Governance Excellence · Resource 042

Cyber and Data Governance as a Board-Level Risk, Not an IT One

Stewardship & Risk · Practical guidance for association boards, directors and CEOs.

Nexus Governance Excellence Series

Cyber and Data Governance as a BoardLevel Risk, Not an IT One The standard is not perfection. It is documented board-level engagement Cyber security is still, in most association boardrooms, treated as an IT problem that gets a brief update slot before the meeting moves on to matters the board considers its own. That framing no longer matches either the legal exposure or the practical reality. It is a governance risk in the same category as the financial and risk appetite discipline covered earlier in this quarter, and it deserves the same level of board ownership.

01 Who Is Actually Required To Comply, And Who Should Anyway 02 The Principle The Courts Have Already Established 03 Why This Belongs At Board Level, Not Just Management'S Desk Use this resource as a board pre-read, discussion guide or governance review prompt.

Who Is Actually Required To Comply, And Who Should Anyway Stewardship & Risk · 16 June 2026 Compliance with the Privacy Act 1988 (Cth) is mandatory for not-for-profits with annual turnover over $3 million, a threshold that happens to align with the ACNC's own large charity tier discussed earlier in this quarter. Organisations above that line must comply with the Australian Privacy Principles and the Notifiable Data Breaches scheme, which requires notifying both affected individuals and the Office of the Australian Information Commissioner following an eligible data breach. Smaller organisations below the threshold are not legally compelled to comply in the same way, but this exemption is a floor, not a safe harbour. A smaller association still handling member health records, payment details, or other sensitive personal information carries real reputational and member-trust exposure regardless of where the legal line technically sits, and the practical case for voluntary compliance is strong even where the statutory obligation is not.

The Principle The Courts Have Already Established The Federal Court's decision in Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496, while decided in the context of an Australian Financial Services Licensee's specific statutory obligations, established a principle that reaches well beyond that sector: cybersecurity risk cannot be reduced to zero, but it can and must be materially reduced to an acceptable level through adequate documentation, controls, and genuine follow-through when incidents occur. The case also illustrates what commentators describe as 'stepping-stones' liability, where an organisation's own failure to manage a risk adequately can expose individual directors to a breach of their duty of care under section 180 of the Corporations Act, the same duty of care standard this series has returned to throughout its discussion of board accountability.

The relevant standard is not perfection. It is documented, board-level engagement with the risk, proportionate to the organisation's actual exposure, rather than an assumption that the IT function or an outsourced provider has it handled without anyone at board level actually confirming that.

Why This Belongs At Board Level, Not Just Management'S Desk Cyber and data risk fits precisely within the risk appetite framework discussed earlier in this quarter. It is a category a board should explicitly address in its risk appetite statement, with tolerance levels stated rather than left implicit, and it connects directly to the delegations of authority discipline covered in the previous quarter: management should own the operational implementation, while the board retains oversight and cannot delegate away its responsibility for confirming that implementation is adequate, the same delegate-authority-not-responsibility principle this series has returned to repeatedly. •

Confirm whether your organisation sits above or below the $3 million Privacy Act threshold, and treat voluntary compliance seriously even if you sit below it, particularly where sensitive member information is involved.

Include cyber and data risk explicitly in your risk appetite statement, with specific tolerance levels rather than a general acknowledgement that it matters.

Confirm basic, low-cost controls are in place, multi-factor authentication, regular backups, and staff training, since these remain the most common gaps identified in real incidents, including RI Advice's own documented failures.

Maintain an incident response plan and confirm it is tested, not just written, since the RI Advice case turned as much on failure to act on known vulnerabilities as on the original gaps themselves.

Report cyber risk to the full board on a genuine, standing cycle, connecting to the delegated authority and reporting discipline discussed earlier this quarter, rather than treating it as a specialist topic outside normal board oversight.

A board does not need deep technical expertise in cyber security to discharge this responsibility properly. It needs to treat the risk with the same governance seriousness applied to every other category this series has covered, oversight, documentation, and

accountability, rather than assuming a technical problem sits permanently outside the board's own remit. This is one of the practical governance topics built into our AI for Association Leaders course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course → — Annie Gibbins General education — not legal, financial, tax, clinical or governance advice. Confirm specifics at the relevant primary source or with your own qualified adviser. Nexus Leadership is operated by Lipstick Consulting Pty Ltd · ABN 15 619 120 482.

CONTINUE YOUR LEARNING

Turn governance principles into practical board action. Self-paced learning, editable resources and strategic support for association leaders.

NEXUS LEADERSHIP Association Management Specialists nexusleadership.com.au

BOARDROOM

ACTION WORKSHEET Turn the article into evidence, a decision and an accountable next step.

Cyber and Data Governance as a Board-Level Risk, Not an IT One Editable boardroom action record 1. What is the issue or decision? State the governance question in one clear sentence.

2. What evidence do we already have? Record the facts, source documents and stakeholder evidence available now.

3. What evidence is still needed? Identify the legal, regulatory, financial, member or operational information still required.

4. What is the agreed next action? Capture the owner, timeframe and how the matter will return to the board.

ACTION REVIEW OWNER DATE Name / DD / role MM / YYYY

BOARD DECISIO N Decision / resolutio n

Apply it with your board

Need support turning this topic into a board decision, policy or facilitated conversation?

Nexus Leadership works with association boards and CEOs through Strategy Days, Board Inductions, workshops and practical governance support.

Discuss governance support →
Related Governance Resources