What counts as a data breach concern?
A data breach concern may involve unauthorised access, accidental disclosure, lost devices, exposed cloud folders, hacked mailboxes, stolen databases, misdirected emails, compromised websites or confidential documents sent to the wrong person. The same incident may require cyber, privacy, legal, customer and operational input.
Questions to answer early
- What information may have been accessed, copied, disclosed or lost?
- Was personal information involved, and whose information was it?
- Was the exposure accidental, malicious, internal or external?
- Can logs show what happened and whether data was downloaded?
- Has the access been contained and are affected systems now secure?
Evidence to preserve
Keep audit logs, mailbox records, access control settings, file sharing links, screenshots, incident timelines, affected data samples, system alerts, user lists and communications already sent. Do not overwrite or delete logs while trying to tidy the incident.
Specialist triage
A consultation can help convert a messy incident into a structured brief for privacy assessment, insurance, lawyers, management, customer communications and remediation work.
Not every exposure is notifiable, but early evidence helps determine whether notification duties may arise.
Related help
Evidence checklist
A practical list of what to preserve before logs, screenshots or account records disappear.
Request specialist consultation
Send the facts you have and we will help organise the next steps.
Australian cyber resources
Helpful public resources for cyber, privacy, scams and online safety.