Post

What school boards need to see: cyber governance, legal duties and evidence (Part 2)

This is Part 2 of Cyber security audits vs managed security: what Australian school boards need to know. Part 1 used a recent Perth school breach and the Friday afternoon incident to explain why assessment and response are different things.

When a school discloses a breach, the technical questions come first. Governance questions follow soon after. What did the governing body know, what had it funded, and what evidence did it rely on?

I think the most useful question a board or council can ask is this:

What evidence allows this governing body to conclude that material cyber risks are understood, appropriately funded and being managed?

An annual audit report is part of that evidence. It is not the whole of it.

Start with who you actually are

School governance structures vary widely. A school board, a governing council, a diocesan financial council and an advisory committee can have quite different legal powers, even when their titles sound alike.

Before discussing duties, document:

  • the operating entity and its legal form
  • the governing body and its delegations
  • advisory committees, including any audit, risk or ICT committee, and what they can actually decide
  • who holds incident authority, including after hours and during holidays.

A council’s title alone does not establish that its members are company directors. Getting this right matters because the obligations that follow depend on it.

The obligations, stated carefully

Cyber governance articles often blur the rules that apply to schools. These are the distinctions I think a school needs to get right. This is general information, and schools should confirm their position with their own advisers.

IssueWhat it means for a school
Privacy Act coveragePrivate educational institutions are usually covered by the Commonwealth Privacy Act 1988. Public schools generally sit within state or territory arrangements. Confirm the entity and jurisdiction.
APP 11Covered entities must take reasonable steps to protect personal information, including technical and organisational measures. An audit report is evidence of an activity, not a statutory safe harbour.
Notifiable Data BreachesCovered entities must assess a suspected eligible breach expeditiously and take reasonable steps to complete the assessment within 30 days. Where there are reasonable grounds to believe an eligible breach has occurred, notification is required as soon as practicable, subject to exceptions.
Director and charity governance dutiesDuties depend on legal structure and registration. Ordinary company-director rules should not be applied to every school council or charity.
Essential EightA baseline of preventative controls, with an appropriate target maturity and supporting evidence. Detection, response, recovery and governance measures are still needed.

Sources: OAIC on children, young people and education, APP 11 guidelines, NDB assessment and notification.

The NDB timing links back to the Friday afternoon problem. The assessment clock is a reason to have a named assessor, a documented process and access to advice before the incident. Otherwise the school is working out the process while the clock is running.

For the broader privacy reform picture, see Privacy Act reforms in 2026: what is changing.

A Queensland note

Many readers here are in Queensland, so this is worth stating plainly. Queensland government agencies, including the Department of Education, which operates the state’s public schools, became subject to the state’s mandatory data breach notification scheme on 1 July 2025 under the Information Privacy Act 2009 (Qld). Commonwealth NDB obligations should not simply be copied into a state-school governance description; the scheme, regulator and processes differ. Queensland OIC guidance.

Charities and companies limited by guarantee

Some independent schools are structured as companies limited by guarantee and registered with the ACNC. For those entities, ACNC guidance explains that certain civil statutory directors’ duties under the Corporations Act are replaced by ACNC governance requirements, although some Corporations Act obligations remain. Governance Standard 5 covers the duties of Responsible People, including acting with reasonable care and diligence.

That does not lower the standard. It means the correct source of the duty should be cited when a board paper describes the governing body’s responsibilities.

Enforcement examples, used carefully

In February 2026, following action by ASIC, FIIG Securities was ordered to pay a $2.5 million penalty over cyber security failures, plus $500,000 towards ASIC’s costs. According to ASIC, a 2023 cyber attack on FIIG resulted in about 385 GB of confidential data being stolen, affecting around 18,000 clients. ASIC’s findings included failures to allocate adequate resources to qualified people, implement multi-factor authentication for remote access, keep key systems patched, have qualified personnel monitoring threat alerts, provide staff training, and maintain an incident response plan tested at least annually. ASIC’s media release.

Several of those findings describe operating failures, not policy gaps. ASIC found FIIG did not have qualified IT personnel monitoring threat alerts, or an incident response plan tested at least annually. This connects directly to the gap between audit and operation in Part 1.

The case concerned financial services licensing obligations. It was not a finding of personal liability against school directors, and it should not be presented that way. It is useful as an illustration of what regulators may treat as inadequate in practice.

Similarly, Essential Eight alignment is not the same as legal compliance, and ASD does not impose a universal requirement for independent Essential Eight certification. Particular government policies, funding arrangements, regulators or contracts may require assessment. ASD Essential Eight maturity model.

From receiving reports to overseeing outcomes

A cyber update to a board can easily be too technical to act on or too reassuring to test. A small set of measures, each backed by evidence that shows whether the arrangement is working, gives the board something it can oversee.

These are recommended governance measures, not prescribed statutory metrics:

Board measureEvidence that makes it useful
Security coveragePercentage of in-scope devices and identities monitored; unsupported and disconnected assets shown separately.
Identity protectionMFA coverage, privileged-access exceptions and overdue account removals.
Vulnerability exposureMaterial weaknesses overdue for remediation, affected services, owners and deadlines.
Detection and containmentTime from alert to investigation and containment, including after-hours performance and missed targets.
Recovery capabilityActual restoration results against approved recovery-time and data-loss tolerances.
Supplier riskCritical suppliers with outstanding assessments, notification gaps or unresolved findings.
Independent assuranceFindings closed and retested, recurring failures, and accepted exceptions with expiry dates.

A few practical notes:

  • Operational teams and boards need different views. Operational staff need timely telemetry. Boards need concise trends, material exceptions and immediate escalation of significant incidents.
  • Live dashboards need honest labels. Any dashboard should show when it was last refreshed and what it does not cover. It cannot give complete real-time visibility of risk.
  • “After hours” belongs on the dashboard. If containment times are only measured during business hours, the Friday afternoon risk will not appear in the board report.
  • Accepted risks should expire. Exceptions should have an owner and a review date, not remain accepted indefinitely.
  • Track closure, not just findings. Western Australia’s Auditor General found that almost two thirds of the information systems findings in its 2025 audit of 53 state government entities were unresolved from previous years. That included 57% of significant findings. Access management and endpoint security were the weakest areas, with fewer than a quarter of entities meeting the benchmark in each. An annual audit that repeats last year’s findings is telling the board something important.

Insurance renewals need evidence too

Cyber insurance proposal forms can ask detailed questions about MFA, endpoint protection, backups, patching, testing and incident response. Chubb’s published proposal form is one example of that level of questioning. That particular form targets technology businesses, not schools, so check your own insurer’s proposal form for the questions that apply to you.

Two practical points follow:

  • Keep evidence that supports each declaration. If the renewal says MFA is enforced for all staff, keep the report that shows it, and record the exceptions.
  • Do not assume managed security guarantees cover or lowers premiums. That is a matter for the insurer and the policy. Ask the broker or insurer directly, and treat a supplier’s promise of premium reductions with scepticism.

Check whether the policy requires a specific incident response panel or insurer notification before engaging a provider. That belongs on the Friday afternoon call list.

What the board should ask for next

At the next meeting, a governing body could reasonably ask management for:

  1. A one-page statement of the entity, the applicable privacy regime and who holds incident authority.
  2. The measures in the table above, with gaps shown honestly.
  3. The date the incident response plan was last exercised, and what changed as a result.
  4. The status of findings from the last independent assessment: closed, retested, open or accepted.

None of these requires a new supplier. They do show whether current arrangements amount to an operating capability or only to a set of documents.

Part 3: Pricing cyber assurance and managed security builds assessment and managed-service budgets from published prices and compares them over three years.


This post is general information about governance and privacy obligations, not legal advice. Schools should confirm how these obligations apply to their own entity and jurisdiction.

This post is licensed under CC BY-NC-ND 4.0 by the author.