The obligation in plain English
Under the NDB scheme, if a data breach is likely to result in serious harm to any individual whose personal information is involved, you must notify the affected individuals and the OAIC as soon as practicable.
You have a maximum of 30 days to assess a suspected eligible data breach — but that is an outer limit, not a target. OAIC expects assessment to be expeditious and documented.
Who to call, and when
Report cybercrime to ReportCyber and, for significant incidents, notify the ACSC. Critical infrastructure operators have separate SOCI Act reporting timeframes of 12 and 72 hours.
Engage legal counsel and your cyber insurer early — most policies require notification before you engage responders.
Evidence discipline
Do not wipe or rebuild affected systems before forensic capture. Preserve endpoint telemetry, identity provider sign-in logs and email audit logs — Australian cloud tenants often have short default retention windows.
The checklist
Hour 0–4: Contain
- Declare an incident and appoint an incident lead
- Isolate affected endpoints without powering them off
- Revoke sessions and reset credentials for implicated accounts
- Start a timestamped decision log
Hour 4–24: Assess
- Identify what personal information was involved and for how many individuals
- Determine whether serious harm is likely (sensitivity, protections, who obtained it)
- Preserve logs and forensic images before remediation
- Notify cyber insurer and legal counsel
Hour 24–72: Notify and remediate
- Submit ReportCyber report; notify ACSC if significant
- Prepare OAIC statement: description, information involved, recommended steps
- Notify affected individuals with clear, actionable guidance
- Close the initial access vector and validate the fix
Post-incident
- Run a blameless post-incident review within 2 weeks
- Update the response plan with lessons learned
- Track remediation actions to completion with owners and dates