
Cybersecurity Expertise Contributes to Landmark AUD5.8 Million Privacy Breach Ruling

Laying the groundwork for the court to determine what reasonable practices were not implemented.
In 2022, ASX-listed healthcare organisation Australian Clinical Labs (‘ACL’) experienced a major data breach, resulting in the personal information of more than 223,000 individuals being exposed on the dark web.
The Office of the Australian Information Commissioner (‘OAIC’) commenced an investigation into the breached organisation to determine whether it had taken reasonable steps to protect the personal information entrusted to it, as is required by the Australian Privacy Act of 1988. In November 2023, The OAIC subsequently commenced Federal Court proceedings against the breached organisation and appointed FTI Consulting as a cybersecurity expert to support the regulator and its counsel, DLA Piper, in building a case against ACL.
Our Impact
In October 2025, the Federal Court found the organisation breached the Privacy Act after our cybersecurity analysis revealed failures in governance, risk management and incident response. The findings strengthened the OAIC’s case, resulting in AUD5.8 million in penalties against ACL.



Slide for Close-up of computer keyboard keys with glowing blue and orange digital icons, including padlocks and code symbols, on a dark purple background.
The Federal Court’s decision was informed by FTI Consulting’s complex, evidence-based cybersecurity expert report that uncovered governance, incident response and due diligence deficiencies that contributed to the breach.

Slide for Close-up of a transparent blue capsule containing a digital DNA helix floating over a blue circuit board background, symbolizing biotechnology and digital health.
Complex technical findings related to ACL’s cyber maturity, governance and operational practices were assessed to determine if reasonable steps were taken that were expected under the circumstances.

Slide for Digital illustration of a blue glowing, wireframe judge's gavel striking a block on a dark blue background, symbolizing law and justice.
This was the first civil penalty case in the history of the Australian Privacy Act, and the multimillion-dollar ruling sent a clear message about the consequences of failing to meet regulatory and privacy obligations in Australia.
In crisis and transformation,real-world experience delivers.
Assessing the reasonableness of the cybersecurity measures applied under the circumstances
FTI Consulting collaborated with the OAIC and DLA Piper to assess whether ACL had taken reasonable steps to protect personal information, ensure compliance with privacy obligations and meet data breach notification requirements.
Our experts conducted extensive document review and provided independent analysis of the breach and of the cybersecurity governance, incident response and due diligence practices.
The team assessed the extent to which ACL had taken reasonable steps to protect the organisation, as well as the adequacy of the incident response process performed by the organisation and its third-party cybersecurity managed services provider.
FTI Consulting developed a comprehensive report of ACL’s cybersecurity controls, including a breakdown of where it fell short of what could be reasonably expected considering the circumstances, which was shared with senior Australian public servants and policymakers.
Our experts assisted with the litigation process by providing input and feedback to key documents, such as the Concise Statement and Statement of Agreed Facts, and advised the OAIC and DLA Piper on how best to brief independent experts.
Discover Your Team
Real-world experience that delivers.
See why FTI Consulting is the leading global expert firm for organizations facing crisis and transformation.

Deep Expertise in Action
See how our expert-driven, industry-focused approach produces real results in an increasingly complex world.




