On this page
Cyber security
Cyber security is the protection of information, devices, networks and systems from unauthorised access, use, disclosure, loss, disruption or attack.
Not-for-profits may hold valuable and sensitive information about clients, service users, donors, members, employees and volunteers. They may also rely heavily on email, online banking, cloud services and other digital systems to deliver services and manage information.
A cyber incident can result in:
- loss or disclosure of information
- financial loss
- disruption to services
- legal and regulatory consequences
- harm to individuals
- loss of community trust
Cyber security is not only an IT issue. Boards, committees and senior staff should oversee cyber risks as part of the organisation’s broader governance and risk management.
Recent Australian Government guidance recommends that boards and executive committees define clear cyber security responsibilities, integrate cyber security across the organisation and seek regular reporting about the organisation’s cyber security position and threat environment.
Reducing cyber risks
Practical measures can reduce the likelihood and effects of a cyber incident.
Your organisation should consider:
- using multi-factor authentication and strong passwords or passphrases
- keeping systems and software up to date
- limiting access to information based on role and operational need
- training personnel to recognise phishing, scams and suspicious requests
- backing up important information and testing recovery processes
- managing cyber risks associated with third-party providers
- preparing and testing cyber incident response plans
The Australian Signals Directorate’s checklist for charities and not-for-profits recommends multi-factor authentication, prompt updates, tested backups, password managers, training, access controls, secure service providers and tested response and recovery plans.
Cyber security fact sheet
Our cyber security fact sheet explains:
- key cyber security terms
- common internal, external and third-party cyber risks
- practical measures to protect systems and information
- cyber incident response planning
- the relationship between cyber security, privacy and data breaches
- obligations under the Cyber Security Act 2024 (Cth)
- reporting cyber incidents and data breaches
More information
For more information, see:
Common questions about cyber security
What cyber security obligations do not-for-profits have?
There is no single cyber security law that applies in the same way to every not-for-profit. An organisation’s obligations depend on its activities, structure, contracts, systems and the information it holds.
Relevant obligations may arise under:
- the Privacy Act 1988 (Cth), including the requirement for covered organisations to take reasonable steps to protect personal information
- the Notifiable Data Breaches scheme
- state or territory privacy and data breach laws
- corporations, charities and incorporated associations legislation
- duties of board or committee members
- work health and safety laws
- government contracts and funding agreements
- insurance policies
- sector-specific regulation
Meeting these obligations may require technical, organisational and contractual safeguards. The appropriate measures will depend on factors such as the sensitivity and amount of information held, the likely consequences of a breach, the organisation’s size and the available security measures.
Even where a specific privacy law does not apply, boards and committees should treat cyber security as an organisational risk and take reasonable steps to protect the organisation’s people, information, funds and services.
How can our organisation reduce cyber security risks?
Cyber security risks can often be reduced through practical measures such as:
- multi-factor authentication
- software updates
- strong passwords or passphrases
- access controls
- backups and recovery testing
- personnel training
- verification of payment requests
- incident response planning
Cyber security is an ongoing process. The appropriate measures will depend on the organisation's operations, systems and risk profile. Seek technical advice where necessary.
The Australian Signals Directorate identifies phishing, business email compromise and ransomware as key threats for charities and not-for-profits.
What should we do after a cyber attack?
Act quickly, but avoid making changes that could destroy evidence or make recovery more difficult.
Your organisation should:
- activate its cyber incident response plan
- contact its IT or cyber security adviser
- contain the incident, where this can be done safely
- protect accounts, systems and funds
- preserve records and evidence
- identify what information and systems are affected
- contact its insurer or broker promptly
- consider legal, regulatory and contractual reporting obligations
- consider whether affected people need to be notified
- report criminal activity or the incident to the appropriate authorities
- record decisions and actions
- review the incident and strengthen controls
If personal information is involved, assess whether the incident is an eligible data breach that must be reported under the Notifiable Data Breaches scheme or another applicable law.
Avoid paying a ransom or communicating with a threat actor without specialist legal, technical and insurance advice. Check the organisation’s insurance terms before incurring response costs or appointing advisers, as the policy may require the insurer’s approval.
Australian Government incident response guidance states that organisations should have a tailored response plan setting out roles and legal and regulatory obligations, aligned with crisis and business continuity arrangements, and that the plan should be tested and regularly reviewed.
Does our insurance cover cyber incidents?
It depends on the wording of the policy and the circumstances of the incident.
Cyber insurance may cover some costs associated with:
- investigating and responding to an incident
- technical and legal advice
- notifying affected individuals
- restoring data or systems
- business interruption
- liability to third parties
- regulatory investigations
- crisis communication
However, policies differ and may contain exclusions, conditions, excesses, sub-limits and notification requirements. General business, professional indemnity or crime policies may provide limited cover or exclude cyber incidents.
Your organisation should:
- review its insurance arrangements to identify which policies may provide cover
- read the insuring clauses, exclusions and conditions
- understand any security measures or other requirements imposed by the policy
- notify the insurer or broker as soon as possible
- obtain approval before appointing advisers or incurring significant costs if the policy requires this
- avoid admitting liability or settling a claim without the insurer's consent
- review insurance cover when the organisation's systems, services or risks change
Insurance does not replace appropriate cyber security. An insurer may consider whether the organisation complied with policy conditions and accurately disclosed its security practices when applying for or renewing cover.
For more information, see our resources on managing risk and insurance.
The content on this webpage was last updated in September 2026 and is not legal advice. See full disclaimer and copyright notice.