governmentnews.com.au

Cyber risks need fresh eyes

Published on Tue, 05/03/2013, 08:55:25

|

By Julian Bajkowski

One of Australia’s most trusted information security firms has warned that public sector organisations need to independently test their cyber-defences to prevent unwanted intrusions and malicious activity rather than relying on existing assumptions of their vulnerability levels.

Saltbush Group senior consultant Geoff Rhodes, who is the immediate past chair of the federal government’s Information Technology Security Expert Advisory Group, believes that local government organisations must consider their potential exposure to vulnerabilities on par with small-to-medium-size businesses because of their limited level of resources for fending off intruders.

The public statement from the normally taciturn consultancy is significant because Saltbush normally works quietly behind the scenes to advise on and harden-up cyber defences for clients with high degrees of sensitivity.

The company’s client list includes defence industry suppliers and agencies including the Defence Signals Directorate as well as the Attorney General’s department, Centrelink and VicRoads.

“There are some key questions all businesses should ask about the data they hold – whether its transactional details like credit card details from purchases or medical records,” Mr Rhodes said. 

Saltbush’s cautionary note closely follows the revelation that an Australian Broadcasting Corporation website for the television program “Making Couples Happy” was hacked.

According to an ABC statement the breach exposed “the name, username and a hashed version of the password that audience members used to register on the program website.”

While that intrusion is believed to have been perpetrated by ideologically motivated hackers seeking to cause embarrassment, Saltbush is pushing the message that both public and private organisations need to start looking at vulnerabilities with a fresh set of eyes and in the same way that hackers do.

A key issue is that even though larger government agencies will often have mature and well-resourced cyber security safeguards, many smaller agencies must make do with constrained resources to protect against intruders.

“Local government organisations are no different from other government organisations,” Mr Rhodes said. “[However] the resources available are often at the lower end. The issues are always that organisations underestimate the level of risk to their systems.”

The government’s own evidence corroborates many of Saltbush’s concerns.

The Cyber Crime and Security Survey 2012 from CERT Australia, the government’s own computer emergency response team, warns that the “reporting of cyber security incidents – which is critical to the effectiveness of the government-business partnership – clearly requires further attention.”

“Anecdotal evidence available to the CERT suggests that some businesses are unaware of the full scope of unauthorised activity on their networks.”

Add your own comment
1,171


Your Vote

Should referenda be held outside the Federal Election cycle?

Yes, the political environment is too toxic

No, it would waste money

Allow voluntary e-voting in referenda



CONFERENCES & EVENTS

The Ninth KM Australia Congress

An academy of knowledge management and content, on 23-25th July 2013, at Crystal Palace, Luna Park, Sydney.

Mon 25/02/2013 10:57:44 / Read More »

COURSES & TRAINING

Mid-Year Intake Advisory Session, Monday 3 June 3:30-6:30pm

Join ANU & pursue your goals.

Mon 20/05/2013 04:30:54 / Read More »

Government funded business and management qualifications.

ITCC has a range of business and management qualifications, some of which are government funded. If eligible, Federal Government funding will cover the total cost of some of the below qualifications for you or your staff.

Mon 10/10/2011 11:08:41 / Read More »

Take the Pain out of Managing your Training

Partner with mytraining.net we help take the headache out of multi-quotation requirements & streamline training reservations

Tue 08/02/2011 12:00:00 / Read More »

SECURITY PROFILE

ADT Security Solutions

ADT Security can provide Government Security solutions such as Grade A1 monitoring, Type 1 certified installation and monitoring.

Thu 01/03/2012 12:11:46 / Read More »

GREEN PROCUREMENT

Zero emissions sweeper

The Green Machines 500ze is a Lithium-ion powered vacuum street sweeper, heralds a significant step in the drive for reduced carbon emissions and improved air quality.

Thu 25/11/2010 12:48:27 / Read More »

NEW PRODUCTS

Synthetic grass from TigerTurf

Artificial turf from New Zealand that is rich in value and realism.

Mon 20/05/2013 09:17:43 / Read More »

Foton Trucks on Sale in Australia

New line-up with performance, reliability and value.

Mon 13/05/2013 01:30:45 / Read More »

Valvoline oil tailored for government

To better serve the government sector Valvoline has introduced the environmentally responsible NextGen range of engine oil.

Tue 26/03/2013 02:46:55 / Read More »