Skip to main content

A/NZ Companies Not Changing Data Management Despite Multiple Breaches

The majority of organizations across Australia and New Zealand (A/NZ) breached over the last year had personally identifiable information (PII) compromised, but most have not yet modified their data management policies, according to the Cybersecurity and PII Report from ManageEngine, the enterprise IT management division of Zoho Corporation.


The survey respondents who had reported their organization experienced between one and five data breaches in the past 12 months said PII was involved in 51% of instances. Despite this, of the respondents who can comment on PII and are aware of major data breaches, the majority (54%) reported either no changes in PII management following the breaches or said they were unaware of any changes. Further, 42% said they have not been advised of their organization's protocols around PII management.

When it came to data categories, 55% of respondents said they store data on past customers, 41% on past employees, 70% on current customers, 66% on current employees and 37% on potential customers.

Vinayak Sreedhar, ManageEngine's country manager for Australia, said the findings highlight alarming gaps in Australia's cybersecurity preparedness. "One year ago, a string of high-profile breaches saw millions of Australians have their data compromised, with identification points traded on the dark web,” he said. "This prompted discussions around the legal right to request the erasure of personal information in company databases. The law is yet to change in Australia and, as this survey indicates, local organizations have not changed their practices."

When it came to cyber resilience, 24% of survey participants who were aware of cyber resilience said their organization either did not have a cyber resilience policy or they were unaware of it. The majority (63%) were also unfamiliar with the Essential Eight, the cybersecurity framework proposed by the Australian Cyber Security Centre that is mandatory at the federal government level, to enhance cyber readiness.

Rajesh Ganesan, President of ManageEngine, said the report underscores the pressing need for stronger cybersecurity measures and more effective PII management strategies among A/NZ companies. "It's imperative that businesses adopt the data protection standards specific to their region, stay compliant, and bolster their cyber resilience to protect not only their own operations, but the sensitive information of staff and customers, both past and present. We hope this report drives home the urgency of these requirements."

Other key findings:

■ Of the respondents that experienced a breach, 73% said it took their organization less than 24 hours after critical systems were taken offline or impacted to recover and restore operations.

■ Of the respondents, 74% said their organization has not paid a ransom to recover data, but 10% indicated they had.

■ Of the 78% of respondents aware of major data breaches in other organizations, 17% of Australian respondents weren't aware of recent major cybersecurity breaches occurring in Q3 2023, while 47% of those in New Zealand were uninformed.

Methodology: Conducted by Sydney-based research and insights advisory firm StollzNow, the study commissioned by ManageEngine surveyed 306 senior IT decision-makers from different organizations in A/NZ, covering topics such as cyber resilience, PII management, cyber practices under hybrid work models, the Essential Eight, malware and ransomware. The study identified key dimensions that require immediate attention by decision-makers and highlighted cybersecurity challenges.

Hot Topics

The Latest

As businesses increasingly rely on high-performance applications to deliver seamless user experiences, the demand for fast, reliable, and scalable data storage systems has never been greater. Redis — an open-source, in-memory data structure store — has emerged as a popular choice for use cases ranging from caching to real-time analytics. But with great performance comes the need for vigilant monitoring ...

Kubernetes was not initially designed with AI's vast resource variability in mind, and the rapid rise of AI has exposed Kubernetes limitations, particularly when it comes to cost and resource efficiency. Indeed, AI workloads differ from traditional applications in that they require a staggering amount and variety of compute resources, and their consumption is far less consistent than traditional workloads ... Considering the speed of AI innovation, teams cannot afford to be bogged down by these constant infrastructure concerns. A solution is needed ...

AI is the catalyst for significant investment in data teams as enterprises require higher-quality data to power their AI applications, according to the State of Analytics Engineering Report from dbt Labs ...

Misaligned architecture can lead to business consequences, with 93% of respondents reporting negative outcomes such as service disruptions, high operational costs and security challenges ...

A Gartner analyst recently suggested that GenAI tools could create 25% time savings for network operational teams. Where might these time savings come from? How are GenAI tools helping NetOps teams today, and what other tasks might they take on in the future as models continue improving? In general, these savings come from automating or streamlining manual NetOps tasks ...

IT and line-of-business teams are increasingly aligned in their efforts to close the data gap and drive greater collaboration to alleviate IT bottlenecks and offload growing demands on IT teams, according to The 2025 Automation Benchmark Report: Insights from IT Leaders on Enterprise Automation & the Future of AI-Driven Businesses from Jitterbit ...

A large majority (86%) of data management and AI decision makers cite protecting data privacy as a top concern, with 76% of respondents citing ROI on data privacy and AI initiatives across their organization, according to a new Harris Poll from Collibra ...

According to Gartner, Inc. the following six trends will shape the future of cloud over the next four years, ultimately resulting in new ways of working that are digital in nature and transformative in impact ...

2020 was the equivalent of a wedding with a top-shelf open bar. As businesses scrambled to adjust to remote work, digital transformation accelerated at breakneck speed. New software categories emerged overnight. Tech stacks ballooned with all sorts of SaaS apps solving ALL the problems — often with little oversight or long-term integration planning, and yes frequently a lot of duplicated functionality ... But now the music's faded. The lights are on. Everyone from the CIO to the CFO is checking the bill. Welcome to the Great SaaS Hangover ...

Regardless of OpenShift being a scalable and flexible software, it can be a pain to monitor since complete visibility into the underlying operations is not guaranteed ... To effectively monitor an OpenShift environment, IT administrators should focus on these five key elements and their associated metrics ...

A/NZ Companies Not Changing Data Management Despite Multiple Breaches

The majority of organizations across Australia and New Zealand (A/NZ) breached over the last year had personally identifiable information (PII) compromised, but most have not yet modified their data management policies, according to the Cybersecurity and PII Report from ManageEngine, the enterprise IT management division of Zoho Corporation.


The survey respondents who had reported their organization experienced between one and five data breaches in the past 12 months said PII was involved in 51% of instances. Despite this, of the respondents who can comment on PII and are aware of major data breaches, the majority (54%) reported either no changes in PII management following the breaches or said they were unaware of any changes. Further, 42% said they have not been advised of their organization's protocols around PII management.

When it came to data categories, 55% of respondents said they store data on past customers, 41% on past employees, 70% on current customers, 66% on current employees and 37% on potential customers.

Vinayak Sreedhar, ManageEngine's country manager for Australia, said the findings highlight alarming gaps in Australia's cybersecurity preparedness. "One year ago, a string of high-profile breaches saw millions of Australians have their data compromised, with identification points traded on the dark web,” he said. "This prompted discussions around the legal right to request the erasure of personal information in company databases. The law is yet to change in Australia and, as this survey indicates, local organizations have not changed their practices."

When it came to cyber resilience, 24% of survey participants who were aware of cyber resilience said their organization either did not have a cyber resilience policy or they were unaware of it. The majority (63%) were also unfamiliar with the Essential Eight, the cybersecurity framework proposed by the Australian Cyber Security Centre that is mandatory at the federal government level, to enhance cyber readiness.

Rajesh Ganesan, President of ManageEngine, said the report underscores the pressing need for stronger cybersecurity measures and more effective PII management strategies among A/NZ companies. "It's imperative that businesses adopt the data protection standards specific to their region, stay compliant, and bolster their cyber resilience to protect not only their own operations, but the sensitive information of staff and customers, both past and present. We hope this report drives home the urgency of these requirements."

Other key findings:

■ Of the respondents that experienced a breach, 73% said it took their organization less than 24 hours after critical systems were taken offline or impacted to recover and restore operations.

■ Of the respondents, 74% said their organization has not paid a ransom to recover data, but 10% indicated they had.

■ Of the 78% of respondents aware of major data breaches in other organizations, 17% of Australian respondents weren't aware of recent major cybersecurity breaches occurring in Q3 2023, while 47% of those in New Zealand were uninformed.

Methodology: Conducted by Sydney-based research and insights advisory firm StollzNow, the study commissioned by ManageEngine surveyed 306 senior IT decision-makers from different organizations in A/NZ, covering topics such as cyber resilience, PII management, cyber practices under hybrid work models, the Essential Eight, malware and ransomware. The study identified key dimensions that require immediate attention by decision-makers and highlighted cybersecurity challenges.

Hot Topics

The Latest

As businesses increasingly rely on high-performance applications to deliver seamless user experiences, the demand for fast, reliable, and scalable data storage systems has never been greater. Redis — an open-source, in-memory data structure store — has emerged as a popular choice for use cases ranging from caching to real-time analytics. But with great performance comes the need for vigilant monitoring ...

Kubernetes was not initially designed with AI's vast resource variability in mind, and the rapid rise of AI has exposed Kubernetes limitations, particularly when it comes to cost and resource efficiency. Indeed, AI workloads differ from traditional applications in that they require a staggering amount and variety of compute resources, and their consumption is far less consistent than traditional workloads ... Considering the speed of AI innovation, teams cannot afford to be bogged down by these constant infrastructure concerns. A solution is needed ...

AI is the catalyst for significant investment in data teams as enterprises require higher-quality data to power their AI applications, according to the State of Analytics Engineering Report from dbt Labs ...

Misaligned architecture can lead to business consequences, with 93% of respondents reporting negative outcomes such as service disruptions, high operational costs and security challenges ...

A Gartner analyst recently suggested that GenAI tools could create 25% time savings for network operational teams. Where might these time savings come from? How are GenAI tools helping NetOps teams today, and what other tasks might they take on in the future as models continue improving? In general, these savings come from automating or streamlining manual NetOps tasks ...

IT and line-of-business teams are increasingly aligned in their efforts to close the data gap and drive greater collaboration to alleviate IT bottlenecks and offload growing demands on IT teams, according to The 2025 Automation Benchmark Report: Insights from IT Leaders on Enterprise Automation & the Future of AI-Driven Businesses from Jitterbit ...

A large majority (86%) of data management and AI decision makers cite protecting data privacy as a top concern, with 76% of respondents citing ROI on data privacy and AI initiatives across their organization, according to a new Harris Poll from Collibra ...

According to Gartner, Inc. the following six trends will shape the future of cloud over the next four years, ultimately resulting in new ways of working that are digital in nature and transformative in impact ...

2020 was the equivalent of a wedding with a top-shelf open bar. As businesses scrambled to adjust to remote work, digital transformation accelerated at breakneck speed. New software categories emerged overnight. Tech stacks ballooned with all sorts of SaaS apps solving ALL the problems — often with little oversight or long-term integration planning, and yes frequently a lot of duplicated functionality ... But now the music's faded. The lights are on. Everyone from the CIO to the CFO is checking the bill. Welcome to the Great SaaS Hangover ...

Regardless of OpenShift being a scalable and flexible software, it can be a pain to monitor since complete visibility into the underlying operations is not guaranteed ... To effectively monitor an OpenShift environment, IT administrators should focus on these five key elements and their associated metrics ...