You're in Privacy Act scope. You're in Cyber Security Act scope. And the ACNC Commissioner has called you out by name.
As a large Australian charity, you sit directly inside the Privacy Act, the Cyber Security Act's mandatory ransomware reporting regime, and the full weight of ACNC Governance Standards. Commissioner Sue Woodward has publicly urged charity directors to prioritise cybersecurity. Pareto Phone affected many of your peers. The ICRC's 515,000-person compromise is the international benchmark for beneficiary-data risk. The defensive evidence your Board relies on has to hold up.
Your specific challenges
Sensitive beneficiary data makes consequences severe
Health, detention, family separation, domestic violence, refugee, and minors-in-care data creates immediate safety risk on exposure — not just reputational harm. The ICRC's Restoring Family Links programme was suspended during an active humanitarian emergency.
GS5 makes cyber oversight a director duty
Under ACNC Governance Standard 5, the duty of reasonable care and diligence is not diminished by a lack of cyber expertise. Directors are expected to seek expert advice — but remain ultimately responsible for the decisions made and the steps taken.
Mission investment and security investment compete for dollars
Every dollar on cyber is a dollar not on mission. That trade-off is real and legitimate — which is why the approach has to be evidence-based, cost-efficient, and prioritised.
Built for your situation
GS5 evidence for the Board
Findings structured against ACNC Governance Standard 5 — concrete evidence that responsible persons have acted with reasonable care and diligence. Reports designed to be read by non-technical directors.
APP 11 "active steps" validation
Moves APP 11 from documented policy to demonstrated control effectiveness. Cloud Pentesting for data-at-rest, External Pentesting for data-in-transit, and Segmentation Testing for access boundaries.
Beneficiary-data reach assessment
Segmentation and internal testing reveal what data is actually accessible from a compromised user or vendor — directly addressing the ICRC-class scenario where beneficiary data concentration amplifies every control gap.
Give your Board the evidence GS5 expects
Book a baseline mapped to ACNC Governance Standards, APP 11, and the ASD Charities Cyber Security Guide