Lander & Rogers logo
1 Insights

Beyond the breach: What the OAIC’s Qantas report tells organisations about cyber resilience and regulatory risk

Beyond the breach: What the OAIC’s Qantas report tells organisations about cyber resilience and regulatory risk

The Office of the Australian Information Commissioner (OAIC) has published its report into its preliminary inquiries regarding the 2025 Qantas cyber incident, providing important guidance on how it assesses whether organisations have taken "reasonable steps" to protect personal information under the Privacy Act 1988 (Cth).

The OAIC chose to publish the report due to the significant public interest in the incident and the educative value of explaining its findings and decision-making process.

The report provides valuable insights for organisations managing cyber risk, as well as insurers assessing cyber risk exposure and claims.

Despite the breach affecting approximately 5.12 million Australians and 5.67 million customer records, following a social engineering ("vishing") attack on an overseas contact centre provider, the OAIC concluded its inquiries without commencing a Commissioner-initiated investigation (CII).

The OAIC found no indication that Qantas had failed to take reasonable steps under Australian Privacy Principles (APPs) 1, 8 or 11 to protect personal information or ensure its overseas provider complied with the APPs.

The report provides one of the clearest indications to date of what the OAIC considers to be "reasonable steps" under APP 11, including security controls, vendor oversight, documentation, incident response capability and data governance.

Key takeaways

The OAIC’s findings reinforce five important lessons:

A large-scale breach does not automatically mean a breach of privacy obligations

It's about reasonable steps, not zero risk

The occurrence of a cyber incident does not, of itself, establish a failure to take reasonable steps under the Privacy Act.

The OAIC’s focus was on whether Qantas could demonstrate a mature and documented security framework, including vendor oversight, staff training, access controls, data governance and incident response capabilities.

For organisations and insurers, the distinction is important: regulatory risk is likely to depend less on whether an incident occurred, and more on whether the organisation can demonstrate appropriate preparation and governance.

Third-party risk is first-party privacy risk

You can outsource services, but not accountability

The breach originated from a social engineering attack against an overseas third-party service provider, yet the OAIC's assessment focused heavily on the steps Qantas had taken to oversee that provider, including audits, training requirements and governance arrangements.

The OAIC placed significant weight on Qantas' management of its overseas service provider, including pre-engagement security assessments, periodic security audits, contractual requirements to comply with privacy obligations, audit rights, and requirements for compliance with recognised standards such as ISO 27001. Importantly, the OAIC concluded that the information available did not suggest Qantas failed to take reasonable steps under APP 8 to ensure the overseas provider handled personal information appropriately.

This reinforces that organisations cannot outsource accountability for personal information merely because it is held or processed by a vendor. For insurers, this highlights the importance of scrutinising vendor governance, outsourcing arrangements (including offshore), audit rights and contractual oversight mechanisms of third-party providers, as these will likely be a key area of regulatory focus following third-party breaches.

Further, robust vendor oversight may materially improve an insured's position when facing regulatory scrutiny following a third-party compromise and prove critical in defending regulatory investigations and privacy claims.

Organisations must be able to demonstrate their security controls

The OAIC’s report highlights that organisations will be assessed not only on the controls they have implemented, but also their ability to demonstrate those controls.

Qantas was able to provide evidence of its security measures, including training programs, audits, access controls, data management practices and retention processes.

Maintaining clear documentation of cyber and privacy controls may be critical in responding to regulatory inquiries and defending claims following a breach.

Incident response maturity can influence regulatory outcomes

It's not the breach that defines the outcome; it's the response

The OAIC highlighted Qantas’ prompt detection, containment, forensic investigation, customer notification and remediation activities.

The report reinforces that a mature incident response capability can significantly influence regulatory outcomes following a cyber incident.

Effective preparation, including tested response plans and access to specialist expertise, remains essential for both cyber resilience and claims defensibility.

Data minimisation and retention remain fundamental privacy controls

The safest data is the data you no longer hold

The OAIC’s report is a reminder that privacy risk is not only about preventing unauthorised access - it is also about managing the information an organisation holds. The OAIC noted Qantas’ processes for destroying and de-identifying personal information that was no longer required.

Strong data retention, deletion and de-identification practices can reduce both the likelihood and impact of a cyber incident, limiting regulatory and liability exposure.

What does this mean for cyber insurers and organisations?

The OAIC’s report reinforces that organisations are not expected to eliminate all cyber risk. Rather, they are expected to demonstrate that they have taken reasonable and proportionate steps to manage it.

The organisations best positioned to withstand regulatory scrutiny will be those that can demonstrate:

  • appropriate security controls;
  • active oversight of third-party providers;
  • robust documentation of governance processes; and
  • a mature and effective incident response capability.

For insurers assessing cyber and privacy risk, the key question may not simply be whether a breach occurred, but whether the insured can demonstrate that it was prepared for one.

That preparedness will often be a critical factor in determining both regulatory exposure and claims defensibility.

All information on this site is of a general nature only and is not intended to be relied upon as, nor to be a substitute for, specific legal professional advice. No responsibility for the loss occasioned to any person acting on or refraining from action as a result of any material published can be accepted.