
By Heidi Bruce, Principal – Managing Director, Sydney
29 June 2017
You will have seen in the press the cyber attacks that have been impacting businesses worldwide, with a recent wave of attacks affecting international businesses. These are not isolated incidents by any stretch, and this is a serious concern that all businesses need to consider. The experts have been warning for some months that the risks of these attacks hitting Australian businesses are very real. The risks include not only critical impacts on business operations, but serious adverse legal and reputational consequences.
Ransomware – what is it?
Ransomware is a form of cyber attack that typically encrypts files on a server, and offers to give a key to unlock the data for a fee. This will generally come in the form of a rudimentary request for a set amount of Bitcoin, a form of digital currency, which can represent a very substantial sum of money. If you or your clients rely on this data and there is no backup, then the decision whether to pay the ransom will be one you don’t want to have to make. Even if the ransom is paid there is no guarantee that the attackers will follow through with their offer to unlock the data, so there is no certainty that the files will be recovered. It can often be impossible to verify whether there has been any actual transfer or sharing of the data so it may be very difficult to know the extent of the problem you are dealing with.
How can it really impact advertising, media, PR, digital and promotional agencies?
Such agencies are increasingly holding or managing some form of client data on their systems, and this may include personal information such as names and contact details or sensitive information such as health or religious details. Agencies can also be involved in the processing of credit card payments, which is extremely valuable.
Many of these agencies will often use the most advanced technologies and processes to ensure the protection of their systems and the data they hold. However in some cases there may be systems that are overlooked for whatever reason, they may be seen as low risk, or they may be old legacy systems that have not been updated or reviewed for some time. These can be especially vulnerable to cyber attackers and even with the best measures in place across the board, there may be hidden weaknesses.
These sorts of attacks are predicted to increase in sophistication and in prevalence, and the valuable nature of the data held by agencies can set them up as high risk targets for these sorts of attacks.
What are the legal consequences?
With new data breach notification laws set to become mandatory in Australia in February 2018, this will carry even heavier consequences. For an eligible data breach, ie one that is likely to result in ‘serious harm’ to an individual, a business will need to notify the Privacy Commissioner and affected individuals.
Under current Australian privacy laws, there is an obligation on APP entities to take reasonable steps to protect personal information it holds from misuse, interference and loss, as well as unauthorised access, modification or disclosure.
Most contracts that agencies have with their clients will have a clause that requires the agency to comply with Australian privacy laws including the above, and can also include a whole raft of obligations on security, back-up of data, restricting access to personal information, and procedures for management of personal information. If security measures are not up to scratch, a ransomware attack could expose flaws and lead to claims that the agency has not fulfilled its obligations.
Client contracts can also include an express requirement for the agency to notify the client if there has been a data breach. So this can mean the agency is obligated to inform the client immediately of the issue and the steps it is taking to resolve it. The client may pressure for notification to consumers, and may claim breach of contract or negligence under the client contract.
What steps should be taken now?
It is critical that agencies take the time now to do a thorough investigation of their systems including servers and applications especially those with access to the internet, and ensure that security settings are in place and up to date, the relevant support is being provided and crucially, patches are installed regularly. As cyber criminals find new vulnerabilities, the technology providers come out with patches, so the longer you take to patch a system, the higher the vulnerability. It is also recommended to consider a routine of penetration testing, and whether adequate data back-up and recovery processes are in place. Training is also prudent, to advise staff not to open certain files and to take other preventative measures.
If a data breach or cyber attack does occur, and these are becoming more inevitable in this environment, the agency will need a robust response process to ensure the agency can react quickly and confidently to fix the issue and reassure any affected clients. It is important that a robust response and escalation procedure is in place, so that staff know exactly what to do and who should be contacted to investigate and manage the issue. It can help to have experts appointed to roles in the technical response and data protection fields, for this purpose. A strong response procedure when properly executed, can help to resolve and shut down an issue successfully before it escalates.
Related Articles
What our clients say
"When you’re a creative business, you’re always taking risks. Clint and his team’s support gives us the confidence to do work that pushes boundaries. Which makes Anisimoff not just a legal firm, but a valuable partner in the creative process."
Adrian Mills, Co-Founder and CEO
"We’ve had the pleasure of working with Anisimoff for over 16 years, right from the very start of the 31ST journey (and from past agencies). They’ve been more than just legal advisors - they’ve been true partners, always guiding us with wisdom, care, and practical advice. Their professionalism and knowledge are second to none, but what really stands out is how they go above and beyond for us at every turn. On top of that, they’re genuinely great people - approachable, thoughtful, and invested in our success. We feel lucky to have them by our side and can’t recommend them highly enough."
Adele Te Wani, Growth & Relationships Partner
“Clint is the first person we think of when there’s any whiff of risk or need for legal support. His advice over the years has always come from a place of legal expertise, but more importantly from an understanding of the challenges of running a business and as a human. I can honestly say he is the most pragmatic and empathic lawyer we’ve worked with. A rare thing in our experience.”
Angela Smith, CEO
“We’ve been working with Anisimoff Legal for over 20 years, and their partnership has been invaluable to Fuel Sydney.
Their team’s thorough understanding of marketing, promotions and compliance gives us total confidence in every piece of work that goes to market. They’re not just legal advisors, they are approachable, trusted collaborators who genuinely understand our industry and the fast pace we operate in.
With the increasing presence of AI, we really value the long-standing relationship and the reliability of being able to pick up the phone and speak to anyone on the team whenever we need”
Sara Roe, Director
“We’ve worked with Clint and the team at Anisimoff for over a decade, and they are truly trusted and reliable advisors. Their advice is always clear, pragmatic and grounded in a strong understanding of both the law and commercial reality. Their support has been consistently invaluable to Calico’s growth.”
Matt Fenton, Managing Director
Dell Australia
McCann Hero
Millie & More
Mont Marte Int.
smrtr Pty Ltd
TalentPay
Loyalty.com.au Pty Ltd
Their knowledge and expertise is second to none and has allowed us to bring brand new promotional concepts to market time and again.”
PROUD MEMBERS OF



Resources for agencies and brands
We'd love to hear from you!
Please reach out to us below or call our office to speak to one of our team.
Sydney: (02) 9460 6611
Melbourne: (03) 9866 3644
Central Coast: (02) 4331 0400
FAX: (02) 9460 7200