Can you prevent a hack?

Clarke McEwan Accountants

Can you prevent a hack?


In the wake of the Optus data leak, legislation before Parliament will lift the maximum fine for serious or repeated breaches of the Privacy Act from $2.2m to up to $50m. But there are no guarantees that even the strongest safety measures will prevent an attack. So, what does that mean for business and their customers?


Legislation before Parliament will lift penalties for serious or repeated privacy breaches, provide new powers to the Australian Information Commissioner, require entities to provide detailed data to the Information Commissioner to assess public risk, and give the regulator greater information sharing powers. In a statement, Attorney General Mark Dreyfus said, “When Australians are asked to hand over their personal data they have a right to expect it will be protected.” But the question is, can any business claim that customer data will be protected from hackers?


If a customer needs to disclose their personal information to your business to work with you, at the point the data is collected, your business is the custodian of that data. A duty of care exists from the moment the data is collected to the point the information is no longer required and destroyed.


The Privacy Act requires organisations to take “reasonable steps” to protect the data collected. ‘Reasonable’ steps “requires the existence of facts which are sufficient to [persuade] a reasonable person.” That is, in the event of a data breach, the business will need to prove the steps they have taken to protect client data.


Lessons from RI Advice


Australian Competition and Consumer Commission v RI Advice Group Pty Ltd was a landmark case. While specific to the obligations of an Australian Financial Services License (AFSL), it demonstrates that ASIC are willing to pursue not just companies that breach their duty of care but the directors and officers involved.


RI advice is a financial services company that, through its AFSL, authorised representatives to provide financial services. As you would expect, as part of providing financial services, the authorised representatives received, stored and accessed confidential and sensitive personal information. Between June 2014 and May 2020, nine cybersecurity incidents occurred at practices of RI Advice’s Authorised Representatives. Enquiries following the incidents revealed:


  • Computer systems which did not have up-to-date antivirus software installed and operating
  • No filtering or quarantining of emails
  • No backup systems or back-ups being performed; and
  • Poor password practices including sharing of passwords between employees, use of default passwords, passwords and other security details being held in easily accessible places or being known by third parties.


RI Advice took steps to manage their cybersecurity introducing a cyber resilience program, controls and risk management measures for its representatives including training, incident reporting, and contractual professional standard terms, but by its own admission, it took too long to implement.


RI Advice was ordered to pay $750,000 towards ASIC's costs. Handing down the decision Justice Rofe said, “It is not possible to reduce cybersecurity risk to zero, but it is possible to materially reduce cybersecurity risk through adequate cybersecurity documentation and controls to an acceptable level.”


Scams and how to avoid them


I got a text the other day “Hi Mum, I have broken my phone and I am using this number.” The “Hi Mum” scam has exploded with more than 1,150 Australians falling victim to the ploy in the first seven months of 2022, with total reported losses of $2.6 million. Once the scammer establishes contact, they start requesting money for an urgent bill or a replacement phone etc. For those with children or dependant family members, it is not that hard to believe. According to the Australian Consumer and Competition Commission (ACCC), two-thirds of family impersonation scams were reported by women over 55 years of age.


Another common scam is the lost or unable to deliver package texts and voicemail. With Christmas just around the corner, we can expect to see another escalation of this scam where tracking links purportedly from Australia Post, Toll, or Amazon etc., are used to instal malware. Once accessed, the malware will access your contacts and spread the malware and potentially access your personal information and bank details.


In July, the Australian Taxation Office (ATO) reported a new wave of ‘Tax refund SMSF scams’. The texts purported to be from the ATO stating that the individual had a tax refund and to click on the link and complete the form. Another scam purporting to be from the ATO advised that the recipient was suspected of being involved in cryptocurrency tax evasion and requested that they connect their wallet. At which point the wallet was accessed and any assets stolen.


The ACCC’s Targeting Scams report states that in 2021, nearly $1.8bn in losses were reported but the real figure is likely to be well over $2bn. 


 The largest combined losses in 2021 were:


  • $701 million lost to investment scams with 2021 figures significantly increased by cryptocurrency scams - more scammers are seeking payment with cryptocurrency and losses to this payment method increased 216% to $84 million.
  • $227 million lost to payment redirection scams.
  • $142 million lost to romance scams.


Protecting yourself from scams


Help educate older relatives. The over 55s are the most likely to fall victim to a scam.

  • Always use the primary website or app of your suppliers not a link from a text or email.
  • Don’t click on links from emails or text messages unless you are (absolutely) certain of the source. For email, if the sending email domain is not clear or hidden, hover over the name of the sending account to check if the email is from the company domain.
  • For Government services, use your MyGov account. Any messages to you from the ATO or other Government services need will be published to your MyGov account. Never click on links purporting to be from a bank, ATO or Government department.


Protecting your business from scams


Payment redirection scams, where the email of the business is compromised, caused the highest reported level of loss for business in 2021 at a combined $227 million.

Payment redirection scams involve scammers impersonating a business or its employees via email and requesting an upcoming payment be redirected to a fraudulent account. In some cases, scammers hack into a legitimate email account and pose as the business, intercepting legitimate invoices and amending the bank details before releasing emails to the unsuspecting business. Other times, scammers

 

 impersonate people using a registered email address that is very similar to one from a legitimate business.


  • Educate your team about threats and what to look out for, the importance of passwords and password security, and how to manage customer information. Phishing attacks, if successful, provide direct access into your systems.
  • Ensure staff only have access to the business systems and information they need. Assess what is required and close out access to anything not required. Also assess how customer personal information is accessed and communicated. Personal information should not be emailed. Email is not secure and it is too easy for staff to inadvertently send data to the wrong person.
  • No shared login details or passwords.
  • Complete a risk assessment of your systems and add cybersecurity to your risk management framework.
  • Develop and implement cyber security policies and protocols. Have policies and procedures in place for who is responsible for cybersecurity, the expectations of staff, and what to do in the event of a breach. Your policies should prevent shadow IT systems, where employees download unauthorised software.
  • Understand your organisation’s legal obligations. For example, beyond the Privacy Act some businesses considered critical infrastructure such as some freight and food supply operations are subject to the Security of Critical Infrastructure Act 2018. This might involve small businesses in the supply chain.
  • Use multifactor authentication on your systems and third-party systems.
  • Update software and devices regularly for patches
  • Back-up data and have backup protocols in place. If hackers use ransomware to lock your systems, you can revert to your backup.
  • If customer data is being shared with related or third parties domiciled overseas, ensure your customer is aware of where their data is domiciled and your business has taken all reasonable steps to enforce the Australian Privacy Principles. Your business is responsible for how the overseas recipient utilises your customer’s data.
  • Only collect the customer data you need to provide the goods and services you offer.
  • Ensure protocols are in place for accounts payable.
  • Don’t forget the hardware – laptops, computers, phones. 
By Clarke McEwan July 23, 2026
Discover practical tax planning strategies for medical specialists in Australia. Learn how proactive structuring, superannuation, practice planning and wealth strategies can help you build long-term financial success.
By Clarke McEwan July 19, 2026
From 1 July 2026, thousands more businesses—including accounting and professional services firms—are now regulated under Australia’s anti-money laundering and counter-terrorism financing (AML/CTF) laws.
By Clarke McEwan July 3, 2026
With the start of the 2026–27 financial year, SMSF trustees should take a proactive approach to ensure funds remain compliant and well positioned. Below is a concise checklist of the key legislative changes, compliance deadlines and practical steps trustees should prioritise. 1. Review Transfer Balance Cap and Pension Planning Indexation of the general TBC: From 1 July 2026 the general transfer balance cap (TBC) increases from $2.0 million to $2.1 million. Members should check whether their personal transfer balance cap is eligible for indexation, particularly if they started a pension before the latest indexation dates. The ATO will calculate a member’s entitlement to indexation of their personal TBC, however, this will be based on reported transfer balance account (TBA) events (eg, commencement or commutation of a pension). It’s important that all TBA events up to 30 June 2026 have been reported to the ATO to ensure an accurate calculation of TBC indexation entitlement. Legacy pensions: The five-year legacy pension exit measure (7 Dec 2024 – 6 Dec 2029) remains available. Where clients hold legacy lifetime, life expectancy or market-linked pensions, confirm deed powers and consider the interaction with Division 296 and commutation rules before acting. 2. Update Contribution Strategies and Caps Higher caps for 2026–27: The concessional contributions cap rises to $32,500 and the standard non-concessional cap becomes $130,000. However, the non-concessional cap is subject the member’s 30 June 2026 total superannuation balance (TSB) being less than $2.1 million. Review your planned contributions to avoid cap breaches. Bring-forward and TSB thresholds: Check each member’s TSB at 30 June 2026 prior to applying bring-forward rules in 2026-27. Thresholds and allowable bring-forward periods changed for 2026–27. The increase to the standard non-concessional cap means the maximum bring forward cap has increased from $360,000 to $390,000. However, if the bring-forward rule was triggered in 2024-25 or 2025-26, the member does not get the benefit of the increase. 3. Pension Minimums, TRIS and ECPI Risks Minimum pension percentages: Check minimum pension percentages for age groups and ensure pensions meet the standards to avoid breaches and potential loss of fund tax exempt income. For a transition to retirement (TTR) pension, in addition to making at least the minimum pension payment, make sure you don’t exceed the 10% maximum. Also, if turning 65 in 2026-27, a TTR pension automatically moves into retirement phase and has TBC consequences. Speak to your adviser about implications and options well before your 65th birthday. Commutations and starting pensions: Follow correct commencement and commutation procedures; incorrect handling can trigger multiple events and adverse tax outcomes. Report all TBA events to the ATO by the due date. 4. Review Related Party Loans and Update Interest Rate The ATO document PCG 2016/5 sets out many of the terms and conditions a related party loan should have, including the interest rate. These are commonly referred to as the ‘safe harbour provisions’. Each year, the interest rate of the loan should be reviewed and updated in line with the relevant rate determined in May immediately before the commence of the financial year. The rate for the 2025-26 year was 8.95% for property and 10.95% for listed securities. As a result of increases in the RBA's cash rate over the last 12 months there has been an increase to the safe harbour interest rates to 9.35% and 11.35% for property and listed securities respectively. The repayments of any related party loans that are complying with the safe harbour provisions will need to be adjusted to reflect these new rates. 5. Check Compliance for Payroll and Contributions (SuperStream 3.0 / Payday Super) NPP readiness: From 1 July 2026 funds and employers must be capable of receiving contributions via the New Payments Platform (NPP). Ensure the SMSF bank account can accept Osko/PayID and other NPP payments. Member Verification Requests (MVRs): Employers will use MVRs to confirm whether a fund can accept a contribution. SMSFs receiving employer contributions should be prepared to respond to MVRs promptly (within required timeframes). Generally, SuperStream messages will be received in the SMSF administration platform that is used by the SMSF’s accountant or administrator. Members should inform their SMSF accountant or administrator if their employer will be sending a message via the MVR to confirm whether their SMSF can accept the contribution. Closely held employees: If your SMSF has related employees, confirm whether SuperStream exemptions apply and ensure payroll systems are updated as late lodgements may result in penalties. Remember the ATO can remove fund details from the SMSF lookup database if tax returns are overdue. This could impact on a fund’s ability to receive employer contributions. 6. Consider the Division 296 Transitional Rules and Tax Traps 2026–27 transitional year treatment: The 2026–27 year has specific transitional rules for Division 296 where the relevant TSB is measured at 30 June 2027. Trustees should assess whether electing to set a Div 296 cost base to 30 June 2026 market values is appropriate. This election does not need to be made until the lodgement of the 2027 SMSF Annual Return (tax return), and if made, applies to all assets and has consequences for capital losses and later adjustments. Seek tailored advice before electing. 7. Practical Housekeeping Deed powers and trustee structure: For SMSFs with individual trustees, consider whether a corporate trustee is a potentially better option. Talk to you adviser about these potential benefits and the process to change. Ensure that any changes to the trustee structure is reported to the relevant authority within the required timeframe (eg, the ATO, ASIC). Document everything: Keep clear records of trustee decisions, valuations used for elections, contribution timing evidence and communications with employers — documentation is key for the annual audit and if the ATO queries an event. Preparing now will reduce 2026-27 year-end stress and help avoid costly compliance issues. Speak to us if you have any questions or wish to discuss any of the issues raised above.
By Clarke McEwan July 3, 2026
The Tax Ombudsman has reported a dramatic 127% increase in complaints about the ATO this financial year (to 30 April 2026), with nearly 3,000 complaints received in the first ten months. Debt collection, penalties, and tax debt interest charges have dominated the issues raised. Tax Ombudsman Ruth Owen has linked the sharp rise directly to the ATO’s intensified focus on recovering outstanding debts amid tighter economic conditions. Many SME owners and individuals are feeling the pressure from cash flow challenges, rising costs, and stricter ATO enforcement. Why Complaints are Rising Debt collection accounted for around 23% of complaints, followed by payment-related issues (16%) and penalties plus interest (15%). Common concerns include: Refund offsets against debts Director Penalty Notices Challenges in setting up or maintaining payment plans The rapid accumulation of General Interest Charge (GIC) on overdue amounts This surge reflects real-world pressures: businesses navigating post-pandemic recovery, higher interest rates, and increased ATO activity to close the tax gap. For many clients, these issues create significant stress and can distract from core operations. Practical wins: Relief is Possible The good news? The Ombudsman’s office is proving effective as an independent escalation point. Around 31% of complaints relating to penalties and interest resulted in some form of debt reduction or remission. This highlights that persistence and proper representation can sometimes deliver favourable outcomes when initial ATO decisions feel overly harsh or inconsistent. Important Developments on GIC Remission A key theme in the complaints data is the GIC – the daily interest applied to unpaid tax debts. In March 2026, the Tax Ombudsman released a major review titled In the Interest of Fairness, which examined the ATO’s handling of GIC remission requests. The review identified inconsistent decision-making, unclear guidance, and communication gaps that left many taxpayers confused about their options. It made several recommendations, including clearer upfront interest-free payment plans for compliant taxpayers. The ATO’s response has been positive. It accepted all recommendations and has already begun implementing improvements, such as: Enhanced website guidance with practical examples New, more user-friendly remission application forms A $2,500 cap on phone approvals with a dedicated review team for larger requests to improve consistency Better support frameworks for vulnerable taxpayers These changes should hopefully make the process fairer and more predictable going forward, but sometimes best intentions don’t translate into practical reality so we will have to wait and see how this plays out. What this Means for You 1. Act early on tax debts: Don’t wait for the ATO to contact you. If you’re facing cash flow pressure, engage proactively before penalties and GIC escalate. Early action often leads to better terms. 2. Keep detailed records: Strong supporting documentation is crucial when seeking remission of penalties or interest. Demonstrate why the delay occurred (eg, unexpected revenue drop, illness, or system issues) and what steps you’ve taken to rectify it. 3. Use professional representation: Tax agents can liaise directly with the ATO on your behalf, prepare strong submissions, and escalate to the Tax Ombudsman where appropriate. This often leads to faster and more commercially practical outcomes than dealing with the matter alone. While the ATO must collect revenue fairly, the Ombudsman plays a vital role in ensuring processes remain reasonable and transparent. With economic headwinds continuing, understanding your rights and options has never been more important.  If you’re concerned about a tax debt, penalty notice, or GIC charge, contact our team promptly. Early intervention can significantly reduce costs and protect your business or personal finances. For more information, visit the Tax Ombudsman’s complaints snapshots and reports: Complaints snapshots - Tax Ombudsman
By Clarke McEwan July 3, 2026
The ATO is sharpening its focus on how taxpayers generating income from personal services deal with that income for tax purposes. In a recent Spotlight bulletin, Small Business Assistant Commissioner Tony Poulakis highlighted the release of Practical Compliance Guideline PCG 2025/5. This guideline clarifies the ATO’s compliance approach to the “alienation” of personal services income (PSI) — essentially, arrangements which involve routing income earned through your personal skills and efforts via a company or trust, rather than receiving it directly. Why the ATO Is Interested Many business owners operate through a company or trust rather than earning income personally. In many cases this is entirely legitimate and provides commercial benefits such as asset protection, flexibility and succession planning. However, where income is generated primarily from the efforts, skills or reputation of one individual, the ATO is concerned about arrangements that divert income away from that individual in order to reduce tax. Even where a business is able to pass certain tests to be classified as a Personal Services Business (PSB) under the tax rules and falls outside the strict PSI attribution rules, the ATO has made it clear that general anti-avoidance provisions in Part IVA can apply if the arrangement is primarily tax-driven. If Part IVA applies then this can lead to higher tax liabilities as well as significant penalties and interest charges. What Does the ATO Consider Low Risk? The ATO's guidance focuses heavily on whether the individual generating the income receives an appropriate share of the profits. Generally, an arrangement is more likely to be considered low risk where: The individual who performs the work receives most of the economic benefit through salary, wages, bonuses, director fees or trust distributions. Profits retained in a company are kept for genuine and short-term business reasons. Family members or associates are only paid reasonable amounts for genuine work performed. For example, retaining profits in a company to fund the purchase of new equipment in the short-term could be viewed favourably if there is evidence supporting those plans and the company actually follows through with these plans. What Will Attract ATO Attention? The ATO has specifically identified a number of higher-risk behaviours, including: Splitting income with family members who have made little or no contribution to earning that income. Retaining substantial profits in a company without a genuine short-term commercial purpose. Directing profits generating from someone’s personal services to entities or beneficiaries primarily because they are taxed at lower rates or because they have tax losses. The ATO’s expectations in this area are very strict. The greater the mismatch between who performed the work and who is ultimately taxed on the profits from that work, the greater the likelihood of ATO scrutiny. A Limited Opportunity to Review Existing Arrangements The ATO has provided a transition period for taxpayers who genuinely review and adjust their arrangements. Businesses that take genuine steps to move from higher-risk arrangements to lower-risk arrangements by 30 June 2027 are unlikely to face Part IVA action in relation to those arrangements if reviewed by the ATO. This is not an amnesty, but it is an opportunity for business owners to proactively assess their position and make changes where necessary. What Should Business Owners Do? Now is an ideal time to review how profits are being distributed within your structure. Questions worth considering include: Are retained profits supported by documented short-term commercial reasons? Are payments to family members commercially justifiable? Would your arrangements withstand ATO scrutiny if reviewed? If you operate through a company or trust and derive income largely from your personal skills or efforts, it is important to review existing arrangements in light of the ATO’s updated guidance. A proactive review today may prevent costly issues tomorrow.
By Clarke McEwan July 3, 2026
One of the most significant changes to the Australian superannuation system in decades has now commenced. From 1 July 2026, Payday Super requires employers to ensure super contributions reach employee super funds within seven business days of each payday. For many businesses, this represents a major shift from a quarterly payment cycle to a more frequent, real-time obligation. While the Government is aiming to get super into employee accounts faster and help close the national super gap, the new system introduces new compliance, cash flow and administrative considerations for employers. Businesses that have prepared well should find the transition manageable, but those still relying on quarterly processes need to act quickly to avoid significant problems. What Exactly Has Changed? Under the previous rules, employers generally had until 28 days after the end of each quarter to make super contributions. Under Payday Super, the clock now starts on each “Qualifying Earnings” (QE) day — essentially your payday for salary, wages, commissions, bonuses and certain contractor payments. Key Requirements Contributions must be received and allocated to the employee’s fund within 7 business days of payday (there are limited exceptions to this).Shortfalls are now calculated per QE day rather than quarterly. The ATO’s Small Business Superannuation Clearing House has closed, meaning businesses previously using the service must now use a SuperStream-compliant alternative. The ATO’s Small Business Superannuation Clearing House has closed, meaning businesses previously using the service must now use a SuperStream-compliant alternative. Penalties are also tougher. The administrative uplift can reach 60% of the shortfall (with reductions available for early voluntary disclosure), although the Superannuation Guarantee Charge itself is deductible in more circumstances. The ATO’s first-year compliance approach (PCG 2026/1) adopts a risk-based view, with businesses that make genuine efforts to comply and promptly rectify mistakes generally treated as lower risk. However, if an employee reports a problem to the ATO then don’t expect the ATO to ignore this. Managing the June – July Changeover There is a technical quirk in the rules which could catch out unsuspecting employers, especially when it comes to SG contributions made across the month of July 2026. If a business has paid employees during the June 2026 quarter then the SG deadline for this quarter would normally be 28 July 2026. However, many employers have decided to pay the SG amount for the June quarter before this deadline to reduce the risk of accidentally triggering a SGC problem. This is because any SG contributions made from 1 July 2026 will reduce the super owing for the June quarter first, before any remaining amount is used to meet Payday Super obligations relating to pay runs that occur in July. The best way to manage this situation to avoid SGC liabilities really depends on the dates of any July pay runs. Please contact us if you need help identifying any potential problems or to help come up with a practical solution. Three Practical Steps to Take Now 1. Review Your Systems: Confirm that your payroll software, clearing house and internal processes are operating correctly under the new rules. If you have not already done so, review pay codes and contribution workflows to ensure QEs are correctly identified. 2. Monitor Cash Flow and Processes: Assess the impact of more frequent super payments on cash flow. Review approval processes, onboarding procedures and the handling of bonuses or out-of-cycle payments. 3. Strengthen Controls and Communication: Ensure payroll and finance teams understand the new requirements and have appropriate controls in place. Ongoing monitoring and periodic reviews will help identify issues before they become compliance problems. The interdependencies between payroll systems, clearing houses and super funds mean small oversights can quickly create larger compliance issues. Businesses that continue to monitor and refine their processes will be best placed to meet their obligations. At Clarke McEwan, we are helping clients navigate the practical implications of Payday Super through readiness reviews, payroll process assessments and cash flow planning. Our goal is to help businesses remain compliant while building stronger and more efficient systems. If you would like to discuss how Payday Super affects your business, contact your Clarke McEwan adviser. We can help identify any remaining gaps and ensure your systems and processes continue to operate effectively under the new system.
More Posts