{"id":2796,"date":"2024-03-26T20:00:00","date_gmt":"2024-03-27T01:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks"},"modified":"2024-03-26T20:00:00","modified_gmt":"2024-03-27T01:00:00","slug":"australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/26\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks\/","title":{"rendered":"Australian Government Doubles Down On Cybersecurity in Wake of Major Attacks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt5c734c10520b1fc9\/65a93790706a01040a10b37b\/_australia_keyboard_Bonaventura_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Australian government is carving out plans to revamp cybersecurity laws and regulations in the wake of a series of damaging high-profile data breaches that rocked the country.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Government officials recently released what it called a consultation paper that outlined specific proposals and solicited input from the private sector in a proclaimed strategy to position the nation as a world leader in cybersecurity by 2030.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As well as addressing gaps in existing cybercrime laws, Australian legislators hope to amend the country&#8217;s Security of Critical Infrastructure (SOCI) Act 2018 to place a greater emphasis on threat prevention, information sharing, and cyber incident response.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Weaknesses in Australia&#8217;s cyber incident response capabilities were laid bare in the September 2022 cyber assault on telecommunications provider Optus, followed in October by a ransomware-based <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.abc.net.au\/news\/2022-11-10\/medibank-data-breach-latest-dark-web-leak\/101632746\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">attack on health insurance provider Medibank<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Millions of sensitive records, including biometric data in driver&#8217;s licenses and passport photos were exposed after <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/fbi-helping-australian-authorities-investigate-massive-optus-data-breach-reports\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">attackers scraped an Optus database<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> containing consumer records; the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/us-uk-au-officials-sanction-russian-medibank-hacker\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Medibank breach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> exposed millions of patient health records.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Both breaches came through basic errors and poor cyber hygiene, so they were avoidable,&#8221; says Richard Sorosina, chief technical security officer for Qualys Australia and New Zealand.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Australia&#8217;s cyber resilience came under painful scrutiny in November 2023 when a nationwide outage left Optus&#8217; fixed line and mobile <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/web.archive.org\/web\/20231117002022\/https:\/www.aph.gov.au\/DocumentStore.ashx?id=2ed95079-023d-49d5-87fd-d9029740629b&amp;subId=750333\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">customers without Internet access<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The outage was blamed on an issue with a Border Gateway Protocol (BGP) routing table update.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Then came a massive cyberattack days later on the shipping industry that led to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/australian-ports-resume-operation-after-crippling-cyber-disruption\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">lengthy disruptions at four Australian ports<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cyber Strategy Reform\">Cyber Strategy Reform<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The cyberattacks on Optus, Medibank, and the nation&#8217;s ports were highly public incidents that affected citizens and businesses, which pushed cybersecurity higher on the nation&#8217;s political agenda. In response, the Australian government revised its cybersecurity strategy and launched <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.homeaffairs.gov.au\/help-and-support\/how-to-engage-us\/consultations\/cyber-security-legislative-reforms\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">the consultation process<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on legislative and regulatory reforms.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Clare O\u2019Neil, Australia&#8217;s minister for cybersecurity, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/minister.homeaffairs.gov.au\/ClareONeil\/Pages\/securing-australias-cyber-future-through-new-era-public-private-partnership.aspx\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">said in a statement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that the government was committed to working with the private sector to usher in a &#8220;new era of public-private partnership to enhance Australia&#8217;s cybersecurity and resilience.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Australia&#8217;s new proposed cybersecurity legislation covers a wide range of measures, including mandating secure-by-design standards for Internet of Things (IoT) devices, establishing a ransomware reporting rule, creating a &#8220;limited use&#8221; obligation for incident information sharing, and establishing a national Cyber Incident Review Board.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Also on the agenda: reforms to the Security of Critical Infrastructure Act 2018, which are geared to addressing cybersecurity shortcomings exposed by recent breaches.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These revisions include providing more prescriptive guidance for critical industries like utilities and telecommunications, simplifying information sharing, providing directives for risk management programs, and consolidating security requirements for the telecommunications sector under the SOCI Act for critical infrastructure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Casey Ellis, founder, chairman, and chief strategy officer of Bugcrowd, says the Australian government is making the right moves. &#8220;The [Cyber Security Strategy] consultation paper addresses IoT security, ransomware reporting, incident sharing, and critical infrastructure management, reporting, and accountability, which are all certainly areas of softness in Australian policy,&#8221; Ellis says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Big Country, Big Cybersecurity Challenges\">Big Country, Big Cybersecurity Challenges<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The sheer expanse of Australia makes it difficult to protect critical infrastructure, especially for strategic industries like mining, which is highly dispersed and with sites in remote locations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, mining, maritime, and other utilities are dropping legacy technologies and embracing Internet-connected and IoT technologies to more efficiently manage and monitor their infrastructure. But this embrace of digital transformation often has left legacy equipment exposed to cyber threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;To make sure attacks such as the one on Australian ports remain isolated instead of a common occurrence, the government is rightly looking into how to legislate a Critical National Infrastructure Policy and looking to other countries to learn lessons on how to protect increased attack surfaces borne out of IT\/OT convergence,&#8221; says Shane Read, CISO at Goldilock, a physical cybersecurity startup.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Australia lacks both the scale and population to go it alone, however \u2014 so referencing known, global standards wherever possible makes sense, according to independent experts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Australia has looked to the UK\/US\/EU for guidance when it comes to cybersecurity policy,&#8221; notes Qualys&#8217; Sorosina.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like many other countries, Australia is struggling to bridge the cybersecurity skills gap.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Phillip Ivancic, APAC head of solutions at Synopsys Software Integrity Group, says that because of the small population relative to the size of the economy, there is a &#8220;huge shortage of skilled engineers and cybersecurity experts&#8221; in Australia.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;That&#8217;s why the government&#8217;s move to be more prescriptive and to provide real standards-based guidance, as well as to force change through mandates, should be welcomed,&#8221; Ivancic says. &#8220;We simply don&#8217;t have the scale to go out on our own, and mandating international standards that are already widely used is the right approach.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The government&#8217;s policy proposals lack key elements like controls around software supply chains, such as software bills of materials listing the components that make up applications, according to Ivancic. That&#8217;s a &#8220;glaring gap,&#8221; he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Major Cybersecurity Investments\">Major Cybersecurity Investments<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The path to becoming a cybersecure nation is not solely a governmental responsibility. Recognizing its own self-interest in improving cybersecurity practices, the private sector in Australia also is making huge investments in improving information security practices.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Australian organizations will spend more than AU$7.3 billion on information security and risk management products and services in 2024, an increase of 11.5% from 2023, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2024-03-19-gartner-forecasts-security-and-risk-management-spending-in-australia-to-grow-more-than-11-percent-in-2024\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">according to Gartner<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Cloud security will enjoy the biggest rise, increasing to A$248m (up 26.9% year-on-year).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The increase in spending is driven by a combination of high-profile cyberattacks and increased regulatory obligations, Gartner wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BugCrowd&#8217;s Ellis believes Australia&#8217;s effort to become a cybersecurity leader is achievable. &#8220;Australia has always been a nation of innovators and rule-breakers, and I do believe that the goal to become a world leader in cybersecurity, while ambitious, is an attainable one.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Australian government is carving out plans to revamp cybersecurity<\/p>\n","protected":false},"author":12,"featured_media":2797,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2796","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?fit=2560%2C1501&ssl=1",2560,1501,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?fit=300%2C176&ssl=1",300,176,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?fit=640%2C375&ssl=1",640,375,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?fit=640%2C375&ssl=1",640,375,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?fit=1536%2C900&ssl=1",1536,900,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?fit=2048%2C1201&ssl=1",2048,1201,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?fit=1024%2C600&ssl=1",1024,600,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/australian-government-doubles-down-on-cybersecurity-in-wake-of-major-attacks-scaled.jpg?fit=2560%2C1501&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2796","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2796"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2796\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2797"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2796"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2796"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2796"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}