Cyber Risk

Mills Oakley Cyber is a collaboration of the Mills Oakley partnership delivering specialist cyber risk advice across all relevant legal areas with true expertise in a frictionless manner.

Who we are

Specialist cyber risk team

Mills Oakley Cyber is a highly experienced team of specialist cyber risk lawyers and subject matter expert partners. Mills Oakley Cyber leverages the national full service capabilities of Mills Oakley to deliver services across every aspect of cyber risk including:

  • cyber risk assessment
  • incident response management
  • privacy and data governance
  • government and critical infrastructure
  • artificial intelligence
  • ICT and digital
  • intellectual property
  • corporate advisory
  • insurance
  • not-for-profit
  • regulatory compliance and investigation
  • dispute resolution and class action.

What we do

Fit for purpose and frictionless

Mills Oakley Cyber understands your organisational needs and works with you to provide tailored legal solutions that are fit for purpose. The structure of the team ensures services are delivered by the right expert cyber risk partner, who works collaboratively and frictionlessly across Mills Oakley’s extended teams and services.

Dedicated cyber risk partners

Mills Oakley Cyber’s 4 dedicated cyber risk partners provide the specialist expertise and deep experience required in today’s cyber threat environment, in areas including cyber risk and incident response management, cyber insurance, technology and government tenders and procurement, SOCI regulation, privacy and data governance, AI and emerging technology, intellectual property and technology and data commercialisation contracts.  See Our Team page for more detail on our partners.

Complete cyber resilience support

The Mills Oakley Cyber team supports organisations with each component of cyber resilience:

  • Detect: We assist organisations with understanding their unique cyber-related risk through cyber and privacy risk assessments, data mapping, contract and policy reviews, cyber incident planning, ‘tabletop’ simulation exercises, staff training, and regulatory advice
  • Manage: We manage cyber incidents for organisations and their insurers, from the initial triage, forensic investigation and data review, to notifying regulators and individuals, government authorities and stakeholders, including engaging all necessary vendors and providing relevant legal advice
  • Recover: We help organisations with getting back to business as usual after a cyber incident, including system recovery, outlining ‘lessons learned’, forensic reviews of business interruption, representing parties in any regulatory investigations or third-party claims that arise, and cyber insurance recovery.

Rapid data reviews

The Mills Oakley Cyber team has developed an internal capability to undertake rapid large scale data reviews in response to a data breach or data governance review by our legal team.  The team also works seamlessly alongside leading data mining and data breach specialist vendors to collect and review data efficiently to assess regulatory compliance and cyber and privacy risk requirements.

‘One-stop-shop’ cyber services

Mills Oakley Cyber has established strong relationships with market leading cyber consultants to deliver advisory and incident response services as an organisation’s ‘one-stop-shop’ to cyber risk services incorporating:

  • cyber security and forensic IT
  • communications and crisis management
  • ransom negotiation
  • ediscovery and data mining
  • forensic accounting and business interruption
  • fraud investigation and crypto tracing
  • identity protection
  • cyber insurance.

International collaboration

The Mills Oakley Cyber team has deep relationships with law firms in New Zealand, Asia, USA, UK and Europe that specialise in providing cyber risk, privacy and data protection legal services enabling cross-jurisdictional advice and incident management.

Cyber insurance

Mills Oakley Cyber is appointed to cyber insurer and broker panels, acting as the incident response law firm covered by an organisation’s cyber insurance, working with the insurer’s vendor panel, and within the required cost guidelines and coverage limits.  With its leading cyber insurance expertise, the team also advises insurers and brokers on cyber insurance coverage matters.

ISO27001 certification

Mills Oakley is committed to information security. Mills Oakley Cyber is supported by the firm’s ISO27001 information security certification. See here for more information.

More information

Please reach out to your Mills Oakley partner or contact [email protected] for more information.

Recent projects

  • Advising Australian law firm that suffered a business email compromise resulting in hundreds of fraudulent emails being sent to clients, law firms, vendors and government agencies, including privacy obligations and other legal obligations arising from the incident.
  • Advising Australian healthcare provider that suffered a ransomware attack and substantial data breach, comprising all aspects of the incident response, including reporting the incident to the ACSC, OAIC and Department of Health, co-ordinating the response with the National Office of Cyber Security and the National Cyber Security Co-ordinator, forensically investigating the attack and data breach with the assistance of the Australian Signals Directorate and Australian Federal Police, and preparing media and website public statements.
  • Advising international IT service provider that suffered a ransomware attack of an Australian customer’s IT infrastructure, including advising on the forensic investigation by multiple teams, engaging with regulators and stakeholders, responding to media coverage, and contractual obligations.
  • Advising international charity that suffered a substantial data breach of a third-party service provider including analysis of the data breach, assessment of the impact on individuals affected, and drafting communications with individuals, media and the privacy regulator.
  • Advising online hire company that suffered a data breach of its customer database and other confidential information following the compromise of multiple email accounts including a complex data review and notification campaign to customers, as well as the OAIC and other stakeholders.
  • Advising Australian manufacturing company that suffered a business email compromise and consequential invoice fraud suffered by a customer including privacy obligations and subsequent contractual dispute concerning invoices paid to third party actor.
  • Advising individual that suffered a social engineering fraud of its financial advisory firm resulting in the sale of their share portfolio, including reporting to Government agencies and financial institutions and the repayment of portfolio value.
  • Conducting a cyber incident simulation exercise for an Australian financial institution, involving the data breach of a third-party supplier of IT platform services, and ransom demand, requiring consideration of privacy obligations and dispute issues.
  • Advising Australian insurer on cyber-related cover provided by various lines of insurance under its business insurance product, including analysis of potential ‘silent cyber’ cover, and drafting amendments to coverages and exclusions to address any unintended cover.
  • Advising Australian investment company preparing for a potential sale with cyber-related aspects of the legal due diligence process and cyber incident preparedness, as well as engaging a cybersecurity firm to conduct a compromise assessment and maturity/uplift program.

Mills Oakley Cyber Hotline

The Mills Oakley Cyber team is available 24 hours a day, 7 days a week, 365 days a year by contacting our hotline on 1800 161 151 or [email protected]