Your Suppliers Are Your Biggest Security Exposure

Handing your data to a supplier does not hand over the responsibility for it. What the first penalty case under the Privacy Act says about relying on somebody else.

Talk to DM1 TodayView Cyber Security

Where Breaches Actually Start

Most businesses picture a breach as somebody breaking into their own systems. In practice the more common story is that the data was somewhere else entirely, held by a supplier the business had stopped thinking about.

Three of the largest Australian breaches of recent years turned on exactly that. One of them has now been through the Federal Court, which means the detail is public and there is no need to speculate about what went wrong.

DM1 is an IT provider, not a legal adviser. This page describes the IT and supplier management side. For advice on your own obligations, consult your legal adviser.

Outsourcing the Work Does Not Outsource the Responsibility

In October 2025 the Federal Court handed down the first civil penalty ever imposed under the Privacy Act. The penalty was five point eight million dollars.

The organisation had acquired another business and taken on its computer systems. When those systems were attacked it relied on an external cyber security firm to investigate. That firm formed a view that the ransom threat was probably a scare tactic and suggested preparing a statement saying no data had been taken. It stopped checking for stolen data within days and closed its investigation inside a fortnight.

The data had in fact been taken. Eighty six gigabytes of it, covering more than 223,000 people, including health information and credit card details. It was published on the dark web four months later.

When the Court set out why the organisation had failed to take reasonable steps, one of the reasons it listed was, in its own words, the overreliance that the organisation placed on third party service providers and its failure to have in place adequate procedures to detect and respond by itself to cyber incidents.

The Court also applied an established principle from earlier cases, that an obligation to take reasonable steps is not capable of being discharged simply by delegating it to another entity and doing nothing more.

That is the sentence every business owner who has ever said "our IT company handles that" should read twice.

The Warning Came From Outside, Twice

The same case makes a second point that is easy to miss. The organisation did not discover the theft. The Australian Cyber Security Centre told them, having received intelligence from a third party.

The organisation replied that it did not believe any data had been taken, and its own technology chief told the board there was no reason to believe anything had been breached. Nearly three months later the Cyber Security Centre had to tell them a second time, this time that the data was published and included identity, health and financial information.

Between the attack and the public announcement, eight months passed.

This is not unusual. Of the incidents the Australian Signals Directorate responded to in 2024 to 2025, thirty seven per cent were found only because the Signals Directorate contacted the organisation. For ransomware it was thirty nine per cent. In two of every five ransomware cases the victim did not know until a government agency made the call.

The Problem You Inherit When Something Changes

The Court also found the organisation had not identified the weaknesses in the systems it acquired before it acquired them. This is what those systems looked like.

Antivirus that could not stop the attack

The software deployed could not prevent certain malicious files from being written or run, and did not detect data being uploaded from the server to the internet.

Firewalls keeping one hour of logs

Activity records were deleted after an hour, which left almost no ability to investigate what had happened or when.

An operating system out of support

The network server was running a version of Windows that Microsoft had stopped supporting in January 2020, more than two years before the attack.

No multi factor authentication on remote access

Staff were not required to use multi factor authentication to use the virtual private network.

No file encryption and no data loss prevention

Nothing was in place to protect files at rest or to detect information leaving the business.

An untrained responder

The person put in charge of the response had no formal cyber security background and had never seen the incident playbooks they were given.

Businesses inherit systems like this constantly, and not only through acquisitions. A supplier changes. A platform gets replaced but the old one stays switched on. Somebody sets up a service for a project that finished years ago and nobody turns it off.

The clearest published example of that last one is the 2022 Optus breach. According to the regulator's own filing, a coding error introduced around September 2018 disabled an access control. The affected system sat on a subdomain made reachable from the internet in June 2020 and then left alone. The organisation found and fixed the same error on its main site in August 2021 and did not apply the fix to the subdomain. The regulator described the attack as not highly sophisticated, and as a simple process of trial and error.

Sometimes the Supplier Is the Way In

The Qantas breach of 2025 involved no technical exploit at all.

According to the regulator's report, attackers telephoned an agent at an outsourced contact centre and impersonated internal technology support. The agent was walked through a series of actions presented as closing a support ticket. Those actions connected their customer system to a tool the attackers controlled. It was picked up around two days later, through unusual failed sign in alerts.

No malware. No vulnerability. A phone call to somebody who was trying to be helpful, at a company the customers had never heard of and had no relationship with.

The Medibank case, still before the Court, is alleged to have started in a similar place. The regulator alleges a contractor at an outsourced service desk saved credentials into a personal browser profile, malware collected them, and the account they belonged to had administrative access across most of the business.

Four Questions Worth Being Able to Answer

You are not going to audit your suppliers the way a bank does, and you do not need to. But most businesses cannot answer any of these.

1

Who holds your data

Not just the obvious ones. The bookkeeping platform, the booking system, the payroll provider, the marketing tool somebody signed up for, and the archive of files still sitting with a company you stopped using.

2

What they hold

A supplier holding names and email addresses is a different problem from one holding identity documents, health information or payment details.

3

What happens if they are breached

Whether your agreement requires them to tell you, how quickly, and whether you would find out any other way if they did not.

4

Whether anyone is watching

Not whether a supplier says it takes security seriously. Whether anybody on your side would notice if something went wrong.

How DM1 Handles This

When DM1 takes on a new client, part of the work is building a written inventory of what the business actually runs. Applications on each machine, browser extensions, the online services in use, and any open source components sitting inside a business system or a website.

Against each one we record who maintains it, how it gets updated, and whether it appears on any current compromise notice.

The reason is straightforward. When a supply chain compromise is announced, and they are announced regularly now, the question "are we affected" should be answerable from a document rather than from a week of guessing.

Open source software is not the risk. Unmanaged software is the risk, and most businesses are carrying more of it than they realise.

If you have never mapped who holds your data, that is the first piece of work, and it is usually more revealing than any scan.

Find Out Where Your Data Actually Sits

DM1 maps who holds your business information and where the real exposure is. Call (08) 6202 6012 to talk it through.

Contact DM1 Today(08) 6202 6012
Need IT help? Chat with us
DM1
DM1 Assistant
Perth IT Support Guide
Scroll to Top