[{"data":1,"prerenderedAt":3776},["ShallowReactive",2],{"navigation":3,"socials":68,"post-\u002Fnext-js-framework":83,"post-related":1512},{"id":4,"extension":5,"footer":6,"header":56,"meta":65,"stem":66,"__hash__":67},"navigation\u002Fnavigation.yml","yml",[7,26,38],{"label":8,"items":9,"path":25},"Web development",[10,13,16,19,22],{"label":11,"path":12},"Vue web development","\u002Fvue-js-development-services",{"label":14,"path":15},"React development services","\u002Freact-js-development-services",{"label":17,"path":18},"Laravel development services","\u002Flaravel-development-services",{"label":20,"path":21},"Shopify developers Melbourne","\u002Fshopify",{"label":23,"path":24},"Next.js developers Melbourne","\u002Fnext-js-framework","",{"label":27,"items":28,"path":25},"Cyber security",[29,32,35],{"label":30,"path":31},"Cyber security for small business","\u002Fcyber-security\u002Fsmall-business",{"label":33,"path":34},"Lessons from famous breaches","\u002Fcyber-security\u002Fbreach-lessons",{"label":36,"path":37},"Free cyber health check","\u002Fcyber-security\u002Fsmall-business\u002Fdiy-cyber-security-health-check",{"label":39,"items":40},"Navigate",[41,44,47,50,53],{"label":42,"path":43},"Home","\u002F",{"label":45,"path":46},"Case Studies","\u002Fcase-studies",{"label":48,"path":49},"Cyber Security","\u002Fcyber-security",{"label":51,"path":52},"Contact Us","\u002Fcontact",{"label":54,"path":55},"Editorial Policy","\u002Feditorial-policy",[57,60,61,62],{"label":58,"path":59},"Web Development","\u002Fweb-development",{"label":45,"path":46},{"label":48,"path":49},{"label":63,"path":64},"About","\u002Fabout",{},"navigation","vaEm85Hrq3ctMNbTgmkywbdLEBklhE1-5zsuR9ZI5Oo",{"id":69,"extension":5,"items":70,"meta":80,"stem":81,"__hash__":82},"socials\u002Fsocials.yml",[71,74,77],{"type":72,"link":73},"facebook","https:\u002F\u002Fwww.facebook.com\u002Fitclub.com.au",{"type":75,"link":76},"linkedin","https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fitclub\u002Fabout\u002F",{"type":78,"link":79},"behance","https:\u002F\u002Fwww.behance.net\u002Felenaitclub\u002F",{},"socials","R3zh7G2Yeky6IFraIEG2izmfHXa3EG7r0rHl4YbjpWk",{"id":84,"title":85,"authorBio":86,"body":87,"coverImage":1484,"date":1485,"description":1486,"extension":1487,"faq":1488,"heroImage":86,"lastReviewed":86,"meta":1500,"metadata":1501,"navigation":223,"path":24,"readingTime":86,"reviewedAgainst":86,"seo":1502,"sitemap":1503,"stem":1504,"summary":1505,"tags":1506,"thumbnail":1484,"__hash__":1511},"blog\u002Fweb-development\u002Fnext-js-framework.md","Next.js Framework For Full-stack and Frontend Development",null,{"type":88,"value":89,"toc":1457},"minimark",[90,94,97,180,185,196,202,214,224,229,232,239,259,266,281,292,299,307,316,327,344,347,353,373,386,395,403,410,412,415,421,428,437,443,458,467,478,489,499,523,526,530,543,545,555,557,559,562,570,582,590,597,599,602,609,618,631,637,639,642,648,663,666,669,682,689,700,706,709,721,727,729,740,746,752,754,761,764,767,773,775,792,794,797,803,816,819,822,827,833,844,847,850,858,861,876,887,890,899,914,917,923,925,928,931,965,972,1001,1006,1010,1013,1019,1021,1024,1032,1035,1041,1043,1046,1051,1054,1057,1063,1065,1069,1072,1093,1098,1164,1166,1170,1236,1238,1241,1252,1254,1256,1260,1269,1271,1275,1282,1347,1349,1353,1356,1361,1368,1370,1374,1377,1381,1383,1389,1391,1398,1425,1428,1434,1436,1445,1447,1453,1455],[91,92,93],"p",{},"This article will explain what Next.js is, why you should consider Next.js for your tech stack, and how you can use Next js features to build fast and performant web experiences.",[91,95,96],{},"Feel free to navigate to any item in the table of content by hitting their respective links below:",[98,99,100,108,114,120,126,132,138,144,150,156,162,168,174],"ul",{},[101,102,103],"li",{},[104,105,107],"a",{"href":106},"#what-is-nextjs","What is Next.js?",[101,109,110],{},[104,111,113],{"href":112},"#nextjs-vs-react-create-react-app","Next.js vs React (Create React App)",[101,115,116],{},[104,117,119],{"href":118},"#nextjs-vs-gatsby","Next.js vs Gatsby",[101,121,122],{},[104,123,125],{"href":124},"#server-side-rendering-vs-client-side-rendering","Server-side rendering vs Client-side rendering",[101,127,128],{},[104,129,131],{"href":130},"#nextjs-and-seo","Next.js and SEO",[101,133,134],{},[104,135,137],{"href":136},"#next-js-performance","Next js performance",[101,139,140],{},[104,141,143],{"href":142},"#hosting-your-nextjs-project","Hosting your Next.js project",[101,145,146],{},[104,147,149],{"href":148},"#is-nextjs-good","Is Next.js good?",[101,151,152],{},[104,153,155],{"href":154},"#what-is-next-js-used-for","What is Next js used for?",[101,157,158],{},[104,159,161],{"href":160},"#why-is-next-js-used","Why is Next js used?",[101,163,164],{},[104,165,167],{"href":166},"#when-to-use-next-js","When to use Next js?",[101,169,170],{},[104,171,173],{"href":172},"#how-does-next-js-ssr-work","How does Next js SSR work?",[101,175,176],{},[104,177,179],{"href":178},"#is-ssr-good-for-web-application-performance","Is SSR good for web application performance?",[181,182,184],"h2",{"id":183},"what-is-nextjs","What is Next.js",[91,186,187,191,192,195],{},[188,189,190],"strong",{},"Next.js"," is a ",[188,193,194],{},"React framework"," created by Vercel. It has just the right level of abstraction and performance optimisation capabilities provided by default, to ensure excellent performance of a web application right from the start.",[197,198,199],"blockquote",{},[91,200,201],{},"Next.js is a lightweight React framework for static and server-rendered React applications.",[91,203,204,206,207,213],{},[188,205,190],{}," runs in both the browser and the server, and since it uses React for UI templating, it offers ",[104,208,212],{"href":209,"rel":210},"https:\u002F\u002Fitclub.com.au\u002Freact-js-development-services",[211],"nofollow","React developers"," an easy and straightforward way to get started with development and get productive fast, providing them with a great Developer Experience.",[215,216],"iframe",{"src":217,"width":218,"height":219,"frameBorder":220,"className":221,"allowFullScreen":223},"https:\u002F\u002Fgiphy.com\u002Fembed\u002FL8K62iTDkzGX6","auto",307,"0",[222],"giphy-embed",true,[225,226,228],"h3",{"id":227},"why-next-js","Why Next js",[91,230,231],{},"One of the reasons why Next.js has become so popular is that it has the benefits of React, which makes it even easier to get a web app up and running.",[91,233,234,235,238],{},"Next.js provides ",[104,236,212],{"href":209,"rel":237},[211]," with a solution for:",[98,240,241,247,253],{},[101,242,243,246],{},[188,244,245],{},"Code bundling"," (e.g. Webpack) and compiling (e.g. Babel), which come out of the box;",[101,248,249,252],{},[188,250,251],{},"Automatic code splitting"," for faster page loads and production optimisations;",[101,254,255,258],{},[188,256,257],{},"Pre-rendering"," for both static site generation (SSG) and server-side rendering (SSR) on a per-page basis for SEO and performance.",[91,260,261,262,265],{},"Another one of Next.js’ strong points is that it handles ",[104,263,264],{"href":124},"server-side rendering"," perfectly providing great performance and consequently positively impacting user experience of a web application.",[91,267,268,269,272,273,276,277,280],{},"Note that the ",[188,270,271],{},"important factors for SEO"," results are ",[188,274,275],{},"great performances"," and ",[188,278,279],{},"user experience"," (UX).",[91,282,283,288,289],{},[284,285],"img",{"alt":286,"src":287,"title":286},"Next.js apps have great performance that is important for SEO","\u002Fuploads\u002FNext_js_performance_Google.jpg"," ",[290,291],"br",{},[91,293,294,295,298],{},"Moreover, ",[104,296,212],{"href":209,"rel":297},[211]," don’t need to worry about:",[98,300,301,304],{},[101,302,303],{},"Server-side rendering and\u002For client-side rendering;",[101,305,306],{},"Writing some server-side code to connect a React app to its data store.",[197,308,309],{},[91,310,311,312,315],{},"Next.js helps web developers create ",[188,313,314],{},"SEO-friendly React SPAs"," (Single-page applications).",[91,317,318,319,322,323,326],{},"There are several other ",[188,320,321],{},"technical considerations"," you need to keep in mind, and which have ",[188,324,325],{},"a huge impact on SEO",", such as:",[98,328,329,332,335,338,341],{},[101,330,331],{},"Website speed",[101,333,334],{},"Responsive design and a must-have mobile optimisation",[101,336,337],{},"Structured metadata \u002F Rich results based on Schems.org",[101,339,340],{},"HTTPS certification for security",[101,342,343],{},"Sitemap.",[91,345,346],{},"You can now see that Next.js can cover most of them.",[91,348,349,352],{},[188,350,351],{},"Additional Next.js features"," include:",[98,354,355,358,361,364,367,370],{},[101,356,357],{},"An intuitive page-based routing system, with support for dynamic routes",[101,359,360],{},"Client-side routing with optimised prefetching",[101,362,363],{},"Built-in CSS and Sass support, and support for any CSS-in-JS library",[101,365,366],{},"Development environment with Fast Refresh support",[101,368,369],{},"API routes to build API endpoints with Serverless Functions",[101,371,372],{},"Fully extendable.",[197,374,375],{},[91,376,377,378,380,381],{},"With Next.js, server rendering React applications has never been easier, no matter where your data is coming from. ",[290,379],{}," > ",[104,382,385],{"href":383,"rel":384},"https:\u002F\u002Ftwitter.com\u002Fvercel",[211],"@vercel",[91,387,388,390,391,394],{},[188,389,190],{}," has become ",[188,392,393],{},"one of the most popular developer tools"," and its popularity is still growing, as you can see from the Google Trends results over the last five years.",[91,396,397,288,401],{},[284,398],{"alt":399,"src":400,"title":399},"Next.js vs React Google Trends results over the last five years","\u002Fuploads\u002FReact_Nextjs_Google_trends_comparison.jpg",[290,402],{},[91,404,405,406,409],{},"Considering the consistent adoption of React over the last years, this is not surprising at all. Most innovative companies like Netflix, Uber, GitHub and ",[104,407,408],{"href":154},"others",", have started using Next.js for their web apps.",[290,411],{},[181,413,113],{"id":414},"nextjs-vs-react-create-react-app",[91,416,417,420],{},[188,418,419],{},"React"," is a JavaScript library that uses a component-based approach which makes it easier to build user interfaces. As React is a UI library, many React developers use additional tools to have a complete build toolchain, like a module bundler (e.g. Webpack) and a transpiler (i.e. Babel).",[91,422,423,424,427],{},"In React, frontend developers now use the ",[188,425,426],{},"Create React App"," tool.",[197,429,430],{},[91,431,432,436],{},[104,433,426],{"href":434,"rel":435},"https:\u002F\u002Fcreate-react-app.dev\u002Fdocs\u002Fgetting-started\u002F",[211]," is an officially supported way to create single-page React applications.",[91,438,439,440,442],{},"Since ",[188,441,426],{}," has a few default optimisations baked into it, it provides a simple and straightforward setup and a complete build toolchain with a single command, and it takes the hassle out of setting up a React application quickly. React developers have a choice whether to eject or modify the configurations themselves.",[91,444,445,449,450,453,454,457],{},[104,446,448],{"href":209,"rel":447},[211],"Building a React application"," is great until you realise that there are ",[188,451,452],{},"a couple of problems"," with rendering your content ",[188,455,456],{},"on the client-side"," (browser):",[459,460,461,464],"ol",{},[101,462,463],{},"It takes longer for a web page to become visible to the user, because all the JavaScript must load first before the content loads.",[101,465,466],{},"As React applications are SPAs, there is an SEO issue for your content. While search engines are able to run and index JavaScript apps, it would be more efficient to send them content instead of letting them figure it out themselves.",[91,468,469,470,473,474,477],{},"Luckily, there is a ",[188,471,472],{},"solution"," to both of these problems, which is ",[188,475,476],{},"server rendering"," (aka static pre-rendering).",[197,479,480],{},[91,481,482,484,485,488],{},[188,483,426],{}," does not allow you to generate a server-side-rendered application easily, so everything that comes with this, like SEO, performance, etc. can be provided by Next.js and ",[104,486,487],{"href":118},"Gatsby",".",[91,490,491,492,494,495,498],{},"While ",[188,493,190],{}," can also be used for creating React apps, it ",[188,496,497],{},"utilises a different and simple approach"," by instantly providing a number of common optimisations that many React developers would like to have but could find difficult to set up. These include:",[98,500,501,504,507,514,517,520],{},[101,502,503],{},"Automatic code-splitting",[101,505,506],{},"Built-in CSS and Sass support",[101,508,509,510],{},"CSS-in-JS styling ",[511,512,513],"code",{},"\u003Cstyled-jsx>",[101,515,516],{},"File-system routing",[101,518,519],{},"Route prefetching",[101,521,522],{},"Server-side rendering.",[91,524,525],{},"Thus, Next.js provides a common structure, allowing to easily build a frontend React application, and transparently handling server-side rendering for you.",[225,527,529],{"id":528},"what-is-the-difference-between-react-and-nextjs","What is the difference between React and Next.js",[91,531,532,533,535,536,538,539,542],{},"While Next.js is a way to leverage React to support ",[188,534,264],{}," (SSR), the ",[188,537,426],{}," tool is a way to leverage React to support ",[188,540,541],{},"client-side rendering"," (CSR).",[290,544],{},[546,547,554],"card",{"link":548,"title":549,"description":550,"logo":551,"site-name":552,"cover-image":553},"https:\u002F\u002Fitclub.com.au\u002Freact-js-development-services\u002F","React Development Services in Melbourne","Learn more about how our experienced React.js developers help startups, SMEs and top Australian companies develop their React projects.\u003Cbr>\u003Cbr>Click here to read about the React development services we offer.","\u002Fuploads\u002Fit-club-logo.svg","Need a web app? Hire us.","\u002Fuploads\u002Freact-js-development-at-itclub.com.au-facebook.png","\n \n",[290,556],{},[290,558],{},[181,560,119],{"id":561},"nextjs-vs-gatsby",[91,563,564,565,276,567,569],{},"Both ",[188,566,190],{},[188,568,487],{}," can help with server-side rendering, but in completely different ways.",[91,571,572,573,191,575,578,579,488],{},"Basically, ",[188,574,487],{},[188,576,577],{},"static site generator"," that allows you to build a static-generated website without using a server. Then, you deploy the result of the build process statically on Netlify, Vercel or any other ",[104,580,581],{"href":142},"static hosting site",[91,583,584,586,587,488],{},[188,585,190],{}," can generate a static site, too. However, this is not its main use. Next.js provides a backend that can server-side render a response to a request, and it allows you to create a dynamic website which can be deployed on a platform that runs on Node.js, such as ",[104,588,589],{"href":142},"Vercel",[91,591,592,593,596],{},"Thus, if you are thinking about building ",[188,594,595],{},"a static website",", you may consider Gatsby that is based on GraphQL. Gatsby has an awesome ecosystem of plugins that would work great for a blogging website, for example.",[290,598],{},[181,600,125],{"id":601},"server-side-rendering-vs-client-side-rendering",[91,603,604,605,608],{},"In short, ",[188,606,607],{},"server-side rendering (SSR)"," is when the rendering process is offloaded to the backend. Then, the fully-rendered HTML views are returned to the client, simplifying the logic on the frontend. Thus, this approach works great for time-sensitive apps.",[91,610,611,612,617],{},"In their ",[104,613,616],{"href":614,"rel":615},"https:\u002F\u002Fmedium.com\u002Fwalmartglobaltech\u002Fthe-benefits-of-server-side-rendering-over-client-side-rendering-5d07ff2cefe8",[211],"article"," “The benefits of server-side rendering over client-side rendering”, WalmartLabs explains that there are two reasons why they use server-side rendering:",[98,619,620,626],{},[101,621,622,625],{},[188,623,624],{},"Performance benefit"," for their customers;",[101,627,628,488],{},[188,629,630],{},"Consistent SEO performance",[91,632,633],{},[284,634],{"alt":635,"src":636,"title":635},"Server-side rendering vs client-side rendering WalmartLabs","\u002Fuploads\u002FSSR_vs_CSR.jpg",[290,638],{},[91,640,641],{},"Based on these diagrams, you can see that SSR can deliver HTML to the client (browser) faster compared to CSR.",[91,643,644,647],{},[188,645,646],{},"The main difference"," here is that:",[98,649,650,657],{},[101,651,652,653,656],{},"for ",[188,654,655],{},"SSR",", your server’s response to the browser is the HTML of your page that is ready to be rendered;",[101,658,652,659,662],{},[188,660,661],{},"CSR",", the browser gets an empty document with links to your JavaScript.",[91,664,665],{},"This means that for SSR, your browser starts rendering the HTML from your server without waiting for all the JavaScript to be downloaded and executed.",[91,667,668],{},"In both cases, React has to be downloaded and has to go through the same process of building a virtual DOM and attaching events to make the page interactive:",[98,670,671,677],{},[101,672,673,674,676],{},"For ",[188,675,655],{},", your web app user can start viewing the page while all of that is happening.",[101,678,673,679,681],{},[188,680,661],{},", your website user has to wait while all of the above happens, and while the virtual DOM moves to the browser DOM so the page becomes interactive.",[91,683,684,685,688],{},"However, there are ",[188,686,687],{},"a few warnings\u002Fconsiderations"," for you to keep in mind:",[98,690,691,694,697],{},[101,692,693],{},"While with SSR the page is rendered earlier and the web app user can see the page sooner, they can’t start interacting with the page (e.g. click a button) until React is done executing.",[101,695,696],{},"SSR Time To First Byte (TTFB) is slower than CSR because a server has to spend time creating the HTML for a page instead of just sending out a relatively empty response;",[101,698,699],{},"SSR throughput of a server is significantly lower than CSR throughput. For React, the throughput impact is extremely large. 'ReactDOMServer.renderToString' is a synchronous CPU bound call that holds the event loop, meaning the server cannot process any other requests until 'ReactDOMServer.renderToString' completes. For example, when you use a dedicated server with limited resources (e.g. CPU and\u002For RAM), it takes about 500ms to server-side render your page, meaning that your server can process at most 2 requests per second. However, when you go serverless (AWS Lambda or Google Cloud Functions) this issue would not occur as you have unlimited resources and pay only when using them.",[91,701,702,703,488],{},"Moreover, considering the fact that more and more people access websites using their mobile devices (see the chart below), this makes ",[188,704,705],{},"high performance critical for any web app",[91,707,708],{},"However, it is important to consider the limitations of both network and CPU, as mobile devices generally have less processing power. This means that heavy JavaScript file parsing and expensive rendering can adversely impact your web app’s performance.",[91,710,711,712,717,718,488],{},"According to ",[104,713,716],{"href":714,"rel":715},"https:\u002F\u002Fwww.statista.com\u002Fstatistics\u002F277125\u002Fshare-of-website-traffic-coming-from-mobile-devices",[211],"Statista",", in Q2 2020, ",[188,719,720],{},"more than 51.5% of website traffic worldwide came from mobile devices",[91,722,723],{},[284,724],{"alt":725,"src":726,"title":725},"Percentage of mobile device website traffic worldwide from 1st quarter 2015 to 2nd quarter 2020","\u002Fuploads\u002FStatista_mobile_websites_traffic.jpg",[290,728],{},[91,730,731,732,735,736,739],{},"Thankfully, the ",[188,733,734],{},"Chrome"," browser provides a ",[188,737,738],{},"developer tool"," that makes it easy for web developers to identify and fix common problems that affect a website's performance and user experience.",[91,741,742,743,488],{},"You can find this tool in Chrome under the ",[188,744,745],{},"View tab > Developer > Developer Tools > Lighthouse",[91,747,748],{},[284,749],{"alt":750,"src":751,"title":750},"Lighthouse, the Chrome developer tool","\u002Fuploads\u002FDeveloper_Tools_Lighthouse.jpg",[290,753],{},[91,755,756,757,760],{},"In addition, web developers need to take into account ",[188,758,759],{},"geography"," as well.",[91,762,763],{},"For example, if your users live in Sydney and your application is on servers in the Sydney region, their experience with your web app will be completely different to those users in other parts of the world, e.g. in Boulder, USA (the distance between Boulder and Sydney is 13,386 km).",[91,765,766],{},"Now, let’s look at what happens with data fetching between SSR and CSR applications.",[91,768,769],{},[284,770],{"alt":771,"src":772,"title":771},"Data fetching between SSR and CSR applications diagram","\u002Fuploads\u002FData_fetching_SSR_CSR.jpg",[290,774],{},[91,776,777,778,781,782,785,786,791],{},"You can now see that with SSR, the browser can display all the HTML faster and with less effort, compared to CSR. Indeed, the results have shown that the First Meaningful Paint for the ",[188,779,780],{},"CSR with 'Create React App’ is 6.5s"," and for an ",[188,783,784],{},"SSR using Next.js is 0.8s",". If you are interested in a more detailed comparison of the SSR and CSR applications performances, take a look at ",[104,787,790],{"href":788,"rel":789},"https:\u002F\u002Fblog.logrocket.com\u002Fnext-js-vs-create-react-app\u002F",[211],"this article"," by LogRocket.",[290,793],{},[181,795,131],{"id":796},"nextjs-and-seo",[91,798,799,800,802],{},"While great performance and user experience (UX) are important for SEO results, here are some additional technical considerations that have ",[188,801,325],{},":",[98,804,805,807,809,812,814],{},[101,806,331],{},[101,808,334],{},[101,810,811],{},"Structured metadata \u002F Rich results based on Schema.org",[101,813,340],{},[101,815,343],{},[91,817,818],{},"As we mentioned before, Next.js, with its server-side rendering, helps web developers create SEO-friendly React SPAs and ensure great performance of your web application.",[91,820,821],{},"As such, a great user experience can be viewed as:",[91,823,824],{},[188,825,826],{},"Great UX = More time users spend on-page & Lower bounce rate = Better Google rankings",[91,828,829,830,326],{},"With Next.js, you can easily cover some of the ",[188,831,832],{},"important SEO considerations",[459,834,835,838,841],{},[101,836,837],{},"Making your website crawlable",[101,839,840],{},"Creating a sitemap",[101,842,843],{},"Adding metadata",[225,845,837],{"id":846},"making-your-website-crawlable",[91,848,849],{},"To make your content crawlable for search engines, Next.js provides you with two options:",[98,851,852,855],{},[101,853,854],{},"prerendering or",[101,856,857],{},"server-side rendering.",[225,859,840],{"id":860},"creating-a-sitemap",[91,862,863,864,867,868,871,872,875],{},"Keep in mind the importance of a sitemap for SEO, as it helps search engines properly index your website. For this purpose, there are a few packages to automate this task. For example, ",[511,865,866],{},"nextjs-sitemap-generate"," that generates a ",[511,869,870],{},"sitemap.xml"," file inside the ",[511,873,874],{},"out"," directory.",[197,877,878],{},[91,879,880,881,886],{},"Don't forget to manually submit your sitemap URL to the ",[104,882,885],{"href":883,"rel":884},"https:\u002F\u002Fsearch.google.com\u002Fsearch-console\u002Fabout",[211],"Google Search Console"," to get recognised by Google crawlers.",[225,888,843],{"id":889},"adding-metadata",[91,891,892,893,276,896,488],{},"Basically, metadata helps crawlers understand the content of your pages, so it's important to have meta tags. Next.js adds most of the metadata attributes automatically, including the ",[188,894,895],{},"viewport",[188,897,898],{},"content type",[91,900,901,902,905,906,909,910,913],{},"However, you would need to define the ",[188,903,904],{},"meta description"," tag by editing the ",[511,907,908],{},"\u003Chead>"," component in your ",[511,911,912],{},"index.js"," file.",[91,915,916],{},"When you complete all these SEO steps, Google Lighthouse will reward you with a great score:",[91,918,919],{},[284,920],{"alt":921,"src":922,"title":921},"Lighthouse. SEO performance results for a Next.js app","\u002Fuploads\u002Fnext-js-seo-results.jpg",[290,924],{},[181,926,137],{"id":927},"next-js-performance",[91,929,930],{},"Next js apps show high performance due to the uniqueness of Next.js' approach and its Incremental Static Regeneration. This feature is available since the release of Next.js 9.5 and here are its main functions:",[98,932,933,944,950,959],{},[101,934,935,936,939,940,943],{},"The ",[188,937,938],{},"Get Static Props"," function allows data fetching at build time. Next.js statically pre-renders the page at build time using the props returned by ",[511,941,942],{},"getStaticProps",", which fetches the data during static generation.",[101,945,935,946,949],{},[188,947,948],{},"Get Static Paths"," function specifies all the paths (dynamic routes) that Next.js statically pre-renders for a page with dynamic routes.",[101,951,935,952,955,956,488],{},[188,953,954],{},"Get Server-Side Props"," async function allows you to fetch data on each request. Next.js will pre-render the page on each request using the data returned by ",[511,957,958],{},"getServerSideProps",[101,960,961,964],{},[188,962,963],{},"Revalidate"," is an optional amount in seconds after which a page regeneration can occur. This background regeneration function ensures traffic is served without interruption.",[91,966,967,968,971],{},"Here is how Next js ",[188,969,970],{},"Incremental Static Regeneration"," works:",[98,973,974,981,984,995,998],{},[101,975,976,977,980],{},"Each Next js page can define the timeout - ",[511,978,979],{},"revalidate"," (e.g. 1 second).",[101,982,983],{},"When a new request comes in, the statically generated page is served.",[101,985,986,987],{},"Then, when after the defined timeout is exceeded, another request comes in:\n",[98,988,989,992],{},[101,990,991],{},"The statically generated page is served, and",[101,993,994],{},"Next js generates a new version of the page in the background and updates the static page for upcoming requests.",[101,996,997],{},"Then, after the regeneration is done and another request comes in, the updated static page is served.",[101,999,1000],{},"This allows the Incremental Static Regeneration to be performed on a per-page basis without rebuilding the full application.",[197,1002,1003],{},[91,1004,1005],{},"Note that this process will always be fast because users will always get a static response.",[225,1007,1009],{"id":1008},"how-does-next-js-work","How does Next js work",[91,1011,1012],{},"Here is a simplified version of how Next js works, where you can see the time required for SSR, static, and API requests to deliver to the client (browser).",[91,1014,1015],{},[284,1016],{"alt":1017,"src":1018,"title":1017},"How Next js works. Next.js runtime diagram","\u002Fuploads\u002FNextjs_Runtime_diagram.jpg",[290,1020],{},[181,1022,143],{"id":1023},"hosting-your-nextjs-project",[91,1025,1026,1027,1031],{},"At this stage, you have probably started thinking about the hosting for your web app. Thankfully, you can do this seamlessly with ",[104,1028,589],{"href":1029,"rel":1030},"https:\u002F\u002Fvercel.com\u002Fsolutions\u002Fnextjs",[211],", the Jamstack deployment platform, which was built by the same team that created Next.js.",[91,1033,1034],{},"Vercel allows production-grade hosting for Next.js websites with zero configuration. It also provides full control of response caching, so your APIs and website are delivered extremely fast.",[91,1036,1037],{},[284,1038],{"alt":1039,"src":1040,"title":1039},"Simplified Next.js deploy and build processes on Vercel","\u002Fuploads\u002FNext_js_Vercel.jpg",[290,1042],{},[91,1044,1045],{},"In addition, Vercel provides security for all deployments automatically and hosts all web apps under HTTPS, auto-renewing SSL certificates.",[197,1047,1048],{},[91,1049,1050],{},"Note that HTTPS is a must-have in today's SEO practices.",[91,1052,1053],{},"With Vercel and Next.js, you can seamlessly integrate any headless CMS, e.g. Contentful CMS, ButterCMS, Storyblok, or any other.",[91,1055,1056],{},"Thus, Vercel has become the easiest way to deploy a production-ready Next.js website, where everything works automatically - with static assets being served through the CDN, built-in support for Next.js’ static optimisation and API routes.",[91,1058,1059],{},[284,1060],{"alt":1061,"src":1062,"title":1061},"Next.js app performance","\u002Fuploads\u002Fnext_js_app_performance.jpg",[290,1064],{},[181,1066,1068],{"id":1067},"is-nextjs-good","Is Next.js good",[91,1070,1071],{},"Yes, Next.js is good due to these main Next.js features, which include:",[98,1073,1074,1084],{},[101,1075,1076,1079,1080,1083],{},[188,1077,1078],{},"Automatic Routing",": Any URL is mapped to the files put in the ",[511,1081,1082],{},"pages"," folder, so you don't need to do any configuration. However, there are customisation options.",[101,1085,1086,1089,1090,1092],{},[188,1087,1088],{},"Automatic Code Splitting",": Instead of generating one single JavaScript file that contains all the application code, Next.js splits the code into several different resources automatically.",[290,1091],{},"This benefits the overall performance because during the page loading, Next.js analyses the imported resources and includes in its bundle only the necessary JavaScript and other libraries, specific for that particular page. This ensures the first page load is as fast as it can possibly be.",[197,1094,1095],{},[91,1096,1097],{},"However, you need to remember that if there are frequently used imports for at least half of the web pages, Next.js combines those frequently used imports into the main JavaScript bundle.",[98,1099,1100,1106,1112,1118,1132,1142,1148,1158],{},[101,1101,1102,1105],{},[188,1103,1104],{},"Dynamic Components"," allow you to import JavaScript modules and React Components dynamically.",[101,1107,1108,1111],{},[188,1109,1110],{},"Ecosystem Compatibility",": Next.js is compatible well with Node, React, and other JavaScript frameworks and the language itself.",[101,1113,1114,1117],{},[188,1115,1116],{},"Hot Code Reloading",": Next.js reloads the page when it detects any changes saved to the disk.",[101,1119,1120,1123,1124,1127,1128,1131],{},[188,1121,1122],{},"Prefetching",": In Next.js, different pages are linked together by the ",[511,1125,1126],{},"Link"," component. It supports a ",[511,1129,1130],{},"prefetch"," prop that prefetches page resources in the background automatically, including any code missing due to the automatic code splitting feature.",[101,1133,1134,1137,1138,1141],{},[188,1135,1136],{},"Single File Components",": Using integrated ",[511,1139,1140],{},"styled-jsx",", it's easy to add any styles to components.",[101,1143,1144,1147],{},[188,1145,1146],{},"Server Rendering",": React components are rendered on the server side, before sending the HTML to the client.",[101,1149,1150,1153,1154,1157],{},[188,1151,1152],{},"Static Exports",": Next.js allows you to export a fully static site from your app by using the ",[511,1155,1156],{},"next export"," command.",[101,1159,1160,1163],{},[188,1161,1162],{},"TypeScript Support"," as Next.js is written in TypeScript.",[290,1165],{},[181,1167,1169],{"id":1168},"what-is-next-js-used-for","What is Next js used for",[91,1171,1172,1173,1178,1179,1184,1185,1184,1190,1184,1195,1184,1200,1184,1205,1184,1210,1184,1215,1184,1220,1184,1225,1184,1230,1235],{},"Next js is used for the production of SEO-friendly websites and web applications. Some of the world's largest brands have ",[104,1174,1177],{"href":1175,"rel":1176},"https:\u002F\u002Fnextjs.org\u002Fshowcase",[211],"moved"," to Next.js and Vercel, such as ",[104,1180,1183],{"href":1181,"rel":1182},"https:\u002F\u002Fwww.nike.com\u002F",[211],"Nike",", ",[104,1186,1189],{"href":1187,"rel":1188},"https:\u002F\u002Fwww.hulu.com\u002Fwelcome",[211],"Hulu",[104,1191,1194],{"href":1192,"rel":1193},"https:\u002F\u002Fwww.marvel.com\u002F",[211],"Marvel",[104,1196,1199],{"href":1197,"rel":1198},"https:\u002F\u002Fwww.lego.com\u002Fen-us\u002Fkids",[211],"Lego",[104,1201,1204],{"href":1202,"rel":1203},"https:\u002F\u002Fjobs.netflix.com\u002F",[211],"Netflix Jobs",[104,1206,1209],{"href":1207,"rel":1208},"https:\u002F\u002Fm.twitch.tv\u002F",[211],"Twitch",[104,1211,1214],{"href":1212,"rel":1213},"https:\u002F\u002Fwww.invisionapp.com\u002F",[211],"Invision",[104,1216,1219],{"href":1217,"rel":1218},"https:\u002F\u002Fauth0.com\u002F",[211],"Auth0",[104,1221,1224],{"href":1222,"rel":1223},"https:\u002F\u002Fwww.audible.com\u002Fabout",[211],"Audible",[104,1226,1229],{"href":1227,"rel":1228},"https:\u002F\u002Fwww.hilton.com\u002Fen\u002Fhilton\u002F",[211],"Hilton",[104,1231,1234],{"href":1232,"rel":1233},"https:\u002F\u002Fwww.ticketmaster.com\u002F",[211],"Ticketmaster",", and many more.",[290,1237],{},[91,1239,1240],{},"Considering Next.js for your web app too? Our team of experienced and reliable web developers can help you with your project.",[1242,1243,1244,1245],"div",{},"\n  ",[104,1246,1251],{"className":1247,"href":52},[1248,1249,1250],"base-button","base-button--dark","base-button--outlined","\n  Hire Next js developers\n  ",[290,1253],{},[290,1255],{},[181,1257,1259],{"id":1258},"why-is-next-js-used","Why is Next js used",[91,1261,1262,1263,1268],{},"Next js uses the ",[104,1264,1267],{"href":1265,"rel":1266},"https:\u002F\u002Fitclub.com.au\u002Freact-js-development-services#why-is-react-good",[211],"benefits of React",", and this makes it even easier to get your web app, website or e-commerce store up and running. Also, Next.js handles server-side rendering exceptionally well and helps web developers create SEO-friendly React SPAs (single-page applications).",[290,1270],{},[181,1272,1274],{"id":1273},"when-to-use-next-js","When to use Next js",[91,1276,1277,1278,1281],{},"Here are ",[188,1279,1280],{},"10 reasons"," when you should use Next js for your tech stack:",[459,1283,1284,1291,1298,1305,1311,1318,1324,1329,1335,1341],{},[101,1285,1286,1287,1290],{},"If you want to ensure ",[188,1288,1289],{},"great performance"," of your web app, a static and server-rendered React application can be your solution.",[101,1292,1293,1294,1297],{},"Next js is ",[188,1295,1296],{},"great for PWAs",", production, the enterprise, fully responsive static sites, etc.",[101,1299,1300,1301,1304],{},"If you aim for ",[188,1302,1303],{},"productivity and effectiveness"," in your web development practices.",[101,1306,439,1307,1310],{},[188,1308,1309],{},"Next js uses React"," for UI templating, this offers React developers an easy and straightforward way to get started with web development and get productive fast.",[101,1312,1313,1314,1317],{},"If you need ",[188,1315,1316],{},"a SEO-friendly React SPA",". Next js helps address critical aspects related to SEO, such as the speed of your web app, responsiveness and mobile optimisation, structured metadata, sitemap, HTTPS certification for security, etc.",[101,1319,1320,1321,488],{},"Next js allows you to utilise an intuitive page-based routing system, with support for ",[188,1322,1323],{},"dynamic routes",[101,1325,1300,1326,488],{},[188,1327,1328],{},"client-side routing with optimised prefetching",[101,1330,1331,1332,488],{},"If you plan to build ",[188,1333,1334],{},"API endpoints with Serverless Functions",[101,1336,1337,1338,488],{},"If you want to have ",[188,1339,1340],{},"a fully extendable framework",[101,1342,1343,1344,488],{},"If you love ",[188,1345,1346],{},"a great Developer Experience",[290,1348],{},[181,1350,1352],{"id":1351},"how-does-next-js-ssr-work","How does Next js SSR work",[91,1354,1355],{},"Briefly, SSR (server-side rendering) is when the rendering process is offloaded to the backend (server). Then, the fully-rendered HTML views are promptly delivered to the client (browser), easing the logic on the frontend. This means that the browser starts rendering the HTML from the server without waiting for all the JavaScript to be downloaded and executed, and your web app user can start viewing the page while all of that is happening.",[197,1357,1358],{},[91,1359,1360],{},"SSR works great for time-sensitive apps.",[91,1362,1363,1364,1367],{},"Check out the ",[104,1365,1366],{"href":178},"diagram"," below that compares SSR with CSR.",[290,1369],{},[181,1371,1373],{"id":1372},"is-ssr-good-for-web-application-performance","Is SSR good for web application performance",[91,1375,1376],{},"Take a look at the simplified diagrams below. You can see that SSR can deliver HTML to the client (browser) faster compared to CSR. However, if we compare an SSR and a static generated site, the performance for the latter would be higher due to the absence of render.",[91,1378,1379],{},[284,1380],{"alt":635,"src":636,"title":635},[290,1382],{},[91,1384,1385],{},[284,1386],{"alt":1387,"src":1388,"title":1387},"Simplified Next js runtime diagram SSR Static API request","\u002Fuploads\u002FNextjs_Runtime_SSR_Static_API.jpg",[290,1390],{},[91,1392,1393,1394,1397],{},"To sum up, it's always necessary to keep in mind ",[188,1395,1396],{},"the main requirements of your web app"," before choosing your tech stack:",[98,1399,1400,1414,1420],{},[101,1401,1402,1403,1406,1407,1184,1410,1413],{},"A ",[188,1404,1405],{},"CSR web app"," (",[104,1408,419],{"href":1409},"\u002Freact-js-development-services#why-is-react-good",[104,1411,1412],{"href":12},"Vue.js",", Angular) would work great when you don't need to worry about SEO.",[101,1415,1402,1416,1419],{},[188,1417,1418],{},"static generated site"," would be perfect for public pages where you don't need user authorisation, for example.",[101,1421,1422,1424],{},[188,1423,655],{}," would be much more efficient when you need to prerender data for each authorised user.",[91,1426,1427],{},"If there are any questions left regarding which tech stack to use in your web project, it's always better to discuss it with experts in web development. One of our team members would be happy to chat with you about your project requrements, so don't hesitate to get in touch with us. Consultations are always free at IT Club.",[1242,1429,1244,1430],{},[104,1431,1433],{"className":1432,"href":52},[1248,1249,1250],"\n  Get in touch\n  ",[290,1435],{},[91,1437,1438,1439,1444],{},"Is Next.js not a perfect match for your project? Check out other ",[104,1440,1443],{"href":1441,"rel":1442},"https:\u002F\u002Fitclub.com.au\u002F",[211],"web development services"," that IT Club has to offer. Our software engineers deliver high-quality web development on time.",[290,1446],{},[546,1448,554],{"link":1449,"title":1450,"description":1451,"logo":551,"site-name":552,"cover-image":1452},"https:\u002F\u002Fitclub.com.au\u002Fvue-js-development-services\u002F","Vue Web Development Services","Our expert Vue development team provides Vue js development services to build mobile and user-friendly web apps and single-page applications (SPAs).\u003Cbr>\u003Cbr>Click to learn more.","\u002Fuploads\u002Fvue-js-development-at-itclub.com.au-fb-vue.png",[290,1454],{},[290,1456],{},{"title":25,"searchDepth":1458,"depth":1458,"links":1459},2,[1460,1464,1467,1468,1469,1474,1477,1478,1479,1480,1481,1482,1483],{"id":183,"depth":1458,"text":184,"children":1461},[1462],{"id":227,"depth":1463,"text":228},3,{"id":414,"depth":1458,"text":113,"children":1465},[1466],{"id":528,"depth":1463,"text":529},{"id":561,"depth":1458,"text":119},{"id":601,"depth":1458,"text":125},{"id":796,"depth":1458,"text":131,"children":1470},[1471,1472,1473],{"id":846,"depth":1463,"text":837},{"id":860,"depth":1463,"text":840},{"id":889,"depth":1463,"text":843},{"id":927,"depth":1458,"text":137,"children":1475},[1476],{"id":1008,"depth":1463,"text":1009},{"id":1023,"depth":1458,"text":143},{"id":1067,"depth":1458,"text":1068},{"id":1168,"depth":1458,"text":1169},{"id":1258,"depth":1458,"text":1259},{"id":1273,"depth":1458,"text":1274},{"id":1351,"depth":1458,"text":1352},{"id":1372,"depth":1458,"text":1373},"\u002Fuploads\u002Fnext_js_thumbnail.jpg","2020-12-27T03:20:12.181Z","Here all you need to know about Next js, its features, great web app performance and user experience. Hire expert React and Next developers based in Melbourne.","md",[1489,1492,1495,1498],{"question":1490,"answer":1491},"What is the difference between React and Next.js?'","While Next.js is a way to leverage React to support server-side rendering (SSR), the Create React App tool is a way to leverage React to support client-side rendering (CSR).",{"question":1493,"answer":1494},"Why Next js?","Next.js has the benefits of React, which makes it even easier to get a web app up and running. Another one of Next.js’ strong points is that it handles server-side rendering (SSR) perfectly. Also, Next.js helps web developers create SEO-friendly React single-page applications (SPAs).",{"question":1496,"answer":1497},"Who created Next js?","Tim Neutkens (@timneutkens) – Vercel and Guillermo Rauch (@rauchg) – Vercel.",{"question":155,"answer":1499},"Next js is used for the production of SEO-friendly websites and web applications. Some of the world's largest brands have moved to Next.js and Vercel, such as Nike, Hulu, Marvel, Lego, Netflix Jobs, Twitch, Invision, Auth0, Audible, Hilton, Ticketmaster, and many more.",{},{"description":1486,"title":85},{"title":85,"description":1486},{"loc":24},"web-development\u002Fnext-js-framework","Learn more about Next js and how your web app can benefit from its features to build fast and performant web experiences.",[1507,1508,419,1509,1510],"Coding","Frontend","UX","Full-stack","AS0d4UNq7y6MstU_WXmHIz9U23bckc1EGReN3Zn4ehM",[1513,2130,2716,3273],{"id":1514,"title":1515,"authorBio":1516,"body":1517,"coverImage":2113,"date":2114,"description":2115,"extension":1487,"faq":2116,"heroImage":2113,"lastReviewed":86,"meta":2117,"metadata":2118,"navigation":223,"path":2120,"readingTime":2121,"reviewedAgainst":2122,"seo":2123,"sitemap":2124,"stem":2125,"summary":2126,"tags":2127,"thumbnail":2113,"__hash__":2129},"blog\u002Fcyber-security\u002Fbreach-lessons\u002Flatitude-financial-breach.md","Latitude Financial Data Breach: Lessons for Small Businesses","Written by Elena Osipova, CPA, an emerging cyber security practitioner with professional background in finance, accounting and business operations. She writes about financial data breaches, cyber security governance and practical security controls for Australian small businesses.",{"type":88,"value":1518,"toc":2097},[1519,1522,1527,1530,1550,1553,1556,1559,1563,1566,1569,1619,1622,1625,1628,1632,1736,1740,1747,1767,1770,1774,1806,1810,1845,1849,1852,1878,1882,1938,1942,1945,1949,1963,1967,2005,2009,2012,2032,2036,2039,2042,2049,2053],[91,1520,1521],{},"In March 2023, Latitude Financial suffered what remains one of the largest data breaches in Australian history.",[197,1523,1524],{},[91,1525,1526],{},"Latitude Financial is the ASX-listed lender behind Gem, GO Mastercard and 28° Global. It provides personal loans, credit cards and point-of-sale interest-free finance to around 2.8 million customer accounts across Australia and New Zealand.",[91,1528,1529],{},"An attacker who compromised one of Latitude's vendors obtained Latitude employee login credentials and used them to extract customer data from two other service providers. The stolen data included:",[98,1531,1532,1535,1538,1541,1544,1547],{},[101,1533,1534],{},"~7.9 million Australian and NZ driver licence numbers",[101,1536,1537],{},"~103,000 copies of driver licences or passports",[101,1539,1540],{},"~53,000 passport numbers",[101,1542,1543],{},"~6.1 million additional records, some dating back to at least 2005",[101,1545,1546],{},"income and expense information used in ~900,000 loan applications, including - ~308,000 bank account numbers and ~143,000 credit card or credit card account numbers;",[101,1548,1549],{},"less than 100 customers with monthly financial statements.",[91,1551,1552],{},"Many affected people were former customers and applicants, and some information dated back nearly two decades.",[91,1554,1555],{},"Due to its impact, this breach is among major Australian breaches along with Optus and Medibank, intensifying the debate about privacy reform, data retention and cyber security.",[91,1557,1558],{},"The weaknesses that contributed to the impact of this breach - third-party access, one compromised account reaching multiple sources of sensitive information, and retaining large volumes of historical data - can exist in businesses of every size. And as for small businesses, there are usually fewer designated defences available for IT and security.",[181,1560,1562],{"id":1561},"what-happened","What happened",[91,1564,1565],{},"On 16 March 2023, Latitude Financial entered a trading halt at ASX and disclosed a cyberattack, describing it as \"sophisticated and malicious\". It was initially disclosed that approximately 103,000 identification documents and 225,000 customer records were stolen.",[91,1567,1568],{},"By 27 March, Latitude confirmed the theft of records relating to approximately 14 million customer and applicant records. The stolen information included:",[98,1570,1571,1577,1583,1589,1595,1601,1607,1613],{},[101,1572,1573,1576],{},[188,1574,1575],{},"Driver licence numbers:"," ~7.9 million Australian and New Zealand",[101,1578,1579,1582],{},[188,1580,1581],{},"Passport numbers:"," ~53,000 records",[101,1584,1585,1588],{},[188,1586,1587],{},"Records containing names, addresses, dates of birth and phone numbers:"," ~6.1 million, with some dating back to at least 2005",[101,1590,1591,1594],{},[188,1592,1593],{},"Images of driver licences or passports:"," 103,000 records",[101,1596,1597,1600],{},[188,1598,1599],{},"Income and expense information:"," ~900,000 loan applications",[101,1602,1603,1606],{},[188,1604,1605],{},"Bank account numbers:"," ~308,000 records",[101,1608,1609,1612],{},[188,1610,1611],{},"Credit card or credit account numbers:","  ~143,000 records",[101,1614,1615,1618],{},[188,1616,1617],{},"Monthly financial statements:"," less than 100 customers.",[91,1620,1621],{},"Latitude said bank-account passwords, card expiry dates and three-digit security codes were not compromised.",[91,1623,1624],{},"Latitude received the ransom demand but refused to pay it, explicitly aligning with the Australian Government's position.",[91,1626,1627],{},"As of July 2026, no attacker has been publicly identified or charged in connection with this breach.",[181,1629,1631],{"id":1630},"the-timeline","The timeline",[1633,1634,1635,1652],"table",{},[1636,1637,1638],"thead",{},[1639,1640,1641,1647],"tr",{},[1642,1643,1644],"th",{},[188,1645,1646],{},"Date",[1642,1648,1649],{},[188,1650,1651],{},"Event",[1653,1654,1655,1666,1676,1686,1696,1706,1716,1726],"tbody",{},[1639,1656,1657,1663],{},[1658,1659,1660],"td",{},[188,1661,1662],{},"Prior to 16 March 2023",[1658,1664,1665],{},"An attacker obtains a compromised employee credential through one of Latitude’s vendors.  Latitude detects unusual activity and begins its response.",[1639,1667,1668,1673],{},[1658,1669,1670],{},[188,1671,1672],{},"16 March 2023",[1658,1674,1675],{},"Latitude enters an ASX trading halt and publicly discloses the breach. Early findings: ~330,000 customers and applicants affected.",[1639,1677,1678,1683],{},[1658,1679,1680],{},[188,1681,1682],{},"27 March 2023",[1658,1684,1685],{},"The full scale of the breach disclosed: ~14 million records.",[1639,1687,1688,1693],{},[1658,1689,1690],{},[188,1691,1692],{},"11 April 2023",[1658,1694,1695],{},"Latitude confirms a ransom demand and refuses to pay.",[1639,1697,1698,1703],{},[1658,1699,1700],{},[188,1701,1702],{},"April - May 2023",[1658,1704,1705],{},"~6 weeks of severe business disruption: new lending paused, collections interruptions.",[1639,1707,1708,1713],{},[1658,1709,1710],{},[188,1711,1712],{},"May 2023",[1658,1714,1715],{},"The OAIC and NZ Privacy Commissioner open a joint investigation into Latitude's information handling.",[1639,1717,1718,1723],{},[1658,1719,1720],{},[188,1721,1722],{},"Aug 2023",[1658,1724,1725],{},"Latitude reports $76M of pre-tax cyber-related costs and provisions related to the incident and $98.2M statutory loss after tax.",[1639,1727,1728,1733],{},[1658,1729,1730],{},[188,1731,1732],{},"2023 - 2024",[1658,1734,1735],{},"Gordon Legal and Hayden Stephens and Associates lodged a representative complaint with the OAIC on behalf of affected individuals.",[181,1737,1739],{"id":1738},"how-the-attacker-gained-access","How the attacker gained access",[91,1741,1742,1743,1746],{},"Based on Latitude’s public disclosures, the incident began with a ",[188,1744,1745],{},"third-party credential compromise",", rather than a technical exploit. Here’s how the cybercriminals got in:",[459,1748,1749,1755,1761],{},[101,1750,1751,1754],{},[188,1752,1753],{},"Third-party compromise."," The attack originated from one of Latitude’s major vendors.",[101,1756,1757,1760],{},[188,1758,1759],{},"Theft of a valid login credential."," From the vendor environment, the attacker obtained active credentials belonging to a Latitude employee.",[101,1762,1763,1766],{},[188,1764,1765],{},"Large-scale data theft."," The attacker used that credential to gain unauthorised access to personal information of current and historical customers and applicants, resulting in approximately 14 million records stolen.",[91,1768,1769],{},"Public disclosures have not identified malware, a zero-day vulnerability, or phishing against Latitude employees as the initial access method. The confirmed starting point was a compromised credential obtained through a third party that unlocked almost two decades of identity data.",[181,1771,1773],{"id":1772},"_5-reasons-the-breach-had-such-a-large-impact","5 reasons the breach had such a large impact",[459,1775,1776,1782,1788,1794,1800],{},[101,1777,1778,1781],{},[188,1779,1780],{},"A third-party compromise reached Latitude."," Based on reports, the attacker obtained a valid employee credential through a compromised third party. This shows how a supplier’s security weakness can become a customer’s security incident. Businesses should know which vendors can access their systems and data, limit that access to what is necessary and remove it when it is no longer needed.",[101,1783,1784,1787],{},[188,1785,1786],{},"Stolen credentials worked, at scale."," The compromised credential provided sufficient access for the attacker to retrieve large volumes of data. Public information does not establish whether MFA was absent, bypassed or otherwise ineffective. The suspicious activity was not detected or interrupted early enough to prevent large-scale data theft.",[101,1789,1790,1793],{},[188,1791,1792],{},"Historical data increased the consequences."," Some stolen records dated back to at least 2005 and related to former customers and unsuccessful applicants. Australian Privacy Principle 11.2 generally requires an organisation to take reasonable steps to destroy or de-identify personal information no longer needed, unless it must be retained under other legal requirements. In May 2023, the OAIC and New Zealand Privacy Commissioner started a joint investigation into whether Latitude met that obligation.",[101,1795,1796,1799],{},[188,1797,1798],{},"Valuable identity information was concentrated."," The attackers were able to reach Latitude’s customer and applicant records in the service-provider systems with one set of employee credentials. The stolen information included driver licence and passport details, document images, Medicare information and financial information provided during credit applications. Where retention is legally or operationally necessary, the information should be isolated, encrypted, tightly access-controlled and deleted when the retention requirement ends.",[101,1801,1802,1805],{},[188,1803,1804],{},"Detection did not prevent large-scale theft."," Latitude detected unusual activity and moved to contain the incident, but substantial information had already been compromised. Businesses should have alerts on unusual behaviour such as mass searches, bulk downloads, large exports, access from new locations and one account rapidly accessing several sensitive systems.",[181,1807,1809],{"id":1808},"what-it-cost","What it cost",[98,1811,1812,1822,1828,1834,1840],{},[101,1813,1814,1815,1818,1819,488],{},"In August 2023, Latitude reported ",[188,1816,1817],{},"$76 million in pre-tax March-incident-related costs and provisions",", contributing to a ",[188,1820,1821],{},"$98.2 million after tax loss from continuing operations for the half-year",[101,1823,1824,1827],{},[188,1825,1826],{},"Business operation disruption:"," For around 6 weeks, Latitude paused the new lending and loan collections were disrupted.",[101,1829,1830,1833],{},[188,1831,1832],{},"Cost for reimbursing identity document replacement"," for millions of people",[101,1835,1836,1839],{},[188,1837,1838],{},"Legal and regulatory exposure:"," Serious privacy contraventions can expose a company to substantial civil penalties, although a data breach does not automatically mean that the maximum penalty will apply.",[101,1841,1842],{},[188,1843,1844],{},"Reputational damage.",[181,1846,1848],{"id":1847},"what-latitude-did-well","What Latitude did well",[91,1850,1851],{},"Although the breach exposed serious weaknesses, several aspects of Latitude’s incident response are worth recognising:",[98,1853,1854,1860,1866,1872],{},[101,1855,1856,1859],{},[188,1857,1858],{},"Early disclosure:"," Latitude disclosed the cyberattack and entered a trading halt on 16 March 2023 while the investigation was still underway.",[101,1861,1862,1865],{},[188,1863,1864],{},"Containment and operational action:"," Latitude isolated affected systems, paused parts of its onboarding new customers and worked with cyber security specialists, the ACSC, AFP and other government agencies.",[101,1867,1868,1871],{},[188,1869,1870],{},"Refusal to pay the ransom:"," Latitude publicly stated that it would not pay the attacker, aligning its position with Australian Government advice.",[101,1873,1874,1877],{},[188,1875,1876],{},"Support for affected people:"," Latitude offered to reimburse reasonable costs for replacing compromised identity documents and provided information about protective steps customers could take.",[181,1879,1881],{"id":1880},"_9-lessons-for-your-business","9 lessons for your business",[459,1883,1884,1890,1896,1902,1908,1914,1920,1926,1932],{},[101,1885,1886,1889],{},[188,1887,1888],{},"Do not keep data longer than necessary."," Review what personal information your business holds, why it’s needed, and how long it must be retained? Australian Privacy Principle 11.2 generally requires an organisation to take reasonable steps to destroy or de-identify personal information it no longer needs, unless it must retain the information under another legal obligation. Historical information increased the scale of the Latitude breach. Cybercriminals cannot steal data your business no longer holds.",[101,1891,1892,1895],{},[188,1893,1894],{},"Minimise stored identity documents."," Verify identity without retaining a full document image where the law and business process allow. If retention is required, store only the minimum information, encrypt it, isolate it, restrict access and delete it as soon as the applicable retention period ends.",[101,1897,1898,1901],{},[188,1899,1900],{},"Your vendors' security affects your business."," Know which third parties hold your data or can access your systems. This may include IT providers, bookkeepers and software platforms. Require MFA, prompt breach notification and clear security obligations.",[101,1903,1904,1907],{},[188,1905,1906],{},"Review third-party access regularly."," Keep a record of every vendor account, what it can access and who approved it. Remove access immediately when it is no longer required.",[101,1909,1910,1913],{},[188,1911,1912],{},"Make stolen credentials insufficient."," Require MFA for remote, administrator and third-party access. Give every account only Limit each account only the access it needs. Set alerts on unusual behaviour, such as new login locations, bulk downloads or access outside expected hours.",[101,1915,1916,1919],{},[188,1917,1918],{},"Control large data exports."," Restrict who can download or export sensitive information. Set alerts on unusually large downloads, repeated searches or one account accessing several sensitive systems in a short period.",[101,1921,1922,1925],{},[188,1923,1924],{},"Test your incident response plan."," A written plan is useful only if people know how to use it. Run a simple exercise covering containment, notifications, customer communication and contact with your IT provider.",[101,1927,1928,1931],{},[188,1929,1930],{},"Decide your ransom position before an incident."," Document who has authority to make the decision and obtain legal, law-enforcement, insurance and incident-response advice. Paying a ransom does not guarantee that stolen data will be deleted, returned or kept private.",[101,1933,1934,1937],{},[188,1935,1936],{},"Explain that early breach figures may change."," Clearly label early figures as preliminary. Then may change as the forensic investigation progresses.",[181,1939,1941],{"id":1940},"how-cyber-security-frameworks-apply","How cyber security frameworks apply",[91,1943,1944],{},"While the publicly available information is limited and does not provide enough technical detail to map every stage of the Latitude attack, the incident can still be examined using established cyber security frameworks.",[225,1946,1948],{"id":1947},"mitre-attck-helps-understand-the-attackers-behaviour","MITRE ATT&CK helps understand the attacker’s behaviour",[98,1950,1951,1957],{},[101,1952,1953,1956],{},[188,1954,1955],{},"Valid Accounts (T1078):"," This technique is consistent with the publicly known facts because the attacker obtained a valid employee credential to gain unauthorised access to sensitive information.",[101,1958,1959,1962],{},[188,1960,1961],{},"Data from Information Repositories (T1213):"," The data theft from customer and applicant systems may be consistent with this technique.",[225,1964,1966],{"id":1965},"nist-cybersecurity-framework-20-helps-organise-the-lessons","NIST Cybersecurity Framework 2.0 helps organise the lessons",[98,1968,1969,1975,1981,1987,1993,1999],{},[101,1970,1971,1974],{},[188,1972,1973],{},"Govern:"," Assign responsibility for cyber security, privacy, data retention and third-party risk. Set security requirements for vendors and check that they are followed.",[101,1976,1977,1980],{},[188,1978,1979],{},"Identify:"," Know what personal information the business holds, where it is stored, why it is needed, who can access it and when it should be deleted.",[101,1982,1983,1986],{},[188,1984,1985],{},"Protect:"," Use least privilege, strong MFA, encryption, access segmentation and controls that limit large downloads or exports.",[101,1988,1989,1992],{},[188,1990,1991],{},"Detect:"," Monitor successful and failed logins. Alert on unusual locations, new devices, mass downloads and access across sensitive systems.",[101,1994,1995,1998],{},[188,1996,1997],{},"Respond:"," Maintain and test an incident-response plan covering containment, legal and privacy assessment, communication and customer support.",[101,2000,2001,2004],{},[188,2002,2003],{},"Recover:"," Restore services safely, support affected people and update systems, contracts and retention practices after the incident.",[225,2006,2008],{"id":2007},"acscs-essential-eight","ACSC’s Essential Eight",[91,2010,2011],{},"Although the Essential Eight does not cover every issue raised by this data breach, it is a useful Australian technical baseline. The most relevant strategies include:",[98,2013,2014,2020,2026],{},[101,2015,2016,2019],{},[188,2017,2018],{},"Multi-factor authentication:"," Require MFA for employees, administrators, vendors and access to sensitive systems.",[101,2021,2022,2025],{},[188,2023,2024],{},"Restrict administrative privileges:"," Give your employees and service providers only the access required for their work. Review privileged access regularly and remove it when it is no longer needed.",[101,2027,2028,2031],{},[188,2029,2030],{},"Regular backups:"," Maintain protected and tested backups to support operational recovery.",[181,2033,2035],{"id":2034},"final-takeaway","Final takeaway",[91,2037,2038],{},"The Latitude breach was not only a story about a compromised credential. It also showed how much sensitive information one account could reach, how third-party access can connect multiple systems, and how historical data can increase the harm caused by an incident.",[91,2040,2041],{},"Small businesses may hold fewer records, but the same risks apply. Know what personal information you hold, remove information you no longer need, limit each account to the minimum access required and monitor unusual activity after login.",[91,2043,2044,2045,2048],{},"Use our ",[104,2046,2047],{"href":37},"DIY cyber security health check"," to review your current controls and identify practical steps for improvement.",[181,2050,2052],{"id":2051},"sources-used","Sources used",[98,2054,2055,2058,2061,2064,2067,2070,2073,2076,2079,2082,2085,2088,2091,2094],{},[101,2056,2057],{},"Latitude Financial, Cybercrime Update, 20 March 2023",[101,2059,2060],{},"Latitude Financial, Cybercrime Update, 27 March 2023",[101,2062,2063],{},"Latitude Financial, Cybercrime Update 11 April 2023",[101,2065,2066],{},"Latitude Financial, Latitude Cyber Response",[101,2068,2069],{},"OAIC, Joint Australia-New Zealand investigation into Latitude group",[101,2071,2072],{},"OAIC, Statement on Latitude Financial data breach",[101,2074,2075],{},"New Zealand Office of the Privacy Commissioner, New Zealand - Australia investigation into Latitude breach begins",[101,2077,2078],{},"Latitude Group Holdings, 1H23 Results",[101,2080,2081],{},"MITRE ATT&CK, Valid Accounts - T1078",[101,2083,2084],{},"MITRE ATT&CK, Data from Information Repositories - T1213",[101,2086,2087],{},"NIST, Cybersecurity Framework 2.0",[101,2089,2090],{},"ASD, ACSC’s Essential Eight Maturity Model",[101,2092,2093],{},"Australian Government, Australian Privacy Principles Guidelines, Chapter 11",[101,2095,2096],{},"Gordon Legal, Latitude Financial privacy breach representative complaint",{"title":25,"searchDepth":1458,"depth":1458,"links":2098},[2099,2100,2101,2102,2103,2104,2105,2106,2111,2112],{"id":1561,"depth":1458,"text":1562},{"id":1630,"depth":1458,"text":1631},{"id":1738,"depth":1458,"text":1739},{"id":1772,"depth":1458,"text":1773},{"id":1808,"depth":1458,"text":1809},{"id":1847,"depth":1458,"text":1848},{"id":1880,"depth":1458,"text":1881},{"id":1940,"depth":1458,"text":1941,"children":2107},[2108,2109,2110],{"id":1947,"depth":1463,"text":1948},{"id":1965,"depth":1463,"text":1966},{"id":2007,"depth":1463,"text":2008},{"id":2034,"depth":1458,"text":2035},{"id":2051,"depth":1458,"text":2052},"\u002Fcovers\u002Fcyber-security\u002Fbreach-lessons\u002Flatitude-financial.jpg","2026-07-27T00:00:00.000Z","The 2023 Latitude Financial breach exposed millions of customer and applicant records. Learn how third-party access, stolen credentials and excessive data retention increased the impact - and what small businesses should do differently.",[],{},{"description":2119,"title":1515},"How the 2023 Latitude Financial incident happened. What Australian small businesses can learn about data retention, vendor access, MFA and breach response.","\u002Fcyber-security\u002Fbreach-lessons\u002Flatitude-financial-breach",10,"Reviewed against current guidance from ASD Australian Cyber Security Centre, the OAIC, NIST CSF 2.0 and MITRE ATT&CK",{"title":1515,"description":2115},{"loc":2120},"cyber-security\u002Fbreach-lessons\u002Flatitude-financial-breach","The 2023 Latitude Financial breach exposed approximately 14 million records, including information dating back to 2005. Here is what Australian businesses can learn about data retention, third-party access, stolen credentials and breach response.",[48,2128],"Breach Lessons","TA8niaCikqD3pvid8DbV6jcw4Bh_aFDwyyEIa8P8djs",{"id":2131,"title":2132,"authorBio":2133,"body":2134,"coverImage":2701,"date":2114,"description":2702,"extension":1487,"faq":2703,"heroImage":2701,"lastReviewed":86,"meta":2704,"metadata":2705,"navigation":223,"path":2707,"readingTime":2708,"reviewedAgainst":2709,"seo":2710,"sitemap":2711,"stem":2712,"summary":2713,"tags":2714,"thumbnail":2701,"__hash__":2715},"blog\u002Fcyber-security\u002Fbreach-lessons\u002Fmedibank-breach.md","What The Medibank Breach Teaches Small Businesses","Written by Elena Osipova, CPA, an emerging Cyber Security Practitioner. Elena writes about enterprise breaches, cyber security governance and practical security controls to help Australian small businesses improve their own defences.",{"type":88,"value":2135,"toc":2685},[2136,2139,2144,2147,2150,2153,2155,2158,2161,2164,2167,2169,2335,2337,2340,2360,2367,2369,2401,2403,2447,2451,2454,2474,2478,2540,2542,2545,2549,2573,2577,2609,2611,2614,2626,2628,2631,2634,2639,2641],[91,2137,2138],{},"In October 2022, Medibank, one of Australia's largest private health insurers, disclosed that a cybercriminal had stolen about 520GB of data. The breach affected around 9.7 million current and former Medibank, ahm and international customers and representatives, including people whose sensitive health claims information was exposed.",[197,2140,2141],{},[91,2142,2143],{},"Through its Medibank and ahm brands, the group insures millions of people across Australia.",[91,2145,2146],{},"The weaknesses that contributed to this breach were not unusual. According to allegations filed by the Australian Information Commissioner, an employee of a Medibank IT contractor saved Medibank credentials in his browser profile on a work computer. When he signed into the same browser profile on a personal computer, the credentials synchronised to that device and were later stolen by malware.",[91,2148,2149],{},"A cybercriminal then used the compromised credentials to access Medibank’s remote-access VPN, which did not require MFA for that login method. Medibank’s security software raised alerts about suspicious activity, but they were delayed to triage for weeks.",[91,2151,2152],{},"Three basic controls failed in a large organisation. Every one of them could be missing in small businesses too.",[181,2154,1562],{"id":1561},[91,2156,2157],{},"On 13 October 2022, Medibank disclosed unusual activity on its network and initially said there was no evidence that customer data had been removed. On 19 and 22 October, an attacker contacted Medibank and supplied sample files. Medibank later confirmed that information connected to around 9.7 million people had been stolen. The OAIC alleges that about 520GB of data was exfiltrated between late August and 13 October 2022.",[91,2159,2160],{},"The attacker demanded US$10 million. Medibank refused to pay, explaining that payment could not guarantee the return or deletion of the data and might encourage further extortion.",[91,2162,2163],{},"From 9 November to 1 December 2022, stolen information was published on a dark-web leak site in stages, fully releasing the dataset. Published files included highly sensitive health claims information, including records about HIV, drug and alcohol treatment, mental health, and abortions. Australian authorities later attributed the attack to Russian national Aleksandr Ermakov, who was associated with the REvil cybercrime group.",[91,2165,2166],{},"In January 2024, Australia used its cyber sanctions framework for the first time and designated Aleksandr Ermakov for his role in the Medibank breach, imposing targeted financial sanctions and a travel ban. Dealing with a designated person or their assets can be a criminal offence carrying severe penalties, including up to 10 years’ imprisonment for an individual.",[181,2168,1631],{"id":1630},[1633,2170,2171,2183],{},[1636,2172,2173],{},[1639,2174,2175,2179],{},[1642,2176,2177],{},[188,2178,1646],{},[1642,2180,2181],{},[188,2182,1651],{},[1653,2184,2185,2195,2205,2215,2225,2235,2245,2255,2265,2275,2285,2295,2305,2315,2325],{},[1639,2186,2187,2192],{},[1658,2188,2189],{},[188,2190,2191],{},"Prior to 7 August 2022",[1658,2193,2194],{},"A contractor employee saved Medibank credentials in a browser profile on a work computer. The credentials were later synchronised to his personal computer.",[1639,2196,2197,2202],{},[1658,2198,2199],{},[188,2200,2201],{},"Around 7 August 2022",[1658,2203,2204],{},"Malware on the personal computer stole the Medibank credentials.",[1639,2206,2207,2212],{},[1658,2208,2209],{},[188,2210,2211],{},"12 August 2022",[1658,2213,2214],{},"The attacker tested the stolen admin credentials against Medibank’s Microsoft Exchange server.",[1639,2216,2217,2222],{},[1658,2218,2219],{},[188,2220,2221],{},"Around 23 August 2022",[1658,2223,2224],{},"The attacker first logged in to Medibank’s GlobalProtect VPN, with no MFA required.",[1639,2226,2227,2232],{},[1658,2228,2229],{},[188,2230,2231],{},"24 - 25 August 2022",[1658,2233,2234],{},"Medibank’s security software generated alerts, sending them to an IT operations mailbox. The OAIC alleges they were not appropriately triaged or escalated.",[1639,2236,2237,2242],{},[1658,2238,2239],{},[188,2240,2241],{},"25 August - 13 October 2022",[1658,2243,2244],{},"The attacker accessed Medibank's internal systems and exfiltrated about 520GB of data.",[1639,2246,2247,2252],{},[1658,2248,2249],{},[188,2250,2251],{},"11 October 2022",[1658,2253,2254],{},"Medibank triaged a high-severity alert and engaged its incident-response partner.",[1639,2256,2257,2262],{},[1658,2258,2259],{},[188,2260,2261],{},"13 October 2022",[1658,2263,2264],{},"Medibank publicly discloses the incident, initially stating that there was no evidence that customer data had been removed.",[1639,2266,2267,2272],{},[1658,2268,2269],{},[188,2270,2271],{},"19 and 22 October 2022",[1658,2273,2274],{},"The attacker contacted Medibank and supplied sample files with stolen data.",[1639,2276,2277,2282],{},[1658,2278,2279],{},[188,2280,2281],{},"7 November 2022",[1658,2283,2284],{},"Medibank confirmed the scale of the breach: 9.7 million people and publicly refused to pay the ransom.",[1639,2286,2287,2292],{},[1658,2288,2289],{},[188,2290,2291],{},"9 November - 1 December 2022",[1658,2293,2294],{},"Stolen information was published on the dark web in stages, ending with the full 520GB released.",[1639,2296,2297,2302],{},[1658,2298,2299],{},[188,2300,2301],{},"27 June 2023",[1658,2303,2304],{},"APRA announced a $250M increase in Medibank’s capital adequacy requirement until remediation was completed to APRA’s satisfaction.",[1639,2306,2307,2312],{},[1658,2308,2309],{},[188,2310,2311],{},"23 January 2024",[1658,2313,2314],{},"Australia imposed its first cyber sanction, designating Aleksandr Ermakov for his role in the breach.",[1639,2316,2317,2322],{},[1658,2318,2319],{},[188,2320,2321],{},"5 June 2024",[1658,2323,2324],{},"The OAIC files civil penalty proceedings in the Federal Court over alleged failure to take reasonable steps to protect personal information.",[1639,2326,2327,2332],{},[1658,2328,2329],{},[188,2330,2331],{},"As of July 2026",[1658,2333,2334],{},"The OAIC proceedings continued, and the Medibank class action remained listed as open in the Federal Court.",[181,2336,1739],{"id":1738},[91,2338,2339],{},"Based on the OAIC’s allegations and Medibank’s public updates, the incident began with stolen credentials, remote access without MFA and an account with extensive privileges. Here’s how the hacker gained access:",[459,2341,2342,2348,2354],{},[101,2343,2344,2347],{},[188,2345,2346],{},"Credential theft through infostealer malware."," TMedibank credentials saved in a contractor employee’s browser profile were synchronised to his personal computer and were stolen by malware.",[101,2349,2350,2353],{},[188,2351,2352],{},"Remote access without MFA."," The VPN was configured to accept a username and password and did not require MFA.",[101,2355,2356,2359],{},[188,2357,2358],{},"Broad access and delayed escalation."," The compromised admin account could access most Medibank systems. The OAIC alleges that security alerts were generated from 24 August onwards but were not appropriately triaged or escalated, allowing the hacker to locate and exfiltrate about 520GB of data over seven weeks.",[91,2361,2362,2363,2366],{},"The publicly available evidence describes a ",[188,2364,2365],{},"data-theft and extortion"," incident rather than ransomware with encrypted systems. The attacker simply used valid credentials to access systems and steal data, then demanded payment to prevent publication.",[181,2368,1773],{"id":1772},[459,2370,2371,2377,2383,2389,2395],{},[101,2372,2373,2376],{},[188,2374,2375],{},"No MFA on remote access."," A username and password were enough for the hacker to access Medibank’s systems. MFA would have added an important barrier and may have prevented or limited the initial access.",[101,2378,2379,2382],{},[188,2380,2381],{},"An unmanaged personal device."," Corporate credentials were synchronised to a personal computer outside Medibank’s managed environment, where malware stole them.",[101,2384,2385,2388],{},[188,2386,2387],{},"Poor alert response."," Detection software generated alerts, but the process for reviewing, triaging and escalating them did not work as intended.",[101,2390,2391,2394],{},[188,2392,2393],{},"One account had very broad access."," The service-desk account had access to \"most, if not all, systems\", so one stolen credential became keys to the whole building.",[101,2396,2397,2400],{},[188,2398,2399],{},"Known weaknesses were not fixed in time."," The OAIC alleges Medibank knew about the security gaps, including the MFA gap, through its cyber security audits, and failed to fix them in time.",[181,2402,1809],{"id":1808},[98,2404,2405,2411,2417,2423,2429,2435,2441],{},[101,2406,2407,2410],{},[188,2408,2409],{},"Direct response and remediation costs reached tens of millions of dollars"," across several financial years, before any final litigation outcomes.",[101,2412,2413,2416],{},[188,2414,2415],{},"Blackmail and ransom demands:"," Medibank refused the US$10M ransom,  and the stolen data was later published.",[101,2418,2419,2422],{},[188,2420,2421],{},"APRA's $250 million capital adequacy adjustment:"," This was not a fine, it required Medibank to hold additional capital until APRA was satisfied with the remediation program.",[101,2424,2425,2428],{},[188,2426,2427],{},"Regulatory and legal scrutiny:"," The ongoing OAIC civil penalty proceedings and a Federal Court class action, still listed as open.",[101,2430,2431,2434],{},[188,2432,2433],{},"Harm to affected people:",": Published information included identity details and sensitive health claims data, creating risks of fraud, scams, blackmail, identity theft and emotional distress for the affected individuals.",[101,2436,2437,2440],{},[188,2438,2439],{},"Wider impact:",": The breach contributed to national debate about privacy, cyber security and ransomware. In 2024, Australia imposed its first cyber sanction in response to the incident.",[101,2442,2443,2446],{},[188,2444,2445],{},"Reputational damage:"," The incident affected customer trust and kept Medibank under public, regulatory and legal scrutiny for years.",[181,2448,2450],{"id":2449},"what-medibank-did-well","What Medibank did well",[91,2452,2453],{},"Although the breach exposed serious weaknesses and early breach figures changed as the incident investigation progressed, several aspects of Medibank’s incident response are worth recognising:",[98,2455,2456,2459,2462,2465,2468,2471],{},[101,2457,2458],{},"Medibank provided frequent public updates as the breach scope became clearer.",[101,2460,2461],{},"It also notified regulators and law-enforcement agencies.",[101,2463,2464],{},"Medibank engaged external cyber incident-response specialists.",[101,2466,2467],{},"It refused to pay ransom, aligning with the Australian Government view.",[101,2469,2470],{},"Medibank also offered support measures, including identity monitoring and hardship support for affected customers",[101,2472,2473],{},"It also committed to remediation and security investment.",[181,2475,2477],{"id":2476},"_10-lessons-for-your-business","10 lessons for your business",[459,2479,2480,2486,2492,2498,2504,2510,2516,2522,2528,2534],{},[101,2481,2482,2485],{},[188,2483,2484],{},"Mandatory MFA."," If one control defines this breach, it's this. Enforce mandatory MFA for VPNs, emails, cloud systems, admin accounts, contractor accounts and third-party support access.",[101,2487,2488,2491],{},[188,2489,2490],{},"Properly manage contractor access."," Administrator access should be role-based rather than universal across internal systems. Privileged access should only be granted when required, time-limited, approved, monitored and reviewed regularly. Contractors should not have privileged access to all systems and databases.",[101,2493,2494,2497],{},[188,2495,2496],{},"Require managed devices for corporate access."," Personal or unmanaged devices should not access sensitive systems unless strong technical controls are in place. Access should be limited to devices that are managed, compliant, patched and monitored.",[101,2499,2500,2503],{},[188,2501,2502],{},"Apply least privilege."," Give each user only the access needed for their role. Review privileged access regularly and remove it when it is no longer required.",[101,2505,2506,2509],{},[188,2507,2508],{},"Strengthen browser and credential security."," Do not allow corporate credentials to be stored in browsers. Use an approved password manager and configure managed browsers to control password saving and profile synchronisation.",[101,2511,2512,2515],{},[188,2513,2514],{},"Every alert needs an owner."," Decide who acts on warnings from your antivirus, bank and software - and how they should respond to them.",[101,2517,2518,2521],{},[188,2519,2520],{},"Reduce sensitive data exposure."," Keep only the information you need, restrict access, separate high-risk data, encrypt it where appropriate and monitor unusual access or large data transfers.",[101,2523,2524,2527],{},[188,2525,2526],{},"Network segmentation."," Consider separating your network into secure zones to reduce access to sensitive data.",[101,2529,2530,2533],{},[188,2531,2532],{},"Act on cyber security findings."," The OAIC alleges that Medibank's cyber security audits flagged the MFA gap. Treat audit findings, penetration-test results and insurer questionnaires as actions with owners, deadlines and management oversight.",[101,2535,2536,2539],{},[188,2537,2538],{},"Train employees and contractors."," Cover secure credential storage, approved password managers, MFA methods, risk of browser synchronisation, phishing methods, incident reporting and how to correctly respond to credential theft attempts.",[181,2541,1941],{"id":1940},[91,2543,2544],{},"While the publicly available information does not provide every technical detail of the Medibank attack, the incident can still be examined using established cyber security frameworks. This can help turn the incident into a structured set of lessons.",[225,2546,2548],{"id":2547},"mitre-attck-helps-understand-the-attackers-behaviours","MITRE ATT&CK helps understand the attacker's behaviours",[98,2550,2551,2557,2563,2568],{},[101,2552,2553,2556],{},[188,2554,2555],{},"Credentials from Web Browsers (T1555.003):"," The OAIC alleges that Medibank credentials saved in a contractor’s work browser profile were synchronised to a personal computer and later stolen by information-stealing malware.",[101,2558,2559,2562],{},[188,2560,2561],{},"External Remote Services (T1133):"," The attacker allegedly used the stolen credentials to connect to Medibank systems through its GlobalProtect VPN.",[101,2564,2565,2567],{},[188,2566,1955],{}," The attacker used an active Medibank administrator account that allowed the login to appear similar to authorised activity.",[101,2569,2570,2572],{},[188,2571,1961],{}," After entering the environment, the attacker allegedly accessed internal systems and databases containing customer identity and health claims information.",[225,2574,2576],{"id":2575},"nist-cybersecurity-framework-20-helps-organise-management-responsibilities","NIST Cybersecurity Framework 2.0 helps organise management responsibilities",[98,2578,2579,2584,2589,2594,2599,2604],{},[101,2580,2581,2583],{},[188,2582,1973],{}," Assign responsibility for cyber security, privacy and third-party access. Set clear security requirements for contractors and ensure that known audit findings are recorded, prioritised and fixed.",[101,2585,2586,2588],{},[188,2587,1979],{}," Know which accounts have broad access, which devices can connect remotely, where sensitive customer information is stored and which systems would create the greatest harm if compromised.",[101,2590,2591,2593],{},[188,2592,1985],{}," Require strong MFA for remote and privileged access. Use managed devices, approved password manager software, least privilege, network segmentation and controls that limit access to sensitive databases.",[101,2595,2596,2598],{},[188,2597,1991],{}," Monitor VPN access, privileged-account activity, unusual devices, large searches or exports and suspicious connections between internal systems. Ensure every important alert has an owner and a defined escalation process.",[101,2600,2601,2603],{},[188,2602,1997],{}," Maintain and test an incident-response plan. It should cover disabling compromised accounts, revoking active sessions, isolating affected systems, investigating alerts, notifying regulators and communicating with affected customers.",[101,2605,2606,2608],{},[188,2607,2003],{}," Restore affected services safely, support affected people, review what went wrong and improve access controls, monitoring, contractor arrangements and incident-response procedures.",[225,2610,2008],{"id":2007},[91,2612,2613],{},"Although the Essential Eight does not cover every issue seen in this breach, it provides a useful Australian technical baseline. The most relevant to Medibank’s breach strategy include:",[98,2615,2616,2621],{},[101,2617,2618,2620],{},[188,2619,2018],{}," Require MFA for VPN access, privileged accounts, contractors and systems holding sensitive information.",[101,2622,2623,2625],{},[188,2624,2024],{}," Give employees and contractors only the access needed for their work. Use separate privileged accounts, review access regularly and remove it when it is no longer required.",[181,2627,2035],{"id":2034},[91,2629,2630],{},"The Medibank breach is sometimes framed as the work of a sophisticated Russian hacker. The practical lesson is simpler: browser-synchronised credentials were stolen from a personal device, remote access did not require MFA for the login method used, an admin account had extensive access, and security alerts were not promptly handled.",[91,2632,2633],{},"Small businesses may have fewer IT and security resources, but the same risks still matter. Know who can access your systems, require MFA, use managed devices, limit each account to the minimum access required, control browser synchronisation and make sure every important security alert has an owner.",[91,2635,2044,2636,2638],{},[104,2637,2047],{"href":37}," to review your current controls and identify practical steps to protect your business.",[181,2640,2052],{"id":2051},[98,2642,2643,2646,2649,2652,2655,2658,2661,2664,2667,2670,2673,2676,2679,2682],{},[101,2644,2645],{},"Office of the Australian Information Commissioner, Civil penalty action against Medibank and the filed concise statement (June 2024).",[101,2647,2648],{},"Australian Prudential Regulation Authority, APRA takes action against Medibank Private in relation to cyber incident” (27 June 2023).",[101,2650,2651],{},"Australian Government - Department of Foreign Affairs and Trade, Cyber sanctions in response to Medibank Private cyber attack (23 January 2024).",[101,2653,2654],{},"Australian Government - Department of Foreign Affairs and Trade, Significant cyber incidents sanctions framework.",[101,2656,2657],{},"Australian Government - Department of Foreign Affairs and Trade — Guidance Note: Cyber sanctions.",[101,2659,2660],{},"Federal Court of Australia, Current class actions - McClure v Medibank Private Limited, VID64\u002F2023.",[101,2662,2663],{},"Medibank, Cybercrime updates published from 13 October to 1 December 2022.",[101,2665,2666],{},"MITRE ATT&CK Enterprise framework, Credentials from Web Browsers, T1555.003.",[101,2668,2669],{},"MITRE ATT&CK Enterprise framework, External Remote Services, T1133.",[101,2671,2672],{},"MITRE ATT&CK Enterprise framework, Valid Accounts, T1078.",[101,2674,2675],{},"MITRE ATT&CK Enterprise framework, Data from Information Repositories, T1213.",[101,2677,2678],{},"National Institute of Standards and Technology, NIST Cybersecurity Framework 2.0.",[101,2680,2681],{},"ASD’s Australian Cyber Security Centre, Essential Eight explained.",[101,2683,2684],{},"ASD’s Australian Cyber Security Centre, Essential Eight maturity model.",{"title":25,"searchDepth":1458,"depth":1458,"links":2686},[2687,2688,2689,2690,2691,2692,2693,2694,2699,2700],{"id":1561,"depth":1458,"text":1562},{"id":1630,"depth":1458,"text":1631},{"id":1738,"depth":1458,"text":1739},{"id":1772,"depth":1458,"text":1773},{"id":1808,"depth":1458,"text":1809},{"id":2449,"depth":1458,"text":2450},{"id":2476,"depth":1458,"text":2477},{"id":1940,"depth":1458,"text":1941,"children":2695},[2696,2697,2698],{"id":2547,"depth":1463,"text":2548},{"id":2575,"depth":1463,"text":2576},{"id":2007,"depth":1463,"text":2008},{"id":2034,"depth":1458,"text":2035},{"id":2051,"depth":1458,"text":2052},"\u002Fcovers\u002Fcyber-security\u002Fbreach-lessons\u002Fmedibank.jpg","How stolen browser-saved credentials, remote access without MFA and missed security alerts contributed to the 2022 Medibank data breach - and what Australian small businesses can learn from it.",[],{},{"description":2706,"title":2132},"How the 2022 Medibank data breach happened & what Australian small businesses can learn about contractor access, browser-saved credentials, MFA and security alerts.","\u002Fcyber-security\u002Fbreach-lessons\u002Fmedibank-breach",11,"Reviewed against public information from the OAIC, APRA, ASD’s Australian Cyber Security Centre, DFAT, Medibank, MITRE ATT&CK and NIST SCF 2.0",{"title":2132,"description":2702},{"loc":2707},"cyber-security\u002Fbreach-lessons\u002Fmedibank-breach","The 2022 Medibank data breach made headlines, but the weaknesses that contributed to it are not unique to large companies. Here are the practical lessons small businesses can take from the incident.",[48,2128],"DrwgvJLPjR03gDBSyfBEqBqmq6B3GAzL3RFiqFrTSww",{"id":2717,"title":2718,"authorBio":2719,"body":2720,"coverImage":3241,"date":2114,"description":3242,"extension":1487,"faq":3243,"heroImage":3241,"lastReviewed":86,"meta":3262,"metadata":3263,"navigation":223,"path":37,"readingTime":2121,"reviewedAgainst":3266,"seo":3267,"sitemap":3268,"stem":3269,"summary":3242,"tags":3270,"thumbnail":3241,"__hash__":3272},"blog\u002Fcyber-security\u002Fsmall-business\u002Fdiy-cyber-security-health-check.md","The DIY Cyber Security Health Check for Small Business","Written by Elena Osipova, CPA, an emerging Cyber Security Practitioner. Elena writes about cyber security governance and practical security controls for Australian small businesses.",{"type":88,"value":2721,"toc":3225},[2722,2725,2731,2737,2743,2746,2750,2761,2807,2810,2830,2834,2841,2845,2848,2887,2891,2921,2925,2963,2967,2999,3004,3008,3017,3028,3031,3073,3080,3087,3091,3094,3097,3120,3124,3127,3130,3139,3148,3152,3155,3166,3169,3183,3185,3187],[91,2723,2724],{},"You don't need a consultant to find many of your most common cyber risks. One structured afternoon can uncover preventable gaps, such as a former employee's active login, a backup that doesn't restore files, or a payment process that trusts email alone.",[91,2726,2727,2730],{},[188,2728,2729],{},"To complete this checklist, allow around three to four hours",". A very small business may finish much sooner, while a business with more users, devices and cloud services may need additional time. You'll need administrator access to Microsoft 365 or Google Workspace, access to your backup system, and a notepad or spreadsheet for recording your findings.",[91,2732,2733,2736],{},[188,2734,2735],{},"The method matters more than the tools: look at evidence, not memory",". “I think only two people have admin access” is an assumption. Opening the admin panel and counting them gives you a fact. Each step below asks you to check an actual setting, process or record.",[91,2738,2739,2742],{},[188,2740,2741],{},"Write down every issue you find",". Unless some findings appear urgent, don’t stop to fix each issue as you go, or you may burn the whole afternoon on the first item. Fixing them comes later, in priority order shown below.",[91,2744,2745],{},"However, act immediately if you find a clear sign of active compromise. Tis includes an unknown account administrator, an unauthorised payment or an email forwarding rule you did not create.",[181,2747,2749],{"id":2748},"step-1-accounts-and-access-60-minutes","Step 1: Accounts and access - 60 minutes",[91,2751,2752,2753,2756,2757,2760],{},"Open the ",[188,2754,2755],{},"Microsoft 365 Admin Centre"," or ",[188,2758,2759],{},"Google Workspace Admin Console"," and check six things:",[98,2762,2763,2769,2783,2789,2795,2801],{},[101,2764,2765,2768],{},[188,2766,2767],{},"The user list."," Read every name. Is anyone no longer with the business but still active? Is there an account you cannot explain? Record former users for removal. Remove unknown users urgently.",[101,2770,2771,2774,2775,2778,2779,2782],{},[188,2772,2773],{},"MFA coverage."," Confirm that every user is required to use MFA and has completed registration. ",[188,2776,2777],{},"In Microsoft 365",", don’t rely only on the legacy per-user MFA status: MFA may instead be enforced through Security Defaults or Conditional Access. Check both - the organisation-wide policy and the users who have registered. ",[188,2780,2781],{},"In Google Workspace",", check 2-Step Verification enrolment and enforcement.",[101,2784,2785,2788],{},[188,2786,2787],{},"Who's an administrator?"," Count the accounts with administrator roles. There should be very few, and you should be able to explain why each person needs that level of access.",[101,2790,2791,2794],{},[188,2792,2793],{},"Guest and external access."," Review guest users, contractors, delegated mailbox access and connected third-party applications. Remove access that is no longer required.",[101,2796,2797,2800],{},[188,2798,2799],{},"Email forwarding rules."," Check the business owner's and finance mailboxes for rules that forward messages outside the business. Cyber criminals who compromise email accounts may create a hidden forwarding rule. It may remain active after the password is changed. Treat anything you do not recognise as urgent.",[101,2802,2803,2806],{},[188,2804,2805],{},"Account recovery."," For owner and administrator accounts, check the recovery email addresses, phone numbers and backup methods. Remove outdated details. Store emergency recovery codes securely and make sure the business - not one employee personally - controls the recovery process.",[91,2808,2809],{},"Other important account checks:",[98,2811,2812,2818,2824],{},[101,2813,2814,2817],{},[188,2815,2816],{},"Email domain protection."," If your business uses its own email domain, ask your email provider or IT administrator to confirm that SPF, DKIM and DMARC are configured correctly. These help other email systems recognise messages that falsely claim to come from your domain.",[101,2819,2820,2823],{},[188,2821,2822],{},"Domain-name protection."," Sign in to your domain registrar and confirm that your business controls the account, MFA is turned on, the recovery details are current and automatic renewal is enabled. Losing control of your domain can affect your website, email and password resets.",[101,2825,2826,2829],{},[188,2827,2828],{},"Passwords and shared accounts."," Check whether staff reuse passwords or share one login. Each person should have their own account. All important accounts should use unique passwords stored in a reputable password manager.",[225,2831,2833],{"id":2832},"evidence-to-keep","Evidence to keep",[91,2835,2836,2837,2840],{},"Export or screenshot the user list and MFA report. Date it. ",[188,2838,2839],{},"This is your baseline"," for next time. Store this user list securely as it contains personal information and details that could help a cyber criminal.",[181,2842,2844],{"id":2843},"step-2-money-paths-30-minutes","Step 2: Money paths - 30 minutes",[91,2846,2847],{},"Review your actual payment process and recent examples:",[98,2849,2850,2860,2881],{},[101,2851,2852,2855,2856,2859],{},[188,2853,2854],{},"How do suppliers change their bank details?"," If the answer is \"by email\", record it as a finding. ",[188,2857,2858],{},"Never accept new or changed payment details without confirming the request through a separate, trusted channel."," For example, call the supplier using a phone number you already have, not a phone number provided in the email.",[101,2861,2862,2865,2866,2869,2870,1184,2873,2876,2877,2880],{},[188,2863,2864],{},"Can one person create and approve payments alone?"," Where separation of duties is not practical, use several compensating controls: ",[188,2867,2868],{},"independent verification"," of new or changed payment details, ",[188,2871,2872],{},"bank transaction limits",[188,2874,2875],{},"payment alerts"," and a ",[188,2878,2879],{},"regular review of payments"," by another owner, director or trusted adviser.",[101,2882,2883,2886],{},[188,2884,2885],{},"Does your banking show information about the recipient before you approve a payment?"," This may include an account-name check, PayID name or Confirmation of Payee result. Make sure whoever pays invoices understands the message,but does not use it as a substitute for independently confirming changed payment details.",[181,2888,2890],{"id":2889},"step-3-backups-and-cloud-systems-30-minutes","Step 3: Backups and cloud systems - 30 minutes",[98,2892,2893,2899,2905,2915],{},[101,2894,2895,2898],{},[188,2896,2897],{},"What is actually backed up?"," Name the systems and information your business could not operate without. Examples may include accounting and payroll records, client files, email, customer databases, contracts, website data, source code, project files, important system settings and more. Confirm that each one is included in the backup, not just \"the computer\".",[101,2900,2901,2904],{},[188,2902,2903],{},"Is one backup copy protected?"," A permanently connected drive or a synchronised folder like OneDrive or Google Drive should not be your only backup. Deleted, encrypted, damaged files or ransomware may be synchronised across devices. Check whether your service offers separate version history or recovery features.",[101,2906,2907,2910,2911,2914],{},[188,2908,2909],{},"Restore one real file now."," Pick any recent document from your backup, restore it and open it. ",[188,2912,2913],{},"This may be the highest-value ten minutes of the whole health check",". A backup that has never been tested is only an assumption. If the restore fails, you have discovered the problem before a real emergency.",[101,2916,2917,2920],{},[188,2918,2919],{},"Critical cloud systems."," List the online services your business relies on. Examples may include accounting, payroll, CRM, website hosting and document storage. Confirm who owns each account, who has administrator access, and what recovery or export options are available.",[181,2922,2924],{"id":2923},"step-4-devices-and-updates-30-minutes","Step 4: Devices and updates - 30 minutes",[98,2926,2927,2933,2939,2945,2951,2957],{},[101,2928,2929,2932],{},[188,2930,2931],{},"Is every work computer and phone supported and automatically updating?"," Check whether the operating system is still receiving updates, and whether automatic updates are on. Put anything that no longer receives security updates on the replacement list - it cannot be protected to the same standard as a supported device.",[101,2934,2935,2938],{},[188,2936,2937],{},"Are laptops encrypted?"," Check whether BitLocker on Windows or FileVault on Mac is turned on.",[101,2940,2941,2944],{},[188,2942,2943],{},"Is computer protection working?"," Check that antivirus or other built-in security protection is turned on and up to date.",[101,2946,2947,2950],{},[188,2948,2949],{},"Do devices lock automatically?"," Make sure computers and phones lock after a short period of inactivity and require a strong password, passcode, PIN or biometric sign-in.",[101,2952,2953,2956],{},[188,2954,2955],{},"Does each person have their own login?"," Ensure that staff do not share accounts and do not use an administrator account for everyday work.",[101,2958,2959,2962],{},[188,2960,2961],{},"Lost phones."," If a phone with company email went missing today, could you wipe it remotely? If you don't know, the answer is no.",[181,2964,2966],{"id":2965},"step-5-people-and-paper-30-minutes","Step 5: People and paper - 30 minutes",[98,2968,2969,2975,2987],{},[101,2970,2971,2974],{},[188,2972,2973],{},"Offboarding checklist."," Is there a written checklist removing a departing employee or contractor’s access to every business system? If not, create one using the user list from Step 1.",[101,2976,2977,2980,2981,2983,2984,2986],{},[188,2978,2979],{},"The two rules for staff."," Make sure everyone who works with email or payments knows these rules:",[290,2982],{},"\n1 - Never approve an MFA prompt you didn't request. Repeated unexpected prompts may mean that someone already has your password.",[290,2985],{},"\n2 - Never change suppliers’ bank details based on an email alone. Confirm the changes by calling a trusted phone number you already have.",[101,2988,2989,2992,2993,2998],{},[188,2990,2991],{},"The incident card."," Print one page with your bank's fraud number, the Australian Cyber Security Hotline 1300 CYBER1 (1300 292 371) - it’s available 24\u002F7, and the ",[104,2994,2997],{"href":2995,"rel":2996},"https:\u002F\u002Fwww.cyber.gov.au\u002Freport-and-recover\u002Fwhere-get-help",[211],"ReportCyber"," web address. Also include your cyber insurer and policy number, IT or incident-response provider, legal or privacy adviser, authorised decision-maker, domain registrar and website host. Keep this card somewhere accessible if your systems are unavailable.",[197,3000,3001],{},[91,3002,3003],{},"If you suspect an active incident, stop the health check and seek professional assistance. Do not delete files, messages or logs that may be evidence. Where safe to do so, disconnect an affected computer from Wi-Fi or the network without wiping or resetting it.",[181,3005,3007],{"id":3006},"step-6-official-checks-and-your-findings-20-minutes","Step 6: Official checks and your findings - 20 minutes",[91,3009,3010,3011,3016],{},"Finish with the Australian government’s free and anonymous ",[104,3012,3015],{"href":3013,"rel":3014},"https:\u002F\u002Fwww.cyber.gov.au\u002Fcyberhealthcheck",[211],"Cyber Health Check Tool",". It takes about five minutes and provides simple, tailored suggestions that you can compare with your findings.",[197,3018,3019],{},[91,3020,3021,3022,3027],{},"For a deeper follow-up with your team, use the ACSC's free ",[104,3023,3026],{"href":3024,"rel":3025},"https:\u002F\u002Fwww.cyber.gov.au\u002Fbusiness-government\u002Fexercise-in-a-box",[211],"Exercise in a Box",".  It provides practical exercises to help you test how your business would respond to a cyber incident.",[91,3029,3030],{},"Turn your notes into an action plan. Use one row for each finding and four columns:",[1633,3032,3033,3057],{},[1636,3034,3035],{},[1639,3036,3037,3042,3047,3052],{},[1642,3038,3039],{},[188,3040,3041],{},"Finding",[1642,3043,3044],{},[188,3045,3046],{},"Risk",[1642,3048,3049],{},[188,3050,3051],{},"Fix",[1642,3053,3054],{},[188,3055,3056],{},"Who \u002F by when",[1653,3058,3059],{},[1639,3060,3061,3064,3067,3070],{},[1658,3062,3063],{},"2 staff accounts do not have MFA",[1658,3065,3066],{},"A stolen password could allow someone to access business email",[1658,3068,3069],{},"Enforce MFA",[1658,3071,3072],{},"Me \u002F Friday",[91,3074,3075,3076,3079],{},"That simple table is the beginning of a practical ",[188,3077,3078],{},"cyber security risk register",". Over time, you can add the severity of the risk, status and date reviewed.",[91,3081,3082,3083,3086],{},"For most small businesses, repeating this ",[188,3084,3085],{},"check every three months"," is a practical starting point. Run it sooner after an employee departure, major system change or suspected incident.",[225,3088,3090],{"id":3089},"prioritise-your-findings-or-what-should-i-fix-first-after-the-health-check","Prioritise your findings, or what should I fix first after the health check?",[91,3092,3093],{},"Deal immediately with any sign of active compromise. Examples may include an unknown administrator, unexplained email forwarding rule, unfamiliar login or unauthorised payment.",[91,3095,3096],{},"For other findings, a practical starting order is:",[459,3098,3099,3102,3105,3108,3111,3114,3117],{},[101,3100,3101],{},"Protect administrator, email and financial accounts with MFA.",[101,3103,3104],{},"Disable former users who still have access.",[101,3106,3107],{},"Confirm that critical information can be restored from backup.",[101,3109,3110],{},"Strengthen payment verification and approval controls.",[101,3112,3113],{},"Update devices and software.",[101,3115,3116],{},"Replace unsupported devices and software.",[101,3118,3119],{},"Address the remaining findings according to their likely business impact.",[181,3121,3123],{"id":3122},"when-diy-isnt-enough","When DIY isn't enough",[91,3125,3126],{},"This health check can identify common security gaps, but it does not test your systems for technical weaknesses. Seek professional help if there’s a suspected cyber security incident, when important findings remain unfixed, when your business needs technical security testing, or when it holds sensitive or high-risk information such as health records, identity documents, TFNs or financial details.",[91,3128,3129],{},"Most Australian businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but important exceptions apply. For example, some health service providers, businesses that trade in personal information and certain Commonwealth contractors may be covered regardless of turnover.",[91,3131,3132,3133,3138],{},"Check the ",[104,3134,3137],{"href":3135,"rel":3136},"https:\u002F\u002Fwww.oaic.gov.au\u002Fprivacy\u002Fprivacy-guidance-for-organisations-and-government-agencies\u002Forganisations\u002Fsmall-business#section-privacy-checklist-for-small-business",[211],"OAIC’s Small Business Privacy Checklist"," or obtain legal advice if you are unsure whether the Privacy Act applies to your business",[91,3140,3141,3142,3147],{},"When engaging a cyber security provider, ask what framework and assessment method they will use. Depending on your systems and risks, an ",[104,3143,3146],{"href":3144,"rel":3145},"https:\u002F\u002Fwww.cyber.gov.au\u002Fbusiness-government\u002Fasds-cyber-security-frameworks\u002Fessential-eight",[211],"Essential Eight"," assessment - often beginning with Maturity Level One - may provide a structured and comparable baseline.",[225,3149,3151],{"id":3150},"cant-spare-a-whole-afternoon","Can't spare a whole afternoon?",[91,3153,3154],{},"Do the ten-minute version:",[459,3156,3157,3160,3163],{},[101,3158,3159],{},"Check that MFA protects the owner's email account.",[101,3161,3162],{},"Explain the payment-verification rule to anyone who pays invoices.",[101,3164,3165],{},"Restore one file from backup.",[3167,3168],"hr",{},[91,3170,3171],{},[3172,3173,3174,3175,3178,3179,488],"em",{},"This article is part of our ",[104,3176,3177],{"href":31},"cyber security for small businesses"," series - including ",[104,3180,3182],{"href":3181},"\u002Fcyber-security\u002Fsmall-business\u002Fwhy-hackers-target-accounting-firms","why hackers target accounting firms",[3167,3184],{},[181,3186,2052],{"id":2051},[98,3188,3189,3192,3195,3198,3201,3204,3207,3210,3213,3216,3219,3222],{},[101,3190,3191],{},"ASD’s ACSC, Cyber Health Check Tool",[101,3193,3194],{},"ASD’s ACSC, Small Business Cyber Security Guide",[101,3196,3197],{},"ASD’s ACSC, Small Business Hub",[101,3199,3200],{},"ASD’s ACSC, Preventing Business Email Compromise",[101,3202,3203],{},"ASD’s ACSC, Review Your Email Account Security",[101,3205,3206],{},"ASD’s ACSC, Exercise in a Box",[101,3208,3209],{},"ASD’s ACSC, Essential Eight",[101,3211,3212],{},"ASD’s ACSC, Cybercrime - getting help",[101,3214,3215],{},"business.gov.au, Cyber Security Checklist",[101,3217,3218],{},"OAIC, Small Business and the Privacy Act",[101,3220,3221],{},"Microsoft Learn, relevant current MFA administration guidance",[101,3223,3224],{},"Google Workspace Admin Help, relevant 2-Step Verification guidance",{"title":25,"searchDepth":1458,"depth":1458,"links":3226},[3227,3230,3231,3232,3233,3234,3237,3240],{"id":2748,"depth":1458,"text":2749,"children":3228},[3229],{"id":2832,"depth":1463,"text":2833},{"id":2843,"depth":1458,"text":2844},{"id":2889,"depth":1458,"text":2890},{"id":2923,"depth":1458,"text":2924},{"id":2965,"depth":1458,"text":2966},{"id":3006,"depth":1458,"text":3007,"children":3235},[3236],{"id":3089,"depth":1463,"text":3090},{"id":3122,"depth":1458,"text":3123,"children":3238},[3239],{"id":3150,"depth":1463,"text":3151},{"id":2051,"depth":1458,"text":2052},"\u002Fcovers\u002Fcyber-security\u002Fsmall-business\u002Fdiy-cyber-security-health-check.jpg","A practical, jargon-free cyber security checklist you can complete this afternoon to see where your business is exposed - no IT department required.",[3244,3247,3250,3253,3256,3259],{"question":3245,"answer":3246},"Can a small business complete a cyber security health check without an IT provider?","Yes. A business owner or manager can check common risks, including inactive accounts, missing MFA, untested backups, unsupported devices and unsafe payment processes. Please note that a DIY review does not test networks, applications or systems for technical vulnerabilities.",{"question":3248,"answer":3249},"Do I need an IT background to run a cyber security health check?","No. You need admin access to your Microsoft 365 or Google Workspace, your backup system login, and a notepad. Follow the cyber security checklist steps and write down your findings to act on them later.",{"question":3251,"answer":3252},"Is OneDrive or Google Drive a backup?","File synchronisation may help recover earlier files, but a synchronised folder should not be your business’ only backup. Deletions, damaged files or ransomware may be synchronised across devices. Keep a separate protected backup and regularly test that you can restore files from it.",{"question":3254,"answer":3255},"How often should a small business run a cyber security health check?","Every three months is a practical starting point. Run the check sooner if there is a major change, such as a staff departure, the introduction of new software, a change of IT provider or a suspected cyber security incident.",{"question":3257,"answer":3258},"Is there a free government cyber security assessment for small businesses?","Yes. The Cyber Health Check Tool on cyber.gov.au is free and anonymous. It provides tailored suggestions based on your answers. The ACSC's free Exercise in a Box can help your team practice responding to realistic cyber incident scenarios.",{"question":3260,"answer":3261},"When should a business get professional cyber security help?","Seek professional help after a suspected cyber security incident, when important security issues remain unresolved, when a technical testing is required, or when your business holds sensitive or high-risk information, such as health records, identity documents, tax file numbers or financial details. Most Australian small businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but important exceptions apply. Obtain privacy or legal advice if you are unsure whether the Privacy Act applies to your business.",{},{"description":3264,"title":3265},"A plain-English cyber security checklist Australian small businesses can complete themselves, with practical steps and no IT department required.","DIY Cyber Security Health Check for Small Business","Reviewed against current guidance from ASD’s Australian Cyber Security Centre, business.gov.au, the OAIC, Microsoft and Google",{"title":2718,"description":3242},{"loc":37},"cyber-security\u002Fsmall-business\u002Fdiy-cyber-security-health-check",[48,3271],"Small Business","Nhqi3lLVSDN8wAzFS-1zxT1E-fupXjMiRnQ7gSAcOXw",{"id":3274,"title":3275,"authorBio":3276,"body":3277,"coverImage":3750,"date":2114,"description":3751,"extension":1487,"faq":3752,"heroImage":3750,"lastReviewed":86,"meta":3765,"metadata":3766,"navigation":223,"path":3181,"readingTime":3768,"reviewedAgainst":3769,"seo":3770,"sitemap":3771,"stem":3772,"summary":3773,"tags":3774,"thumbnail":3750,"__hash__":3775},"blog\u002Fcyber-security\u002Fsmall-business\u002Fwhy-hackers-target-accounting-firms.md","Why Hackers Target Accounting Firms and How to Reduce the Risk","Written by Elena Osipova, CPA and emerging cyber security practitioner. Drawing on her accounting and business experience, Elena writes about cyber security governance, real-world incidents and practical security controls for Australian small businesses.",{"type":88,"value":3278,"toc":3738},[3279,3282,3285,3288,3291,3294,3298,3301,3346,3349,3352,3355,3359,3362,3365,3374,3378,3381,3401,3404,3408,3411,3415,3418,3450,3454,3457,3592,3596,3602,3608,3614,3620,3625,3629,3686,3689,3691],[91,3280,3281],{},"In May 2025, the Qilin ransomware group listed Melbourne accounting practice MKA Accountants on its darknet leak site. The group published 12 sample documents it claimed were taken from the firm, including financial statements, insurance information and internal correspondence.",[91,3283,3284],{},"MKA Accountants confirmed that it was investigating unauthorised access and had notified clients and relevant authorities, including the Australian Cyber Security Centre (ACSC) and the Office of the Australian Information Commissioner (OAIC). Later reports said Qilin claimed to have released more than 185GB of data, although the exact volume was not independently confirmed.",[91,3286,3287],{},"In May 2026, Brisbane accounting firm Kennedy McLaughlin & Associates confirmed unauthorised access to part of its IT environment after the same ransomware group listed it on their darknet leak site. Cyber Daily reported that a dataset containing client financial details and banking information appeared to have been published. The firm said it had notified affected individuals, the ACSC and the OAIC about this incident.",[91,3289,3290],{},"These were not large organisations. They were local accounting practices - the kind of businesses that hold tax and financial records, payroll and identity document information for many clients.",[91,3292,3293],{},"That set of valuable information is exactly what makes accounting firms attractive targets to cyber criminals.",[181,3295,3297],{"id":3296},"why-accounting-firms-are-valuable-targets","Why accounting firms are valuable targets",[91,3299,3300],{},"Cybercriminals may target an accounting firm for money, but the greater attraction is often the client information and trusted access the firm holds for every client, going back years. This may include:",[98,3302,3303,3308,3313,3318,3324,3330,3335,3340],{},[101,3304,3305],{},[188,3306,3307],{},"Tax file numbers",[101,3309,3310],{},[188,3311,3312],{},"Bank account details",[101,3314,3315],{},[188,3316,3317],{},"Financial statements",[101,3319,3320,3323],{},[188,3321,3322],{},"Payroll data"," such as clients’ employee names, addresses, salaries, bank and superannuation details",[101,3325,3326,3329],{},[188,3327,3328],{},"Identity documents information"," collected for verification",[101,3331,3332],{},[188,3333,3334],{},"Director ID numbers",[101,3336,3337],{},[188,3338,3339],{},"Trust, company and superannuation fund account details",[101,3341,3342,3345],{},[188,3343,3344],{},"Tax and lodgement access information"," like practice-management software, online services for agents, myID-linked access and authorisations that allow staff to act for their clients.",[91,3347,3348],{},"Together, these records can provide enough information for identity theft, tax fraud, and various elaborate, targeted scams.",[91,3350,3351],{},"Accounting and professional service firms are regularly affected by reportable data breaches. In 2025, the OAIC received 1,205 data breach notifications. Legal, accounting and management services accounted for 81 notifications, or approximately 6.7% of the total. This placed the combined sector among the five highest by notification volume.",[91,3353,3354],{},"The information held by accountants for their clients can be used for identity crime, refund fraud and highly convincing scams.",[181,3356,3358],{"id":3357},"what-information-attackers-want","What information attackers want",[91,3360,3361],{},"A stolen TFN isn't just sold once - it's put to work. Cybercriminals have used stolen identities to create fake myGov accounts, link them to real taxpayers' ATO records, then lodge fraudulent tax returns and activity statements and redirect the refunds.",[91,3363,3364],{},"In the two years to February 2023, the ATO cancelled more than 37,000 fraudulent tax returns and business activity statements with a claimed value of $557.8 million. This affected more than 15,000 taxpayers. Some claims were stopped before payment, and the ATO could not attribute the entire amount of claims to a single fraud method.",[91,3366,3367,3368,3373],{},"In February 2024, the ATO said it was defending its websites, services and infrastructure against an average of 4.7 million attempted cyber attacks each month. The ATO maintains the dedicated ",[104,3369,3372],{"href":3370,"rel":3371},"https:\u002F\u002Fwww.ato.gov.au\u002Fonline-services\u002Fscams-cyber-safety-and-identity-protection\u002Fhelp-with-data-breaches\u002Fdata-breach-guidance-for-tax-professionals",[211],"data breach guidance for tax professionals"," so firms can report incidents quickly when client identities, tax information or agent access may have been compromised.",[181,3375,3377],{"id":3376},"how-cyber-attacks-commonly-happen","How cyber attacks commonly happen",[91,3379,3380],{},"Three common attack paths show how a cyber incident may unfold:",[459,3382,3383,3389,3395],{},[101,3384,3385,3388],{},[188,3386,3387],{},"Phishing and email takeover."," An employee receives a convincing email prompting them to enter their username and password on a fake but look-alike Microsoft 365 login page. The attacker gets the access and reads the mailbox for weeks, downloads client records, and uses the trusted address to send invoice-redirection emails to clients.",[101,3390,3391,3394],{},[188,3392,3393],{},"Ransomware with data theft."," An attacker gains access, quietly copies information, may then encrypt systems before threatening to publish the stolen data. The MKA Accountants and Kennedy McLaughlin & Associates incidents were publicly associated with this type of attack. Paying a ransom does not guarantee that stolen data will be deleted or kept private.",[101,3396,3397,3400],{},[188,3398,3399],{},"Credential theft against practice software and portals."," Stolen logins for practice management systems or lodgement services give cybercriminals the same reach the practice has - across every client at once.",[91,3402,3403],{},"Highly sophisticated hacking is not always required. Many incidents begin with a stolen password, a phishing message, an unpatched system or access that should have been removed.",[181,3405,3407],{"id":3406},"what-a-breach-can-cost","What a breach can cost",[91,3409,3410],{},"In 2024-25, the average self-reported financial loss per cybercrime report from a small business was approximately $56,600, 14% higher than the previous year.",[181,3412,3414],{"id":3413},"legal-and-professional-obligations","Legal and professional obligations",[91,3416,3417],{},"For an accounting practice, stolen money and ransomware demands are only the beginning. A data breach triggers a stack of obligations that most other small businesses never face. These may include:",[98,3419,3420,3426,3432,3438,3444],{},[101,3421,3422,3425],{},[188,3423,3424],{},"Privacy Act and Notifiable Data Breaches scheme."," Many small accounting practices are TFN recipients and may have Privacy Act obligations for the TFN information they hold, even when annual turnover is $3 million or less. They must notify the OAIC and affected individuals when the breach meets the legal test for an eligible data breach, including that it is likely to cause serious harm.",[101,3427,3428,3431],{},[188,3429,3430],{},"Tax Practitioners Board."," Registered tax practitioners must report a significant breach of the Code of Professional Conduct to the TPB within 30 days of when they know, or ought to know that the breach occurred. A cyber incident may trigger this obligation if it involves a significant breach of duties such as client confidentiality or causes, or is likely to cause material loss or damage. Whether reporting is required depends on the circumstances.",[101,3433,3434,3437],{},[188,3435,3436],{},"ATO notification."," Where client identities, TFNs, tax records or agent access may have been compromised, accounting firms should promptly contact the ATO, so it can assess and apply appropriate protections.",[101,3439,3440,3443],{},[188,3441,3442],{},"Professional standards."," Members of professional accounting bodies, such as CPA Australia, may also have confidentiality obligations under APES 110, the Code of Ethics for Professional Accountants. Registered tax practitioners have separate confidentiality obligations under the TPB Code of Professional Conduct. A failure to take reasonable safeguards may also raise professional and ethical issues, depending on the circumstances.",[101,3445,3446,3449],{},[188,3447,3448],{},"Reputational damage and client attrition."," Clients trust their accountants with everything. A public data leak can cause lasting damage to client trust and the firm’s reputation.",[181,3451,3453],{"id":3452},"controls-that-reduce-the-risk","Controls that reduce the risk",[91,3455,3456],{},"The following controls help reduce the risks discussed above. And most of them are low effort.",[1633,3458,3459,3478],{},[1636,3460,3461],{},[1639,3462,3463,3468,3473],{},[1642,3464,3465],{},[188,3466,3467],{},"Control",[1642,3469,3470],{},[188,3471,3472],{},"Risk it reduces",[1642,3474,3475],{},[188,3476,3477],{},"Effort",[1653,3479,3480,3491,3501,3512,3522,3532,3542,3552,3562,3572,3582],{},[1639,3481,3482,3485,3488],{},[1658,3483,3484],{},"MFA on email, practice software and tax-related accounts",[1658,3486,3487],{},"Account takeover after password theft",[1658,3489,3490],{},"Low",[1639,3492,3493,3496,3499],{},[1658,3494,3495],{},"Password manager and strong, unique passwords",[1658,3497,3498],{},"Password reuse and credential-stuffing attacks",[1658,3500,3490],{},[1639,3502,3503,3506,3509],{},[1658,3504,3505],{},"Protected backup copy",[1658,3507,3508],{},"Loss of all recoverable copies during ransomware",[1658,3510,3511],{},"Medium",[1639,3513,3514,3517,3520],{},[1658,3515,3516],{},"Segregation of payment duties and independent verification of changed payment details",[1658,3518,3519],{},"Invoice and payment-redirection fraud",[1658,3521,3490],{},[1639,3523,3524,3527,3530],{},[1658,3525,3526],{},"Practical staff training on phishing, unexpected MFA prompts and payment changes",[1658,3528,3529],{},"Staff responding to phishing, unexpected MFA prompts and approving fake payment requests",[1658,3531,3490],{},[1639,3533,3534,3537,3540],{},[1658,3535,3536],{},"Automatic security updates on operating systems and practice software",[1658,3538,3539],{},"Exploitation of known vulnerabilities in unpatched software",[1658,3541,3490],{},[1639,3543,3544,3547,3550],{},[1658,3545,3546],{},"Regular access reviews and offboarding checklist for staff",[1658,3548,3549],{},"Unnecessary access and active former-staff access",[1658,3551,3490],{},[1639,3553,3554,3557,3560],{},[1658,3555,3556],{},"Regular review of third-party, contractor and connected-app access",[1658,3558,3559],{},"Unnecessary access by old providers, contractors or connected apps",[1658,3561,3511],{},[1639,3563,3564,3567,3570],{},[1658,3565,3566],{},"Sign-in and administrator alerts",[1658,3568,3569],{},"Undetected misuse of compromised accounts",[1658,3571,3511],{},[1639,3573,3574,3577,3580],{},[1658,3575,3576],{},"Data retention and secure deletion",[1658,3578,3579],{},"Unnecessary exposure of old client records and identity documents",[1658,3581,3511],{},[1639,3583,3584,3587,3590],{},[1658,3585,3586],{},"Tested incident-response plan",[1658,3588,3589],{},"Delayed containment and missed reporting steps",[1658,3591,3511],{},[225,3593,3595],{"id":3594},"four-controls-worth-a-closer-look","Four controls worth a closer look",[91,3597,3598,3601],{},[188,3599,3600],{},"Review what you keep."," Retain records for the periods required by law and professional standards, but securely delete duplicate files, outdated identity documents and other information when there is no longer legal, professional or business reason to keep it. Holding less unnecessary information reduces the potential impact of a breach.",[91,3603,3604,3607],{},[188,3605,3606],{},"Review connected services."," Check which cloud platforms, software integrations, contractors and service providers can access client information. Remove unused and unnecessary connections, confirm who has administrator access and understand how each provider protects and backs up your data.",[91,3609,3610,3613],{},[188,3611,3612],{},"Train staff on real warning signs."," Make sure employees know how to recognise suspicious login pages, unexpected MFA prompts and urgent payment requests. They should know who to contact and what to do before clicking, approving a prompt or making a payment.",[91,3615,3616,3619],{},[188,3617,3618],{},"Protect at least one backup copy."," Keep one backup offline, immutable or otherwise protected from normal user accounts and devices. Test regularly that important files can be restored from it.",[91,3621,2044,3622,3624],{},[104,3623,2047],{"href":37}," for a structured review of your accounts, payments, backups, devices and business processes.",[181,3626,3628],{"id":3627},"five-actions-to-take-this-week","Five actions to take this week",[459,3630,3631,3637,3656,3662,3668],{},[101,3632,3633,3636],{},[188,3634,3635],{},"Turn on MFA"," for every supported business account, beginning with email, administrator, financial and tax-related accounts. Where available, use phishing-resistant methods like passkeys or security keys.",[101,3638,3639,3642],{},[188,3640,3641],{},"Give staff two clear rules:",[459,3643,3644,3650],{},[101,3645,3646,3649],{},[188,3647,3648],{},"Never approve an MFA prompt they did not request",". An unexpected prompt may mean someone is trying to access the account.",[101,3651,3652,3655],{},[188,3653,3654],{},"Never change payment details based on an email alone",". Confirm the request by calling a trusted phone number already held by the firm.",[101,3657,3658,3661],{},[188,3659,3660],{},"Enable automatic security updates where supported."," Keep computers, servers, browsers, practice software, remote access tools and internet-facing devices protected against known vulnerabilities.",[101,3663,3664,3667],{},[188,3665,3666],{},"Review your user list."," Check every account and access role. Promptly disable accounts belonging to former staff. Treat any unknown or suspicious account as urgent.",[101,3669,3670,3673,3674,3677,3678,3681,3682,3685],{},[188,3671,3672],{},"Print your incident contacts."," Include the ATO's ",[104,3675,3372],{"href":3370,"rel":3676},[211],", the OAIC, the TPB, ",[104,3679,2997],{"href":2995,"rel":3680},[211]," and the Australian Cyber Security Hotline ",[188,3683,3684],{},"1300 CYBER1 (1300 292 371)",". You should also include your IT or incident-response provider; cyber insurer and policy number; legal or privacy adviser; authorised decision-maker.",[91,3687,3688],{},"Cybercriminals target accounting firms because the information and access they hold can be highly valuable. The good news is that you can strengthen your defences  with basic, consistent controls to make many common attack paths much harder.",[181,3690,2052],{"id":2051},[98,3692,3693,3696,3699,3702,3705,3708,3711,3714,3717,3720,3723,3726,3729,3732,3735],{},[101,3694,3695],{},"ASD, Annual Cyber Threat Report 2024-25",[101,3697,3698],{},"OAIC, Data breach notifications increase to all-time high in 2025",[101,3700,3701],{},"OAIC, Quick reference guide for responding to data breaches",[101,3703,3704],{},"OAIC, The Privacy (Tax File Number) Rule 2015 and the protection of TFN information",[101,3706,3707],{},"ATO, Agent checklist for client-to-agent linking process",[101,3709,3710],{},"ATO, Accessing Online services for agents",[101,3712,3713],{},"ATO, Data breach guidance for tax professionals",[101,3715,3716],{},"Australian Government, Privacy (Tax File Number) Rule 2015",[101,3718,3719],{},"TPB, Breach reporting obligations;",[101,3721,3722],{},"TPB, Protect your practice from cyber-attacks",[101,3724,3725],{},"TPB, Debunking myths about breach reporting",[101,3727,3728],{},"iTnews, ATO attackers filed $557 million in false claims",[101,3730,3731],{},"Cyber Daily, MKA Accountants confirms Qilin ransomware attack",[101,3733,3734],{},"Cyber Daily, Kennedy McLaughlin confirms cyber incident",[101,3736,3737],{},"ABC, Outgoing ATO boss says getting rid of work-related tax deductions would be a 'big step'",{"title":25,"searchDepth":1458,"depth":1458,"links":3739},[3740,3741,3742,3743,3744,3745,3748,3749],{"id":3296,"depth":1458,"text":3297},{"id":3357,"depth":1458,"text":3358},{"id":3376,"depth":1458,"text":3377},{"id":3406,"depth":1458,"text":3407},{"id":3413,"depth":1458,"text":3414},{"id":3452,"depth":1458,"text":3453,"children":3746},[3747],{"id":3594,"depth":1463,"text":3595},{"id":3627,"depth":1458,"text":3628},{"id":2051,"depth":1458,"text":2052},"\u002Fcovers\u002Fcyber-security\u002Fsmall-business\u002Fwhy-hackers-target-accounting-firms.jpg","Learn why accounting firms attract cybercriminals and the practical steps small practices can take to protect client data and reduce cyber risk.",[3753,3756,3759,3762],{"question":3754,"answer":3755},"Why would hackers target a small accounting firm instead of a big company","A small accounting firm may hold the same kinds of valuable client information as a big company, including TFNs, payroll records, bank details and identity documents. At the same time, smaller firms may have fewer dedicated IT and security resources. This combination can make them attractive to cybercriminals.",{"question":3757,"answer":3758},"Does the Privacy Act apply to my accounting practice if turnover is under $3 million?","Under the Privacy (Tax File Number) Rule 2015, many accounting practices with annual turnover of $3 million or less still have Privacy Act obligations because they receive and hold TFN information. If a breach is likely to cause serious harm, the practice may need to notify the OAIC and affected individuals under the Notifiable Data Breaches scheme. Other Privacy Act exceptions may also apply. Obtain legal or privacy advice for your circumstances.",{"question":3760,"answer":3761},"What is the single most effective protection for an accounting firm?","Multi-factor authentication (MFA) is one of the most important protections for administrator, email, practice management software and tax-related accounts. It adds another layer of protection when a password is stolen or phished.",{"question":3763,"answer":3764},"What should an accounting firm do immediately after discovering a data breach?","Where safe and appropriate, disconnect an affected computer from Wi-Fi or the network without wiping or resetting it, and seek qualified IT or incident-response support. Contact the ATO promptly if client tax information or agent access may be affected. The firm should then assess its notification obligations. These may include notifying the OAIC and affected individuals under the Notifiable Data Breaches scheme, the TPB where a significant Code of Professional Conduct breach may have occurred; professional associations, insurers, and other affected parties",{},{"description":3751,"title":3767},"Why Hackers Target Accounting Firms & How to Reduce the Risk",9,"Reviewed against current guidance from ASD’s Australian Cyber Security Centre, the OAIC, business.gov.au, the ATO and TPB",{"title":3275,"description":3751},{"loc":3181},"cyber-security\u002Fsmall-business\u002Fwhy-hackers-target-accounting-firms","Accounting firms hold the keys to their clients' finances - which is exactly why they're such an attractive target for cybercriminals. Here's what makes them vulnerable, and how to close the cyber security gaps.",[48,3271],"JKrfW2SpuQSHKmIm97ylyA-qvnCXZppsJchpqGZpN5c",1785204198119]