Guides · Privacy & trust

Data breaches just hit a record high — what your website should show customers

Australia logged more data breaches in 2025 than in any year since reporting began, and four in five Australians now name breaches their biggest privacy worry. You can't promise a breach will never happen. But there are visible signals on your own website that tell a customer — and a regulator — that you take their data seriously. Here are the ones worth checking this week.

On its 2025 figures, the Office of the Australian Information Commissioner (OAIC) received the highest number of data breach notifications since the Notifiable Data Breaches scheme began in 2018. The numbers are worth sitting with for a moment, because they change how your customers think when they land on your site.

1,205
Breach notifications in 2025
The most in any year since the scheme began — up 8% on 2024's 1,112.
716
From malicious or criminal attacks
The leading cause. Cyber attacks on businesses, not honest mistakes.
82%
Of Australians worried about breaches
Now the top-ranked privacy concern, up from 74% in 2023.

Health providers were the most affected sector (225 notifications, 19% of the total), followed by finance, government, professional associations, education, and legal, accounting and management services. In other words: not just the big end of town. The Notifiable Data Breaches scheme applies to organisations covered by the Privacy Act — and after the 1 July 2026 changes, a good many small businesses that were previously exempt are now covered too.

You can't guarantee you'll never have a breach. What you can control is whether a customer looking at your website today can tell that you're careful.

None of the steps below is a promise of perfect security — no honest business, and no honest scanner, can offer that. They're the visible, checkable signals of a business that takes data seriously. Each one follows the same shape: what it is, why it matters to your business, and how to check it this week.

1. The padlock — and the word "Not secure"

What it is. A valid SSL certificate, so every page of your site loads over an encrypted https:// connection.

Why it matters. Without it, anything a customer types — a name, an email, a card number — travels in the clear, and modern browsers stamp the word "Not secure" right next to your address. In a year of record breaches, that label is the first thing a cautious customer sees.

How to check this week. Load your own site and look at the address bar. If there's no padlock, or the page still opens on http://, ask your host or web person to install a certificate and force HTTPS — for most small sites it's free and takes an afternoon.

2. A privacy policy that says how to complain

What it is. A real, current privacy policy — not a copied template — that tells people what you collect, where it goes, how it's stored, how to make a complaint, and when it was last updated.

Why it matters. A policy that exists but doesn't explain how someone raises a concern is exactly the kind of gap the regulator is looking at. The OAIC has an active sweep of privacy policies underway, and with community concern at record highs, "we have a policy somewhere" is no longer enough.

How to check this week. Open your own policy and read it as a customer would. Can you find, in plain English, how to complain and who to contact? Is there a last-updated date this decade? If not, those are the first two things to fix.

3. Email that scammers can't send as you

What it is. Two DNS settings — SPF (which declares who is allowed to send email using your domain) and DMARC (which tells receiving mail servers to reject anyone who isn't) — set to actually enforce, not just monitor.

Why it matters. When breaches are in the news, criminals impersonate trusted businesses to phish their customers. If your domain has no enforced DMARC, anyone can send email that looks like it came from you — and your customers have no way to tell the difference. It's one of the cheapest protections a small business routinely skips.

How to check this week. This one lives in your DNS settings rather than on the page, so it's the hardest to eyeball. A free scan will tell you whether SPF and DMARC exist and whether DMARC is set to enforce; if it's missing or only "monitoring," that's a quick fix for whoever manages your domain.

4. Software that's actually up to date

What it is. Your website's building blocks — for most small sites that means WordPress and its plugins and themes — kept patched and current.

Why it matters. Malicious and criminal attacks were the single largest cause of last year's breaches, and out-of-date plugins are the most common way a small-business site gets broken into. The attacks are automated: bots scan the whole internet for known-vulnerable versions, so "we're too small to be a target" doesn't apply when the targeting is a machine working through a list.

How to check this week. Log into your site's admin and update anything with a pending update — core, plugins and themes. Delete plugins you no longer use rather than leaving them dormant, and turn on automatic updates where you can.

5. Who you're quietly sharing your visitors with

What it is. The advertising and analytics trackers — Meta and Google pixels and the like — that load on your pages and send data about your visitors to third parties.

Why it matters. Third-party tracking pixels on sites handling sensitive information have become a proven enforcement target: the Privacy Commissioner has recently found businesses interfered with people's privacy through exactly this. Most owners have no idea how many trackers are running, or what they collect.

How to check this week. Make a list of every tracking or advertising tool on your site and ask, for each, whether you still need it and whether your privacy policy actually discloses it. If a pixel is collecting data you can't justify, remove it.

6. A visible way to reach you

What it is. Clear contact details — a contact page, an email, or a phone number a customer can actually find.

Why it matters. If something ever does go wrong, the first thing a worried customer does is look for a way to reach you. A site with no visible contact path reads as either abandoned or evasive — the opposite of the trust you want in a nervous market.

How to check this week. Try to contact your own business the way a stranger would. If it takes more than a few seconds to find a working email or phone number, put one somewhere obvious in your footer.

What none of this promises

These are trust signals and basic hygiene, not a guarantee. Checking all six won't make a breach impossible — nothing will — and a clean scan is a point-in-time snapshot, not a certification. What they do is show a customer, and a regulator, that you've done the obvious, visible things right. If you'd like something reviewed properly, some of this (like whether your refund or privacy wording meets your legal obligations) is worth a professional's eye — we flag it; we don't rule on it.

If you want to see how many of these six your own site already passes, that's exactly what our free Scorecard checks — no payment, and the result comes to your inbox.

Two-minute check

See how many of the six your site passes.

Run a free Scorecard and we'll email you how your website scores on security, privacy and consumer-law basics — no payment, no cold calls.