Filed Under Compliance, Better Understood as Malpractice
The Australian Information Commissioner has ordered American Express to implement access controls after a series of insider privacy breaches. According to iTnews, Amex has six months to comply. Six months, to implement least-privilege access controls, at one of the largest financial services organisations on the planet.
Nothing in this involves a sophisticated adversary, a zero-day, or an emerging threat that blindsided a mature programme. Insiders reached data they had no business reaching, at a company that apparently could neither prevent nor detect it, and a regulator has now had to mandate remediation work that should have finished before most of its current security team left university. That the industry is filing this under compliance rather than professional failure tells you more about enterprise security governance than any breach statistic.
Least-Privilege Is Not New Thinking
Giving users only the access their role requires is not an emerging practice, a post-pandemic lesson, or a recent addition to NIST guidance still working its way into the mainstream. It has been foundational in every serious security framework for more than twenty years. ISO 27001 has it. CPS 234 embeds it. The Essential Eight lists it explicitly. The OAIC’s expectations under the Privacy Act have long included protecting personal information from internal misuse.
No credible argument exists that Amex’s security leadership did not know this was required. The knowledge, the frameworks and the regulatory expectation were all in place. What was missing was the organisational will to do the work.
Why Organisations Tolerate Known Risk
This is where the conversation needs to become more honest than it usually is in industry circles.
Access control remediation at scale is genuinely hard. It requires mapping roles to data assets, rationalising legacy permissions that have accumulated over years of staff changes and system growth, managing the operational disruption of access revocations, and sustaining the governance process that prevents privilege creep from rebuilding itself within eighteen months. It is unglamorous, internally contentious, and produces no visible product at the end. Security teams struggle to get budget for it. CISOs struggle to get executive attention for it. And so it gets deferred — not because nobody knew it needed doing, but because the organisational cost of doing it felt more immediate than the risk of not doing it.
That calculation has a name: tolerating known risk because the remediation is inconvenient. In engineering, medicine or law, knowingly maintaining a condition that falls below the minimum standard of practice, and deferring the fix for operational convenience, is malpractice. Security has largely escaped that framing because its failures get attributed to adversaries, complexity or resourcing rather than to the judgement of the people who decided not to act.
This case removes the cover. No external attacker defeated sophisticated defences. Insiders reached data they should not have been able to reach, which is the exact scenario least-privilege exists to prevent, and the control, the requirement and the risk were all known and documented years in advance.
The Quiet Relief in the Industry Is Telling
The dominant reaction across Australian financial services will be quiet relief that the headline said Amex. Boards at those peer institutions should treat that reaction as a signal rather than a comfort.
If your organisation’s access control posture is materially better than Amex’s — if you have done the role-mapping, rationalised legacy permissions, implemented detection for anomalous internal access, and have governance in place to prevent privilege creep — then your relief is warranted. But if you have deferred the same work for the same reasons, then what you are feeling is not relief. It is proximity to the same regulatory and reputational exposure, with the outcome not yet realised.
The OAIC’s action here is a preview. The Privacy Act reforms currently moving through Australian legislative process will increase the Commissioner’s enforcement powers and the potential penalties for exactly this kind of failure. APRA has been explicit that CPS 234 compliance is not a checkbox exercise. Regulators in this country are becoming less patient with organisations that acknowledge known gaps and produce roadmaps rather than remediation.
What a Six-Month Window Signals
The six-month timeframe the OAIC has allowed deserves scrutiny too. It is a reasonable implementation window for a programme of this complexity. It is not, by any measure, a short fuse that reflects regulatory urgency. Regulators tend to set timelines that are achievable rather than aspirational, because they need compliance, not failure.
What the six months tells us is that access control remediation at an organisation the size of Amex is a substantial undertaking — which means that if your organisation has not started it, and you are of comparable size and complexity, six months is also roughly what you need. Not what you have available in some theoretical future planning cycle. What you need, starting now, if you want to be ahead of the same conversation rather than in it.
The Board Question
One question is worth putting to the CISO or CIO this quarter, and it is not whether an access control policy exists. Ask when the access control posture was last independently validated against the current role and data landscape, and what came back.
A policy is not a control and a roadmap is not remediation. Six months from a regulator is not generosity either; it is a deadline issued after the breach.
What makes this case worth writing about is precisely that it is not novel. Foundational controls fail at major institutions regularly, the industry files it under compliance rather than examining the governance failures that let known risk sit there for years, and the same failures keep accumulating somewhere else. Naming it accurately at least makes the next conversation more honest.