Privacy risk is no longer just a “big business” problem. Alisha sits down with Chris Haigh to unpack the Australian Privacy Act changes pulling thousands of small and medium businesses into scope including reforms linked to anti-money laundering changes, and the growing expectation that every organisation knows exactly what personal data it holds and why.
We also cover what’s coming around children’s privacy protections and automated decision-making — and why the simplest first step is updating your privacy policy to reflect what you actually do, since regulators are now auditing policy against practice.
From there, we get tactical: the first hour after a breach, why panic causes expensive delays, and how tabletop exercises expose gaps before a real incident hits. We also look at why cyber insurance only helps if your declared security measures are genuinely in place, plus supply chain risk — the due diligence questions to ask suppliers, and what security certifications like ISO 27001 and SOC 2 actually tell you.
If you found this useful, subscribe, share it with a business owner who needs it, and leave us a review.