Origin Energy filed its first ASX notice about a suspected cyber incident on the afternoon of 22 July 2026. By the following day the company had confirmed unauthorised access to customer data across 4.8 million accounts. Names, contact details, account information, and partial payment card and bank account digits were caught in the exposure. The Australian Federal Police, the Australian Signals Directorate's Cyber Security Centre, and the Office of the Australian Information Commissioner were engaged within hours.
For most listed companies operating critical infrastructure in Australia, the more important story is not what Origin has confirmed. It is what the timeline reveals about the disclosure cascade every board in this category now has to run inside a 72 hour window.
The direct answer for boards
An Australian critical infrastructure operator suffering a material cyber incident has four reporting tracks running in parallel, each with its own clock. The Security of Critical Infrastructure Act (SOCI) requires notification to the Australian Signals Directorate within 12 hours for a critical impact incident and 72 hours for other reportable incidents. The Notifiable Data Breach scheme gives the entity 30 calendar days as an outer limit to assess whether an eligible breach has occurred, with the expectation that assessment happens as fast as possible. ASX Listing Rule 3.1 demands immediate market disclosure of any information that a reasonable person would expect to have a material effect on the entity's share price, subject to the narrow carve out in Rule 3.1A. Customer notification is triggered when the assessment confirms serious harm is likely.
These clocks do not run in a neat sequence. They run at the same time, on the same evidence, with different thresholds. The board's job in the first 72 hours is to make sure the entity clears all four without one obligation compromising another.
What actually happened at Origin
Origin's first ASX release described a potential security incident that may involve unauthorised access to some customers' data. The initial statement said credit card and bank details were not believed to be affected. Within 24 hours the company had to walk that back. The updated release confirmed unauthorised access and disclosure, and included partial financial information in the exposed dataset.
An anonymous party claimed responsibility and said more than two million customers were compromised. Origin has not confirmed that figure. The company has also not named the entry point, the affected system, or any third party involved.
Two things about the sequence are worth studying. First, Origin filed with the ASX before it had full clarity on the scope of the incident. That is aligned with the guidance ASX published in Guidance Note 8 in 2024, which effectively closed the door on entities sitting on cyber knowledge while awaiting perfect information. Second, the shift in the confirmed data categories inside 24 hours shows how quickly initial containment assumptions can be overturned once forensic work begins.
Both patterns are now typical. Boards should assume that any incident significant enough to hit the market will require at least one substantive follow up disclosure inside the first week.
The four track reporting cascade
The SOCI framework has moved from an aspirational structure to enforced reality. Since the 2022 and 2024 rounds of reform, responsible entities operating a defined critical infrastructure asset in Australia must run a Critical Infrastructure Risk Management Program (CIRMP) with defined uplift against categories including cyber and information security. When a cyber security incident has a significant impact on the availability of an asset, notification to the ASD Cyber Security Centre is required within 12 hours. Other reportable incidents get a 72 hour window. These timelines start from awareness, not from confirmation.
The Notifiable Data Breach scheme operates on a different logic. Under the Privacy Act, an eligible data breach exists where personal information is accessed or disclosed without authorisation, or is lost, in circumstances likely to result in serious harm. The entity has 30 days as an outer limit to complete the assessment, with a clear signal from the Commissioner that this is a ceiling, not a target. Once the assessment confirms an eligible breach, notification to the OAIC and to affected individuals is required as soon as practicable.
ASX continuous disclosure sits above both regimes. Listing Rule 3.1 requires immediate disclosure of information likely to have a material effect on share price once the entity is aware of it. The carve out in Rule 3.1A allows a listed entity to withhold information where it is confidential and one of a set of narrow conditions applies, including that the information is insufficiently definite to warrant disclosure. The 2024 guidance made clear that a company cannot indefinitely rely on the "insufficiently definite" ground while making no active effort to investigate. Silence is not a strategy.
Customer notification runs alongside all of this. Reputational damage from a delayed or contradictory public statement can be more expensive than the incident itself. The pattern established across Optus in 2022, Medibank in the same year, and Latitude in 2023 shows that market punishment attaches to disclosure quality far more than to whether an intrusion happened.
Why the cascade produces conflict, not co-ordination
Each obligation was written by a different regulator to solve a different problem. Nobody drafted them to work together in the middle of an active incident. That is where boards get caught.
The SOCI 12 hour window forces an early notification to a government agency on incomplete information. The ASX 3.1A carve out invites the temptation to hold public disclosure while facts firm up. The OAIC 30 day assessment period is often misread by legal teams as a shield when it is really a ceiling. The customer notification obligation, once triggered, can move faster than the market announcement drafting cycle.
The most damaging failure mode is a public ASX statement that has been overtaken by ASD reporting or by draft OAIC notification content. The information the market has does not match what the regulator has. That mismatch, once discovered, becomes its own market event and often its own enforcement matter.
The mitigation is not a bigger playbook. It is a single, dated, timestamped source of truth about what the entity knows and when it knew it, shared across incident response, legal, company secretary, and communications. Every outbound artefact, whether ASX release, ASD notification, or customer email, gets versioned against that single record.
What Australian boards should ask in the first 72 hours
The best boards move to a small number of high impact questions rather than trying to shadow the technical response. The questions worth asking, in order, are:
- When did the entity first become aware of unauthorised access, and how is that awareness timestamp documented?
- Has SOCI notification been issued? If not, why is the 12 hour or 72 hour clock not running?
- Has an ASX 3.1 assessment been performed and documented, including any reliance on the 3.1A carve out and the reasons for it?
- What is the current best estimate of affected records and data categories, and how confident is that estimate?
- Who has been engaged externally: legal, forensic, communications, insurer? Is there a single external counsel co-ordinating privilege?
- Which board committee owns oversight of this response, and how often will it meet until the incident is closed?
- Is our CIRMP being followed as documented, and where are the deviations?
- What is the customer notification threshold and who has authority to trigger it?
- What is the sequenced public communication plan for the next 72 hours, including a second ASX release?
- Where is the single source of truth for what we know and when we knew it?
The tenth question is the most under practised. Post incident reviews consistently find that different parts of the response were operating from different drafts of the facts. Fixing that is a structural governance decision, not a technical one.
The pattern beneath Optus, Medibank, Latitude, and Origin
Each of these incidents told the same underlying story with different masks. A large customer database attached to essential services. A gap between operational security posture and stated governance maturity. A period of contradictory public messaging in the first 48 hours. A significant share price and reputational cost that would have been substantially reduced by tighter disclosure discipline.
The Australian regulatory response has been to compress the timelines and expand the enforcement surface. APRA and ASIC have been public since 2024 about their willingness to act on governance failures. Home Affairs has escalated SOCI enforcement expectations. The OAIC has broader powers under the Privacy Act reforms staged through 2024 and 2025.
The board level takeaway is not that regulators are becoming stricter. It is that the discretion boards used to enjoy in the first 24 to 48 hours after a breach has effectively disappeared. Every hour of delay now carries a documented cost against at least one of the four reporting tracks.
What Wai has seen in Australian cyber response engagements
Wai works with Australian technology, SaaS, professional services, and enterprise teams on the infrastructure that sits under this kind of exposure: identity, data governance, third party risk, and the discoverability layer through ARC. The consistent pattern in engagements after an incident is that the technical response is usually competent. The reporting cascade is where the failures cluster.
Three practical shifts help. First, run a documented tabletop exercise every quarter that specifically pressure tests the SOCI, OAIC, and ASX co-ordination, not the technical response. Most tabletop exercises still test firewalls when the real failure will be the release drafting queue. Second, pre approve a bank of ASX release templates with the company secretary and legal team, with placeholder wording that has been reviewed against the current 3.1A guidance. Third, appoint one external counsel to co-ordinate privilege across every workstream from day one, so that forensic reports, board briefs, and regulator communications sit under a single privilege architecture rather than being reconstructed after the fact.
None of this eliminates a breach. It compresses the window between awareness and clean, aligned disclosure, which is the window where reputational value is destroyed or preserved.
What buyers, users, and regulators are likely to expect next
The Origin incident will not be the last major Australian customer database breach. The likely direction of travel across the next 12 months includes:
- Faster market expectation of first ASX disclosure, with silence past the first business day being treated as a signal in itself.
- More detailed regulator questions about CIRMP execution, particularly whether the documented program was followed during the incident.
- Higher scrutiny of vendor and identity based attack paths, given the pattern established through the Qantas 2025 breach that was traced to a tech support scam involving an outsourced supplier.
- Tighter director attention to how the four track cascade was managed, tied to director duties under section 180 of the Corporations Act.
- Growing customer expectation of an itemised breach summary at the individual level, not just a corporate statement.
Boards that treat cyber disclosure as a legal risk only, rather than as a strategic communication event with a governance backbone, are the ones most likely to underperform their peers when their turn comes.
FAQ
How long do critical infrastructure companies have to report a cyber incident in Australia? Under the SOCI Act, a responsible entity must notify the Australian Signals Directorate's Cyber Security Centre within 12 hours of becoming aware of a critical cyber security incident that has a significant impact on the availability of a critical infrastructure asset. Other reportable cyber incidents must be notified within 72 hours. These clocks start at the point of awareness, not confirmation of scope.
When does a data breach trigger ASX continuous disclosure? ASX Listing Rule 3.1 requires immediate disclosure of any information a reasonable person would expect to have a material effect on the entity's share price. For a cyber incident, this typically means disclosure is triggered when the entity has reasonable evidence of unauthorised access to customer data at material scale, or where the operational or reputational impact is likely to move the market. The carve out in Rule 3.1A allows temporary withholding where information is confidential and either insufficiently definite or the subject of active negotiation, but the 2024 guidance in Guidance Note 8 makes clear this is not an indefinite shield.
What should a board do after a data breach in Australia? The board should confirm the awareness timestamp is documented, verify that the SOCI 12 hour or 72 hour notification clock is being actively managed, review the ASX 3.1 assessment and any reliance on 3.1A, appoint external counsel to co-ordinate privilege, and require a single dated source of truth for what the company knows and when. The best boards meet daily until the incident is closed and set clear authority for customer notification.
How does the Origin Energy breach compare to Optus and Medibank? The scale of affected records is similar, in the low millions of customer accounts. The pattern of a first cautious disclosure followed within 24 hours by a broader confirmation of financial data exposure has now repeated across all three. What is different in 2026 is the tighter regulatory surface: SOCI enforcement expectations, updated ASX cyber guidance from 2024, and Privacy Act reforms have all reduced the room for delay compared with 2022.
What is the SOCI Act 12 hour reporting rule? The Security of Critical Infrastructure Act requires responsible entities for defined critical infrastructure assets to notify the ASD Cyber Security Centre within 12 hours of becoming aware of a cyber security incident that has, or is having, a significant impact on the availability of the asset. Incidents that have a relevant impact but not a significant availability impact get a 72 hour window. Failure to notify carries civil penalty exposure.
Can an ASX listed company delay disclosure of a cyber incident? Only under narrowly defined conditions. Rule 3.1A permits withholding where the information is confidential and either insufficiently definite to warrant disclosure, or where disclosure would breach a law, involve incomplete negotiations, or relate to internal management. ASX guidance since 2024 has explicitly limited the ability to rely on the "insufficiently definite" ground where the entity is not taking active steps to investigate and confirm the position.
What is a Critical Infrastructure Risk Management Program? A CIRMP is the documented, board approved program a responsible entity must maintain under the SOCI framework, setting out how the entity identifies, manages, and mitigates material risks across cyber and information security, personnel, supply chain, and physical and natural hazards. It must be reviewed annually and reported on to the responsible minister, and its actual execution during an incident is now under increasing regulator scrutiny.
What does the Notifiable Data Breach scheme require? Where an entity has reasonable grounds to suspect an eligible data breach, it must complete an assessment within 30 days as an outer limit. If the assessment confirms the breach is likely to result in serious harm and remediation cannot prevent that harm, the entity must notify the OAIC and affected individuals as soon as practicable. The Commissioner treats the 30 day period as a maximum, not a grace period.
Where this leaves Australian technology and business leaders
Every board of a large Australian entity should treat the Origin timeline as a stress test of its own readiness. The four track cascade is now the operating environment. Whether the next major breach comes from a critical infrastructure operator, a listed SaaS platform, a health provider, or a financial services firm, the disclosure obligations will run in parallel and the market will judge the response inside the first business week.
The organisations that will preserve trust are the ones that treat disclosure as a governance capability, not a compliance chore. That means investing in the plumbing of information flow, decision rights, and communication as deliberately as the investment already made in perimeter and detection controls.
Wai works with technology leaders, boards, and enterprise teams on the infrastructure that supports this posture, including identity and data governance, third party assurance, and the AI visibility layer through ARC that determines how organisations are represented in the answers regulators, customers, and journalists find first. The Origin incident will be studied for months. The best time to prepare for the next one is before the awareness timestamp is set.