shield_person Andrew Roberts Advisory

Briefing No. 028

The Origin Hack: What Directors Need to Do Now

·8 min read·1,646 words

A major Australian energy retailer suffers a cyber breach. Customer data is exposed. The board is asked, at the next meeting, whether it knew the risk existed and what oversight it had in place. What does the board minute say?

Does this apply to you?

ASX-listed: Yes. Continuous disclosure obligations require timely notification of material cyber incidents. [1] The Origin hack is a direct prompt to test whether your disclosure triggers and escalation paths are clearly defined and board-approved.

APRA-regulated: Yes. Entities under APRA oversight carry explicit notification and resilience obligations. A breach of this scale at a major utility is a direct comparator for stress-testing your own incident response posture.

NFP / SME: Yes, in principle. Smaller organisations hold customer and employee data and face the same data breach notification obligations under the Privacy Act. The Origin hack is a reminder that size does not eliminate exposure.

What Happened at Origin

Origin Energy confirmed a breach involving unauthorised access to systems holding customer data. The incident exposed personal information across a significant portion of its customer base. The breach was not the result of a sophisticated nation-state attack. It followed a pattern seen repeatedly in Australian and global incidents: credential compromise, insufficient access controls, and a gap between when the intrusion occurred and when it was detected.

That detection gap is the critical detail for directors. An attacker who sits inside a network undetected has time to map systems, exfiltrate data, and establish persistence. By the time an organisation identifies the breach, the damage is done. The question the board must answer is not just what happened, but how long it took to find out, and whether the board had any visibility into that risk before the incident occurred.

Why This Is a Director-Level Issue, Not Just a Technology Problem

There is a persistent tendency in boardrooms to treat cyber incidents as IT failures. The Origin hack is not an IT story. It is a governance story.

Under the Cyber Security Act 2024, certain entities carry mandatory incident reporting obligations. Those obligations sit with the organisation, and the board is responsible for ensuring the organisation meets them. Separately, directors owe a duty of care and diligence under the Corporations Act. [2] A director who cannot demonstrate that the board received adequate cyber risk reporting, set clear risk appetite, and oversaw management's response posture is exposed, not just reputationally but legally.

The AICD, as the professional body for Australian directors, has been clear for several years that cyber risk is a board-level governance matter, not a delegated technical function. The Origin breach gives that position renewed weight. The question is no longer whether directors should engage with cyber risk. The question is whether they can demonstrate they already were.

The Three Specific Gaps the Origin Hack Reveals

Detection and Dwell Time

If your organisation does not know how long an attacker could sit undetected inside your environment, the board does not have a credible picture of cyber risk. Dwell time, the period between initial compromise and detection, is one of the most important indicators of security posture. Ask management what the organisation's detection capability looks like and what the last independent assessment of that capability found.

Third-Party and Supply Chain Access

Many breaches, including a significant proportion of Australian incidents, originate through third-party access. Vendors, contractors, and service providers with legitimate credentials are a consistent entry point. The board should know whether management maintains an accurate register of third-party access, and whether that access is reviewed and revoked when no longer needed.

Incident Response Readiness

Having an incident response plan is not the same as having a tested one. A plan that has never been exercised will not perform under real breach conditions. Directors should know when the plan was last tested, who participated in that test, and whether the board itself has been walked through its own role in a major incident, including decisions about disclosure, regulatory notification, and external communications.

The Regulatory Dimension Directors Cannot Ignore

The Cyber Security Act 2024 is in force. [3] For entities that fall within its scope, mandatory reporting of significant cyber incidents is a current legal obligation, not a future one. Failure to report within the required timeframes carries consequences.

Beyond the Cyber Security Act, the Privacy Act imposes notification obligations where a data breach is likely to result in serious harm. [4] The Origin breach, involving personal customer data at scale, is precisely the kind of incident the notifiable data breaches scheme was designed to address. Directors of organisations holding material volumes of personal data need to know that the notification decision-making process is clear, documented, and fast. When a breach occurs, hours matter.

ASIC is the regulator responsible for enforcing directors duties and has signalled consistently that cyber risk governance is within its supervisory focus. [5] A director who cannot point to documented board engagement with cyber risk before an incident is in a weak position after one.

What a Director Should Check Now

The Origin hack is a prompt, not a panic. Use it as a structured reason to ask the questions that should already be on the board agenda.

Governance red flags

  • The board has not received a formal cyber risk report in the last six months, or those reports are purely technical and contain no board-level risk assessment.
  • The organisation has an incident response plan but it has not been tested or exercised in the last twelve months.
  • The board has not formally set or reviewed its cyber risk appetite, and management cannot point to a board-approved threshold for what constitutes a material incident.
  • There is no documented process for escalating a suspected breach to the board and to regulators within the required timeframes under the Cyber Security Act 2024 and the Privacy Act.
  • Third-party and vendor access to critical systems is not subject to regular review or a formal access management process.

Questions to ask management

  1. What is our current average detection time for a breach, and when was this last independently assessed?
  2. Who holds third-party and contractor access to our critical systems, and how recently was that access list reviewed and validated?
  3. When was our incident response plan last tested, who participated, and what were the findings?
  4. What are our exact notification obligations under the Cyber Security Act 2024 and the Privacy Act, and who is responsible for making those notifications when a breach occurs?
  5. Has the board been briefed on its own role and decision points in a major incident scenario, and is that role documented?

Origin is not an outlier. It is the latest in a pattern that Australian directors have now watched play out across retail, finance, health, and critical infrastructure. The organisations that fare better are not necessarily the ones with the largest security budgets. They are the ones where the board was already engaged, the questions were already being asked, and the answers were already documented. That preparation is now a legal and governance expectation, not an optional best practice. If your board cannot demonstrate it, the Origin hack is the moment to start.

"The board reviewed the Origin Energy cyber incident as a governance matter, confirmed that management has been asked to report on detection capability, third-party access controls, and incident response readiness, and resolved that a formal cyber risk report addressing these areas be tabled at the next meeting."

Suitable for board minutes or a risk register entry

Frequently Asked Questions

Does the Origin hack create any direct legal exposure for directors of other organisations?

Not directly. The legal exposure for directors arises from their own organisation's governance failures, not from what happened at Origin. However, a high-profile incident like this one is exactly the kind of event regulators and courts point to when assessing whether a director should have known a risk existed. If your board was not engaging with cyber risk before this incident, that position is harder to defend after it.

What does the Cyber Security Act 2024 actually require of our board?

The Cyber Security Act 2024 establishes mandatory reporting obligations for significant cyber incidents affecting entities within its scope. The obligations sit with the organisation, and the board is responsible for ensuring the organisation has the processes in place to meet them. Directors should confirm with management and legal counsel whether the organisation falls within scope, what the relevant reporting timeframes are, and who is authorised to make those reports.

We are a smaller organisation. Is this really relevant to us?

Yes. The Privacy Act notifiable data breaches scheme applies to organisations above the relevant threshold and to many smaller entities in specific sectors. If your organisation holds personal information and a breach occurs that is likely to result in serious harm, you have notification obligations regardless of size. More broadly, the duty of care directors owe under the Corporations Act does not scale down with company size.

What is the single most useful thing a board can do right now in response to the Origin hack?

Put a structured cyber risk item on the next board agenda and ask management to address detection capability, third-party access, and incident response readiness in writing. The act of asking, and recording that the board asked, is itself a governance step. It creates a documented record that the board was actively engaged with cyber risk, which is precisely what a regulator or court would look for.

If this resonates, I would welcome a conversation about the Cyber Governance Deep Review, or get in touch directly.

Andrew Roberts

Briefing by

Andrew Roberts

Founder and Principal Advisor at Andrew Roberts Advisory. I help Australian boards translate cyber and AI governance obligations into clear, defensible oversight. Former ASX-listed Group CEO, AICD and ACS member, ACS MACS (Snr) CP (Cyber).

Sources

Related briefings

More Briefings

Cyber Governance & Oversight

Cyber Governance for Boards Australia: Moving Beyond Technical Metrics to Defensible Oversight

Apr 29, 2026
Cyber Governance & Oversight

What is a Technology Consultant? A Director’s Guide to Strategic Advisory in 2026

Apr 30, 2026
Governance Strategy & Advisory

Digital Strategy Consulting: A Board-Level Governance Template for 2026

May 01, 2026
Cyber Governance & Oversight

Defensible Oversight: A Cyber Security Audit Checklist for Australian Boards

May 04, 2026
Governance Strategy & Advisory

Tech Consulting for Australian Boards: Bridging the Governance Gap in 2026

May 06, 2026
AI Governance

AI Ethics Governance for Australian Boards: A Director's Framework

May 08, 2026
Board Reporting & Disclosure

Cyber Risk Reporting to the Board Australia: Establishing Defensible Oversight in 2026

May 11, 2026
AI Governance

AI Risk Management Framework for Directors: A Defensible 2026 Guide for Australian Boards

May 13, 2026
Regulation & Compliance

Regulatory Settlement Agreements: A Director’s Guide to Defensible Governance

May 15, 2026
Cyber Governance & Oversight

Cyber Security for Australian Boards: Moving from Technical Metrics to Defensible Oversight

May 18, 2026
Regulation & Compliance

Privacy Act Obligations and the Crimes Act: A Director’s Guide to Defensible Oversight

May 20, 2026
Third-Party & Supply Chain Risk

Third Party Cyber Risk Governance Australia: A Director’s Guide to Defensible Oversight

May 22, 2026
Cyber Governance & Oversight

Board Cyber Governance Strategy Australia: A 2026 Reference for Directors

May 25, 2026
Cyber Governance & Oversight

How to Challenge a CISO Report: A Director’s Guide to Defensible Oversight

May 27, 2026
AI Governance

Board Oversight of Generative AI Risks: A Defensible Governance Framework for 2026

May 29, 2026
AI Governance

AI Governance Reporting for Boards: A Guide to Defensible Oversight

Jun 01, 2026
AI Governance

Questions for Boards to Ask About Corporate AI Strategy: A 2026 Director’s Checklist

Jun 05, 2026
AI Governance

Director's Guide to Artificial Intelligence Risks: Defensible Oversight in 2026

Jun 08, 2026
Board Reporting & Disclosure

Linking Cyber Risk to Financial Impact: A Director’s Guide to Defensible Board Reporting

Jun 10, 2026
Regulation & Compliance

APRA CPS 234: Board Obligations Checklist for Directors

Jun 03, 2026
Board Reporting & Disclosure

Investor Expectations for Board Cyber Oversight in 2026

Jun 10, 2026
Cyber Governance & Oversight

Essential Eight Board Oversight for Australian Directors

Jun 12, 2026
Regulation & Compliance

Cyber Security Act 2024: Australian Director Obligations

Jun 05, 2026
Cyber Governance & Oversight

Board Cybersecurity Duties: A Director's Guide to Defensible Oversight in Australia

Jun 15, 2026
Cyber Governance & Oversight

AICD Cyber Security Governance Principles Version 2: What Australian Directors Need to Know

Jun 16, 2026
Third-Party & Supply Chain Risk

Third-Party Cyber Risk: A Director's Guide to Defensible Board Oversight in Australia

Jun 17, 2026
AI Governance

What an Independent AI Governance Review Actually Involves for Australian BoardsNew

Aug 02, 2026