Getting the right people will be the best investment your organisation ever makes
Posted on 15 Apr 2026
Lately I’ve been spending a lot of time in interview rooms.
Posted on 11 Oct 2023
By Greg Thom, journalist, Institute of Community Directors Australia
Fear of cyber attack tops the list of risks that organisations are most concerned about, according to a new study.
More than 68% of respondents polled for the Risk, Regulation and Resilience report by legal firm Maddocks cited cyber-crime as a leading business vulnerability worry.
This was followed by threats posed by employees (50%), reputational risk (37%) and regulatory breaches (34%).
The report’s authors said there had been a significant shift in recent years in the factors that drive business resilience.

The covid pandemic, ageing IT systems, increased penalties for regulatory breaches and heightened environmental, social and governance (ESG) risks have all made an impact.
While some organisations felt well prepared to handle any incident, budget constraints and a lack of crisis management planning remained a problem for many.
The Maddocks study surveyed 400 businesses across a range of industries to identify areas where they felt most vulnerable.
The probe also aimed to highlight what measures organisations were taking to boost their resilience.
Among the report’s key findings:
About 34% of organisations cited budget constraints as the main barrier to having a robust resilience plan.
“When conducting threat assessments or crisis drills, do not assume you will only be dealing with one issue at a time. Test your resilience to deal with a confluence of events.”
The report said it was unsurprising that organisations identified cyber and privacy risks as their biggest vulnerabilities, given the “crippling nature” of recent high-profile attacks by hackers.
More than 87% of government sector organisations and 81% of educational institutions rated cyber threats as a key vulnerability.
“The threat landscape in Australia is constantly evolving and changing – and with changes to Australia’s Privacy Act, the penalties are very significant,” said Maddocks partner Sonia Sharma.
The report said recognising and understanding some of the most common features of a crisis is crucial to ensuring an organisation is well placed to deal with the consequences of an unexpected event.
Chief among these features is that teams will often need to respond to challenges without the aid of timely or accurate information.
The report said organisations should consider appointing a liaison person to deal with authorities and regulators; selecting crisis team members based on their abilities, not their titles; and seeking expert internal and/or external advice from those experienced in dealing with a crisis is vital..
The report highlighted that the worst threat or crisis involved the emergence of two or more risks simultaneously.
“When conducting threat assessments or crisis drills, do not assume you will only be dealing with one issue at a time. Test your resilience to deal with a confluence of events.”
While 71% of organisations that took part in the study had business continuity plans and more than half had crisis management plans, just 22% had procedures in place that were shared with employees.
Barriers to achieving business resilience ranged from budget constraints (34%) and lack of awareness of best practice (27%) to a failure to make it a business priority (17%).
The report includes a checklist to help organisations identify and manage business risks, and it recommends these actions:

“By adopting these strategies,” the report says, “businesses can overcome barriers to managing risk effectively and build a resilient organisation capable of navigating uncertainties and seizing opportunities.”
NFP sector in Canberra cyber security talks
Mass charities data breach prompts warnings about outsourcing fundraising
Sector experiencing growing pains on the road to data maturity: report
Posted on 15 Apr 2026
Lately I’ve been spending a lot of time in interview rooms.
Posted on 15 Apr 2026
Tania Sacco knows what it means to aim carefully. As a competitive archer who has represented…
Posted on 15 Apr 2026
Australian boards are being urged to strengthen their oversight of technology and artificial…
Posted on 15 Apr 2026
Earlier this year, a nine-member board I worked with lost four of its directors on the same day. It…
Posted on 15 Apr 2026
Many new directors walk into their first board meeting unprepared – not because they lack…
Posted on 15 Apr 2026
The average Australian not-for-profit sector employee is less satisfied about the rewards and…
Posted on 15 Apr 2026
Not-for-profits that seek to solve performance problems by hiring new staff might be missing the…
Posted on 15 Apr 2026
The Australian Red Cross has overhauled its governance, replacing a large member-based board with a…
Posted on 13 Apr 2026
A Community Directors survey of not-for-profit leaders’ biggest governance concerns has prompted a…
Posted on 12 Mar 2026
Australia’s not-for-profits win nearly half the grants they apply for, but time and resourcing…
Posted on 12 Mar 2026
If government were to give you a blank cheque for one million dollars tomorrow, what would you do…
Posted on 12 Mar 2026
Sector advocates are ramping up a campaign to give tens of thousands more charities favoured tax…