Responding to a global cyber incident - Major Multinational Corporation
The attack had significant implications for the corporation beyond standard data breach response, including compliance obligations under Australia's security of critical infrastructure legislation in addition to reporting requirements under Australian privacy law.
We advised on the full range of legal issues and the practical implementation of solutions to enable the corporation to meet both its national security obligations and its privacy obligations. This included managing notifications to various governmental authorities and regulators, and advising on communications with potentially affected employees and individuals. These communications carried an added degree of complexity given the critical infrastructure implications of the attack.
Our client was able to navigate a complex, multifaceted incident with confidence, meeting its obligations under both the security of critical infrastructure framework and Australian privacy law. By addressing the interplay between national security and privacy requirements, the corporation fulfilled its reporting and notification obligations in a coordinated and timely manner, while managing sensitive communications with affected individuals appropriately.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.
We are your global partner in critical cyber moments.
Get ahead of cyber risk