- Market services
-
Compliance audits & reviews
Our audit team undertakes the complete range of audits required of Australian accounting laws to help you to help you meet obligations or fulfil best practice procedures.
-
Audit quality
We are fiercely dedicated to quality, use proven and globally tested audit methodologies, and invest in technology and innovation.
-
Financial reporting advisory
Our financial reporting advisory team helps you understand changes in accounting standards, develop strategies and communicate with your stakeholders.
-
Audit advisory
Grant Thornton’s audit advisory team works alongside our clients, providing a full range of reviews and audits required of your business.
-
Digital assurance
We capture actionable, quality insights from data within your financial reporting and auditing processes.

-
Corporate tax & advisory
We provide comprehensive corporate tax and advisory service across the full spectrum of the corporate tax process.
-
Private business tax & advisory
We work with private businesses and their leaders on all their business tax and advisory needs.
-
Tax compliance
We work alongside clients to manage all tax compliance needs and identify potential compliance or tax risk issues.
-
Employment tax
We help clients understand and address their employment tax obligations to ensure compliance and optimal tax positioning for their business and employees.
-
International tax
We understand what it means to manage tax issues across multiple jurisdictions, and create effective strategies to address complex challenges.
-
GST, stamp duty & indirect tax
Our deep technical knowledge and practical experience means we can help you manage and minimise the impact of GST and indirect tax, like stamp duty.
-
Tax law
Our team – which includes tax lawyers – helps you understand and implement regulatory requirements for your business.
-
Innovation Incentives
Our national team has extensive experience navigating all aspects of the government grants and research and development tax incentives.
-
Transfer pricing
Transfer pricing is one of the most challenging tax issues. We help clients with all their transfer pricing requirements.
-
Tax digital consulting
We analyse high-volume and unstructured data from multiple sources from our clients to give them actionable insights for complex business problems.
-
Corporate simplification
We provide corporate simplification and managed wind-down advice to help streamline and further improve your business.
-
Superannuation and SMSF
Increasingly, Australians are seeing the benefits, advantages and flexibility of taking control of their own superannuation and retirement planning.

-
Payroll consulting & Award compliance
Many organisations are grappling with a myriad of employee agreements and obligations, resulting in a wide variety of payments to their people.
-
Cyber resilience
The spectrum of cyber risks and threats is now so significant that simply addressing cybersecurity on its own isn’t enough.
-
Internal audit
We provide independent oversight and review of your organisation's control environments to manage key risks, inform good decision-making and improve performance.
-
Financial crime
Our team helps clients navigate and meet their obligations to mitigate crime as well as develop and implement their risk management strategies.
-
Consumer Data Right
Consumer Data Right (CDR) aims to provide Australians with more control over how their data is used and disclosed.
-
Risk management
We enable our clients to achieve their strategic objectives, fulfil their purpose and live their values supported by effective and appropriate risk management.
-
Controls assurance
In Australia, as with other developed economies, regulatory and market expectations regarding corporate transparency continue to increase.
-
Governance
Through fit for purpose governance we enable our clients to make the appropriate decisions on a timely basis.
-
Regulatory compliance
We enable our clients to navigate and meet their regulatory and compliance obligations.

-
Forensic accounting and dispute advisory
Our team advises at all stages of a litigation dispute, taking an independent view while gathering and reviewing evidence and contributing to expert reports.
-
Investigations
Our licensed forensic investigators with domestic and international experience deliver high quality results in the jurisdictions in which you operate.
-
Asset tracing investigations
Our team of specialist forensic accountants and investigators have extensive experience in tracing assets and the flow of funds.

-
Mergers and acquisitions
Our mergers and acquisitions specialists guide you through the whole process to get the deal done and lay the groundwork for long-term success.
-
Acquisition search & strategy
We help clients identify, finance, perform due diligence and execute acquisitions to maximise the growth opportunities of your business.
-
Selling a business
Our M&A team works with clients to achieve a full or partial sale of their business, to ensure achievement of strategic ambitions and optimal outcomes for stakeholders.
-
Operational deal services
Our operational deal services team helps to ensure the greatest possible outcome and value is gained through post merger integration or post acquisition integration.
-
Transaction advisory
Our transaction advisory services support our clients to make informed investment decisions through robust financial due diligence.
-
ESG Due Diligence
Our ESG due diligence process evaluates a company's environmental, social, and governance factors during the pre-investment phase to determine the overall maturity of the entity, manage potential risks, and identify opportunities.
-
Business valuations
We use our expertise and unique and in-depth methodology to undertake business valuations to help clients meet strategic goals.
-
Tax in mergers & acquisition
We provide expert advice for all M&A taxation aspects to ensure you meet all obligations and are optimally positioned.

-
Corporate finance
We provide effective and strategic corporate finance services across all stages of investments and transactions so clients can better manage costs and maximise returns.
-
Debt advisory
We work closely with clients and lenders to provide holistic debt advisory services so you can raise or manage existing debt to meet your strategic goals.
-
Working capital optimisation
Our proven methodology identifies opportunities to improve your processes and optimise working capital, and we work with to implement changes and monitor their effectiveness.
-
Capital markets
Our team has significant experience in capital markets and helps across every phase of the IPO process.
-
Debt and project finance raising
Backed by our experience accessing full range of available funding types, we work with clients to develop and implement capital raising strategies.
-
Private equity
We provide advice in accessing private equity capital.
-
Financial modelling
Our financial modelling advisory team provides strategic, economic, financial and valuation advice for project types and sizes.
-
Payments advisory
We provide merchants-focused payments advice on all aspects of payment processes and technologies.

-
Voluntary administration & DOCA
We help businesses considering or in voluntary administration to achieve best possible outcomes.
-
Corporate insolvency & liquidation
We help clients facing corporate insolvency to undertake the liquidation process to achieve a fair and orderly company wind up.
-
Complex and international insolvency
As corporate finance specialists, Grant Thornton can help you with raising equity, listings, corporate structuring and compliance.
-
Safe Harbour advisory
Our Safe Harbour Advisory helps directors address requirements for Safe Harbour protection and business turnaround.
-
Bankruptcy and personal insolvency
We help clients make informed choices around bankruptcy and personal insolvency to ensure the best personal and stakeholder outcome.
-
Creditor advisory services
Our credit advisory services team works provides clients with credit management assistance and credit advice to recapture otherwise lost value.
-
Small business restructuring process
We provide expert advice and guidance for businesses that may need to enter or are currently in small business restructuring process.
-
Asset tracing investigations
Our team of specialist forensic accountants and investigators have extensive experience in tracing assets and the flow of funds.

-
Independent business reviews
Does your company need a health check? Grant Thornton’s expert team can help you get to the heart of your issues to drive sustainable growth.
-
Commercial performance
We help clients improve commercial performance, profitability and address challenges after internal or external triggers require a major business model shift.
-
Safe Harbour advisory
Our Safe Harbour advisory helps directors address requirements for Safe Harbour protection and business turnaround.
-
Corporate simplification
We provide corporate simplification and managed wind-down advice to help streamline and further improve your business.
-
Director advisory services
We provide strategic director advisory services in times of business distress to help directors navigate issues and protect their company and themselves from liability.
-
Debt advisory
We work closely with clients and lenders to provide holistic debt advisory services so you can raise or manage existing debt to meet your strategic goals.

-
Business planning & strategy
Our clients can access business planning and strategy advice through our value add business strategy sessions.
-
Private business company secretarial services
We provide company secretarial services and expert advice for private businesses on all company secretarial matters.
-
Outsourced accounting services
We act as a third-party partner to international businesses looking to invest in Australia on your day-to-day finance and accounting needs.
-
Superannuation and SMSF
We provide SMSF advisory services across all aspects of superannuation and associated tax laws to help you protect and grow your wealth.
-
Management reporting
We help you build comprehensive management reporting so that you have key insights as your business grows and changes.
-
Financial reporting
We help with all financial reporting needs, including set up, scaling up, spotting issues and improving efficiency.
-
Forecasting & budgeting
We help you build and maintain a business forecasting and budgeting model for ongoing insights about your business.
-
ATO audit support
Our team of experts provide ATO audit support across the whole process to ensure ATO requirements are met.
-
Family business consulting
Our family business consulting team works with family businesses on running their businesses for continued future success.
-
Private business taxation and structuring
We help private business leaders efficiently structure their organisation for optimal operation and tax compliance.
-
Outsourced CFO services
Our outsourced CFO services provide a full suite of CFO, tax and finance services and advice to help clients manage risk, optimise operations and grow.
-
ESG, sustainability and climate reporting
There is a growing demand for organisations to provide transparency on their commitment to sustainability and disclosure of the nonfinancial impacts of their business activities. Commonly, the responsibility for sustainability and ESG reporting is landing with CFOs and finance teams, requiring a reassessment of a range of reporting processes and controls.
-
ESG, sustainability and climate advisory
With the ESG and sustainability landscape continuing to evolve, we are focussed on helping your business to understand what ESG and sustainability represents and the opportunities and challenges it can provide.
-
ESG, sustainability and climate reporting assurance
As the demand for organisations to prepare information in relation to ESG & sustainability continues to increase, through changes in regulatory requirements or stakeholder expectations, there is a growing need for assurance over the information prepared.
-
ESG and sustainability due diligence
As environmental, social, and governance (ESG) considerations become increasingly pivotal for dealmakers in Australia, it is important for investors to feel confident in assessing transactions through an ESG lens.

-
Management consulting
Our management consulting services team helps you to plan and implement the right strategy to deliver sustainable growth.
-
Financial consulting
We provide financial consulting services to keep your business running so you focus on your clients and reaching strategic goals.

-
China practice
The investment opportunities between Australia and China are well established yet, in recent years, have also diversified.
-
Japan practice
The trading partnership between Japan and Australia is long-standing and increasingly important to both countries’ economies.
-
India practice
It’s an exciting time for Indian and Australian businesses looking to each jurisdiction as part of their growth ambitions.
-
Singapore practice
Our Singapore Practice works alongside Singaporean companies to achieve growth through investment and market expansion into Australia.
-
Vietnam practice
Investment and business opportunities in Vietnam are expanding rapidly, driven by new markets, diverse industries, and Vietnam's growing role in export manufacturing, foreign investment, and strong domestic demand.
-
Client Alert Tax treatment of the proceeds on the sale of landThe Federal Court decision in Morton v Commissioner of Taxation [2025] FCA 336 (“the Morton case”) provides key guidance on the tax treatment of proceeds derived from land development arrangements. This is particularly relevant to landowners considering development partnerships with third-party developers.
-
Client Alert ATO releases new GST guidance on prepared mealsThe ATO’s GSTD 2025/1 clarifies the GST treatment of prepared meals following the Simplot case. Learn how the new four-step test and transitional compliance approach affect food suppliers.
-
Client Alert Wine not? Primary production land tax exemption no longer on the vineFor wine producers and vineyard owners, the recent New South Wales Civil and Administrative Tribunal decision in Zonadi Holdings Pty Ltd ATF Wombat Investment Trust v Chief Commissioner of State Revenue [2025] NSWCATAD 84 may spell trouble for their current primary production land tax exemptions.
-
Client Alert Unlock 2025: government grants updateIf government grants are part of your 2025 strategy, take note of the available quarter one funding opportunities. With increasing inflationary pressures, government grants can be an essential alternative funding source for businesses with critical investment projects.
-
Insight Impact of retaliatory tariffs on Australian and New Zealand exportersAs of April 9, 2025, a minimum universal tariff of 10 per cent has been applied to all imported goods into the United States, while certain countries face higher reciprocal tariffs based on their US trade deficit.
-
Insight Critical Minerals and Hydrogen Production Tax Incentives – legislation passedThe Australian Parliament recently passed legislation to introduce two significant tax incentives aimed at bolstering Australia’s critical minerals and hydrogen production sectors. The incentives form a significant part of the Government’s ’Future Made in Australia‘ policy.
-
Client Alert Unlock 2025: government grants updateIf government grants are part of your 2025 strategy, take note of the available quarter one funding opportunities. With increasing inflationary pressures, government grants can be an essential alternative funding source for businesses with critical investment projects.
-
Insight Tax planning essentials for successful M&A transactionsDiscover key tax planning steps for a smooth, tax-efficient M&A transaction.
-
Insight Moving from Designated Business Group to the Reporting Group modelThe AML Reforms introduce the concept of a 'reporting group'—a flexible model that allows both related and unrelated entities to manage and mitigate ML/TF risks under a single, comprehensive AML/CTF Program.
-
Insight The introduction of Value Transfer ServicesThe introduction of Value Transfer Service obligations under Australia’s AML/CTF reforms significantly broadens the scope of compliance requirements, affecting a wide range of businesses and requiring new processes, technology, and training.
-
Insight Know Your Customer: From simplicity comes complexityAustralia’s AML/CTF reforms represent a fundamental shift from a prescriptive, compliance-based regime to a flexible, outcomes-focused framework – prioritising the effective prevention of money laundering, terrorism financing and proliferation financing, rather than merely following prescriptive rules.
-
Client Alert Eight key changes to the new AML/CTF Rules for existing entitiesThe final amendments to the Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) Rules, published on 30 August 2025, introduce a series of structural and operational changes following extensive consultation by AUSTRAC and industry feedback.
-
Insight Prospects for the banking sector in health and aged careThe health and aged care industry in Australia is complex and there are a range of challenges and opportunities for the banking sector which can be explored in relation to its various sub-sectors.
-
Report Considerations for the Aged Care Quality and Safety Commission’s proposed Financial StandardsExplore recommendations to improve Aged Care Financial Standards and support provider stability.
-
Insight Financial elder abuse or executor misconduct: funds tracing is the answerWith the recent rise in awareness of financial abuse of elderly individuals and the misconduct of executors of deceased estates, it is imperative to validate any suspected wrongdoing in order to pursue legal proceedings.
-
Client Alert Implications of the aged care overhaul for businessesThe aged care overhaul is here, with major reforms shaping the future of care for older Australians. From funding shifts to enhanced home care options, these changes will require careful planning from businesses in the sector. Find out how the $5.6b investment into the quality, viability, and accessibility of aged care services and related reforms will affect providers and why strategic planning is crucial for the year ahead.
-
Client Alert A new trade landscape: insights for Australian businessesUS tariffs 2025: Impact on Australian exports, trade strategy & customs review insights.
-
Report Manufacturing benchmarks 2025: navigating complexity and building resilienceDiscover how Australian manufacturers are responding to slower growth, rising costs and tighter margins in our 2025 Manufacturing Benchmarks report, with insights on performance, reinvestment and capability-building.
-
Insight Sustainability: Maximising value for manufacturingExplore how sustainability reporting can enhance compliance, supply chain resilience, and meet consumer expectations for manufacturing businesses.
-
Insight Impact of retaliatory tariffs on Australian and New Zealand exportersAs of April 9, 2025, a minimum universal tariff of 10 per cent has been applied to all imported goods into the United States, while certain countries face higher reciprocal tariffs based on their US trade deficit.
-
Insight Navigating financial sustainability in a complex Not-for-Profit landscapeAgainst a backdrop of rising cost-of-living pressures and economic uncertainty, Not for Profits (NFPs) are facing increasingly complex challenges to maintain financial sustainability. With public expectations rising, funding pathways under strain, and operational costs climbing, many organisations are being forced to reassess how they operate. While the pressures are real, this also creates an opportunity to rethink collaboration, strengthen governance and build long-term resilience.
-
Insight Strengthening resilience for charities in a cost-of-living crisisAustralian charities are feeling the pinch of rising costs and increased demand as over 3.3m people live in poverty. From streamlining operations to diversifying funding streams and using technology like AI, leaders are finding ways to meet rising demand and stay resilient in today’s cost-of-living crisis.
-
Podcast Yalari: empowering the next generation through educationYalari is a not-for-profit organisation offering secondary education scholarships to Australian schools for First Nations students. The organisation champions the value of education and nurtures an encouraging community for students to thrive in their studies.
-
Insight Federal Budget health and aged care initiatives announcedThe Health and Aged Care industry faces continued uncertainty, but following the Federal Budget announcements on 14 May, improvements are expected.
-
Insight How to practically achieve AML/CTF compliance for the Legal IndustryAustralia has commenced reforming its Anti-Money Laundering and Counter-Terrorist Financing (AML/CTF) regime including the ‘Tranche 2’ reforms, which expand AML/CTF compliance to apply to additional professions including lawyers.
-
Podcast The role of Boards in Australia's evolving AML/CTF landscapeIn this episode, Risk Consulting Partners and AML/CTF experts Neil Jeans and Katherine Shamai discuss the implications of the new AML/CTF Amendment Act, AUSTRAC’s expanded authority to investigate organisations, and the important questions Board should be asking management teams when it comes to the new reforms.
-
Insight Tax planning essentials for successful M&A transactionsDiscover key tax planning steps for a smooth, tax-efficient M&A transaction.
-
Insight The significance of shareholder agreements in professional services firmsLearn why shareholder agreements are essential for governance, continuity, and protection. Explore key issues and benefits for business owners and partners.
-
Insight How to practically achieve AML/CTF compliance for the real estate industryAustralia has commenced reforming its Anti-Money Laundering and Counter-Terrorist Financing (AML/CTF) regime including the ‘Tranche 2’ reforms, which expand AML/CTF compliance to apply to additional professions including real estate agents and conveyancers.
-
Client Alert Navigating the new era of sustainability reporting: what property leaders need to knowMandatory sustainability reporting under AASB S2 will apply to Australian property and corporate entities meeting size thresholds from 2025, requiring disclosure of climate-related risks, emissions, and transition strategies. Early preparation is essential for compliance and to create long-term value.
-
Client Alert Residential colleges – do you know your GST position?A practical guide for residential colleges reviewing GST treatment for the 2026 academic year – covering endorsed charity concessions, PCG 2022/3, Division 129 adjustments, and strategies to manage GST liability and compliance with confidence.
-
Client Alert Wine not? Primary production land tax exemption no longer on the vineFor wine producers and vineyard owners, the recent New South Wales Civil and Administrative Tribunal decision in Zonadi Holdings Pty Ltd ATF Wombat Investment Trust v Chief Commissioner of State Revenue [2025] NSWCATAD 84 may spell trouble for their current primary production land tax exemptions.
-
Client Alert A new trade landscape: insights for Australian businessesUS tariffs 2025: Impact on Australian exports, trade strategy & customs review insights.
-
Report What’s driving Australian retail spending in today’s economy?Australian consumers are demanding more from retailers – better value, faster service, and consistently high quality. Discover what drives Australian retail and how to meet rising expectations.
-
Insight Aligning automation with business strategy: designing future-ready supply chainsAligning automation with business strategy is crucial for creating future-ready supply chains. Emphasising flexibility, scalability, and simplicity in automation solutions enhances efficiency and adaptability while meeting evolving customer demands.
-
On-Demand Unlocking retail opportunities in a transformative eraThe retail landscape is undergoing rapid transformation, reshaping consumer expectations and industry dynamics. To remain competitive, retailers need to carefully consider their value propositions and be on the front foot with innovative solutions.
-
Podcast From capital to sale: securing funding and exit strategies in the technology sectorIn this episode, National Head of Corporate Finance & M&A Partner Holly Stiles and National Head of Technology, Media & Telecommunications and Private Business Tax & Advisory Partner Jace Gawne-Buckland discuss the current technology landscape in Australia, evolving expectations of investors, and tangible steps tech leaders can take to strengthen their position for future raises or exits.
-
Report Unlocking value: navigating funding and exit strategies in technology businessesExplore strategies for scaling in Australia’s tech and SaaS sector in this report, covering capital raising, investor expectations, and long-term growth.
-
Insight Tax planning essentials for successful M&A transactionsDiscover key tax planning steps for a smooth, tax-efficient M&A transaction.
-
Client Alert R&D investment trends in Technology, Media, and Telecommunications from the ATOThe recent release of the Australian Taxation Office’s (ATO) R&D Tax Transparency Report for the 2021-22 period delivers valuable insights into the state of research and development (R&D) using claim data across various sectors, particularly in Technology, Media, and Telecommunications (TMT).
-
Flexibility & benefits
The compelling client experience we’re passionate about creating at Grant Thornton can only be achieved through our people. We’ll encourage you to influence how, when and where you work, and take control of your time.
-
Your career development
At Grant Thornton, we strive to create a culture of continuous learning and growth. Throughout every stage of your career, you’ll to be encouraged and supported to seize opportunities and reach your full potential.
-
Diversity & inclusion
To be able to reach your remarkable, we understand that you need to feel connected and respected as your authentic self – so we listen and strive for deeper understanding of what belonging means.
-
In the community
We’re passionate about making a difference in our communities. Through our sustainability and community engagement initiatives, we aim to contribute to society by creating lasting benefits that empower others to thrive.
-
Graduate opportunities
As a new graduate, we aim to provide you more than just your ‘traditional’ graduate program; instead we kick start your career as an Associate and support you to turn theory into practice.
-
Vacation program
Our vacation experience program will give you the opportunity to begin your career well before you finish your degree.
-
The application process
Applying is simple! Find out more about each stage of the recruitment process here.
-
FAQs
Got questions about applying? Explore frequently asked questions about our early careers programs.
-
Our services lines
Learn about our services at Grant Thornton
-
Remarkable people
Our team members share their remarkable career journeys and experiences of working at Grant Thornton.
-
Working at Grant Thornton
At Grant Thornton we reach for remarkable and set the bar high to deliver a strikingly different experience for our people.
- Contact us
Technology companies must adopt a new approach to digital risk
Jutting out into Austria’s skyline, emerging from the surrounding forest, lies an ancient medieval wonder – Hochosterwitz Castle. The thousands of tourists that flock here every year soon learn a surprising fact: it is one of only a very small number of castles around the world that has never been breached.
Its inhabitants thank Baron George Khevenhüller. He knew that holding the castle was strategically important to the region. Fearing an onslaught of marauding armies, he ordered the construction of a series of 14 fortified gates on its gentlest slope, the most likely avenue of attack. Each has a unique defence structure designed to flummox invaders. It worked. The most successful conqueror only reached the fourth gate.
Today’s technology companies can learn something from Khevenhüller. They may not fear foreign conquerors, but they do face attack from malicious actors that are set on stealing their IP or the personal data they hold.
Like Khevenhüller, they must identify the assets that are most important, consider the most likely lines of attack, and tailor a defensive strategy accordingly.
Of course, a holistic digital risk strategy (which should span cybersecurity and data privacy risk across the enterprise) must incorporate more than defending against cyberattack. Ever stricter data protection regulation, not to mention the public’s growing awareness of privacy, means technology companies must regularly reexamine privacy controls. Data asset categorisation is essential in this process too.
Technology companies are most vulnerable
The annual global cost of cybercrime is estimated to hit US$6tn in 2021, up from US$3tn in 2015. James Arthur, partner and head of cyber consulting at Grant Thornton UK agrees. “Technology companies are particularly impacted.”
“It is important for technology companies to develop a digital risk strategy based on their most strategically important data assets,” says James. “After all, they typically hold more data than non-tech companies and often lead the way in adopting new technologies, which can create cyber vulnerabilities.”
B2C technology companies also house and process huge volumes of sensitive, personal information. It is, therefore, no surprise that IT was the most targeted sector for web application cyber-attacks last year.
Added together, this means that technology companies are now more vulnerable to cyber attacks and customer data breaches than ever before. This not only exposes them to hefty regulatory fines but also business-crippling reputational damage.
Get ahead of regulators
In the last three years, technology companies made great efforts to comply with new data privacy and protection regulations, not least GDPR. Most large technology companies are now compliant, but they must remain vigilant. Data protection regulations are becoming stricter and the penalties for non-compliance are increasing. What’s more, customers are becoming more aware of privacy issues and are prepared to punish companies for not taking it seriously.
Technology companies must respond by going above and beyond the minimum required by the regulator on privacy. “Tech companies today need to go beyond the basics to ensure compliance because these companies service their clients in a regulated industry and are largely data controllers, while their clients may be data processors,” confirms Akshay Garkel, advisory partner at Grant Thornton India.
“Cloud service providers may be required to maintain 10 out of 20 (for example) data controls for minimum compliance. But they shouldn’t stop there. In the spirit of ensuring security and privacy they might want to go at least four or five notches above the minimum expected from the regulator because clients will demand it.”
The tightrope between privacy and analytics
But a careful balance must be struck. Customers will appreciate technology companies going the extra mile on privacy, but not if it restricts their ability to receive personalised offers or the development of products tailored to their individual needs.
Individual companies aside, overbearing privacy law prevents the use of data to drive positive societal outcomes, be that in relation to healthcare, disease monitoring or traffic accident reduction. So, governments and regulators must also be careful not to enact overly restrictive privacy laws.
“The balance between data protection and using data for the public good is a key debate for society,” says Nick Watson, partner and technology sector lead at Grant Thornton UK. “Germany has very strong privacy rules, but this has resulted in traffic accident data not being collected on particular stretches of roads. Therefore, they weren’t able to collect data that would have pinpointed a particular accident hotspot. You could take data privacy to a level where even non-personalised data is not collated on a group-wide, anonymous basis. In this case society would lose out.”
The middle-man in surveillance
Judging how far to go on privacy has become more complex because, like it or not, many technology companies are now surveillance intermediaries. Whether it be messages sent on social media, recordings from Echo devices or location data stored on smart phones, technology companies possess information that is useful for fighting crime.
There is no question that they must comply with the law regarding requests for information, but they have discretion over how swiftly they reply and the depth of information they provide.
Many now wonder whether law enforcement data requests should be processed without question, or heavily scrutinised in the interest of preserving privacy.
In the past, some technology companies resisted rather than cooperated with law enforcement. But as technology companies unwittingly accumulate more and more vital evidence, there is controversy in some markets about which data is shared, how much and for what purpose.
After all, being perceived as uncooperative with counter-terrorism forces is far more damaging than not adhering to the absolute strictest privacy standards.
Strengthen protection of digital assets
How should technology businesses respond to rising digital risk? First and foremost, they must classify, categorise and map out their digital assets to understand the specific risks and value associated with them.
Armed with this insight, they should develop and implement a nuanced, risk-based digital risk strategy that fortifies the digital crown jewels – those deemed most critical to the business and its customers.
Of course, one company’s most valuable data may be completely unimportant to another. For example, fintech companies highly value customers’ financial information, entertainment technology companies place high importance on consumer preference data and high-tech companies treasure their IP.
This approach sounds sensible. But a surprisingly large number of technology companies do not do this, and instead rely on an outdated one-size-fits-all approach to cyber security and data privacy based on perimeter security.
Orus Dearman, managing director of risk advisory services at Grant Thornton US, explains how this classification process can lead to practical change that reduces vulnerability.
“We assisted a technology company client in performing a data categorisation process to enable them to efficiently identify sensitive and personal information within their databases and networks as part of an overall data inventory. This allowed the company to deploy data protection resources where they are needed and would have the most impact,” he says. “Now, if anyone wants to change anything to do with this data or these systems, the privacy team is brought into the process as part of the workflow.”
Bin useless data
In contrast, data revealed to be not at all useful to the business and not required for regulatory and compliance purposes should be deleted or appropriately anonymised. This reduces the risk of it being compromised.
Naturally, technology companies can be reluctant to delete information due to concerns they might need it for an audit or that it is essential for something they are unaware of. Data mapping helps realise interdependencies, which can assist in deleting data.
But data asset categorising doesn’t just reduce risk. It also creates value. This exercise might identify a dataset or combination of datasets that can be used to improve the efficiency of internal operations or gain insight into customer preferences.
When strategy changes, so should data categorisation
Technology companies must remember two things when profiling data assets. First, it is not a one-off exercise. They must constantly map out their digital assets as the nature of the threat changes and as their business priorities evolve.
Second, this task cannot be left to the information security officer or head of IT. It is a critical business decision that must align to business objectives. Senior business leaders must be involved in the process.
Drive competitive advantage through trust
There is a real opportunity for B2B technology companies to market themselves around digital trust. Those that demonstrate readiness to respond to a cyber threat, responsibly handle customer data and empower customers to manage privacy controls stand to gain a competitive advantage.
To start building trust, technology companies must offer value-added cyber security solutions such as malware and ransomware screening that plugs vulnerabilities as part of their core offering. Customers will also be impressed with suppliers that conduct comprehensive cybersecurity audits and produce independent assurance reports.
“Reports that demonstrate capability, security, and a serious commitment to risk management (such as SOC2 or ISAE3402) are without question a way for technology companies to differentiate themselves from the competition,” says Matthew Green, technology advisory partner at Grant Thornton Australia. “The more astute clients are now starting to ask for the validation and the ongoing assurance that the organisation is maintaining an appropriate level of data security and are requesting those reports as a way of demonstrating it.”
There are a number of security standards that technology companies can use to demonstrate best practice digital resilience. But because every technology company is different, these merely provide a starting point. Technology companies should evaluate what their customers want when it comes to privacy and security and prioritise this.
Consumers value control
The jury is out on whether B2C technology can truly differentiate themselves through digital trust. Still, there is no harm in making it incredibly easy for customers to identify and delete data that is held about them and manage privacy settings.
B2C technology companies must also make privacy policies crystal clear. Today, most are displayed in tiny lettering across multiple pages, making them impossible to decipher.
“Privacy should be an enabler and not hinder innovation. Companies who have embraced good privacy practices should use that as a branding platform in the market,” confirms Orus.
“Clearly communicating privacy policies in a transparent way is essential. The general trend for technology companies is to develop a user hub that allows users to see what data is being held about them and allows them to opt in and out of various things."
"Privacy regulations such as the GDPR and upcoming California Consumer Privacy Act (CCPA) require clear and concise privacy notices for applicable data subjects. However, for those of us that don’t fall into the GDPR or CCPA buckets, many user agreements are over a hundred pages long, so they can still be made more user-friendly.”
Our five recommendations
Technology companies should implement the following recommendations to build and maintain digital trust:
- Categorise data assets according to their strategic importance. Those that will disrupt the business or customer experience or cause untold reputational damage if compromised should be heavily protected.
- Regularly review your data asset categorisation in collaboration with senior business leaders. This categorisation must align with business objectives, which may change over time.
- Don’t just think about the minimum required from the regulator when implementing data protection controls. Instead, consider what regulations may look like in the future.
- Collaborate fully with valid requests for data and information and know the extent to which data should be provided.
- Demonstrate your commitment to data protection by having your cyber risk practices tested regularly by an independent third-party. This will help to build trust.
When it comes to protecting your business to become immune to a cyber attack or data breach, one size does not fit all. However, technology companies can bolster their resilience by applying some or all of these recommendations so long as they tailor their actions to suit their unique position, and that of their clients.