About Us

We work collaboratively with our clients to build strong, sustainable relationships. Our team is committed to delivering consistent high standards of service, and we understand the importance of accessibility. Working with us, you'll enjoy open communication, meaning well scoped, properly resourced and effectively managed matters.

Learn More

Latest Case

Providing innovative procurement solutions for local government projects April 20, 2018

We advised City of Casey on the procurement process of the Bunjil Place Project. Bunjil Place is a $125 million civic and cultural precinct for the City of Casey, encompassing an 800-seat theatre and 200-seat … Continued

Latest News

In good hands: Maddocks advises on physio business acquisition April 11, 2018

Wednesday 11 April 2018 Maddocks has advised Zenitas Healthcare Limited on its acquisition of the Agewell Physiotherapy business. Agewell is a mobile physiotherapy provider servicing residential aged care facilities, retirement villages and communities in New … Continued

Latest Article

The right to use plans prepared by a design consultant: the devil is in the detail April 11, 2018

When a design consultant (such as an architect or engineer) brings their plans or designs into material form, copyright will usually subsist in those documents as an artistic work. The designer owns that copyright unless … Continued

No escape from cyber security duties for Commonwealth officials and directors

In a recent blog post and more comprehensive article, we discussed directors’ duties under the Corporations Act 2001 (Cth) as they extend into the field of cyber security. Similar (and, as discussed below, in some cases even broader) duties are imposed on Commonwealth entity officials, and Commonwealth company directors.

Commonwealth entity officials are required under the Commonwealth’s Public Governance, Performance and Accountability Act 2013 (Cth) (PGPA) to perform their powers and functions and discharge their duties with care and diligence. These duties are analogous to directors’ duties under the Corporations Act.

In the case of Commonwealth company directors, they must also comply with their Corporations Act directors’ duties, and with additional duties and obligations under the PGPA, including keeping the responsible Minister informed of significant issues affecting the relevant Commonwealth company. In our view, this duty to inform extends to informing the responsible Minister of any significant cyber breach or cyber security related issues.

We have identified six key cyber security standards that Commonwealth entity officials and Commonwealth company directors should be aware of as follows:

  1. The Australian Signals Directorate’s Top Four Migration Strategies to Protect Your ICT System
  2. The Australian Government Cyber Security Operations Centre’s Questions Senor Management Need to be Asking About Cyber Security
  3. ASIC’s Cyber Resilience: Health Check (ASIC Report 429)
  4. The Office of the Australian Information Commissioner’s Guide to Security Personal Information – ‘Reasonable Steps’ to Protect Personal Information
  5. The Payment Card Industry’s Data Security Standard (DSS): Requirements and Security Assessment Procedures and
  6. ISO/IEC Standards.

The six cyber security standards referred to above are by no means exhaustive and we have discussed these standards in more detail in our related article here.

In a recent blog post and more comprehensive article, we discussed directors’ duties under the Corporations Act 2001 (Cth) as they extend into the field of cyber security. Similar (and, as discussed below, in some cases even broader) duties are imposed on Commonwealth entity officials, and Commonwealth company directors.

Commonwealth entity officials are required under the Commonwealth’s Public Governance, Performance and Accountability Act 2013 (Cth) (PGPA) to perform their powers and functions and discharge their duties with care and diligence. These duties are analogous to directors’ duties under the Corporations Act.

In the case of Commonwealth company directors, they must also comply with their Corporations Act directors’ duties, and with additional duties and obligations under the PGPA, including keeping the responsible Minister informed of significant issues affecting the relevant Commonwealth company. In our view, this duty to inform extends to informing the responsible Minister of any significant cyber breach or cyber security related issues.

We have identified six key cyber security standards that Commonwealth entity officials and Commonwealth company directors should be aware of as follows:

  1. The Australian Signals Directorate’s Top Four Migration Strategies to Protect Your ICT System
  2. The Australian Government Cyber Security Operations Centre’s Questions Senor Management Need to be Asking About Cyber Security
  3. ASIC’s Cyber Resilience: Health Check (ASIC Report 429)
  4. The Office of the Australian Information Commissioner’s Guide to Security Personal Information – ‘Reasonable Steps’ to Protect Personal Information
  5. The Payment Card Industry’s Data Security Standard (DSS): Requirements and Security Assessment Procedures and
  6. ISO/IEC Standards.

The six cyber security standards referred to above are by no means exhaustive and we have discussed these standards in more detail in our related article here.