Governance Excellence Series · Stewardship & Risk · Article 42 of 52
Association Management · 8 June 2027

Cyber and Data Governance as a Board-Level Risk, Not an IT One

The standard is not perfection. It is genuine, documented board-level engagement

Cyber security is still, in most association boardrooms, treated as an IT problem that gets a brief update slot before the meeting moves on to matters the board considers genuinely its own. That framing no longer matches either the legal exposure or the practical reality. It is a governance risk in the same category as the financial and risk appetite discipline covered earlier in this quarter, and it deserves the same level of board ownership.

Who is actually required to comply, and who should anyway

Compliance with the Privacy Act 1988 (Cth) is mandatory for not-for-profits with annual turnover over $3 million, a threshold that happens to align with the ACNC's own large charity tier discussed earlier in this quarter. Organisations above that line must comply with the Australian Privacy Principles and the Notifiable Data Breaches scheme, which requires notifying both affected individuals and the Office of the Australian Information Commissioner following an eligible data breach. Smaller organisations below the threshold are not legally compelled to comply in the same way, but this exemption is a floor, not a genuine safe harbour. A smaller association still handling member health records, payment details, or other sensitive personal information carries real reputational and member-trust exposure regardless of where the legal line technically sits, and the practical case for voluntary compliance is strong even where the statutory obligation is not.

The principle the courts have already established

The Federal Court's decision in <i>Australian Securities and Investments Commission v RI Advice Group Pty Ltd</i> [2022] FCA 496, while decided in the context of an Australian Financial Services Licensee's specific statutory obligations, established a principle that reaches well beyond that sector: cybersecurity risk cannot be reduced to zero, but it can and must be materially reduced to an acceptable level through adequate documentation, controls, and genuine follow-through when incidents occur. The case also illustrates what commentators describe as 'stepping-stones' liability, where an organisation's own failure to manage a risk adequately can expose individual directors to a breach of their duty of care under section 180 of the Corporations Act, the same duty of care standard this series has returned to throughout its discussion of board accountability.

The relevant standard is not perfection. It is genuine, documented, board-level engagement with the risk, proportionate to the organisation's actual exposure, rather than an assumption that the IT function or an outsourced provider has it handled without anyone at board level actually confirming that.

Why this belongs at board level, not just management's desk

Cyber and data risk fits precisely within the risk appetite framework discussed earlier in this quarter. It is a category a board should explicitly address in its risk appetite statement, with genuine tolerance levels stated rather than left implicit, and it connects directly to the delegations of authority discipline covered in the previous quarter: management should own the operational implementation, while the board retains genuine oversight and cannot delegate away its responsibility for confirming that implementation is actually adequate, the same delegate-authority-not-responsibility principle this series has returned to repeatedly.

A board does not need deep technical expertise in cyber security to discharge this responsibility properly. It needs to treat the risk with the same governance seriousness applied to every other category this series has covered, genuine oversight, genuine documentation, and genuine accountability, rather than assuming a technical problem sits permanently outside the board's own remit.

Explore the Board Director course

Want the fully branded, board-ready PDF of this article? Download the whole 52-part series — free.

Until next week,
Annie

Part of the Governance Excellence Series — 52 evidence-based articles on association governance, one published every week.

More from Nexus Association Management →

Lead with Annie · 3,500+ subscribers · Weekly

Bold leadership, real governance, no-fluff AI.

From a five-time CEO who's done it. Get the newsletter on LinkedIn, or by email — choose your edition (Association, Business or Practice). Unsubscribe anytime.