How we can help
Cyber incidents test not only technology, but also leadership, governance and operational resilience.
Our dedicated, cross-functional cyber security team supports clients through every stage of the cyber lifecycle – readiness, response and recovery – providing rapid, strategic advice on legal and regulatory obligations while helping organisations build resilient governance frameworks and manage future risk.
We provide end-to-end support, including cyber risk assessments, incident response planning, tabletop exercises, board and executive governance, third-party and supply chain risk management, and compliance with evolving Australian and international regulatory requirements.
During active incidents, we deliver urgent legal advice, coordinate regulatory notifications and engagement, conduct privileged investigations, manage stakeholder communications, and oversee legal, technical and communications workstreams under intense time pressure. Through partnerships with leading forensic, technical and crisis communications providers, we deliver coordinated, end-to-end incident response. Our multidisciplinary approach ensures advice that is practical, commercially focused and capable of withstanding regulatory and public scrutiny when it matters most.
Following incidents, we assist with regulatory investigations, remediation programs, lessons-learned reviews, governance uplift, contractual risk management and ongoing compliance obligations.
Our team has extensive experience advising clients across financial services, health, telecommunications, retail, government and critical infrastructure sectors. We advise on the full range of SOCI obligations, including CIRMPs, mandatory cyber incident reporting, government assistance measures, and enhanced cyber security obligations introduced by the Cyber Security Act 2024 (Cth).
Experience
-
Global data and cloud provider
Advised a provider of end-to-end cyber readiness and incident response advisory services, including tabletop exercises, supply chain security reviews and advice, on its obligations under the Security of Critical Infrastructure Act 2018 (Cth) including with key customer engagements. -
A leading Australian retailer
Advised on post-incident remediation, lessons-learned review and governance uplift following a cyber security event impacting customer data, including regulatory engagement, individual claims management and communications/PR strategy. -
Fleet Space Technologies
Advised on cyber risk and data governance frameworks for satellite enabled technology deployments, including contractual risk allocation, protection of cloud based systems and cross jurisdictional operations. -
Federal Government
Delivered privacy, secrecy and legal risk advice on an agency-wide rollout of AI tools across a workforce which handles sensitive data regulated by multiple pieces of Commonwealth legislation. -
Tabcorp
Advised on group-wide data privacy strategy, including designing the Group's data breach response plan, structuring data-sharing arrangements between entities, developing privacy policies, undertaking AI-related privacy audits, and providing ongoing privacy compliance and breach readiness advice. -
International AI technology provider
Advised on the development and implementation of a platform services arrangement for the deployment of advanced cyber-intelligence solutions, including supporting rollouts to major financial institutions, telecommunications providers, and multinational enterprises across the UK and Asia-Pacific.