Summit 2026 · facilitator copy
Run sheet
Twenty stages. The incident runs in the background and the questions interrupt it, so that each statistic arrives with something already at stake. Every question is answered privately before anybody sees a number.
01
Summit 2026
Reality Check
Everything you are about to answer, you answer privately. Nobody sees anybody else’s number until all three are in.
Hand out the join link. Wait until every name is on the screen before you advance.
on screen
02
Before we start
How confident are you that you understand this organisation’s current data and security risk?
Show the average. Say nothing about it. Do not react. Advance.
collect privately → team’s number
03
Monday · 08:03
You are the first manager to read that message. What do you tell her?
- A Approve one so they stop, then look into it
- B Ignore them and get on with the morning
- C Deny them, change her password now, ring IT
- D Deny them, report it, leave the password until IT calls back
Happens anyway — At 08:11 a prompt is approved. Jane says she was holding the phone and the milk at the same time. The prompts stop. Everyone assumes that means it is over.
Read the split out loud but do not grade it. The point is that the room disagreed.
collect privately → every answer → what happened anyway
04
Reality check 01
What percentage of notified Australian data breaches are caused by human error rather than by an attacker?
Answer 31% · scored
Human error caused 194 of the 670 breaches Australian organisations notified in the second half of 2025 — 30.6%.
OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).
collect privately → team’s number → the real number → the gap
05
Monday · 08:24
Before you know anything else, what is the first call you make?
- A Tell the participants and families on Jane’s caseload
- B Notify the NDIS Quality and Safeguards Commission
- C Notify the OAIC
- D Nobody outside the building yet — contain it first
- E Ring our insurer and our lawyer
Happens anyway — It takes until 09:40 to answer the only question that matters: the rule has been in place for nine days. 1,840 emails matched it.
Do not resolve the disagreement here. It comes back in the debrief.
collect privately → every answer → what happened anyway
06
Reality check 02
Once an Australian organisation has identified a breach, what percentage report it to the regulator within ten days?
Answer 21% · scored
Only 21.0% of breaches were reported to the OAIC within ten days of being identified — and the legal obligation is to assess within thirty.
OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).
collect privately → team’s number → the real number → the gap
07
Reality check 03
And going the other way: what percentage of Australian breaches were identified within ten days of happening?
Answer 64% · scored
64.3% were identified within ten days. Australian organisations are far better at finding breaches than at reporting them.
OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).
This is the question that stops them simply guessing worse and worse. Let that land.
collect privately → team’s number → the real number → the gap
08
Reality check 04
What percentage of notified Australian breaches affected one hundred people or fewer?
Answer 61% · scored
61.3% of notified breaches affected one hundred people or fewer. The headlines are about millions; the reality is about dozens.
OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).
If they guessed low, ask why. The answer is usually "because I only hear about the big ones."
collect privately → team’s number → the real number → the gap
09
Reality check 05
Of every industry in Australia, what share of notified breaches came from health and care providers?
Answer 19% · scored
Health service providers notified 128 of 670 breaches — 19%, more than any other sector in Australia, for the twelfth reporting period running.
OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).
This is us. Say that plainly, once.
collect privately → team’s number → the real number → the gap
10
Monday · 11:15
A journalist has the story before you do
A reporter emails the general enquiries inbox. They have been sent a document. It is a support plan. It has a participant’s name, address, diagnosis and the name of the school their child attends. They would like a comment by four o’clock.
Read it slowly. Then go straight into the next question without commentary.
on screen
11
Reality check 06
Of all the human-error breaches in Australia, what percentage were simply an email sent to the wrong person?
Answer 44% · scored
Misdirected email accounted for 86 of the 194 human-error breaches — 44%. It is the single most common way Australian organisations lose personal information.
OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025 (670 notifications).
collect privately → team’s number → the real number → the gap
12
Reality check 07
How many data breaches did Australian organisations notify the regulator about across the whole of 2025?
Answer 1205 · not scored
1,205 notifications in 2025 — the highest year since the scheme began in 2018, and 8% up on 2024.
OAIC media release, "Data breach notifications increase to all-time high in 2025".
Not scored — it is a count, not a percentage. Use it for scale, not for the scoreboard.
collect privately → team’s number → the real number → the gap
13
Reality check 08
How many people can open a file containing a participant’s health information right now?
Answer set on the day · not scored
Enter the real number on the run screen BEFORE the session. If you have not established it, skip this stage — a guessed "actual" destroys the whole exercise.
collect privately → team’s number → the real number → the gap
14
Reality check 09
If a forwarding rule were added to one of our mailboxes this morning, how many days until we found it?
Answer set on the day · not scored
The honest answer is usually "we would not". If that is the answer, put it on the screen as the answer.
collect privately → team’s number → the real number → the gap
15
Where that leaves us
As a management team, how far out were we?
Read the team line, not the individual lines. Nobody wins this.
scoreboard
16
The same question as the first one
How confident are you that you understand this organisation’s current data and security risk?
Do not remind them what they said the first time. Not yet.
collect privately → team’s number
17
Both answers
What changed?
Ask the question. Then stop talking. This is the longest silence of the session and it is the point of it.
before and after
18
Debrief
What have we learned about ourselves?
Which of our assumptions turned out to be wrong? What did we learn about how we would actually respond? What did we learn about the risks we are actually carrying?
Four to six minutes. Write what they say on the whiteboard, verbatim, in their words.
on screen
19
One last private answer
Knowing what we know now: is there anything we think should improve?
- Yes
- No
- Not sure
All three at once. Whatever comes up, that is the mandate — or the absence of one.
collect privately → every answer
20
Summit 2026
That is the session.
Nothing on this screen was designed to frighten anybody. It was designed to be checked.
on screen
Where the numbers come from
- OAIC, Notifiable Data Breaches report, 1 July – 31 December 2025
670 notifications. Source for every percentage in reality checks 01–06.
- OAIC media release — data breach notifications at an all-time high in 2025
1,205 notifications across calendar 2025, up 8% on 2024. Source for reality check 07.
- OAIC blog — notifiable data breach statistics, January to June 2025
The earlier half-year, where human error was 37% of 532 notifications. Kept here because it is the figure most people have seen quoted; the run sheet uses the newer period.
How to run it
- Open /run, pick a code and a four-digit PIN, press Create it.
- Enter the real answers to the two “about us” questions. If you cannot establish one, jump past that stage — a guessed actual undoes the whole exercise.
- Open /stage on the projector, enter the same code, press F.
- The room scans the code on the opening slide, types a name, and puts the phone down.
- Drive from /run on your phone. Space advances one phase.
- Wait for every name to light up before revealing. The whole mechanic depends on them having committed.