Summit 2026 · facilitator copy

Run sheet

Twenty stages. The incident runs in the background and the questions interrupt it, so that each statistic arrives with something already at stake. Every question is answered privately before anybody sees a number.


  1. 01

    Summit 2026

    Reality Check

    Everything you are about to answer, you answer privately. Nobody sees anybody else’s number until all three are in.

    Hand out the join link. Wait until every name is on the screen before you advance.

    on screen

  2. 02

    Before we start

    How confident are you that you understand this organisation’s current data and security risk?

    Show the average. Say nothing about it. Do not react. Advance.

    collect privately → team’s number

  3. 03

    Monday · 08:03

    You are the first manager to read that message. What do you tell her?

    • A Approve one so they stop, then look into it
    • B Ignore them and get on with the morning
    • C Deny them, change her password now, ring IT
    • D Deny them, report it, leave the password until IT calls back

    Happens anyway — At 08:11 a prompt is approved. Jane says she was holding the phone and the milk at the same time. The prompts stop. Everyone assumes that means it is over.

    Read the split out loud but do not grade it. The point is that the room disagreed.

    collect privately → every answer → what happened anyway

  4. 04

    Reality check 01

    What percentage of notified Australian data breaches are caused by human error rather than by an attacker?

    Answer 31% · scored

    Human error caused 194 of the 670 breaches Australian organisations notified in the second half of 2025 — 30.6%.

    OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).

    collect privately → team’s number → the real number → the gap

  5. 05

    Monday · 08:24

    Before you know anything else, what is the first call you make?

    • A Tell the participants and families on Jane’s caseload
    • B Notify the NDIS Quality and Safeguards Commission
    • C Notify the OAIC
    • D Nobody outside the building yet — contain it first
    • E Ring our insurer and our lawyer

    Happens anyway — It takes until 09:40 to answer the only question that matters: the rule has been in place for nine days. 1,840 emails matched it.

    Do not resolve the disagreement here. It comes back in the debrief.

    collect privately → every answer → what happened anyway

  6. 06

    Reality check 02

    Once an Australian organisation has identified a breach, what percentage report it to the regulator within ten days?

    Answer 21% · scored

    Only 21.0% of breaches were reported to the OAIC within ten days of being identified — and the legal obligation is to assess within thirty.

    OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).

    collect privately → team’s number → the real number → the gap

  7. 07

    Reality check 03

    And going the other way: what percentage of Australian breaches were identified within ten days of happening?

    Answer 64% · scored

    64.3% were identified within ten days. Australian organisations are far better at finding breaches than at reporting them.

    OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).

    This is the question that stops them simply guessing worse and worse. Let that land.

    collect privately → team’s number → the real number → the gap

  8. 08

    Reality check 04

    What percentage of notified Australian breaches affected one hundred people or fewer?

    Answer 61% · scored

    61.3% of notified breaches affected one hundred people or fewer. The headlines are about millions; the reality is about dozens.

    OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).

    If they guessed low, ask why. The answer is usually "because I only hear about the big ones."

    collect privately → team’s number → the real number → the gap

  9. 09

    Reality check 05

    Of every industry in Australia, what share of notified breaches came from health and care providers?

    Answer 19% · scored

    Health service providers notified 128 of 670 breaches — 19%, more than any other sector in Australia, for the twelfth reporting period running.

    OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).

    This is us. Say that plainly, once.

    collect privately → team’s number → the real number → the gap

  10. 10

    Monday · 11:15

    A journalist has the story before you do

    A reporter emails the general enquiries inbox. They have been sent a document. It is a support plan. It has a participant’s name, address, diagnosis and the name of the school their child attends. They would like a comment by four o’clock.

    Read it slowly. Then go straight into the next question without commentary.

    on screen

  11. 11

    Reality check 06

    Of all the human-error breaches in Australia, what percentage were simply an email sent to the wrong person?

    Answer 44% · scored

    Misdirected email accounted for 86 of the 194 human-error breaches — 44%. It is the single most common way Australian organisations lose personal information.

    OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).

    collect privately → team’s number → the real number → the gap

  12. 12

    Reality check 07

    How many data breaches did Australian organisations notify the regulator about across the whole of 2025?

    Answer 1205 · not scored

    1,205 notifications in 2025 — the highest year since the scheme began in 2018, and 8% up on 2024.

    OAIC media release, "Data breach notifications increase to all-time high in 2025".

    Not scored — it is a count, not a percentage. Use it for scale, not for the scoreboard.

    collect privately → team’s number → the real number → the gap

  13. 13

    Reality check 08

    How many people can open a file containing a participant’s health information right now?

    Answer set on the day · not scored

    Enter the real number on the run screen BEFORE the session. If you have not established it, skip this stage — a guessed "actual" destroys the whole exercise.

    collect privately → team’s number → the real number → the gap

  14. 14

    Reality check 09

    If a forwarding rule were added to one of our mailboxes this morning, how many days until we found it?

    Answer set on the day · not scored

    The honest answer is usually "we would not". If that is the answer, put it on the screen as the answer.

    collect privately → team’s number → the real number → the gap

  15. 15

    Where that leaves us

    As a management team, how far out were we?

    Read the team line, not the individual lines. Nobody wins this.

    scoreboard

  16. 16

    The same question as the first one

    How confident are you that you understand this organisation’s current data and security risk?

    Do not remind them what they said the first time. Not yet.

    collect privately → team’s number

  17. 17

    Both answers

    What changed?

    Ask the question. Then stop talking. This is the longest silence of the session and it is the point of it.

    before and after

  18. 18

    Debrief

    What have we learned about ourselves?

    Which of our assumptions turned out to be wrong? What did we learn about how we would actually respond? What did we learn about the risks we are actually carrying?

    Four to six minutes. Write what they say on the whiteboard, verbatim, in their words.

    on screen

  19. 19

    One last private answer

    Knowing what we know now: is there anything we think should improve?

    • Yes
    • No
    • Not sure

    All three at once. Whatever comes up, that is the mandate — or the absence of one.

    collect privately → every answer

  20. 20

    Summit 2026

    That is the session.

    Nothing on this screen was designed to frighten anybody. It was designed to be checked.

    on screen


Where the numbers come from


How to run it

  1. Open /run, pick a code and a four-digit PIN, press Create it.
  2. Enter the real answers to the two “about us” questions. If you cannot establish one, jump past that stage — a guessed actual undoes the whole exercise.
  3. Open /stage on the projector, enter the same code, press F.
  4. The room scans the code on the opening slide, types a name, and puts the phone down.
  5. Drive from /run on your phone. Space advances one phase.
  6. Wait for every name to light up before revealing. The whole mechanic depends on them having committed.

Join screen · Big screen · Facilitator