This Isn’t a Compliance Story. It’s a Malpractice Story.
The Australian Information Commissioner has ordered American Express to implement access controls after a series of insider privacy breaches. According to iTnews, Amex has been given six months to comply. Six months. To implement least-privilege access controls. At one of the largest financial services organisations on the planet.
Let’s be precise about what that means. This is not a story about a sophisticated adversary, a zero-day exploit, or an emerging threat that caught a mature security programme off guard. This is a story about insiders accessing data they had no business accessing, at a company that apparently lacked the controls to prevent or detect it, and a regulator now having to mandate remediation work that should have been completed before most of its current security staff graduated university. The fact that the industry is treating this as a compliance matter rather than a professional failure says more about the state of enterprise security governance than any breach statistic does.
Least-Privilege Is Not New Thinking
The principle of least-privilege access — giving users only the access they need to perform their role, nothing more — is not an emerging practice. It is not a post-pandemic lesson. It is not something that appeared in recent NIST guidance and is still working its way into mainstream adoption. It has been a foundational control in every serious security framework for over two decades. It appears in ISO 27001. It is embedded in APRA’s CPS 234. The ASD’s Essential Eight lists it explicitly. The OAIC’s own regulatory expectations under the Privacy Act have long included the obligation to protect personal information from internal misuse.
There is no credible argument that Amex’s security leadership was unaware that least-privilege access was required. The knowledge existed. The frameworks existed. The regulatory expectation existed. What apparently did not exist was the organisational will to do the work.
Why Organisations Tolerate Known Risk
This is where the conversation needs to become more honest than it usually is in industry circles.
Access control remediation at scale is genuinely hard. It requires mapping roles to data assets, rationalising legacy permissions that have accumulated over years of staff changes and system growth, managing the operational disruption of access revocations, and sustaining the governance process that prevents privilege creep from rebuilding itself within eighteen months. It is unglamorous, internally contentious, and produces no visible product at the end. Security teams struggle to get budget for it. CISOs struggle to get executive attention for it. And so it gets deferred — not because nobody knew it needed doing, but because the organisational cost of doing it felt more immediate than the risk of not doing it.
That calculation has a name. It is called tolerating known risk because remediation is inconvenient. In any other professional discipline — engineering, medicine, law — knowingly maintaining a condition that fails to meet the minimum standard of practice, and deferring its correction for operational convenience, is malpractice. The security industry has largely escaped that framing because its failures tend to be attributed to adversaries, complexity, or resource constraints rather than to the professional judgement of the people who chose not to act.
The Amex case removes that cover. This was not an external attacker who defeated sophisticated defences. This was insiders accessing data they should not have been able to reach, which is precisely the scenario that least-privilege access exists to prevent. The control was known. The requirement was known. The risk was known. It was not managed.
The Quiet Relief in the Industry Is Telling
Here is what should concern boards and executives at Amex’s peers: the dominant reaction in Australian financial services and beyond will be quiet relief that it was Amex in the headlines rather than them. That reaction should be treated as a signal, not a comfort.
If your organisation’s access control posture is materially better than Amex’s — if you have done the role-mapping, rationalised legacy permissions, implemented detection for anomalous internal access, and have governance in place to prevent privilege creep — then your relief is warranted. But if you have deferred the same work for the same reasons, then what you are feeling is not relief. It is proximity to the same regulatory and reputational exposure, with the outcome not yet realised.
The OAIC’s action here is a preview. The Privacy Act reforms currently moving through Australian legislative process will increase the Commissioner’s enforcement powers and the potential penalties for exactly this kind of failure. APRA has been explicit that CPS 234 compliance is not a checkbox exercise. Regulators in this country are becoming less patient with organisations that acknowledge known gaps and produce roadmaps rather than remediation.
What a Six-Month Remediation Window Actually Signals
The six-month timeframe the OAIC has allowed deserves scrutiny too. It is a reasonable implementation window for a programme of this complexity. It is not, by any measure, a short fuse that reflects regulatory urgency. Regulators tend to set timelines that are achievable rather than aspirational, because they need compliance, not failure.
What the six months tells us is that access control remediation at an organisation the size of Amex is a substantial undertaking — which means that if your organisation has not started it, and you are of comparable size and complexity, six months is also roughly what you need. Not what you have available in some theoretical future planning cycle. What you need, starting now, if you want to be ahead of the same conversation rather than in it.
The Board Question
If you are a board member or senior executive reading this, there is one question worth putting to your CISO or CIO this quarter: not whether you have an access control policy, but when your access control posture was last independently validated against your current role and data landscape, and what the findings were.
A policy is not a control. A roadmap is not remediation. And six months from a regulator is not a gift — it is a deadline that arrived after the breach already happened.
The Amex case is not novel. That is precisely the point. When foundational controls fail at major institutions, and the industry’s response is to categorise it as a compliance matter rather than examine the professional and governance failures that allowed known risk to persist, the same failures continue to accumulate elsewhere. Name it for what it is, and the conversation about what to do about it becomes considerably more honest.