Early in 2019, unknown threat actors attempted to hack the Australian federal Parliament’s computer network and the servers used by every politician, staffer, and security officer in Parliament House. Authorities believe there is a strong chance this could have been executed by a state-based actor.
Though investigators never found any proof that data was compromised or stolen in the breach, the hacking ultimately exposed the vulnerabilities that are present within the country’s federal digital infrastructure. With countries becoming more prevalent targets of hacker activity, it’s critical that their networks are strengthened to prepare for external attacks and that cyber risk management needs to become a national priority.
It’s common knowledge that data breaches are occurring more frequently and will continue to do so. In the last three months of 2018 alone, Australian authorities were made aware of 262 data breaches with the potential to expose the personal information (including tax numbers) of a significant number of Australians. This affected a variety of industries, including private health service providers, finance, legal, accounting and management services, private education providers, as well as mining and manufacturing.
In order to prepare for when a data breach occurs, organizations should be taking the appropriate measures to strengthen their cybersecurity programs like implementing ongoing threat education and awareness training for employees, instituting responsible data protection practices, and allocating sufficient security spending according to their risk appetite. If companies only implement risk management programs that encapsulate the ‘bare minimum,’ their program will not be set up to be both effective and scalable.
However, Australian companies are much less confident in their security controls than their global peers. According to Accenture’s recent Securing the Digital Economy: Reinventing the Internet for Trust report, only 22% of Australian companies who responded to the report (which surveyed 1,700+ CEOs and C-suite executives across the globe) said they are confident in their Internet security. In other countries worldwide, however, this figure reached at least 30%. This indicates that either Australian companies are especially prone to third-party risk, or it has been difficult for them to manage and mitigate that risk.
While data breaches continue to remain an issue for Australia, national regulations are starting to force the issue of cyber risk management. Both the Australian Prudential Regulation Authority (APRA) and the Australian Government Information Security Manual (AG-ISM) have impending regulatory standards that will affect most Australian businesses by early 2020. APRA regulations have been making headlines recently because of their impending July enforcement date.
