Regulations spell danger for Australia's cybersecurity

Schneider Electric

By Nikki Saunders, cybersecurity EcoSystem Program Manager, Pacific, Schneider Electric
Wednesday, 12 October, 2022

Regulations spell danger for Australia's cybersecurity

Cybercrime is the biggest threat facing corporate Australia today, costing the economy more than an estimated $3 trillion.

With the sophistication, agility and frequency of attacks increasing (one every eight minutes in Australia), it’s encouraging to see the federal government implementing new legislation in response. However, while the intention is to better protect Australia’s critical infrastructure, this new cybersecurity framework could do the opposite.

Originally designed in 2018, the reformed Critical Infrastructure Protection Act 2022 came into effect in July this year. With an improved framework for handling cyber threats, it includes an array of measures to which Australian businesses and services must adhere.

In theory, the new Act is imperative for safeguarding a modern Australia. Its existence provides a benchmark for IT and OT professionals across a greater variety of industries and ensures security is a collective responsibility.

The importance of addressing this responsibility cannot be overstated in an environment of increased cyber threats to essential services and businesses over the past few years — including federal parliamentary networks, the medical sector, universities and key software businesses.

Take the most recent attack on Optus’s network as an example, which has seen millions of customers potentially affected, with full names, dates of birth and contact details stolen. While Optus was covered by insurance, it’s a reminder that sufficient scenario planning and risk mitigation is integral to preventing these attacks. Potentially one of the largest Australia has seen to date, it’s a warning to us all that cybersecurity has never been more critical.

The introduction of the new Act then is a positive sign that Australia is taking cybersecurity threats more seriously. However, some of the amendments foreshadow an evolution of increasingly stringent rules that could become unrealistic and unachievable — ultimately threatening system effectiveness and integrity.

One such update is the change to incident reporting deadlines. In line with the new law, organisations are now required to notify the Australian Cyber Security Centre (ASCS) within 12 hours of becoming aware of an incident. Failure to comply can result in fines starting at $11,000.

Not only could this have implications for smaller businesses, which often have fewer resources to identify and manage attacks on their assets, it detracts from what should be the priority of risk management. The standard 12-hour reporting deadline also doesn’t take into consideration the challenges and processes of different industries — finance vs the food sector, for example. The sophistication and complexity of cybercrimes mean that, in many instances, the time it takes to correctly identify an attack and potential solution is also difficult to predict.

On a global scale, reporting time for incidents was previously around 72 hours, meaning deadlines have reduced from three days to one. The risk in this continued reduction of reporting times is that requirements may get so low — potentially to immediate notification or ‘zero hours’ — that it’s simply unsustainable. Organisations must have adequate time to identify a breach, investigate the incident and produce an accurate report without fear of potentially devastating legal, cost and brand ramifications.

While the latest guidelines hint at a stricter framework in future, the current requirements are achievable for organisations that are prepared. For any organisation, whether 300 or 30,000, the key to effectively managing cybersecurity is understanding responsibilities and having a clear plan.

To implement the most effective cybersecurity, you must first have visibility over all your systems. That means working with a partner that understands your unique challenges and ensures open lines of communication. It’s imperative that your partner has dedicated cybersecurity leads to ensure clearly defined roles and responsibilities.

At Schneider, we practise what we preach and upskill our people through mandatory annual cybersecurity certification. Our customer-facing Cybersecurity Virtual Academy is a valuable online resource providing educational cybersecurity content, as well as opportunities to engage with industry experts through webinars and Q&As. Our relationships with other leaders in the cybersecurity space help our customers best leverage the investment they’ve made in their existing IT environment.

Whether you’re a start-up, SME or global enterprise, the new guidelines are an important reminder that investing in cybersecurity is not just the right thing to do, but critical for your business.

Image credit:

Related Articles

If you want to fix cyber, stop trying to fix people

We need to stop trying to fix people and start understanding and supporting them with the right...

Managing through uncertainty requires facing security unknowns head on

Understanding the attack surface in its entirety is not just a tactical advantage; it is a...

Why the success of modern cyber defence hinges on identity security

 A single compromised identity could easily provide the keys to the kingdom if it isn't...

  • All content Copyright © 2024 Westwick-Farrow Pty Ltd