Helios Salinger

  • About
    • About Salinger Privacy – now Helios Salinger
    • Meet our team
    • Work with us
    • Videos, Podcasts and Media Mentions
    • Privacy Awareness Week
  • Consulting
    • Overview – Our Consulting Services
    • Privacy Impact Assessment
    • Privacy Maturity Assessment
    • Privacy by Design advice
    • Privacy Compliance and Gap Analysis
    • Algorithmic Impact Assessment
    • Re-identification Risk Assessment
    • Data ethics
    • Privacy Helpdesk
  • Training
    • Overview – Our Training Services
    • Privacy Compliance Training
    • Privacy Professionals Training
    • All Online Modules
    • Training Calendar
    • Public Courses and Workshops
    • In-house Privacy Training and Workshops
    • Webinars
    • IAPP Certifications
    • Training Advisory Services
    • Login
  • Resources
    • Overview – Our Resources
    • THE PRIVACY PULSE
    • Privacy Act Reforms
    • Compliance Kits
    • Resources on key privacy topics
    • Free Handbook
    • Newsletter
    • Login
  • Case Study
  • Blog
  • Calendar
  • Contact
  • Compliance Kits
    • For Business & Non-profits
    • For Peak Bodies
    • For Australian Government
    • For NSW Public Sector
    • For VIC Public Sector
    • For QLD Public Sector
    • For WA Public Sector
    • Login

Insider risk: 15 examples of why training and controls matter

February 7, 2024, Anna Johnston

Cyber risk from external bad actors is a keen area of government, public and industry focus right now – but there are also significant risks posed by trusted insiders.

Cyber is having a moment.  Ever since a small number of big brand names became synonymous with super-sized data breaches in 2022, focus on organisations’ vulnerability to cyber attacks from organised or opportunistic outsiders has catapulted from the IT team to national-security-level political players.

But last week, a shark attack in Sydney Harbour not only prompted some second thoughts about popping out for an evening swim, but also served as a reminder that data breaches, and other types of privacy harms, can be facilitated by trusted insiders as well.

When ‘gruesome shark bite’ photos of a female patient, taken inside the emergency department of a hospital, popped up on social media, the hunt was on for who leaked the images.  The investigation included hospital personnel, attending police officers, and Department of Primary Industries scientists, all of whom had legitimate access to photos (for example, so as to assess what type of shark it was), before the NSW Ambulance Service ‘fessed up that one of its paramedics was behind the leak.

NSW Ambulance has apologised for the breach of the patient’s privacy, but as of yet has not said what action will be taken against their employee.

For NSW public servants, the unauthorised but intentional disclosure of health information, that was gained in the exercise of their official functions, is ‘corrupt disclosure’ (even if no money is changing hands), a crime punishable by up to 2 years imprisonment.  And a heads up: anyone else who now shares those images may also be committing a separate crime.

Clearly, the law alone is not enough to stop privacy breaches.

Some people will be motivated by curiosity, greed, fun, financial need, boredom, revenge, family disputes, jealousy, a workplace grievance or the pursuit of power to look up and misuse personal information or confidential records.

Even when the law says it is a crime.  Even when they have been warned they could be sacked.  (In one case, even when the same employee was warned for doing it previously!)

It happens in hospitals.  It happens in police forces.  It happens in banks and in credit card companies and hotels.  It happens in government departments and in call centres.

Some people will do the wrong thing.

So relying on the law alone to prevent the misuse of personal information by authorised users is about as useful as building a bank vault with an unlocked door and no alarms, but telling customers their money will be safe because it is illegal to steal.

Yet when we conduct privacy compliance reviews for clients, we so often hear some refrain about how “our staff will never misuse personal information because it’s against the law”.  A related argument is “… because it’s in our code of conduct”.

We hear this as a reason not to tighten up role-based access controls, implement other risk mitigation strategies, or why comprehensive, auditable privacy compliance training is not needed.

In a recent case involving a human-error-caused data breach, the NSW Civil and Administrative Tribunal placed little weight on the fact that the recipients of the disclosed personal information had privacy obligations under legislation, or confidentiality obligations under contract, which the agency argued should operate to prevent anyone from misusing the information sent to them in error.  The Tribunal found that the agency’s “responsibility to have reasonable security safeguards on the personal and health information it has in its possession and control cannot be delegated in this way”.

The message is clear: to protect the privacy of the personal information you hold, you need to apply privacy by design, build in technical controls, train all staff, and enforce a security culture, in order to make attempted misuse – as well as accidental disclosure – as difficult as possible.

 

Contact us to find out more about privacy compliance training across your organisation, Privacy by Design training for select teams, or how to get your hands on our Checklist of 81 Common Privacy Risks & Controls.

Photograph © Shutterstock

Filed Under: Uncategorized

If you enjoyed this blog, subscribe to our newsletter to receive more privacy insights and news every month.

Privacy Compliance Kits

Privacy Compliance Kits

Recent Posts

  • Privacy law reform: weaving threads for a harmonious whole
  • Tick and flick: what ’I agree’ really means to Australians in 2026
  • Inching towards individuation: OAIC decision on pixels broadens scope of the Privacy Act
  • How dark patterns can land you in hot water: new case offers lessons for all
  • How to sniff out the landmines that can ruin your AI project
  • Privacy reforms to impact over 100,000 small businesses
  • The view from the summit: trust and hope, caution and concern, and plenty of hard work
  • Is identifiability in the eye of the beholder?  EU case tests limits of pseudonymisation
  • Mind the gap: when legal permission is not enough to ensure compliance
  • Why “Don’t worry it’s de-identified” should (still) be a red flag when considering privacy risk

Archive

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015

Search

Helios Salinger can help you navigate the complexity of the regulatory environment, and ensure the trust of your customers.

CONTACT US

T: 02 9043 2632
Level 37, 180 George Street
Sydney NSW 2000
Email Enquiry

© Helios Salinger Pty Ltd
ACN 655 748 593
ABN 59 655 748 593

Our Privacy Policy

Terms of Engagement

Subscribe to our newsletter.

These details will be added to our mailing list to receive the Helios Salinger eNews and Product News newsletters. You can unsubscribe or adjust your preferences at any time, from the bottom of any newsletter.