third-party incidents. Coordinate containment with evidence preservation. Record decisions, times, systems, actions, responsible persons and known effects.
NSI Global’s Digital Forensic Incident Response services support authorised matters requiring triage, forensic acquisition, evidence preservation, analysis and reporting. Specialist involvement should be planned in advance so procurement, access and authority do not become incident-time obstacles.
Domain 6: Harm Assessment, Notification and Communications
The OAIC’s general response model is contain, assess, notify and review. Assessment should establish what happened, which personal information was involved, who may be affected, the likelihood and consequence of harm, whether remedial action can prevent likely serious harm and which obligations apply.
Maintain one evidence-led decision record. Communications should accurately distinguish confirmed facts from estimates and avoid implying that absence of evidence is evidence of absence. Notification decisions should be made with legal advice appropriate to the entity, jurisdiction, contracts and affected individuals.
Domain 7: Recovery, Learning and Resilience
Define recovery criteria before restoring normal operations. Confirm that persistence mechanisms are addressed, compromised credentials and sessions are revoked, affected vulnerabilities are treated, monitoring is strengthened, evidence is retained and business owners accept residual risk.
After the incident, assign corrective actions with owners and deadlines. Feed lessons into risk assessments, supplier management, architecture, training and the organisational security master plan. A post-incident review should examine decisions and system design, not search for a convenient individual to blame.
4. Decision Thresholds for Suspected Breaches
The following matrix illustrates governance triggers. Organisations should tailor it to their systems, legal obligations and risk appetite.
| Observed condition | Immediate decision | Evidence priority | Escalation consideration |
| Suspicious privileged or administrator activity | Restrict or monitor access without alerting the actor unnecessarily | Identity, endpoint, cloud-control and authentication records | Insider threat, external compromise, legal and HR coordination |
| Suspected data exfiltration | Contain the channel while preserving scope evidence | Network, endpoint, cloud, application and data-access records | Privacy assessment, contractual notice, law enforcement or regulator |
| Ransomware or destructive activity | Isolate affected systems and protect backups | Volatile data, ransom note, process, account and lateral-movement evidence | Business continuity, safety, insurer and external incident response |
| Compromised email or payment workflow | Suspend risky sessions and verify pending transactions independently | Mailbox rules, sign-ins, messages, audit logs and payment records | Bank recall, affected counterparties, BEC investigation |
| Third-party breach notification | Establish what services, data and access paths are affected | Contracts, integration logs, shared accounts, data flows and supplier evidence | Joint assessment, coordinated notification and alternate service arrangements |
| Lost or stolen device | Determine encryption, access state and remote-control options | Device inventory, management records, credentials and last activity | Remedial action, personal information exposure and physical security |
5. The First 24 Hours
The first day should produce controlled action and a reliable incident record, not premature certainty.
0-2 Hours: Establish Control
- Confirm a secure reporting and coordination channel
- Appoint the incident lead and decision authority
- Record what was observed, by whom, when and on which systems
- Identify immediate safety, operational and information risks
- Engage legal, privacy and specialist support according to triggers
- Begin proportionate containment and preservation
2-8 Hours: Build the Initial Evidence Picture
- Identify affected and adjacent systems, accounts, data and suppliers
- Preserve volatile, short-retention and high-value records
- Establish whether unauthorised access may remain active
- Record containment actions and their effect on evidence and operations
- Separate confirmed facts, working assessments and unknowns
- Identify contractual, regulatory, insurance and law-enforcement considerations
8-24 Hours: Set the Investigation and Recovery Plan
- Define the technical and legal questions the investigation must answer
- Prioritise collections by volatility and decision value
- Establish an initial harm assessment and affected-population hypotheses
- Set communication approval and update intervals
- Define recovery prerequisites and business continuity options
- Record decisions, rejected alternatives, owners and review times
These time bands are governance targets, not guarantees that breach scope can be established within one day. Complex incidents can require sustained investigation.
6. Measuring Whether the Organisation Is Ready
Avoid maturity scores based only on document existence. Measures should test whether the organisation can perform under realistic conditions.
| Readiness question | Weak evidence | Stronger evidence |
| Can the incident team be activated? | A contact list exists | An out-of-hours exercise reached decision-makers and deputies within the target time |
| Can material data be located? | A policy names data classes | Priority datasets are mapped to owners, systems, suppliers and retention controls and have been sampled |
| Can the organisation investigate? | Logging is enabled | Scenario tests retrieved usable, time-aligned records across relevant sources within the required time |
| Can containment preserve evidence? | IT has isolation tools | Playbooks document preservation choices and exercises record the effects of containment actions |
| Can notification be assessed? | A privacy policy exists | Legal and privacy teams have practised serious-harm assessment using incomplete facts |
| Can operations recover safely? | Backups complete successfully | Restoration and security validation have been tested against defined recovery criteria |
| Are suppliers response-ready? | Contracts mention security | Notification, log access, preservation, technical support and exit arrangements have been exercised or evidenced |
Useful performance indicators include activation time, evidence-access time, proportion of critical systems with tested logging, time to revoke high-risk sessions, restoration-test success, overdue corrective actions and supplier-response coverage. Metrics should drive decisions rather than reward superficial compliance.
7. How NSI Global Services Support Breach Readiness
The original article correctly recognised that breach risk extends beyond a single technical control. The service mapping should, however, be tied to defined risks and decisions.
Cyber Security Consultation and Testing
Cyber security consultation and audit services can assess network, endpoint, cloud, remote-access and operational-technology exposure; test vulnerabilities; and support prioritised remediation. These services address prevention and control assurance, not every aspect of incident governance.
Digital Forensic Incident Response
Digital Forensic Incident Response supports investigation of suspected compromise, data exfiltration, ransomware, business email compromise, insider activity and other authorised incidents. The work may include triage, acquisition, preservation, analysis and reporting according to the matter and lawful scope.
NSI Global’s Nine-Stage DFIR Electronic Discovery Model
When a suspected breach progresses into a formal forensic investigation, regulatory response, insurance matter or litigation, NSI Global can apply its Nine-Stage Digital Forensic Incident Response Electronic Discovery Model. The model connects incident response with legally defensible evidence management so that material remains traceable from authority and preservation through to production and reporting.
| Stage | Purpose in a breach investigation |
| 1. Legal Notices and Authority | Establish who may direct the work, which notices or holds apply, the authorised questions, relevant custodians and repositories, and who will receive the results. |
| 2. Chain of Custody | Give each evidence item a unique identity and maintain a continuous record of its condition, possession, movement, access and secure storage. |
| 3. Preservation | Stabilise potentially relevant devices, accounts and short-retention records before routine processes or response actions can change them. |
| 4. Collection | Capture selected electronically stored information through repeatable procedures appropriate to the source, urgency and questions under investigation. |
| 5. Processing | Transform acquired material into a searchable and reviewable form, managing duplicates and formats without losing the connection to original evidence. |
| 6. Analysis | Build and test the incident timeline by correlating technical artefacts, evaluating alternative explanations and labelling conclusions according to evidential support. |
| 7. Review | Enable authorised reviewers to address relevance, privilege, privacy, confidentiality and proportionate use before material is disclosed or relied upon. |
| 8. Production | Assemble approved evidence or disclosure packages with controlled versions, integrity checks and documented quality assurance. |
| 9. Reporting and Expert Support | Communicate the instructions, work performed, findings, qualifications and limitations in the form required by investigators, counsel, insurers, regulators or courts. |
The stages are an operating framework rather than a rigid sequence or universal legal standard. New findings may require renewed preservation, collection or analysis. The engagement scope, lawful authority and decision record should document every material change. The model does not guarantee complete recovery, attribution, admissibility or a particular legal outcome.
Risk Advisory and Security Master Planning
Security master planning connects security philosophy, risk assessment, treatment priorities, implementation and ongoing review to business objectives. It is relevant where breach readiness is fragmented across cyber, physical, personnel, supplier and operational functions.
Corporate Investigations and Insider Risk
Where an incident may involve employee conduct, fraud, collusion, unauthorised disclosure or third-party relationships, corporate investigators can support an authorised fact-finding strategy. Investigative and forensic work should be coordinated so interviews, surveillance, access changes or device handling do not compromise evidence or procedural fairness.
TSCM and Counterintelligence
Not every data breach creates a technical-surveillance requirement. Where the risk profile includes covert recording, compromised meeting spaces, physical access to sensitive discussions or suspected corporate espionage, Technical Surveillance Counter Measures can address channels outside conventional cyber monitoring. Scope should follow the threat assessment rather than be added as a standard breach-response step.
The appropriate engagement may involve one service or a coordinated combination. NSI Global should not be positioned as replacing the organisation’s legal counsel, privacy officer, internal technology team, communications advisers, insurer or regulator.
8. A Three Phase Implementation Roadmap
Phase One: Establish Authority and Material Exposure
- Confirm executive ownership, incident leadership, deputies and decision rights
- Map priority business services, sensitive information, systems and key suppliers
- Review current response, privacy, communications and business continuity plans
- Identify short-retention evidence sources and access dependencies
- Resolve critical contact, procurement, insurance and external-support gaps
Phase Two: Validate Controls and Evidence Access
- Test high-risk identity, remote-access, email, cloud and backup controls
- Retrieve and assess logs for priority scenarios
- Define preservation and containment procedures for likely incidents
- Review supplier notification, evidence-access and support clauses
- Build harm-assessment and communication decision records
Phase Three: Exercise and Improve
- Run an executive tabletop exercise using incomplete and changing facts
- Test technical evidence retrieval and selected recovery procedures
- Record decision times, assumptions, blockers and evidence gaps
- Assign corrective actions with owners, deadlines and executive oversight
- Schedule re-testing after material technology, supplier or threat changes
This roadmap is a prioritisation model, not a claim that enterprise-wide readiness can be completed in 90 days. High-risk or regulated organisations may require deeper technical validation and more frequent exercising.
9. Questions Boards and Executives Should Ask
- Which information holdings could cause the greatest harm if exposed, and where are they actually stored?
- Who can authorise containment that disrupts revenue or customer access?
- How quickly can we retrieve identity, endpoint, email, cloud and data-access evidence?
- Which critical logs expire before a complex investigation could begin?
- What actions could our IT team take that would unintentionally alter or destroy evidence?
- How do legal, privacy, cyber, communications and business continuity teams maintain one factual record?
- Which suppliers hold our sensitive data or privileged access, and what evidence must they provide after an incident?
- Have we tested restoration as well as backup completion?
- What would trigger external DFIR, specialist investigation, TSCM or crisis support?
- When was the last exercise, what failed, and which corrective actions remain open?
- Can we explain why a suspected breach was or was not assessed as notifiable?
- What residual risk has management accepted, and on what evidence?
In Sum
The data breach epidemic should not be reduced to a list of historic incidents or alarming statistics. The durable question is whether the organisation can make sound, evidence-led decisions when facts are incomplete, operations are under pressure and harm may be developing.
Prepared organisations understand material data, validate controls, retain usable evidence, assign decision authority, coordinate containment with preservation, assess notification obligations and recover against defined criteria. They also recognise when the risk crosses organisational boundaries and requires specialist support.
No framework can guarantee that a breach will be prevented or that every fact will be recovered. A disciplined readiness program reduces avoidable uncertainty and gives boards a defensible basis for action.
For an authorised assessment of breach preparedness, cyber controls, forensic readiness or incident-response requirements, contact NSI Global.
Frequently Asked Questions
What Is a Data Breach?
A data breach involves the loss of information or access to, or disclosure of, information without authorisation. Causes can include malicious activity, human error, system faults, lost devices, misconfiguration or inappropriate internal access.
Is Every Cyber Incident a Notifiable Data Breach?
No. A cyber incident may not involve personal information or meet the legal threshold for notification. Covered entities must assess whether an eligible data breach has occurred under the NDB scheme and consider other applicable legal, regulatory and contractual duties.
How Long Does an Organisation Have to Assess a Suspected Eligible Data Breach?
Under the NDB scheme, an entity that has reasonable grounds to suspect an eligible data breach must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days. This is not a reason to delay containment, remedial action or evidence preservation.
What Should a Data Breach Response Plan Include?
It should define reportable events, roles, decision authority, containment and preservation procedures, investigation access, harm assessment, notification, communications, supplier coordination, recovery criteria and post-incident review. It should be tested through exercises.
When Should Digital Forensic Specialists Be Engaged?
Engage specialists early when evidence may be volatile, unauthorised access may remain active, data exfiltration is suspected, legal or regulatory scrutiny is likely, insider conduct is possible or internal actions could alter evidence. Early advice may begin with preservation and scoping rather than a full examination.
Does Having Backups Mean the Organisation Is Prepared?
No. Backups support recovery but do not establish breach scope, remove attacker access, preserve evidence, assess harm or satisfy notification duties. Restoration should be tested and connected to security validation and business recovery criteria.
How Often Should Breach Readiness Be Tested?
Testing frequency should reflect risk, regulatory requirements and organisational change. Exercises should also follow significant platform migrations, supplier changes, acquisitions, incidents, leadership changes or material findings from audits.
Sources and Further Reading
- OAIC: Latest Notifiable Data Breach statistics for January-June 2025
- OAIC: Notifiable Data Breach statistics dashboard
- OAIC: Quick reference guide for responding to data breaches
- OAIC: Preparing a data breach response plan
- OAIC: Responding to data breaches – four key steps
- OAIC: Notifiable Data Breaches scheme
- OAIC: Statutory tort for serious invasions of privacy
- OAIC: Civil penalties for serious or repeated interference with privacy
- ASD: Annual Cyber Threat Report 2024-2025
- ASD: Cyber security incident response planning – practitioner guidance
- ASD ISM: Guidelines for cyber security incidents
- Privacy Act 1988 (Cth)