Cybersecurity & data advisory · Australia

The data you're required to hold is a target.

Australian businesses are collecting and storing more sensitive client information than ever — under new obligations, for years at a time. Circuit Risen helps you find the gaps before a breach, or a regulator, finds them first.

MLC Centre · 25 Martin Place, Sydney Fixed-price reviews · No jargon, no scare tactics Senior-led · You work directly with the specialist on your review
What's landed on Australian business — this month

This isn't a warning about the future. It's already here.

Two real breaches from the last few weeks — and one obligation that now makes the data your responsibility. Click any card to read what happened, and what it means for you.

The pattern is always the same: the data was there, the gap was known, and no one had looked.

The risk nobody's advising you on

AI didn't just change your industry. It walked into your office.

The fastest-growing threat to your client data isn't a distant hacker — it's the AI tools your own staff are already using, often without realising the risk. Most businesses have no policy for any of it.

Client data, pasted into public AI

A staff member drops a client file into ChatGPT to "summarise it faster." That data may now sit on a third party's servers — and, in some cases, be used to train the model. A disclosure that never touched your firewall.

Phishing that fools trained staff

AI writes flawless, personalised phishing emails at scale — no typos, no tells. The advice your team was given five years ago ("look for bad grammar") no longer works.

Deepfake voice and video

A cloned voice on the phone, or a familiar face on a video call, authorising a payment or a data release. It's already happening to Australian businesses, and it's convincing.

Recording devices in the room

Smart glasses and always-on wearables can capture a privileged meeting, a client's documents, or a screen — synced straight to a personal cloud account. Few businesses have thought about it.

Take the AI risk check →
Find your check

Two minutes tells you where you stand.

Whatever your business, the questions are plain and the result is instant. Pick the check built for your world — or start with the AI risk check if you're not sure. No systems access, no cost.

Not one of these? Start with the AI risk check → — it applies to every business.

How it works

From a two-minute check to a clear plan.

STEP ONE

Take the check

Ten plain-language questions about how your business stores and protects client data. You get an instant result, and we get a picture of where you stand.

STEP TWO

The review

A fixed-price Data Security Review, delivered in a week. We look at where your data lives, who can reach it, and what would happen in a breach — then hand you a prioritised roadmap.

STEP THREE

Close the gaps

You get a plain-English report and a clear order of what to fix first. We can help you close the gaps, or work alongside your existing IT provider. Your call.

Why now

The rules changed. The attackers already knew.

Australian professional practices are being pulled into data-handling obligations they've never had before — and being targeted more than ever. This isn't hypothetical.

1 July 2026
AML/CTF Tranche 2 obligations commenced for real estate, accounting and legal practices — including seven-year record retention.
~90,000
Australian businesses newly captured by the reforms, most holding client identity documents for the first time.
$80,850
Average cost of a cybercrime report to a business, per the ACSC's 2024–25 figures. The headline fine is only part of it.
The language of the obligation

The terms your obligations are written in — in plain English.

You'll hear these from your regulator, your insurer, and your lawyer. Here's what they actually mean. Knowing them is half of staying compliant.

Customer Due Diligence (CDD)
The identity checks and records AML/CTF now requires you to collect and keep — the documents that make you a target.
Notifiable Data Breach (NDB) scheme
The law that requires you to tell affected clients — and the OAIC — when their personal data is likely compromised.
Multi-Factor Authentication (MFA)
A second proof of identity beyond a password. The single highest-impact control most small practices still haven't switched on everywhere.
Data at rest & in transit
Whether your files are protected while stored (at rest) and while being sent (in transit). Email is usually neither.
Shadow AI
AI tools your staff use without approval or oversight — and the client data quietly flowing into them.
Principle of least privilege
People should have access to exactly what their role needs — no more. Most breaches spread because everyone can reach everything.

You already know you should look. Take two minutes and find out.

No cost, no systems access, no sales pitch. Just an honest read on where your client data stands.

Find your check