Dependence Has a Cost
Why Energy Independence Matters More Than Ever
In Brief
Affected by the Origin data breach, I began asking a bigger question: how much trust and control have we handed to the companies managing our information, money and essential services?
This article explains what affected customers can do now, provides a free privacy complaint template, examines what meaningful corporate accountability should involve, and explores practical ways households can reduce their dependence on systems that may fail.
We Hand Over More Than Money
Yesterday, I received an email from Origin Energy telling me that my personal information had been affected by a data security incident.
My name. My address. My date of birth. My phone number. Parts of my banking and credit card information. Details that Origin required me to provide so it could manage my account and withdraw payments by direct debit.
Then, at the bottom of the email, came the familiar corporate response:
“I am sorry that this incident has occurred.”
I’m sure the apology was carefully written and approved, but it does little to address what happens next.
Origin does not have to spend the coming months wondering whether an unexpected phone call is genuine. Its executives do not have to examine every email for signs of identity fraud, watch their credit files or question whether their personal details are circulating among criminals.
We do.
Approximately 900,000 current and former Origin customers may now be dealing with that same uncertainty.
And Origin is hardly alone.
Australians have already watched similar incidents unfold at Optus, Medibank, Latitude Financial and MediSecure. Internationally, enormous platforms such as Yahoo and Facebook have also demonstrated that even the largest companies can fail to keep personal information secure.
Each time, the pattern feels much the same.
We are told the company takes privacy seriously. We receive an apology, a support telephone number and instructions explaining what we should now do to protect ourselves.
Change your passwords. Monitor your bank account. Check your credit report. Be alert for scams. Verify every unexpected call.
In other words, a company fails to protect the information it required from us and the work, anxiety and risk are handed straight back to the customer.
That is what makes these breaches so infuriating.
We are increasingly expected to surrender more of our identity for ordinary services: electricity, telecommunications, insurance, finance, healthcare and online communication. Companies encourage direct debit because it makes their operations easier and more predictable. They store enormous quantities of information because it benefits their systems and business models.
Our reasonable expectation in return is that they protect it properly.
An apology after the damage has been done is not accountability. Asking affected customers to clean up the consequences is not a complete solution.
This is about more than one energy company or one data breach. It is about how dependent we have become on organisations that hold extraordinary power over our money, essential services and private lives, while customers have very little control when those organisations fail.
That dependence has a cost.

What Affected Customers Can Do Now
Anger is understandable, but the most useful response is to create a clear record, protect the accounts connected to your identity and require the company to answer specific questions in writing.
1. Save the breach notification
Keep the original email or letter, along with screenshots and copies of any later updates. Record when you received each communication and what the company said may have been exposed.
Do not delete the notification after taking the recommended steps. It may become important if suspicious activity appears later.
2. Confirm exactly what information may be involved
Ask the company to state, in writing, which categories of your information were accessed or disclosed.
That may include:
- your name and contact details
- date of birth
- account information
- identity-document numbers
- banking or payment details
- passwords or security questions
- health or other sensitive records
Do not assume that changing one password solves everything. The correct response depends on the type of information exposed.
3. Secure your email account first
Your email account is often the gateway to password resets for other services.
Use a strong, unique password and enable two-step authentication. Change any password that was reused on another account, particularly banking, telecommunications, utilities and social-media accounts.
4. Treat unexpected contact with suspicion
Criminals may already know enough personal information to sound convincing.
Do not trust a caller merely because they know your name, address, service provider or part of your account details. End the call and contact the organisation using a telephone number taken from its official website, app, statement or card.
Avoid clicking links in unexpected breach-related emails or text messages.
5. Monitor financial and credit activity
Check bank and card transactions regularly. Contact the relevant financial institution immediately if anything is unfamiliar.
Where identity or financial information may have been exposed, consider using a credit-monitoring service or requesting additional protection from the credit-reporting bodies.
For the Origin incident, the company has offered affected customers free IDCARE support and a 12-month Equifax Protect subscription.
6. Keep a record of the impact
Create a simple diary recording:
- suspicious calls, messages or transactions
- time spent dealing with the incident
- telephone calls and complaint-reference numbers
- replacement-document costs
- bank fees or financial losses
- professional assistance obtained
- significant distress or disruption
Keep receipts and copies of correspondence. Accurate records are far more useful than trying to reconstruct events months later.
7. Make a formal written complaint
Ask the organisation to register the matter as a formal privacy complaint and provide a reference number.
Request clear answers about:
- what information was affected
- when the incident occurred
- when the company became aware of it
- whether the information was copied or published
- what security measures have changed
- what support, reimbursement or remedy is available
Keep the complaint factual. Do not accuse the organisation of criminal conduct, deliberate concealment or breaking the law unless that has been established by a regulator or court.
8. Escalate an unresolved complaint
In Australia, people can generally complain directly to the organisation first and then consider escalation to the Office of the Australian Information Commissioner if the matter is not adequately resolved.
Depending on the industry, an external ombudsman or dispute resolution scheme may also be available.
People facing identity theft, substantial financial loss or complicated legal issues should consider obtaining independent professional advice.
For customers affected by the Origin incident
Origin has advised that potentially accessed information may include names, addresses, dates of birth, phone numbers, partial bank or credit-card details and customer-account information.
Affected customers can request the offered Equifax Protect subscription and contact IDCARE using Origin’s referral code ORGN26
Download a Data Breach Privacy Complaint Template
Affected customers should not have to work out from scratch how to raise a formal complaint. This editable template is designed to help people clearly record what happened, ask the right questions and request an appropriate response from the organisation involved.
General information only, not legal advice. Make a copy of the document and edit it so every statement accurately reflects your own circumstances.
Choose the editable Google Doc to create your own personalised copy, or download the PDF to review, save or print the template.
General information only, not legal advice. Edit the template so every statement accurately reflects your own circumstances.
Accountability Should Not End With an Apology
When a company loses control of customer information, an apology is necessary, but it is not enough.
The consequences do not remain inside the organisation that failed. They follow customers home.
People are left checking bank accounts, changing passwords, monitoring credit files, questioning suspicious calls and wondering whether their identity may be misused months or even years later.
Meaningful accountability should involve more than a carefully worded statement from a chief executive. It should include a clear explanation of what happened, prompt notification, practical support, reimbursement for reasonable costs and fair consideration of compensation where customers suffer genuine harm.
Regulators and governments also have a responsibility to ensure that protecting customer information is treated as a core obligation, not simply another business risk.
Companies benefit from collecting our data. They use it to manage accounts, automate payments, analyse customers and make their operations more efficient.
The responsibility must travel in both directions.
If an organisation cannot adequately protect sensitive information, it should be required to explain why it collected and retained that information in the first place, how long it intended to keep it, and what consequences will follow when those protections fail.
Trust should not be restored by an apology alone. It should be earned through transparency, action and accountability.
What Real Accountability Could Look Like
- Prompt and honest disclosure
- Clear identification of the information affected
- Free identity and credit protection
- Reimbursement of reasonable costs
- Fair remedies for proven harm
- Stronger security and independent review
- Meaningful regulatory penalties where failures are established
- Limits on unnecessary data retention

Dependence Goes Beyond Our Data
The problem with dependence is that it rarely reveals itself while everything is working.
We depend on companies to safeguard our information, process our payments, keep us connected and deliver essential services into our homes. Most of the time, those systems feel invisible.
Then something fails.
During Cyclone Alfred, our power disappeared at the height of the storm and did not return for five days. Suddenly, the electricity grid was no longer an abstract utility operating quietly in the background. It became the difference between keeping food cold, charging a phone and remaining connected, or simply going without.
We had prepared the basics, but the BLUETTI AC70P became the piece of equipment that genuinely changed the experience. It powered the fridge, charged our phones and kept smaller rechargeable devices operating. When it needed topping up, we disconnected it and recharged it from my car. It worked quietly, steadily and without drama.
That experience changed the way I think about energy independence.
It is not about pretending we can completely remove ourselves from the grid. It is about making sure the grid is no longer our only option.
When the Grid Was No Longer There
The five-day blackout was only part of the damage.
When the electricity supply was restored, several pieces of equipment in our home failed, including the television, hot-water system and garage-door opener. We could not conclusively prove whether the failures were caused by a surge, overload or another problem associated with the restoration of power, but the timing was difficult to ignore.
We submitted an insurance claim, expecting that this was exactly the kind of situation household insurance was meant to address. In practice, very little of the loss was covered.
Our solar system had also been damaged. It was included in the claim, but the replacement process took approximately seven or eight months.
During that period, we had no working solar generation and were forced to purchase considerably more electricity from the grid at Origin’s retail rates. When the solar system was eventually replaced, the compensation we received for the additional electricity costs was just $60.
That experience exposed another side of dependence.
When a central system fails, the cost does not remain with the company controlling it. The household absorbs the interruption, the damaged equipment, the insurance shortfall, the months of higher bills and the time spent chasing repairs and explanations.
The power may eventually return, but that does not mean the customer has been restored to the position they were in before the failure.
The Grid Came Back. The Costs Remained.
Backup power cannot prevent every loss, but it can reduce how completely a household is exposed when the grid, insurers and repair systems all move more slowly than life requires.
Regaining a Measure of Control
None of this means a household can completely remove itself from the companies and systems it relies on.
We still need electricity providers, insurers, telecommunications networks and financial institutions. But there is a difference between relying on a system and having no alternative when that system fails.
Cyclone Alfred taught me that even a modest amount of stored power can change the experience of an extended outage. It kept essential devices operating, gave us a way to recharge communications equipment and reduced the feeling that we were simply waiting helplessly for someone else to restore normality.
That is what practical energy independence looks like to me.
It is not complete self-sufficiency. It is having enough resilience to protect the essentials, buy time and make better decisions when the grid is unavailable.
During Cyclone Alfred, our BLUETTI AC70P kept the fridge operating, charged phones and powered smaller essential devices throughout the five-day outage. I documented the full experience, including what worked, what I would do differently and why greater backup capacity matters, in a separate real-world field test.
Free Guide: Planning for a Power Outage
Preparing for an outage can feel overwhelming, particularly when you are trying to decide what equipment matters, how much stored power you may need and which household devices should take priority.
To make that easier, I have created a practical guide covering the basics of backup power, essential-device planning and the first steps towards greater household energy resilience.
General information only. Your household requirements will depend on the devices you need to operate, their power consumption and how long an outage may last.
Resilience Is Not About Going It Alone
None of us should have to become cybersecurity experts, energy engineers or legal specialists simply because the companies we rely on fail to meet their responsibilities.
Accountability still matters. Governments, regulators and businesses must do more to protect the people whose data, money and daily lives depend on them.
But while that pressure builds, households can also take practical steps to reduce how exposed they are.
That may mean securing accounts, keeping better records, questioning what information companies retain, preparing for outages or investing in backup power that keeps essential devices operating when the grid fails.
Resilience is not about accepting corporate failure.
It is about refusing to remain completely powerless when it happens.
An apology may acknowledge the damage. Real responsibility means preventing it, repairing it and ensuring customers are not left carrying the burden alone.
Explore backup-power options designed to help households stay connected and protect essential devices during outages.
Frequently Asked Questions
What should I do after receiving a data-breach notification?
Save the notification, confirm what information may have been affected, secure your email and other important accounts, monitor financial activity and keep records of suspicious contact or expenses.
Can I make a formal complaint after a company data breach?
Yes. You can write to the organisation’s privacy or complaints team, ask for a complaint reference number and request clear information about what happened, what information was affected and what support or remedy is available.
Does a data breach automatically entitle customers to compensation?
No. Compensation is not automatic. However, affected customers can document genuine financial loss, expenses, distress or disruption and request an appropriate remedy.
What does energy independence mean for an ordinary household?
It does not necessarily mean leaving the grid completely. It can mean having enough backup power and preparation to keep essential devices operating when normal services fail.
Affiliate Disclosure:
This post may contain affiliate links. If you click through and make a purchase, we may earn a small commission at no extra cost to you. We only recommend products we believe in and would use ourselves.
