InsightsSolutionsProductsEngagementsTrust CentreAbout
Client access Start a conversation
InsightsSolutionsProductsEngagementsTrust CentreAbout Client access Start a conversation

Security & Trust Centre

Incident Response Policy

Last updated 17 June 2026

Establishes how UniMatter detects, contains, investigates, and reports security incidents and eligible data breaches.

1. Purpose and scope

This policy establishes the framework by which UniMatter identifies, responds to, and learns from security incidents, including those that may amount to an eligible data breach under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). Its objective is to limit harm, restore normal operation, meet the firm’s legal obligations, and preserve the trust of clients and individuals.

This policy applies to all UniMatter systems and data and to all users, including the principal, contractors, and subprocessors. It applies to incidents affecting information held by the firm and to incidents affecting information processed on a client’s behalf.

2. Definitions

A security incident is an event or series of events that compromises, or threatens to compromise, the confidentiality, integrity, or availability of UniMatter systems or data. A data breach is a security incident involving unauthorised access to, unauthorised disclosure of, or loss of, personal information.

An eligible data breach is a data breach that is likely to result in serious harm to one or more individuals to whom the information relates, and that the firm has not been able to remediate so as to prevent that likely serious harm.

3. Detection and reporting

All users must report a suspected or actual security incident without delay, irrespective of the time of day or apparent severity. Early reporting is treated as a mitigating factor and is never penalised.

Reports may be made directly to the principal at security@unimatter.com.au. On receipt, the incident is recorded, assigned a severity, and triaged to determine the response required.

4. Containment and eradication

On confirmation of an incident, UniMatter acts to contain it and to prevent further compromise. Containment measures are selected to limit harm while preserving evidence necessary for investigation.

  1. Isolate or disable affected systems, accounts, credentials, and access tokens.
  2. Preserve logs, system images, and other evidence before remediation where practicable.
  3. Remove the cause of the incident, including malware, unauthorised access paths, and exploited vulnerabilities.
  4. Restore affected systems and data from verified, clean backups in accordance with the Business Continuity and Disaster Recovery Policy.

5. Assessment of eligible data breaches

Where an incident involves personal information, UniMatter conducts a prompt and reasonable assessment to determine whether the incident is an eligible data breach. The firm aims to complete this assessment expeditiously and, in any case, to take all reasonable steps to complete it within 30 days of becoming aware of grounds to suspect an eligible data breach, consistent with the Privacy Act 1988 (Cth).

The assessment considers the type and sensitivity of the information, the circumstances of the breach, the persons who may have obtained access, and whether remedial action has prevented the likelihood of serious harm.

6. Notification

Where UniMatter is satisfied that there are reasonable grounds to believe an eligible data breach has occurred, and remedial action has not prevented the likely serious harm, the firm notifies the Office of the Australian Information Commissioner and affected individuals as soon as practicable, in accordance with Part IIIC of the Privacy Act 1988 (Cth).

Where UniMatter processes personal information on behalf of a client, the firm notifies the client without undue delay so that the controller can discharge its own notification obligations, and the firm assists the client in doing so. Notification statements describe the breach, the information involved, and the steps individuals can take to protect themselves.

7. Roles and external engagement

The principal leads the response to each incident and is accountable for decisions on containment, assessment, and notification. Where an incident exceeds the firm’s internal capability, the principal engages qualified external specialists, including forensic, legal, and where appropriate the Australian Cyber Security Centre.

Communications with regulators, clients, and affected individuals are coordinated to ensure they are accurate, timely, and consistent.

8. Post-incident review

Following each significant incident, UniMatter conducts a post-incident review to identify the root cause, evaluate the effectiveness of the response, and determine the corrective and preventive actions required. The findings are recorded and the actions are tracked to completion.

Lessons from incidents are fed back into the firm’s controls, this policy, and related policies, so that the firm’s security posture improves over time.

9. Testing and review

UniMatter periodically tests its incident-response arrangements through exercises proportionate to the firm’s scale and risk profile. This policy is reviewed at least annually and after any significant incident. Enquiries may be directed to UniMatter at security@unimatter.com.au.

This policy forms part of the UniMatter Security & Trust Centre. It is reviewed at least annually. Questions may be directed to administrator@unimatter.com.au.

Your partner in clarity.

Level 1, 16 McDougall Street
Milton QLD 4064
administrator@unimatter.com.au
+61 493 522 896

Research Insights & research The research discipline The Principle Solutions Systems Architecture & Security Business Transformation
Products UniMatter Assurance UniMatter Excel Engage Engagements & advisory Request a proposal Start a conversation
Access Client access Security & Trust Centre
Legal Privacy Policy Terms & Conditions Responsible Disclosure Security Policy Cookie & Tracking Policy Practice About

© 2026 Maxwell Vidler, trading as UniMatter. All rights reserved.

Measurement · Verifiability · Accountability

Insight