Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • The Australian Notifiable Data Breaches Scheme: Are You Prepared to Comply? current page
Link copied

The Australian Notifiable Data Breaches Scheme: Are You Prepared to Comply?

Feb 14, 2018
Author:
Slang
Scott Lang
Sr. Director, Product Marketing at BeyondTrust
Blog banner default
The Australian Notifiable Data Breaches Scheme: Are You Prepared to Comply?
Slang
Scott Lang
Sr. Director, Product Marketing at BeyondTrust

Australian Notifiable Data Breaches Scheme

This month, the Essential 8 turns one year old, and it’s not an accident that its first anniversary will coincide with the launch of the mandatory data breach notification law in Australia, the Notifiable Data Breaches scheme (NDB scheme). These two acts underscore Australia’s efforts to lift its cyber-security game – but is your organization ready to comply?

What is Australian Notifiable Data Breaches Scheme and who does it apply to?

The NDB scheme of the Privacy Act of 1988 obliges organizations to notify individuals whose personal information has been involved in a data breach that could result in serious harm. Called “eligible data breaches” under the Act, all Australian organizations – government, commercial, not for profit and others with an annual turnover of $3 million or more – must be prepared to conduct an assessment of a suspected breach to determine whether it’s likely to result in serious harm.

Proactive Controls Mitigate Risks

The best way to protect your organisation from the repercussions of a public breach notification is to prevent the breach from happening, or stop the intruders before they cause real damage. Easier said than done, for certain.

Consider a typical attack chain and where the weakest links in that chain are. If you look at the most common pathway that outside attackers take, for example, it’s first to exploit the perimeter in some way; taking advantage of asset vulnerabilities, phishing, other social engineering-type attacks. Next, the attacker hijacks and exploits privileges or passwords in order to move to the final step –lateral movement and their ultimate goal – your customer’s private data.

Shrinking the Attack Surface

Overcoming the weak links in the attack chain involves a multi-layered approach to data protection and security, including:

  • Closing perimeter vulnerabilities and gaps through constant scanning, correlation of risks and prioritization
  • Eliminating credential sharing – those highly-privileged accounts in use by administrators and power users
  • Restricting user administrator privileges and monitoring behaviour
  • Monitoring and auditing privileged user sessions and protected files

Adopting the “Essential 8” Mitigation Strategies Recommended by the ASD is a Good Start

The Australian Signals Directorate has identified eight of the most important controls organizations can put in place to mitigate cyber security risks, such as data breaches. This common-sense framework enforces the basics and addresses the weak points in the attack chain noted above, including:

  • Application allow listing
  • Patching applications
  • Restricting administrator privileges
  • Patching operating systems
  • Disabling untrusted Microsoft Office macros
  • Hardening user applications
  • Implementing multi-factor authentication
  • Backing up important data daily

Accomplishing this feat doesn’t have to be gruelling, expensive or require several vendors. In fact, BeyondTrust’s privileged access management and vulnerability management solutions – unified by a central console – addresses seven of the eight ASD strategies, including all “Top 4.”

Are you ready for the enforcement of the NBD scheme? Start by comparing your cyber security practices against the ASD Essential Eight.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • Using least privilege to achieve compliance: The dual benefit
    Oct 20, 2017 Using least privilege to achieve compliance: The dual benefit
    Blog
    1m
  • Securing Agentic AI Workloads with Visibility and Privileged Control
    Mar 23, 2026 Securing Agentic AI Workloads with Visibility and Privileged Control
    Blog
    6m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.