Biting the cybersecurity bullet
David Crosbie
What are the issues that need to be seriously considered if the sector wants to improve data security? David Crosbie explains.
A donor rang a CCA member this week indicating a willingness to contribute to the charity. His motivation was to support the cause, but he wanted to speak to the CEO about a condition that needed to be met if he was to donate his money.˜
He would only give to the charity if 100 per cent of the money was to be directed to the cause and none of his money would be spent on administration or fundraising.
The CEO spoke to me about this request expressing their concern. What should they do? Refuse the donation because it was such an ill-informed condition, or play along, agree to the terms even though they are impossible to truly meet, and try to ensure the money was spent appropriately?˜
My response was that the CEO needed to have an honest discussion with the donor and maybe raise the issue of cybersecurity.
CCA has spent quite a bit of time recently talking about cybersecurity, not only because it is a hot issue across all organisations, but also because there was an important data security related bill in the federal parliament.
The Privacy Legislation Amendment (Enforcement and Other Measures) Bill 2022 was passed this week, increasing the penalties for ?serious or repeated data breaches? from $2.2 million to whatever is the most of:
- $50 million
- 30 per cent of adjusted turnover for the period
- three times the financial gain from the misuse of data in the case of outstandingly shocking breaches.