Back to Insights Risk Management

How much of the Qantas CEO’s bonus was cut due to a data security incident?

Qantas Sends a Clear Message: Management Is Also Responsible for Cyber Safety
Executive Compensation Penalized Following Airline Customer Service Attack

The Australian airline Qantas has announced a $250,000 cut to the bonus of its CEO, Vanessa Hudson, following a cyberattack that occurred in July 2025. The attack targeted an external service platform connected to the customer service center, leading to the exposure of details belonging to nearly six million customers. The decision to cut the bonus—even if symbolically—is seen across the industry as a warning sign: the responsibility for protecting customer data does not rest solely with Information Security Managers, but also with senior executive management.

A Shift in Management Perception: Not Just the CISO’s Responsibility
Information security responsibility also lies with the CEO. As senior professionals in the field note, responsibility for information security does not end with technical teams. Management is also responsible for budgetary decisions, prioritizing defensive investments, and implementing an organizational culture of threat awareness. Today, CEOs are required not only to “talk cyber” but to demonstrate accountability in practice. Reducing Hudson’s bonus sends a clear message to shareholders: maintaining customer trust starts at the top. In some cases, cybersecurity is even integrated into annual Key Performance Indicators (KPIs), encouraging management to invest proactively rather than reacting retroactively.

Punishment Is Not Enough—Proactivity Is Required
Cybersecurity is not just a “cost center”—it is a business tool. Although the cut was received with relative approval, experts warn that it remains a symbolic step; a 15% reduction in a bonus does not drive genuine organizational change. The correct approach is to integrate information security metrics into management’s performance goals—for example, vulnerability reduction, shortening incident response times, or improving compliance with standards. Treating cyber as a “cost center” is a mistake; it is a vital component for ensuring customer trust and business continuity. The more management leads, the more IT and cyber teams will receive the necessary support and funding.

Recommendations from IPV Security Information Security Experts:
* Integrate cyber metrics into executive performance—not just financial metrics, but also response times, risk management, and regulatory compliance.
* Ensure that information security budgets are considered at the highest levels and do not remain solely within the IT department.
* Build a Management Accountability Model that includes the Board of Directors, executive management, legal, and information security.
* Avoid isolated punishments after an incident; instead, create positive incentives for preventive action.
* Conduct periodic audits of organizational cyber responsibility, including the definition of roles and authorities for every scenario.
* Encourage a culture of transparency and accountability rather than concealment or blame, especially following incidents.

In conclusion, the Qantas case illustrates a new reality: information security is not just a technical responsibility—it is a business and managerial one. A clear message has been sent to executives: customers expect answers, shareholders demand accountability, and the market rewards proactive leadership. The time has come to bring cybersecurity to the boardroom table.

For more information: [https://www.scworld.com/news/qantas-trims-ceos-bonus-following-july-cybersecurity-incident]

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation