Cyber security is still, in most association boardrooms, treated as an IT problem that gets a brief update slot before the meeting moves on to matters the board considers genuinely its own. That framing no longer matches either the legal exposure or the practical reality. It is a governance risk in the same category as the financial and risk appetite discipline covered earlier in this quarter, and it deserves the same level of board ownership.
Who is actually required to comply, and who should anyway
Compliance with the Privacy Act 1988 (Cth) is mandatory for not-for-profits with annual turnover over $3 million, a threshold that happens to align with the ACNC's own large charity tier discussed earlier in this quarter. Organisations above that line must comply with the Australian Privacy Principles and the Notifiable Data Breaches scheme, which requires notifying both affected individuals and the Office of the Australian Information Commissioner following an eligible data breach. Smaller organisations below the threshold are not legally compelled to comply in the same way, but this exemption is a floor, not a genuine safe harbour. A smaller association still handling member health records, payment details, or other sensitive personal information carries real reputational and member-trust exposure regardless of where the legal line technically sits, and the practical case for voluntary compliance is strong even where the statutory obligation is not.
The principle the courts have already established
The Federal Court's decision in <i>Australian Securities and Investments Commission v RI Advice Group Pty Ltd</i> [2022] FCA 496, while decided in the context of an Australian Financial Services Licensee's specific statutory obligations, established a principle that reaches well beyond that sector: cybersecurity risk cannot be reduced to zero, but it can and must be materially reduced to an acceptable level through adequate documentation, controls, and genuine follow-through when incidents occur. The case also illustrates what commentators describe as 'stepping-stones' liability, where an organisation's own failure to manage a risk adequately can expose individual directors to a breach of their duty of care under section 180 of the Corporations Act, the same duty of care standard this series has returned to throughout its discussion of board accountability.
The relevant standard is not perfection. It is genuine, documented, board-level engagement with the risk, proportionate to the organisation's actual exposure, rather than an assumption that the IT function or an outsourced provider has it handled without anyone at board level actually confirming that.
Why this belongs at board level, not just management's desk
Cyber and data risk fits precisely within the risk appetite framework discussed earlier in this quarter. It is a category a board should explicitly address in its risk appetite statement, with genuine tolerance levels stated rather than left implicit, and it connects directly to the delegations of authority discipline covered in the previous quarter: management should own the operational implementation, while the board retains genuine oversight and cannot delegate away its responsibility for confirming that implementation is actually adequate, the same delegate-authority-not-responsibility principle this series has returned to repeatedly.
- Confirm whether your organisation sits above or below the $3 million Privacy Act threshold, and treat voluntary compliance seriously even if you sit below it, particularly where sensitive member information is involved.
- Include cyber and data risk explicitly in your risk appetite statement, with genuine, specific tolerance levels rather than a general acknowledgement that it matters.
- Confirm basic, low-cost controls are genuinely in place, multi-factor authentication, regular backups, and staff training, since these remain the most common gaps identified in real incidents, including RI Advice's own documented failures.
- Maintain a genuine incident response plan and confirm it is actually tested, not just written, since the RI Advice case turned as much on failure to act on known vulnerabilities as on the original gaps themselves.
- Report cyber risk to the full board on a genuine, standing cycle, connecting to the delegated authority and reporting discipline discussed earlier this quarter, rather than treating it as a specialist topic outside normal board oversight.
A board does not need deep technical expertise in cyber security to discharge this responsibility properly. It needs to treat the risk with the same governance seriousness applied to every other category this series has covered, genuine oversight, genuine documentation, and genuine accountability, rather than assuming a technical problem sits permanently outside the board's own remit.
Explore the Board Director course
Want the fully branded, board-ready PDF of this article? Download the whole 52-part series — free.
Until next week,
Annie