The Technology Translator
Technology is now part of every business, but most business owners, managers and leaders were never taught how to make technology decisions.
The Technology Translator is a practical podcast that breaks down technology, cybersecurity, AI and digital business topics into plain English.
Hosted by Vic, a technology professional with more than a decade of experience working with Australian organisations, each episode explores the questions business leaders are asking every day:
What technology do we actually need?
How do we reduce risk?
What should we know about AI?
How do we get value from technology without getting lost in the jargon?
No buzzwords. No vendor sales pitches. No unnecessary complexity.
Just practical conversations designed to help Australian businesses make technology make sense.
The Technology Translator
Cybersecurity Isn't Optional Anymore: What Every Australian Business Is Now Expected to Do
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Cybersecurity is no longer just an IT problem.
It's a business risk, a governance issue, and increasingly, a legal and regulatory responsibility.
In this episode of The Technology Translator, Vic breaks down what Australian business owners, directors and managers actually need to know about cybersecurity obligations—without the jargon.
You'll learn why the Australian Government has been warning businesses for years, what the Australian Cyber Security Centre (ACSC) recommends, what the landmark RI Advice case means for directors, how privacy laws have changed, and why cybersecurity is now influencing tenders, supplier questionnaires and even insurance claims.
Vic also explores why the conversation has shifted from "if" your business experiences a cyber incident to "when", and why resilience is becoming just as important as prevention.
Whether you're a small business owner or leading a growing organisation, this episode will help you understand what "reasonable steps" really look like and why asking the right questions today could save your business tomorrow.
In this episode, you'll learn:
- Why cybersecurity is now a business responsibility, not just an IT issue
- The role of the ASD and ACSC in protecting Australian businesses
- What Scamwatch data tells us about the scale of cybercrime in Australia
- What the RI Advice case changed for directors and governance
- Australia's privacy obligations and potential penalties
- Why cyber insurance isn't a guaranteed safety net
- How cybersecurity is becoming a competitive advantage when bidding for work
- Practical questions every business owner should ask their IT provider
Because cybersecurity isn't about being perfect.
It's about being prepared.
Thanks for listening to The Technology Translator.
If you found this episode useful, please follow the podcast and share it with someone who has ever been responsible for making a technology decision.
You can connect with me on LinkedIn - https://www.linkedin.com/in/victoriaccole/
Instagram - @thetechnologytranslator
Email - vic@thetechnologytranslator.au
Remember:
You don't need to become technical.
You do need to become informed.
Welcome to the Technology Translator. I'm Vic. Every episode we break down technology, cybersecurity, and AI into plain English for Australian business leaders. Welcome to the podcast. Hello and welcome back to the Technology Translator. I'm Vic, and today we're tackling a topic that I think every business owner, executive, director, and manager needs to understand. And it's not because it's exciting, not because it's particularly technical, but because whether we like it or not, it's becoming part of running a business in Australia. Today's episode is called Cybersecurity Isn't Optional Anymore. Now, before we begin, I want to make something very clear. I'm not trying to terrify you. I'm not trying to convince you that the hackers are hiding behind every email. I'm certainly not suggesting every business needs a million dollar security budget. But I do want to challenge a common assumption because a lot of business owners still see cybersecurity as an IT problem. Something the IT provider handles, something the IT manager will worry about, something that sits somewhere in the corner until it breaks. The reality is that regulators, customers, insurance, government agencies, and even your suppliers are increasingly seeing cybersecurity as a business responsibility. And today we're going to talk about why. We're going to talk about what Australian businesses are actually expected to do, what the law expects, what regulators expect, what directors and business owners are responsible for, what happens when organizations get this wrong. And why cybersecurity is increasingly becoming a requirement to win contracts. And most importantly, why we didn't know is becoming a much weaker excuse than it used to be. So let's get into it. So to start with, the most important point. No one expects your business to be perfect. Not ASIC, not the Privacy Commissioner, not the Australian Cybersecurity Centre, not your customers. The expectation is not perfection. The expectation is responsibility. Because every organization has cyber risk. Every organization. Whether you have five staff or five thousand, whether you sell cupcakes, accounting services, engineering solutions, or software. You use technology, you store information, you process payments, you communicate electronically, which means cyber risk exists. The question isn't can I stop every cyber incident? The question is have I taken reasonable steps to reduce my risk? Because increasingly, that is a question that regulators are asking as well. One of the biggest mindset shifts I've seen in cybersecurity over the last decade is moving away from prevention alone. Most people think cybersecurity means stopping attacks. Buy antivirus, buy a firewall, have email filtering, train staff, done. But modern cybersecurity isn't just prevention. It's prevention, detection, response, and recovery. Because eventually something gets through. A supplier may be compromised, a password will be stolen, a staff member clicks something, an attacker will find a vulnerability, and an AI tool may be used incorrectly. There will be something that will eventually happen. And that's why you've probably heard people in the industry say, it's not if you'll be breached, it's when. Now that sounds dramatic, but it's actually about planning. It's about accepting that eventually something will go wrong and making sure that you are ready when it does. One of the most frightening statistics in cybersecurity today isn't actually how many attacks occur, it's how quickly they move. Security researchers measure something called breakout time. That's the amount of time it takes for an attacker to move from the first compromise system to other systems inside a business. Recent threat intelligence reporting has shown average breakout times measured in minutes. In some cases, attackers have moved laterally through environments in under a minute. Think about that. By the time you've made a coffee, somebody may already be moving through your systems. Which means resilience matters just as much as prevention. The organizations that survive cyber incidents aren't necessarily the ones that never get breached. They're often the organizations that detect it quickly, contain it quickly, communicate effectively, recover quickly, and continue serving their customers at the same time. One thing that surprises many business owners is that none of this is new. The Australian government has been talking about cyber resilience for years. The Australian Signals Directorate, or ASD, has spent decades providing guidance on how Australian organisations should secure their systems. The ASD also established the Australian Cybersecurity Centre, or ACSC. And if you've never heard of the ACSC or gone to their website, go spend an hour there. There are resources specifically designed for small business, medium business, large organizations, government agencies, as well as critical infrastructure providers. The information is practical and it's free. And most importantly, it's written in language normal people can actually understand. One of the things I often tell business owners is this: the government has actually done a pretty good job of explaining what organizations should be doing. The problem is that most people don't know those resources even exist. Now, if you really want to understand the scale of the problem, I want you to visit ScamWatch and fair warning. It's probably the most depressing government website you will ever visit. And even just saying its name makes my hair stand on end. Because suddenly cybercrime stops being technical. It becomes financial, it becomes personal, and it becomes really real. Recent Australian reporting has shown Australians losing more than two billion dollars a year to scams. More than two billion dollars, not million, billion with a B. Investment scams alone have accounted for hundreds of millions of dollars in losses. Business email compromise scams have cost Australian organizations hundreds of millions more. Phishing scams continue to generate enormous losses. And every single one of those incidents started with someone believing it won't happen to me. And that's why I encourage every business owner to spend 10 minutes looking at ScamWatch. Not because I want you to be scared, because I want you to understand the scale of what we're actually dealing with here. Now let's talk about one of the most important cybersecurity court cases in Australia, the RI Advice case. A lot of people assume this case resulted in some enormous financial penalty. It didn't. And that's actually why it's important. Ultimately, if you haven't heard about it, the federal court found that RI Advice had failed to adequately manage cybersecurity risks across its authorized representative network. And what they ordered was they had to pay approximately $750,000 towards ASIC's costs. They had to engage independent cybersecurity experts, they had to implement remediation activities, and they had to report back on those remediation efforts. Now, on the surface, that may not sound dramatic, but the significance was enormous because ASIC effectively demonstrated that cybersecurity is not just an IT issue. It's an operational risk, a governance risk, a leadership risk. And that means that directors and executives need to understand it. Not every technical detail, not every software product, but enough to ask good questions and make informed decisions. Most directors understand finance and legal risk and people management, operations strategy. But increasingly, directors are expected to understand enough to exercise proper oversight. Questions like what are our biggest cyber risks? How are we protecting our customers' information? Have our backups been tested? How quickly could we recover? Do we have cyber insurance? What happens if systems go offline tomorrow? And these are no longer IT questions, those are boardroom questions. And internationally, we're starting to see examples of where executives are being held personally accountable for decisions surrounding cybersecurity incidents and disclosure obligations. And that trend is unlikely to reverse. So let's start talking about privacy, because this is genuinely where the numbers become eye-opening. For serious or repeated privacy breaches, penalties can now reach $50 million, three times the benefit obtained from the breach, or 30% of adjusted turnover during the breach period. Whichever amount is greater. Think about that. This isn't a slap on the wrist anymore. The government has clearly signaled that protecting personal information matters. Now, does that mean that every small business is going to be hit with a $50 million penalty? Of course not. But it demonstrates the direction Australia is moving. The expectation is that organizations treat customer and employee information seriously. Because if you're collecting customer records, employee information, payroll data, health information, identification documents or financial information, you're effectively holding information that does belong to somebody else. And regulators increasingly expect businesses to protect it accordingly. But here's something interesting. I don't actually think that fines are the biggest risk. And I don't think every business fully understands what cyber insurance does either. I've spoken to business owners who've said that's okay, we have cyber insurance. And look, it can definitely be incredibly valuable. But it isn't a magic wand. Because just like home insurance, car insurance, income protection, or any other insurance product, there are conditions attached. The insurer is expecting you to have taken reasonable steps to reduce risk. Depending on the policy, that may include things like multi-factor authentication, backups, patch management, access controls, security awareness training, documented processes. And if you haven't maintained the controls you've declared on your application, you may find yourself having a very uncomfortable conversation with your insurer after an incident. Now, I'm not an insurance broker, I'm not providing insurance advice, but I do think every business owner should understand exactly what their policy covers as well as what it expects from them. Because when a cyber incident occurs, the costs start adding up very quickly. You have incident response consultants, digital forensic specialists, legal advice, recovery efforts, customer notification, public relations support, staff overtime, business downtime, there's lost productivity, lost revenue, you have your insurance excesses, there's also potential regulatory investigations, potential contractual disputes, potential reputational damage. And if you have ever been involved in a major incident, one thing becomes very clear. It's everything that happens afterwards that becomes incredibly expensive. And that's why cybersecurity isn't just about stopping incidents. It's about making sure your business can survive them. And this is becoming increasingly important for growing businesses, particularly organizations trying to win larger contracts. Imagine your sales team finds the perfect opportunity, a great customer, great fit, potentially life-changing revenue. And then the supplier questionnaire arrives. Do you have MFA? Do you conduct awareness training? Do you have an instant response plan? Can we see it? Do you align to essential eight? What level of essential eight? Do you have insurance? Do you have cyber insurance specifically? What is the actual maximum value of that? Do you perform independent security testing? Do you have documented security controls? And if the answer is no, you may not even get to participate. The deal can be lost before the sales process even starts. I've seen organizations spend months pursuing opportunities only to discover that they couldn't satisfy the security requirements. Australia is continuing to strengthen cyber legislation. The Cybersecurity Act introduced measures around ransomware reporting, cyber incident review mechanisms, and broader cyber resilience initiatives. The direction of travel is obvious. There is going to be more accountability, there is the expectation of more transparency. You will have to do more reporting, and you will have to be resilient. There's not going to be any less. The expectation on businesses will continue increasing over the coming decade. And if you're waiting until a customer, regulator, insurer, or government agency to force your conversation, you're already behind. So what should you actually do? And at this point you might be thinking, Alright, Vic, this is a long list right here. Where do I start? What do I do? I'm going to tell you the basics. Start simple. Visit the ACSC website. Understand the essential eight. They are about to change it to be called the Essentials, however, the same mechanisms will still be applicable. You need to ask your IT provider questions. Ask whether you have backups and whether they're tested. Ask whether or not your MFA is enforced at every level. Ask whether you have privilege accounts that are controlled. Ask whether systems are patched. Ask whether your staff receives cyber awareness training. And ask what happens if someone clicks the wrong thing tomorrow. Not next year, tomorrow. Because the quality of that answer tells you a lot about your organization's preparedness. And if you're a director or business owner, don't stop at asking whether or not a control exists. Ask whether or not it's actually being tested. Because there is a huge difference between having a backup and being able to recover from a disaster. So if there is one thing I want you to take away from today's episode, is this cybersecurity is no longer optional. And it's not because tech companies say so, it's not because your cybersecurity vendors say so. It's not because your IT provider says so. But it's because modern businesses depend on technology. And when technology fails, businesses suffer. The government isn't asking you to be perfect. ASIC isn't asking you to be perfect. Your customers are not asking you to be perfect. They're asking you to just be responsible, understand the risks, take reasonable steps, ask better questions, make informed decisions. Because cybersecurity really isn't about the technology, it's about protecting your business, protecting your people, protecting your customers, and protecting your future. Thanks for listening to the Technology Translator. I'll see you in the next episode. Thanks for joining the episode. If you do want to follow me on Instagram at all, you can find me under the Technology Translator. If you would like to email me, Vic at the Technology Translator.au And I guess I wouldn't be doing this properly if I didn't say if you like what you hear, hit the follow button. There will be more of these episodes coming up.