Add Think Technology as a trusted source Moving beyond cyberattack blame | Think Technology

Moving beyond cyberattack blame

Singapore city skyline

A Brisbane professional services firm we work with had a phishing email slip through their filters last year. Within an hour, a staff member had clicked a link and entered credentials. The instinct from leadership was immediate: who clicked it? But the more useful question turned out to be: why did the link get through, and what stops the next one? Getting that second question answered is what actually made them more secure.

The urge to assign blame after a cyber incident is understandable. It protects reputations and gives leaders a sense of control. But it rarely improves defences, and it often makes things worse. Australia’s regulators and security bodies have now made this position official policy, and it is worth understanding what that means for your business. For more on building a resilient security posture, take a look at our IT security assessments and how we approach risk for Queensland SMEs.

The cost of the blame game

According to the ASD’s Annual Cyber Threat Report 2024-25, the average self-reported cost of a cybercrime incident for a small Australian business rose 14 per cent to $56,600. For medium businesses, it jumped 55 per cent to $97,200. These are self-reported figures, which means the true cost including lost productivity, reputational damage, and staff churn is likely higher. In that context, any time spent pointing fingers after a breach is expensive time not spent on recovery.

When a breach hits, panic sets in fast. Leaders rush to identify who is responsible, sometimes in front of regulators, insurers, or the media. Premature or speculative blame can contradict formal findings later, expose the business to legal risk, and signal to attackers exactly where your detection gaps are. The pattern is familiar to anyone who has watched a public incident unfold badly.

Why attribution is hard and why it is not your priority

Determining who is behind an attack is genuinely difficult, even for intelligence agencies with significant resources. In 2026, the boundary between state-sponsored and financially motivated cyber activity has continued to blur, making it harder for incident response teams to pin down who is responsible. Threat actors routinely reuse tools, shared infrastructure, and overlapping techniques. What looks like a nation-state attack may be a criminal group using the same toolkit.

  • Technical ambiguity: attackers share and resell tools, so attribution based on code or infrastructure is rarely conclusive.
  • Geopolitical weight: publicly naming a state actor carries diplomatic consequences that governments weigh carefully and that private businesses are not equipped to manage.
  • Operational cost: chasing attribution burns time and budget that should go into containment, recovery, and closing the gaps that let the attacker in.

Australia has now made no-fault review official policy

In May 2026, the Australian Government formally established the Cyber Incident Review Board under the Cyber Security Act 2024. Its mandate is to conduct no-fault, post-incident reviews of significant cybersecurity incidents, focusing on systemic lessons rather than individual or corporate culpability. The board’s reviews will produce recommendations for government and industry on how to prevent, detect, respond to, and reduce the impact of future attacks.

This is a deliberate policy choice. The no-fault model is designed to encourage organisations to share information openly, because they know the findings cannot be used for regulatory enforcement against them. The same logic applies inside your own business. When people fear blame, they withhold information. When they feel safe reporting, you get the full picture and you can actually fix the problem.

Build a no-blame reporting culture before an incident happens

Your staff are your earliest warning system. If someone notices a suspicious email, an unusual login, or something odd happening on their device, you want them to report it immediately. If they fear being blamed for clicking something, they will stay quiet and hope it goes away. Small signals get missed, and small signals are often the only warning you get before a significant incident.

Create clear, easy channels to report suspicious activity. Reinforce that reporting quickly matters far more than being certain something is wrong. Run regular phishing simulations so that clicking a test link becomes a learning moment rather than a source of shame. Security training that sticks is built on psychological safety, not fear of consequences.

Incident response: what to focus on when it happens

Speed and structure matter more than blame when a breach is active. The Cyber Security Act 2024 introduced mandatory ransomware payment reporting within 72 hours for businesses with annual turnover above $3 million. Separately, if your organisation holds personal information, the Privacy Act 1988 requires you to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to cause serious harm.

  1. Contain fast: isolate affected systems, revoke compromised credentials, and block known malicious infrastructure.
  2. Preserve evidence: retain forensic artefacts to support any investigation and meet regulatory obligations.
  3. Communicate with purpose: keep stakeholders informed without speculative attribution. Focus on what happened, what you are doing, and what changes as a result.
  4. Bring in expertise: engage your incident response provider, legal counsel, and cyber insurer early, not after the dust settles.
  5. Report appropriately: follow your obligations to the Australian Cyber Security Centre (ACSC)OAIC, and any relevant industry regulator. Information you voluntarily provide to the ACSC is protected by limited-use provisions and cannot be used against you in regulatory proceedings.

Learning and improving after every incident

A blameless post-incident review (sometimes called a post-mortem) is one of the highest-value activities you can run after a breach or near-miss. The objective is to understand the what and the why, not the who. When team members feel safe being honest about what happened, you get an accurate timeline, you find the real root cause, and you can fix it. Finger-pointing kills honest analysis and leaves the underlying problem in place.

After each review, translate findings into specific improvements:

  • Routine cyber awareness training and phishing simulations.
  • Multi-factor authentication (MFA) across all accounts, particularly public-facing services.
  • Strong event logging, detection, and 24/7 monitoring, the ASD’s 2024-25 report identified poor logging as a key factor that allowed incidents to escalate.
  • Immutable backups and a tested recovery plan.
  • Secure credential practices using a password manager and tighter data security controls.

Governance and board responsibility

The ASD’s cyber security priorities for boards in 2025-26 are direct: understanding and managing cyber risk is a core governance responsibility, not an IT function. Boards need visibility of the risk, clear ownership of the response plan, and confidence that controls are tested regularly. A breach that follows good-faith preparation lands very differently with regulators and insurers than one that follows neglect.

Practical governance steps worth confirming now:

  • Documented and tested incident response and crisis communication plans.
  • Regular IT audits and third-party validation of controls.
  • Alignment to the ACSC Essential Eight maturity targets.
  • Clear risk ownership and board-level reporting on cyber posture.

A practical 90-day starting point

  1. Weeks 1-2: confirm incident response roles, run a tabletop exercise, and close obvious MFA and patching gaps.
  2. Weeks 3-6: complete an external security assessmentuplift event logging, and harden privileged access controls.
  3. Weeks 7-12: introduce regular phishing simulations, build an asset inventory, and formalise a no-blame reporting policy in writing.

FAQ

Does finding out who attacked us help us recover faster?

Rarely. For most businesses, recovery depends on containment, remediation, and fixing the vulnerability that was exploited. Formal attribution is a job for government intelligence agencies. Your priority after an incident is restoring operations and closing the gaps, not identifying a perpetrator that you have no power to pursue.

Are we legally required to report a cyber incident in Australia?

It depends on your situation. If personal information is involved and the breach is likely to cause serious harm, you must notify the OAIC and affected individuals under the Privacy Act 1988. If you make a ransomware payment and your annual turnover exceeds $3 million, mandatory reporting to the ACSC applies within 72 hours under the Cyber Security Act 2024. Critical infrastructure operators have additional obligations under the SOCI Act.

What is a blameless post-mortem and why does it matter?

A blameless post-mortem is a structured review after an incident that focuses on what happened and why, not who is at fault. It brings together everyone involved to reconstruct the event timeline accurately. When people feel safe being honest, you get the full picture and can find the real root cause. Blame-focused reviews produce incomplete accounts and leave the underlying problem unsolved.

How do we encourage staff to report suspicious activity without fear?

Make it easy and make it normal. Provide a simple, accessible way to report suspicious emails, logins, or system behaviour. Run phishing simulations regularly so that clicking a test link is treated as a learning moment. Publicly recognise staff who report early. If someone is blamed for clicking a test phishing link, others will stop reporting, and you lose your earliest warning system.

When should we bring in outside help after a breach?

As early as possible, ideally before one happens. Having an incident response provider, legal counsel, and your cyber insurer already briefed means you are not making those calls under pressure. Once a breach is active, bring them in immediately. Do not wait until the scope is fully understood. Early involvement improves outcomes on every measure: speed, cost, and regulatory standing.

How does the Australian Cyber Incident Review Board affect our business?

For most SMEs, it will not directly apply. The board reviews significant incidents affecting government and large organisations. But the principle it embeds, learn from incidents without assigning blame, is exactly the approach that makes businesses more resilient. If a major incident affecting your industry is reviewed, the board’s public recommendations may also shape regulatory expectations for your sector.

Where do we get started?

An objective review of your current setup is the best first step. We work with businesses across Brisbane and South-East Queensland to assess their security posture, close gaps, and build practical plans they can actually execute. Get in touch and we will help you move forward with confidence.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.