Here’s a question that’s now being asked at board level, in insurance renewals, and by regulators:
Can your business demonstrate it has taken reasonable steps to protect customer and business data?
Not your IT team. Not your managed service provider.
You. The director, the owner, the person ultimately responsible.
If that feels confronting, you’re not alone.
For many SMBs, cybersecurity has always lived in the “IT handles that” bucket.
But the rules have changed, and accountability now sits firmly with leadership.
This Is a Governance Conversation, Not a Technical One
Regulators including ASIC, the OAIC, and the Australian Institute of Company Directors have all said the same thing: cyber risk needs active oversight from directors and business owners.
That doesn’t mean you need to understand how a firewall works. It means you need to know whether your business has the right protections in place, whether they’re current, and what happens if something goes wrong.
Courts and regulators are now treating cyber incidents the same way they treat financial mismanagement or workplace safety failures. If something goes wrong and leadership has not taken reasonable steps, it is seen as a failure of governance, not bad luck.
What’s Actually Changed in Australian Law
Two key reforms have raised the bar for business leaders:
The Privacy Act 1988 (amended 2024) now strengthens what “reasonable steps” means when it comes to protecting personal information. It specifically calls out both technical and organisational measures. Penalties for serious failures remain significant – up to $50 million, 30% of turnover, or three times the benefit obtained.
The Notifiable Data Breaches Scheme requires organisations to notify affected individuals and the OAIC if a breach is likely to cause serious harm. Getting this wrong doesn’t just expose the business – it exposes leadership personally to regulatory action.
The Questions Every Director Should Be Able to Answer
You don’t need to be a technical expert.
But you do need to be able to answer these with confidence:
- Are we actively investing in cyber security protection and compliance, or are we still running on break-fix?
- What would a cyber incident actually cost us in revenue, downtime, and reputation?
- How quickly could we recover if something happened today?
- Are we meeting the legal and contractual obligations that apply to our business?
Regulators want to see that cyber risk is on the leadership agenda, sitting in your risk register, and being actively reviewed. Not set up once and left to gather dust like that old project to move everything to 365.
Two Assumptions That Catch Businesses Out
“Our IT provider has it covered.” Your MSP can implement and manage technical controls, but the accountability for whether those controls are adequate still sits with you. An IT provider is a partner in this, not a replacement for governance.
“Our cyber insurance will take care of it.” Insurers are increasingly asking for proof of controls before they’ll pay out. Weak governance can mean a denied claim at the worst possible time.
Both of these tend to surface after an incident or a regulatory inquiry, when it’s too late to fix them.
What “Reasonable” Looks Like in 2026
Drawing on guidance from ASIC, the OAIC, and the AICD, the expectation is that your business can demonstrate:
- That you’ve taken steps aligned to the risks your business actually faces today
- That systems and data have ongoing protection, not just a one-time setup
- That risk management is continuous, not a project that finished three years ago
- That your security posture is being reviewed and improved as threats evolve
Nobody expects perfection. But “reasonable” in 2026 means controls that reflect today’s threat landscape, not what was considered acceptable five or ten years ago.
There’s a Commercial Upside Too
This isn’t all about avoiding penalties. Businesses that get their cyber posture right tend to find it easier to win contracts, pass audits, build trust with customers, and recover faster when something does go wrong. For businesses in regulated, health, education, NFP, or government-adjacent sectors, cyber maturity is increasingly part of commercial due diligence.
What We’re Doing About It
As a Microsoft Cloud Solution Provider, we see this as part of our responsibility, not just a service we offer.
We’ve invested in building a foundational security baseline designed specifically for our smaller and currently unmanaged clients. We’re rolling this out over the next 3-5 months because we believe every business we work with should have a security posture that meets today’s expectations, regardless of size.
In practice, that means helping leadership teams:
- Turn regulatory and legal expectations into practical, workable controls
- Move from one-off fixes to ongoing security maturity
- Stay current with modern technical solutions
- Manage risk without creating friction in the business
If you’re not sure how your current setup stacks up, that’s usually the best place to start a conversation. Give us a call 1300 705 062.



