Change Management Strategy
Managing change requires open and creative thinking, change frameworks and the right tools to ensure the transition of change is flexible. Read our...
2 min read
ait-admin
:
August 11, 2026
Cyber security used to be something boards received a report on. Increasingly, it is something they are held responsible for. Financial services felt this first. In early 2026, in ASIC's case against FIIG Securities, the Federal Court confirmed that failing to manage cyber risk adequately can breach an organisation's core obligations, with penalties to match.[1]
That was a financial services matter. But the thinking behind it is not confined to financial services, and the not-for-profit sector is now on the same path. Charity boards should understand why.
Strip away the sector and the regulator, and one idea is doing the work. Adequacy is no longer about good intentions or paperwork. It is about whether an organisation can demonstrate that the controls it says it has are real, operating and proportionate to the risk it carries. A policy describing a control you never implemented offers no protection. If anything, it becomes the record of what you knew and did not act on.
That principle is not specific to any one industry. It is the standard regulators are applying wherever organisations hold information that matters, and it maps directly onto the not-for-profit sector.
For charities, the reference point is privacy law rather than financial services regulation. In December 2024 the Office of the Australian Information Commissioner accepted an enforceable undertaking from Oxfam Australia following a major data breach.[2] What makes it significant for the wider sector is not the incident itself, but the signal it sends.
Legal commentators made the point quickly. Bird & Bird described the undertaking as instructive for not-for-profits, setting expectations for how charities are expected to comply with the Privacy Act and the Australian Privacy Principles.[3] In effect, a regulator has now indicated what good looks like for a charity holding personal data, which means every other charity can be measured against it. Successive Privacy Act reforms, with expanded penalties and a sharper enforcement posture, only raise the stakes.
For an enterprise-scale charity, holding donor, beneficiary and staff data across national operations and a web of third-party platforms, this is not an abstract concern. It is a live governance question.
Here the connection to the financial services experience becomes practical. Just as the directors of a licensed firm can no longer treat cyber as purely an IT matter, ACNC Governance Standard 5 places duties of care and diligence on every Responsible Person and requires them to stay genuinely informed about how their charity is run.[4] The duty is personal, and it cannot be handed to an IT team, a managed services provider or a privacy officer and considered closed.
The question a board should be able to answer is simple to ask and harder to satisfy. If a regulator asked us today, could we demonstrate that we are managing personal information to the standard now expected of us? For many charities the honest answer is not yet, and closing that gap is where governance attention is now turning.
The practical question for any charity board is whether it could demonstrate, today, that personal data is being managed to the standard now expected. Working through that question in board language, rather than treating it as a technical issue, is where the value is.
andersenIT works with Australian charities and not-for-profits on exactly this.
1. HSF Kramer, "First ASIC penalty for cybersecurity failures: Federal Court imposes $2.5m penalty on FIIG." https://www.hsfkramer.com/insights/2026-02/first-asic-penalty-for-cybersecurity-failures-federal-court-imposes-two-point-five-million-penalty
2. OAIC, "OAIC accepts Oxfam Australia enforceable undertaking." https://www.oaic.gov.au/news/media-centre/oaic-accepts-oxfam-australia-enforceable-undertaking
3. Bird & Bird, "Oxfam enforceable undertaking instructive for not-for-profit sector." https://www.twobirds.com/en/insights/2025/australia/oxfam-enforceable-undertaking-instructive-for-notforprofit-sector
4. ACNC, "Governance Standard 5: Duties of Responsible People." https://www.acnc.gov.au/for-charities/manage-your-charity/governance-hub/5-duties-responsible-people
Managing change requires open and creative thinking, change frameworks and the right tools to ensure the transition of change is flexible. Read our...
Projects are all about change Projects are the catalyst of change. Projects are provided funding and resources not so they can simply be delivered on...
Our Role Insights series covers a range of roles within the andersenIT team. This week, we look at the Change Manager.