IDCARE, the national identity support service, has expressed concerns that the increased penalties for privacy breaches by the Australian government could lead to more companies paying ransoms to keep the breaches secret.
In its submission to the government’s review of the Privacy Act, IDCARE criticized the breach frameworks, saying that they are more focused on reporting to regulators and protecting interests than informing and supporting vulnerable people. This leaves Australian businesses vulnerable to ongoing ransom attacks, the organization said.
IDCARE also noted that the fear of penalties up to $50 million or one-third of the turnover for an affected company could lead to worse outcomes. Companies may choose to pay ransoms, and this would encourage further attacks, it said.
Although making the payment of ransoms a specific offence could discourage companies from paying, IDCARE warned of the complexities involved, such as unnamed insurance companies that may encourage ransom payments. IDCARE also criticized the proposed amendments to the Privacy Act, saying that they could make privacy compliance more litigious.

