Modern Australian
The Times

How can we stay safe after data breaches? Step 1 is to change the cybersecurity laws

  • Written by Adam Andreotta, Lecturer, School of Management and Marketing, Curtin University
How can we stay safe after data breaches? Step 1 is to change the cybersecurity laws

Last week, Australian airline Qantas announced cyber attackers had accessed personal data about some of its customers. The company later confirmed that 5.7 million customer records were involved.

The attackers targeted an offshore IT call centre, which enabled them to gain access to a third-party system.

The airline contacted affected customers shortly after the announcement, and sent a follow-up email a week later. The email apologised to customers and informed them attackers had accessed information about customers’ names as well as frequent flyer numbers and tier status.

The email may have felt familiar to Australians impacted by the 2022 Optus Breach or the 2024 Medisecure Hack — a routine apology, an assurance that immediate steps have been taken, and a statement that the company takes seriously the trust placed in it to safeguard personal information.

It’s an adequate response. But it ignores something that might genuinely make customer data safer in the future: stronger cybersecurity laws to prevent these kinds of breaches from happening in the first place.

How should we respond to data breaches?

If your data were involved in the Qantas breach, you might be wondering what to do about it.

The first sensible step might be to find out what personal information was compromised. Next, you might research the potential harm that could come from your name, Qantas Frequent Flyer number, and tier status being accessed.

You may learn about the risks of identity theft, account hijacking, and scams.

After that, you might want to figure out what actions you could take to protect yourself – that is, how to best secure your data. Plenty of websites offer advice along these lines.

If you are a Qantas customer, and received the follow-up email, you may have noticed a section titled “What steps can I take to protect myself?”. This part encourages users to stay alert, use two-factor authentication, stay informed about the latest threats, visit IDCARE’s Learning Centre, and never share passwords or sensitive information (stating that Qantas will never ask for them).

While these are helpful suggestions, they place a significant burden on the customer. They also imply that if our data becomes compromised, we may be partially to blame for not doing more to protect ourselves.

Is this fair or useful? Rather than just trying to protect ourselves after data breaches, we might be better off focusing our attention on why breaches occur and the legislators who make the rules for the companies that hold our data.

Does the law have an unhealthy obsession with data breaches?

It may seem that, to improve cybersecurity laws, we need to pay more attention to Qantas-like data breaches and impose bigger fines on companies when they occur. However, this is not necessarily the best solution.

As US privacy scholars Daniel Solove and Woodrow Hartzog point out in their 2022 book Breached!: “Data privacy law has an obsession with data breaches.”

Ironically, the authors claim, “this obsession has […] been the primary reason why the law has failed to stop the deluge of data breaches. The more obsessed with breaches the law has become, the more the law has failed to deal with them.”

Solove and Hartzog argue that focusing solely on the breaches themselves prevents us from concentrating on prevention.

How effective is Australian cyber security law?

In Australia, recent reforms to the Cyber Security Act 2024 introduced the Cyber Incident Review Board, which can:

make recommendations to government and industry about actions that could be taken to prevent, detect, respond to or minimise the impact of, cyber security incidents of a similar nature in the future.

These reforms are an important step in addressing prevention, and the Cyber Incident Review Board will undoubtedly draw many lessons from the Qantas case when it performs its post-incident review – such as identifying potential weaknesses at the offshore IT call centre.

However, we shouldn’t have to wait until an incident occurs to start thinking about how to protect against breaches. There are also concerns about whether the recommendations it offers will be put into law.

Ideally, we need legislation that focuses on prevention, not just post-incident responses. If we had laws that required companies to conduct audits, provide legally binding safety checks applicable to all relevant stakeholders, and impose penalties for non-compliance with these standards, it would genuinely improve prevention.

Revising our flight path

Our response to the Qantas breach will no doubt follow a familiar pattern: first, we panic! Then we get angry at the company. Next, we attempt to follow privacy advice – at least for a short while – changing a password or two before becoming complacent and then lowering our privacy vigilance. And then the cycle repeats the next time a breach occurs.

We don’t need to accept this eternal pattern, however. If we focus our attention on lawmakers, rather than these immediate responses we are all too familiar with, prevention becomes a possibility.

Authors: Adam Andreotta, Lecturer, School of Management and Marketing, Curtin University

Read more https://theconversation.com/how-can-we-stay-safe-after-data-breaches-step-1-is-to-change-the-cybersecurity-laws-260816

Why Retail Cleaning Plays a Key Role in Customer Experience and Business Success

Professional retail cleaning services are an essential part of maintaining a welcoming, safe, and professional environment for customers and staff...

Simple Ways to Make a Commercial Property More Appealing to Buyers

Selling or leasing a commercial property isn’t just about listing the square metres, taking a few photos and waiting for the right person to appea...

What Café Owners Should Know Before Upgrading Their Display Setup

A café display fridge does a lot more than keep cakes cold and sandwiches fresh. It quietly shapes the way customers browse, the way staff move beh...

Creating a Backyard That Feels Comfortable All Year Round

A great backyard doesn’t need to be huge, expensive or perfectly styled. Most of the time, the spaces people actually use are the ones that feel e...

How Homeowners Can Make Smarter Energy Decisions Before Upgrading

Energy upgrades used to feel like something you only looked into after a power bill gave you a nasty surprise. These days, though, more homeowners a...

Why Retail CX Breaks During Peak Sales Events and How to Prevent It

Retail customer experience has become one of the most important drivers of revenue growth, especially during high-intensity sales periods. However, ev...

15 South Indian Dishes Everyone Should Try

If your only experience of "Indian food" is butter chicken and garlic naan, South Indian cuisine is going to feel like discovering an entirely new c...

What Every Homeowner Should Know About Roof and Drainage Maintenance

A home's roof and drainage system work together every day to protect the property from water damage. While many homeowners focus on visible areas such...

From Plans to Priced Quote: The Estimating Workflow Most Builders Skip

For a small one-off job, an experienced builder can size up the materials in their head. The problem is that most jobs are not small one-off jobs, and...

Organisational Experts Share Their Tips for Achieving a Clutter-Free Kitchen

They say the kitchen is the heart of a house which means a clutter-free kitchen not only makes your home in general look nicer, it also makes cookin...

10 Creative Ways AI Image Extenders Are Transforming Digital Content Creation in 2026

Introduction Artificial intelligence continues to reshape the digital landscape, and one of the most exciting innovations in 2026 is the rise of AI i...

What to Do When You're Arrested in Victoria

Most people have thought about this in the abstract. A knock at the door, a hand on the shoulder, a car pulled over on the Hume. In the abstract, th...

Common Financial Disputes During Separation

Separation hits on many levels, not just emotionally. When a partnership ends, untangling the financial side — assets, debts, and everything built t...

Why Posting More Content is Killing Your Brand

More content. More often. More platforms.Most brands have been running this playbook for three years. Most brands have nothing to show for it.Not be...

Garden Clean-Up vs. Regular Maintenance: Which Do You Really Need?

Most people ring a gardener and ask for a "tidy up." What they mean by that, and what the garden actually needs, are often two completely different ...

Solar Panel Maintenance Tips for Melbourne Homes

Three years in and the panels are still on the roof. The inverter is still blinking. The electricity bills are still lower than they used to be, rou...

Cost Effective Kitchen Renovations – From the Ground Up

Even in times of uncertainty, it seems renovations continue to be on the to-do list for many Australian property owners. As a result, demand on materi...

Why Bathroom Product Selection Matters More Than Most Homeowners Realise

Most homeowners think wrong when it comes to a bathroom renovation. They think hard about the layout. Spend hours choosing tiles. Agonise over pain...