Beyond Security: Protecting the Business
Estimated reading time: 9 minutes
Cybersecurity incidents rarely arrive with clear evidence and a simple decision.
The harder challenge is knowing what to do when the warning is real but the picture is incomplete.
For most business leaders, the most difficult cybersecurity situation is not necessarily learning that an attack has occurred. It is deciding what to do when there are indications that something may be wrong, but the evidence does not yet confirm it. How credible is the warning? Who needs to know? Who has the authority to escalate? How quickly should the business act?
These questions became particularly relevant in the case of Origin Energy. On 28 July 2026, Origin said it believed information belonging to approximately 900,000 current and former customers had been accessed. The company had been reviewing a potential security threat since early July but said that, based on the information available at the time, the threat was not assessed as credible. New information received on 22 July indicated that a potential security incident may have occurred, prompting further action.
The significant lesson is not simply that a large Australian organisation experienced a data security incident. The deeper lesson is that cybersecurity leadership often requires decisions to be made before there is complete certainty. For executives, readiness means more than having security controls in place. It means having the governance, accountability and escalation processes to respond when the situation remains unclear.
Sources: Reuters, "Australia's Origin Energy flags possible data exposure of about 900,000 customers," 28 July 2026. Origin Energy, "Further Update on Data Security Incident," 28 July 2026. ABC News, "Origin Energy believes 900,000 customers' data accessed in breach," July 2026. Full citations in the References section below.
When Cyber Risk Is Uncertain
Traditional cybersecurity discussions often focus on prevention. Organisations invest in controls, monitoring, policies, assessments and technical capabilities with the goal of stopping an incident before it occurs. These remain important. But prevention is only one part of organisational readiness.
There is a different kind of challenge that receives less attention. What happens when something does not appear serious enough to trigger a full response, but could become serious if the organisation gets the decision wrong? This space between a confirmed incident and a dismissed alert is where executive readiness is tested.
A warning may be incomplete. An alert may require investigation before its significance becomes clear. An external claim may not initially appear credible. A technical team may still be gathering evidence. In each of these situations, leadership cannot always wait for certainty before acting.
The organisation needs a clear process for determining:
- What level of information is sufficient to warrant investigation?
- At what point does uncertainty itself justify escalation?
- Who should be involved in assessing potential impact?
- When does a technical concern become a business risk?
- Who has the authority to make the next decision?
The Origin Energy timeline illustrates why this matters. The company said it had been reviewing a potential threat since early July and was working to establish its credibility and potential impact. New information received on 22 July changed the assessment. The lesson for other organisations is not to treat every warning as a confirmed incident. It is to ensure there is a clear and defensible process for deciding what happens when the answer is not yet clear. Through vCISO advisory, we help organisations build exactly this kind of escalation clarity before it is needed under pressure.
Executive readiness is not about having complete information.
It is about having the capability to make informed decisions when you do not.
What Is Actually at Stake
A cybersecurity warning may begin as a technical question. The consequences, however, can quickly become a business question that touches every part of the organisation.
| Area | What Leadership Needs to Consider |
|---|---|
| Customers | Could affected individuals face fraud, scams, identity risks or loss of confidence in the organisation? |
| Operations | Could the incident affect critical systems or the ability to continue serving customers? |
| Leadership visibility | Does senior management have the information required to make timely, informed decisions? |
| Regulatory obligations | Are there notification, reporting, privacy or other obligations that may apply? |
| Reputation | How will customers, employees, partners, regulators and other stakeholders respond? |
| Financial impact | Could the incident result in response costs, operational disruption, lost revenue, legal exposure or damage to market confidence? |
In Origin Energy's case, approximately 900,000 current and former customers may have had information accessed, including names, addresses, dates of birth, phone numbers, account information and partial credit card or bank account details. Origin subsequently contacted affected customers and engaged cybersecurity and forensic specialists while taking steps to secure its systems.
This illustrates why cybersecurity cannot remain isolated within the technology function. The technical question of whether a system was compromised matters. But the executive question is different. It is about what the situation means for the business and what needs to happen next. Making that assessment quickly and accurately requires governance structures that connect technical findings to business decisions.
What Business Leaders Can Learn
Uncertainty should have an escalation process. Not every security warning will prove credible. That does not mean uncertainty should lead to inaction. Organisations benefit from clear criteria for when a potential threat is escalated, who evaluates it, and what information is required before the next decision is made. The objective is not to treat every alert as a confirmed incident. It is to ensure that uncertainty itself does not become a reason for delay.
Cybersecurity decisions should have clear ownership. When an issue emerges, leadership should not have to determine who is responsible for making the decision. Accountability should be defined across technology, risk, legal, communications, operations and executive leadership where appropriate. Through security leadership engagements, we see that organisations with clearly assigned decision authority consistently respond faster and with greater confidence than those where ownership is determined during the event.
Technical findings need to become business information. Executives do not necessarily need every technical detail. They need to understand what happened, what could be affected, how confident the team is in the current assessment, what is still being investigated, what decisions are required, and what happens if the organisation waits. This translation from technical evidence to business information is a security management responsibility that should be established well before it is tested.
Readiness must account for changing information. Cyber incidents evolve. New evidence can change the assessment of a threat, its potential impact and the appropriate response. The Origin timeline demonstrates this clearly. An initial assessment in early July reached one conclusion. New information on 22 July changed the picture. An organisation that has a process for reassessing risk as new information emerges is better positioned than one that relies on a single initial assessment. Readiness is not a fixed state. It is an ongoing capability.
The Escalation Test
If a potential cyber threat emerged in your organisation today, could your team answer these questions within an hour?
Who decides whether it warrants escalation?
What information do they need to make that decision?
Who else needs to be informed, and by when?
If the answers depend on the specific individuals available that day rather than a defined process, the organisation may be relying on people rather than governance.
Questions Every Executive Should Ask
Executives should consider whether their organisation can confidently answer the following:
- What triggers escalation when a potential cyber threat is identified?
- Who has the authority to escalate and involve senior leadership?
- How does the organisation distinguish a technical issue from a material business risk?
- What information does leadership need before making a decision?
- How does the organisation reassess its position when new evidence emerges?
- Are escalation processes documented, tested and understood by the people who would use them?
If these questions are difficult to answer, the issue may not be a lack of cybersecurity controls. It may indicate a gap in executive readiness and governance. The Origin experience suggests that the window between receiving an early warning and needing to act decisively can be measured in days, not weeks. Organisations that have thought through these questions in advance are better positioned to use that window effectively.
From Incident Response to Executive Readiness
The traditional approach to cybersecurity asks how to prevent an attack. That question remains important. But organisations also need to ask how prepared they are to make the right decisions when prevention alone is not enough.
This represents a broader shift from technical security toward organisational readiness. It means connecting cybersecurity with business strategy, risk management, governance, leadership accountability and operational resilience. The goal is not to eliminate uncertainty. The goal is to ensure that uncertainty does not prevent the organisation from acting.
Through vCISO and security leadership advisory, SeComPass works with leadership teams to strengthen governance, clarify escalation processes, and build the decision making capability that allows organisations to respond effectively when the situation is still developing. This includes helping leadership understand where the organisation currently stands, identifying gaps in escalation and accountability, and establishing clearer pathways from early warning to informed action.
The Origin Energy incident is a reminder that the most challenging moment in cybersecurity is rarely the point where the facts are clear. It is the period before that, when the warning has arrived but the full picture has not. Organisations that have prepared for that moment will handle it differently from those discovering their process in real time.
Key Takeaways
- Cyber risks rarely arrive with complete evidence. Organisations need clear processes for deciding how to respond when the situation is uncertain but the potential consequences are significant
- The Origin Energy incident illustrates the challenge of assessing an evolving threat. Initial information may not appear credible, but new evidence can change the picture quickly
- Escalation processes should define clear criteria, ownership and authority so that uncertainty does not lead to delay
- Technical findings must be translated into business information that allows leadership to make informed decisions about impact, obligations and next steps
- Readiness is not a fixed state. It is an ongoing capability that accounts for changing information, evolving threats and the reality that prevention alone is not sufficient
- Executive readiness means having the governance, accountability and decision making capability to act effectively before the full picture is available
Test Your Escalation Readiness
Could Your Organisation Act Decisively Under Uncertainty?
The Executive Readiness Review helps leadership teams understand whether their cybersecurity governance, escalation processes and decision making structures are ready for the moments that matter most. It includes:
- Assessment of current escalation criteria and decision authority
- Review of governance structures connecting technical findings to business decisions
- Identification of gaps in accountability, communication and readiness
- Strategic priorities for strengthening executive preparedness
Start by understanding where your organisation stands today.
Start the Executive Readiness Review →References
- Reuters. "Australia's Origin Energy flags possible data exposure of about 900,000 customers," 28 July 2026. reuters.com
- Origin Energy. "Further Update on Data Security Incident," 28 July 2026
- ABC News. "Origin Energy believes 900,000 customers' data accessed in breach," July 2026
- Australian Cyber Security Centre (ACSC). Guidance for business leaders on cyber resilience and incident response. Accessed August 2026. cyber.gov.au
- Australian Signals Directorate and AICD. Joint guidance for boards on cyber security priorities, 2025-26. cyber.gov.au
This article is for general informational purposes only and does not constitute legal, technical, or professional cybersecurity advice. SeComPass recommends engaging a qualified adviser before making decisions based on this content. Guidance referenced above was current as at August 2026 and is updated periodically by relevant government and standards bodies.