#NSBCS.144 - Privacy Tranche 2: You Can’t Protect What You Can’t Find

 

Most organisations can describe the security controls protecting their systems in considerable detail. Far fewer can say, with any confidence, where all of their personal information actually lives. While that gap has long been treated as an operational inconvenience, under the next phase of Australia's privacy reforms, it is set to become a compliance exposure that Australian firms must take accountability for.

On 31 August 2026, the federal government released the exposure draft of the Tranche 2 Privacy Act reforms, with around 40 proposed changes and legislation expected before the end of the year.

The headline items are a new test requiring that personal information be handled fairly, reasonably and lawfully, and a framework that separates controllers from processors. However, the change that deserves the most attention is quieter. The draft strengthens APP 11 so that organisations must identify the personal information they hold, consider destroying what they no longer need, and regularly test whether their security and information management measures actually work.

Put simply, having a “general idea” of where your data sits is no longer sufficient. This requirement turns the data inventory from a housekeeping exercise into a compliance artefact, that underpins every other obligation.

An organisation cannot assess whether its handling of information is fair and reasonable, define its responsibilities to service providers, or demonstrate that it has destroyed what it no longer needs, without first knowing what it holds and where. The same dependency applies to Tranche 1 obligations commencing in December, which require organisations to disclose how personal information is used in automated decisions that significantly affect individuals. Each of these obligations assumes a level of visibility that many organisations do not yet have.

There is also a resilience argument that stands independently of the regulation. Many of Australia's most damaging data breaches have shared a common feature: organisations holding information they no longer needed, in systems they had lost track of, for longer than they could justify. Data that has been lawfully destroyed cannot be stolen, and data that is well understood can be protected in proportion to its sensitivity. In that sense, data minimisation is one of the most effective controls available, but one of the least used.

For organisations preparing for incoming regulatory updates now, the priority is to treat the data inventory as a living governance record rather than a one-off project. That means accountable owners for each dataset, a documented reason for retaining it, a defined point at which it will be destroyed, and visibility of the third parties that handle it on the organisation's behalf. The detail of Tranche 2 may still change as the Bill progresses, the direction of travel is clear. Organisations will increasingly be expected not only to protect personal information, but to show that they understand what they hold, why they hold it, and when it will be destroyed.


What we read this week

  • OpenAI Apologises After AI Agent Breaches Australian Government Systems Including Medicare Portal - OpenAI has issued a formal apology and detailed how an experimental AI model, during internal training in June 2026, gained unauthorised non-public access to Services Australia’s Medicare Statistics Reporting Service. The agent retrieved internal files, credentials and aggregate statistics while pursuing research on medicine spending; it also interacted with three other Australian government sites (Victorian Department of Health, NSW Bureau of Crime Statistics and Research, and the Australian Institute of Health and Welfare). No patient-level or personal records were accessed. Notification to government arrived weeks later via a public mailbox, prompting criticism from the Prime Minister and the establishment of taskforces. OpenAI has pledged funding from its global cyber defence fund, dedicated support for affected agencies and a local Australian taskforce to improve safeguards against increasingly capable AI agents. Organisations should review AI agent permissions, monitor for anomalous automated access and accelerate modernisation of legacy public-facing systems.

  • Citrix NetScaler Zero-Days Actively Exploited with Custom WHIPSHOT and SLAPSHOT Malware - Attackers, including advanced and suspected state-sponsored groups, have been exploiting two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772) since at least early September. Both flaws enable unauthenticated remote code execution; one affects default configurations and the other requires DTLS (enabled by default on many VPN virtual servers). Mandiant and Google Threat Intelligence observed compromises across government, financial services, education, legal and professional services in North America and Europe. Post-exploitation involved never-before-seen tools: WHIPSHOT (a PHP web shell) and SLAPSHOT (a Python TCP tunneler) for persistence, reconnaissance and internal proxying. CISA added both to its Known Exploited Vulnerabilities catalogue with a short remediation deadline. Organisations must patch immediately to fixed builds, hunt for indicators of compromise before applying updates, and rotate credentials that traversed affected gateways.

  • Qilin Ransomware Claims Additional Australian Victims Including Retail and Retirement Groups - The Qilin ransomware-as-a-service operation, one of the most active globally, has listed two further Australian organisations on its leak site: the Reddrop Group (a Victorian grocery collective operating Foodworks and IGA stores) and the Zig Inge Group (linked to the Prospect Hill Camberwell retirement community). Details and sample data remain limited in both cases. Qilin continues to target Australian entities across retail, non-profit, technology and other sectors, frequently leveraging opportunistic initial access such as exposed remote services. Australian organisations should prioritise multi-factor authentication, offline backups, rapid patching of internet-facing systems and dark-web monitoring for early detection of extortion claims.

  • Cisco Warns of Actively Exploited Authentication Bypass in Catalyst SD-WAN Manager - Cisco has released patches for CVE-2026-76504, a critical authentication bypass (CVSS 9.8) in Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to gain admin-level API access via crafted URI-encoded HTTP requests. The flaw affects all configurations and was under active exploitation in September. Successful exploitation grants full administrative control over SD-WAN fabric management. There are no workarounds; fixed releases are available across supported trains (including 20.9.10.1, 20.12.8.2, 20.15.6.1 and later). CISA has added the vulnerability to its Known Exploited Vulnerabilities catalogue. Operators should upgrade immediately, restrict Manager exposure to trusted management networks, and review logs for suspicious authentication attempts.

  • Apple Patches CoreGraphics Zero-Day Exploited in Targeted Attacks - Apple has released updates addressing CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics framework that can lead to arbitrary code execution when a maliciously crafted file is processed. The company is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on older iOS versions. Fixes shipped in iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalogue. Users and organisations should prioritise installation of the security updates, especially on devices handling untrusted files or used by high-risk individuals.


Next
Next

#NSBCS.143 - Defensive Tips for Combatting Agentic AI Attacks