governmentnews.com.au

Cyber risks need fresh eyes

Published on Tue, 05/03/2013, 08:55:25

|

By Julian Bajkowski

One of Australia’s most trusted information security firms has warned that public sector organisations need to independently test their cyber-defences to prevent unwanted intrusions and malicious activity rather than relying on existing assumptions of their vulnerability levels.

Saltbush Group senior consultant Geoff Rhodes, who is the immediate past chair of the federal government’s Information Technology Security Expert Advisory Group, believes that local government organisations must consider their potential exposure to vulnerabilities on par with small-to-medium-size businesses because of their limited level of resources for fending off intruders.

The public statement from the normally taciturn consultancy is significant because Saltbush normally works quietly behind the scenes to advise on and harden-up cyber defences for clients with high degrees of sensitivity.

The company’s client list includes defence industry suppliers and agencies including the Defence Signals Directorate as well as the Attorney General’s department, Centrelink and VicRoads.

“There are some key questions all businesses should ask about the data they hold – whether its transactional details like credit card details from purchases or medical records,” Mr Rhodes said. 

Saltbush’s cautionary note closely follows the revelation that an Australian Broadcasting Corporation website for the television program “Making Couples Happy” was hacked.

According to an ABC statement the breach exposed “the name, username and a hashed version of the password that audience members used to register on the program website.”

While that intrusion is believed to have been perpetrated by ideologically motivated hackers seeking to cause embarrassment, Saltbush is pushing the message that both public and private organisations need to start looking at vulnerabilities with a fresh set of eyes and in the same way that hackers do.

A key issue is that even though larger government agencies will often have mature and well-resourced cyber security safeguards, many smaller agencies must make do with constrained resources to protect against intruders.

“Local government organisations are no different from other government organisations,” Mr Rhodes said. “[However] the resources available are often at the lower end. The issues are always that organisations underestimate the level of risk to their systems.”

The government’s own evidence corroborates many of Saltbush’s concerns.

The Cyber Crime and Security Survey 2012 from CERT Australia, the government’s own computer emergency response team, warns that the “reporting of cyber security incidents – which is critical to the effectiveness of the government-business partnership – clearly requires further attention.”

“Anecdotal evidence available to the CERT suggests that some businesses are unaware of the full scope of unauthorised activity on their networks.”

Add your own comment
1,162


Your Vote

Should referenda be held outside the Federal Election cycle?

Yes, the political environment is too toxic

No, it would waste money

Allow voluntary e-voting in referenda



CONFERENCES & EVENTS

Graduate Studies Information Evening - Tuesday 21 May 4-7pm

Thinking about further study? The Australian National University (ANU).

Tue 07/05/2013 01:29:33 / Read More »

The Ninth KM Australia Congress

An academy of knowledge management and content, on 23-25th July 2013, at Crystal Palace, Luna Park, Sydney.

Mon 25/02/2013 10:57:44 / Read More »

COURSES & TRAINING

Government funded business and management qualifications.

ITCC has a range of business and management qualifications, some of which are government funded. If eligible, Federal Government funding will cover the total cost of some of the below qualifications for you or your staff.

Mon 10/10/2011 11:08:41 / Read More »

Take the Pain out of Managing your Training

Partner with mytraining.net we help take the headache out of multi-quotation requirements & streamline training reservations

Tue 08/02/2011 12:00:00 / Read More »

Funded diplomas, for your future in government

Business Success Group has funded places available for existing workers.

Mon 08/03/2010 11:24:34 / Read More »

SECURITY PROFILE

ADT Security Solutions

ADT Security can provide Government Security solutions such as Grade A1 monitoring, Type 1 certified installation and monitoring.

Thu 01/03/2012 12:11:46 / Read More »

GREEN PROCUREMENT

Zero emissions sweeper

The Green Machines 500ze is a Lithium-ion powered vacuum street sweeper, heralds a significant step in the drive for reduced carbon emissions and improved air quality.

Thu 25/11/2010 12:48:27 / Read More »

NEW PRODUCTS

Foton Trucks on Sale in Australia

New line-up with performance, reliability and value.

Mon 13/05/2013 01:30:45 / Read More »

Valvoline oil tailored for government

To better serve the government sector Valvoline has introduced the environmentally responsible NextGen range of engine oil.

Tue 26/03/2013 02:46:55 / Read More »

Turn your data centre into a profit centre

Companies that have made the switch recommend HP ProLiant. HP has led the market for 16 years and continues to deliver end-to-end solutions. HP ProLiant Gen8 servers are the answer for insatiable demand for services and data...

Fri 15/02/2013 10:06:19 / Read More »