When a cyber incident strikes, technical containment is only one part of the response. In that situation, boards and executives must make regulatory, legal and communication decisions before the technical investigation is complete. The governance challenge is to act quickly without overstating uncertain facts, and to document how each decision was reached.
A documented incident response plan is therefore not proof of operational resilience. Boards need evidence that decision rights, escalation pathways, notification thresholds and communication protocols will work when the organisation is under pressure.
What a Developing Investigation Reveals
On 22 July 2026, Origin Energy announced that it was investigating a potential security incident involving possible unauthorised access to customer data. At that stage, the company stated that it did not believe customer credit card or bank details were included.
On 23 July, Origin confirmed that unauthorised access and disclosure of some customer data had occurred. It continued working to determine the number of affected customers and said it would contact customers whose information was confirmed as affected. Origin also engaged relevant Australian government agencies while its investigation continued.
The incident illustrates a challenge every organisation should prepare for: initial findings may change as new evidence emerges. Governance arrangements must allow leaders to update decisions and communications without compromising the investigation or damaging regulatory credibility.
Governing the Fog of War
In the first hours of an incident, leaders must identify what information may be affected and whether notification thresholds have been reached. They must also decide who can communicate externally and how key decisions will be documented while the technical investigation continues.
These are not purely technical questions. They require coordinated input from cyber security, privacy, legal, risk, compliance, communications and executive leadership.
When these functions operate from different escalation thresholds or conflicting versions of the incident, delays and inconsistencies become more likely. A governance structure that has not been rehearsed can become as significant a constraint as the technical investigation itself.
Australia Does Not Have One Reporting Clock
Under Australia’s Notifiable Data Breaches scheme, covered organisations must assess suspected eligible data breaches promptly and take reasonable steps to complete the assessment within 30 calendar days. Once there are reasonable grounds to believe an eligible data breach has occurred, the OAIC and affected individuals must be notified as soon as practicable, unless an exception applies.
APRA-regulated entities face separate requirements under CPS 234, including notifying APRA of qualifying information security incidents as soon as possible and no later than 72 hours after becoming aware of them. Other obligations may arise under critical infrastructure legislation, contracts, insurance policies and sector-specific regulation.
The governance challenge is to determine which requirements apply, when each threshold has been reached and who is authorised to make and document that decision. A regular cyber security audit should test whether this process works in practice.
The Governance Test Extends Across the Tasman
Under New Zealand’s Privacy Act 2020, organisations must notify the Office of the Privacy Commissioner when a privacy breach has caused, or may cause, serious harm. The Commissioner recommends notification within 72 hours of becoming aware of a notifiable breach, while affected individuals must generally be informed as soon as practicable.
Although Australia and New Zealand apply different frameworks, organisations in both markets must be able to assess harm, identify applicable obligations and justify decisions while an investigation continues.
Five Decisions to Test Before an Incident
1. Who Has Decision Authority?
Define who may activate the response plan, engage specialists, notify regulators and approve customer or public communications. Include delegated authority and alternates.
2. How Will Notification Thresholds Be Assessed?
Create decision trees reflecting the organisation’s jurisdictions, industry, data types and regulatory status. Identify who records the evidence and approves the decision.
3. How Will Legal Oversight Be Established?
Determine when legal counsel will be engaged and how legal, privacy and technical teams will share information without delaying containment.
4. How Will Evidence Be Preserved?
Define requirements for log retention, forensic imaging, investigation records and chain of custody. A targeted secure configuration review can determine whether critical systems generate and protect the evidence an investigation may require.
5. Who Controls Stakeholder Communications?
Assign responsibility for preparing, validating and approving communications to regulators, customers, employees, insurers, partners and the media.
Organisations should decide in advance who prepares, verifies and approves each communication. Every external statement should align with the latest verified facts while making clear where the investigation remains incomplete.
Why Untested Runbooks Fail
A runbook stored on a shared drive is a statement of intent, not evidence of readiness. Tabletop exercises frequently expose conflicting severity definitions, unclear notification authority, gaps in board reporting and tension between containment and evidence preservation.
These issues are difficult to identify through document review because they emerge from how people interpret responsibilities and make decisions under pressure.
Independent Assurance Should Connect Governance and Controls
Executive readiness cannot be separated entirely from the underlying control environment.
Organisations handling payment card data may need experienced PCI QSA compliance auditors. They can assess whether incident response arrangements cover cardholder data, evidence preservation and PCI DSS reporting obligations.
Similarly, experienced ISO 27001 information security auditors can assess the organisation’s incident management and risk treatment processes. They can also review whether roles, responsibilities and continual improvement are operating effectively within the information security management system.
An ISO 27001 audit evaluates the organisation’s information security management system against the relevant standard.
The value comes from connecting their findings.
• A control weakness should inform the incident scenario.
• An exercise finding should influence remediation priorities.
• A regulatory decision gap should be reflected in policies, training and future assurance work.
Turning Incident Plans Into Tested Governance
Cybernetic Global Intelligence helps organisations across Australia and New Zealand test whether their incident response arrangements will operate under realistic executive pressure.
Clients work directly with experienced cybersecurity practitioners who can engage with boards, executives, legal advisers, risk teams and technical leaders throughout the assessment.
A tabletop exercise can test:
• executive decision authority;
• regulatory notification processes;
• evidence preservation;
• legal and privacy coordination;
• customer and media communications;
• third-party responsibilities;
• insurer engagement; and
• board reporting.
The objective is not to produce another generic policy. It is to identify practical gaps, establish clear accountabilities and provide prioritised actions that the organisation can implement.
Organisations looking for a certified cyber security consultant in Australia should verify the consultant’s credentials and the firm’s accreditations. They should also confirm that the assessor will remain directly involved throughout the engagement.
Cybernetic Global Intelligence provides incident response planning, tabletop exercises, ISO 27001, PCI DSS, security assessment and governance, risk and compliance services across Australia and New Zealand.
Defensible Readiness Starts Before the Incident
A cyber incident response plan becomes defensible only when the organisation has tested the decisions and dependencies behind it.
Boards should know:
• who will assess regulatory thresholds;
• who may authorise notifications;
• how evidence will be preserved;
• who may speak to customers and the public;
• how third parties will be coordinated; and
• how decisions will be documented while the facts continue to change.
The first days of an investigation will always involve uncertainty. The organisation does not need perfect information to respond effectively, but it does need clear authority, reliable evidence and a governance process capable of adapting as new facts emerge.