Australian businesses are collecting and storing more sensitive client information than ever — under new obligations, for years at a time. Circuit Risen helps you find the gaps before a breach, or a regulator, finds them first.
MLC Centre · 25 Martin Place, SydneyFixed-price reviews · No jargon, no scare tacticsSenior-led · You work directly with the specialist on your review
What's landed on Australian business — this month
This isn't a warning about the future. It's already here.
Two real breaches from the last few weeks — and one obligation that now makes the data your responsibility. Click any card to read what happened, and what it means for you.
The pattern is always the same: the data was there, the gap was known, and no one had looked.
Retail · ASX-listed
A national retailer, taken offline
Disclosed August 2026
In mid-August 2026, furniture retailer Nick Scali — a listed company with the resources most small businesses can only dream of — told the market it was investigating a cyber incident. It took systems offline as a precaution, and customers felt it: orders slowed and enquiries went unanswered while the business worked to recover.
Its managing director was blunt about it afterwards, describing an attack "like everyone else" is facing, and admitting recovery was harder than first expected. At the time of reporting, no attacker had publicly claimed responsibility.
What it means for you. If a listed national brand with a real IT budget can be forced offline, the question isn't whether your business is a smaller target — it's whether anyone has actually checked where your gaps are. Most businesses find out during the incident, not before it.
A suburban Victorian medical centre confirmed it was investigating a cyber incident after a ransomware group claimed to have taken around 20,000 patient records — names, dates of birth, Medicare numbers, clinical notes and insurance files — along with staff identity documents like passports and licences.
The group listed the practice on its leak site and set a deadline to publish everything if it wasn't paid. This wasn't a hospital with a security team. It was an ordinary local practice holding exactly the kind of sensitive records every professional business now keeps.
What it means for you. The most damaging breaches aren't always the biggest — they're the ones exposing data people trusted you to protect. Identity documents, health details, financial records: if you hold them, you're responsible for them, and a breach means telling every affected person yourself.
You don't need to be breached to be exposed. Since 1 July 2026, AML/CTF "Tranche 2" reforms have pulled real estate agencies, accountants and law firms into obligations they've never had before: verifying customers, and keeping their identity documents and due-diligence records for seven years.
Around 90,000 Australian businesses are newly captured — most now holding sensitive ID data for the first time, often in email inboxes and shared drives that were never built to protect it. AUSTRAC has signalled an educative early approach, but the obligations are not optional, and the retention clock is already running.
What it means for you. The records you're now legally required to keep are exactly what attackers want most. Compliance and security are now the same problem — and "we hadn't got to it yet" is not an answer you want to give a regulator, or a client whose passport just leaked.
AI didn't just change your industry. It walked into your office.
The fastest-growing threat to your client data isn't a distant hacker — it's the AI tools your own staff are already using, often without realising the risk. Most businesses have no policy for any of it.
Client data, pasted into public AI
A staff member drops a client file into ChatGPT to "summarise it faster." That data may now sit on a third party's servers — and, in some cases, be used to train the model. A disclosure that never touched your firewall.
Phishing that fools trained staff
AI writes flawless, personalised phishing emails at scale — no typos, no tells. The advice your team was given five years ago ("look for bad grammar") no longer works.
Deepfake voice and video
A cloned voice on the phone, or a familiar face on a video call, authorising a payment or a data release. It's already happening to Australian businesses, and it's convincing.
Recording devices in the room
Smart glasses and always-on wearables can capture a privileged meeting, a client's documents, or a screen — synced straight to a personal cloud account. Few businesses have thought about it.
Whatever your business, the questions are plain and the result is instant. Pick the check built for your world — or start with the AI risk check if you're not sure. No systems access, no cost.
Ten plain-language questions about how your business stores and protects client data. You get an instant result, and we get a picture of where you stand.
STEP TWO
The review
A fixed-price Data Security Review, delivered in a week. We look at where your data lives, who can reach it, and what would happen in a breach — then hand you a prioritised roadmap.
STEP THREE
Close the gaps
You get a plain-English report and a clear order of what to fix first. We can help you close the gaps, or work alongside your existing IT provider. Your call.
Why now
The rules changed. The attackers already knew.
Australian professional practices are being pulled into data-handling obligations they've never had before — and being targeted more than ever. This isn't hypothetical.
1 July 2026
AML/CTF Tranche 2 obligations commenced for real estate, accounting and legal practices — including seven-year record retention.
~90,000
Australian businesses newly captured by the reforms, most holding client identity documents for the first time.
$80,850
Average cost of a cybercrime report to a business, per the ACSC's 2024–25 figures. The headline fine is only part of it.
The language of the obligation
The terms your obligations are written in — in plain English.
You'll hear these from your regulator, your insurer, and your lawyer. Here's what they actually mean. Knowing them is half of staying compliant.
Customer Due Diligence (CDD)
The identity checks and records AML/CTF now requires you to collect and keep — the documents that make you a target.
Notifiable Data Breach (NDB) scheme
The law that requires you to tell affected clients — and the OAIC — when their personal data is likely compromised.
Multi-Factor Authentication (MFA)
A second proof of identity beyond a password. The single highest-impact control most small practices still haven't switched on everywhere.
Data at rest & in transit
Whether your files are protected while stored (at rest) and while being sent (in transit). Email is usually neither.
Shadow AI
AI tools your staff use without approval or oversight — and the client data quietly flowing into them.
Principle of least privilege
People should have access to exactly what their role needs — no more. Most breaches spread because everyone can reach everything.
You already know you should look. Take two minutes and find out.
No cost, no systems access, no sales pitch. Just an honest read on where your client data stands.