●  Melbourne-based · Local support you can actually reach
← All insights
Cyber security

Optus and Medibank: what two breaches taught every Australian business

In the space of a few weeks in 2022, two of Australia’s biggest companies were breached, and the country’s relationship with cyber security changed. First Optus, with the personal details of around 9.8 million current and former customers exposed. Then Medibank, where the private health information of roughly 9.7 million people was stolen and, when the company refused to pay the ransom, published on the dark web. The Home Affairs Minister called the Medibank attack the single most devastating cyber attack the nation had experienced.

These were enormous companies with enormous resources, and it’s easy to file the whole episode under “nothing to do with me”. But the lessons from those two breaches scale all the way down to a business of five people. Here’s what they actually taught us.

Optus: it’s often a basic gap, not a movie hack

The Optus breach didn’t involve some genius criminal operation. Reports pointed to an exposed connection to its systems that wasn’t properly locked, the digital equivalent of a back door left open. A basic gap, and millions of records walked out through it.

That’s the first lesson, and it’s oddly reassuring: the breaches that hurt are usually not sophisticated. They’re a misconfiguration, an unpatched system, a door someone forgot to lock. Which means the basics, done properly, prevent a real share of them. You don’t need to defend against movie hackers. You need to not leave doors open.

Optus, again: the data you keep is the data you can lose

The detail that stung most was that Optus held identity documents, passport and licence numbers, on former customers. People who’d left years ago were still exposed, because the data was still being held.

For any business, that’s the uncomfortable question to sit with: what are you keeping that you no longer need? Old customer records, scanned IDs, spreadsheets of details from a project that finished three years ago. Every piece of personal information you hold is something you can lose. The safest data is the data you never collected, or properly deleted. Collect less, keep it for less time, and there’s simply less to go wrong.

Medibank: you can’t pay your way out

Medibank refused to pay the reported ten million dollar ransom. That was the right call, paying funds crime and guarantees nothing, but the attackers published the data anyway, including deeply sensitive health information. Once data is stolen, it’s gone. No payment reliably gets it back.

The lesson that follows is the one that keeps coming up: there’s no buying your way back to safety after a breach. Backups can get your systems running again, but they can’t make a copy of stolen data disappear from a criminal’s hands. Protecting the data in the first place, who can reach it, how well it’s secured, how much of it you even hold, is the only thing that actually works.

The casualty underneath both: trust

Both companies survived. But the lasting damage wasn’t the technical clean-up, it was the trust. Customers remember being told their details were exposed. For a giant, that’s a bad year. For a small business, where the whole relationship is built on people trusting you with their information, it can be the thing you don’t come back from. Your reputation is more fragile, and more valuable, than a big company’s.

What it means for a business your size

You’re not going to lose ten million records, because you don’t have them. That’s an advantage, not a footnote. Being small means you can actually know what data you hold and look after it properly, which is something Optus and Medibank, at their scale, struggled to do. The same principles protect you:

  • Know what personal information you hold, and stop keeping what you don’t need.
  • Close the basic gaps: multi-factor authentication, patching, secured access.
  • Assume you can’t pay your way out, so prevention and tested backups are the plan.
  • Treat your customers’ trust as the asset it is.

The takeaway

Optus and Medibank turned cyber security from an IT issue into a national conversation, and that was overdue. The lesson for a small business isn’t to panic at the scale of it. It’s the opposite: the things that would have helped those giants are the same affordable, unglamorous basics available to you, and you’re small enough to actually get them right.

What would a breach mean for your business?

Book a free, no-obligation security assessment. We'll show you what data you hold, where the gaps are, and the basics that protect you, scaled to a business your size.

Actively managed IT

Want your protection this clear?

Every article here comes from how we look after Melbourne businesses every day. See where your business stands, and what “actively managed” really feels like.

Book a free assessment

Or explore cyber security in Melbourne.