
Zoe Tishler is a highly experienced cyber and privacy lawyer. She advises insurers, government agencies and private sector organisations on managing cyber and privacy risks, from prevention and preparedness through to incident response and recovery.
Zoe has extensive experience advising on high-profile, complex and multi-party cyber incidents across highly regulated industries, including financial services, government, healthcare and technology. Her expertise spans the full incident lifecycle, from immediate risk management and containment through to regulatory investigations and third-party claims.
Beyond incident response, Zoe provides proactive advice on cyber and privacy risk mitigation, including cyber security risk management, privacy and regulatory compliance, incident readiness, governance and directors’ duties, and cyber insurance coverage. She also assists clients with privacy complaints and claims, including matters escalated to the OAIC and state and territory privacy regulators.
Experience
Cyber and data breach response
Zoe is highly experienced in all aspects of data breach and cyber incident response. She works with clients from the outset of an incident to identify and manage legal and regulatory risks, coordinate forensic and other specialist advisers, assess compromised data and identify notification obligations as well as managing engagement with regulators, affected individuals and other stakeholders.
Zoe has particular experience coordinating large-scale and multi-party incidents where the response involves significant volumes of data, multiple affected organisations or stakeholders, overlapping regulatory regimes and potential third-party claims.
Examples of Zoe’s experience include advising:
- a large national law firm following a significant cyber event, including on complex regulatory requirements and obtaining a first-of-its-kind injunction against a cyber threat actor in the Supreme Court of NSW
- a payroll software as-a-service provider in a ransomware attack requiring notification of over 100,000 individuals, including complex data review, corporate and government client engagement, coordinating multi-party data breach obligations, engaging with multiple regulators and agencies and dealing with privacy complaints and compensation claims by individuals;
a credit union on regulatory obligations arising out of a business email compromise including on AFSL and CL reporting obligations to ASIC, reporting obligations to APRA and privacy notifications to the OAIC and affected individuals.
Disputes and regulatory response
Zoe advises clients on third-party complaints, claims and regulatory matters arising from cyber incidents and in broader privacy contexts. She assists clients in strategically managing and resolving complex complaints and claims, including matters escalated to privacy regulators and the subject of formal regulatory investigations. Zoe also advises on liability, recovery and disputes arising from cyber incidents, including matters involving social engineering and invoice fraud.
Cyber and privacy advisory
Zoe advises organisations with proactive cyber and privacy and risk mitigation advice, including advising on cyber security risk management, compliance with privacy legislation including personal information handling, other regulatory compliance, incident response preparation, training and simulations, corporate governance and directors’ exposures. This has included, for example advising:
a managed services provider on applicability of reforms to the Privacy Act 1988 (Cth) and implementation plan for key action items;
a not-for-profit organisation on its compliance with the Privacy Act 1988 (Cth) and developing its privacy policy and collection notices;
a managed services provider on changes to its managed services agreement as to information handling practices and responsibilities and customer termination rights in the event of a data breach;
a university in advising on data retention and destruction obligations under a range of different legislative regimes;
an international software company on its potential cyber liability in providing data hosting services
Awards and recognition
Best Lawyers in Australia
General Insurance (Ones to Watch) | 2026
Memberships and community involvement
Law Society of NSW
Young Insurance Professionals (YIPs) Australia & New Zealand