Read The Times Australia

Daily Bulletin

Lack of cyber security knowledge leads to lazy decisions from executives

  • Written by: Craig Horne, PhD candidate, Chairman of the Australian Computer Society in Victoria, University of Melbourne

The numbers and size of cyber security attacks are increasing and Australia is one of the world’s largest targets. The Federal government noted the current impact of cyber attacks on the Australian economy is A$17 billion annually.

The reasons are many and include a lack of direction and commitment to understanding information security at the strategic level. Research from the Australian National University shows executive/board knowledge of cyber risks among medium sized businesses is inadequate and board-level governance of cyber security risks varies wildly between organisations. This is troubling given the ultimate accountability of board directors.

The report found that only 58% of cyber security professionals thought their board had a sufficient understanding of cyber risks. Less than half (46%) said their board discusses cyber security rarely or never. Almost a third (30%) even said their board does not receive reports of cyber threats to the company.

Research from Cambridge University and retail bank Lloyds, also shows this level of uncertainty is causing boards to realise they have no idea what they are dealing with and giving up. Boards are doing this by simply outsourcing the risk of a cyber attack through the purchase of cyber insurance. The report comments:

“The amount of cyber insurance being purchased in Australia [has] increased 168-fold (16,828%) in the last two years, as more and more businesses seek to protect their balance sheets from this emerging threat.”

The problem with this approach to cyber risk is that too little effort is being made to understand the value, control and cost of the information that an organisation holds.

Cyber insurance is a product that covers businesses for the risk of data breaches, employee errors in mishandling data and computer hacking attacks. It covers liabilities and the expense involved in responding to a cyber attack. For example, Sony estimated that it spent US$171 million in cleaning up after its PlayStation Network was famously hacked in 2011.

Simply outsourcing the risk of an attack by purchasing cyber insurance fails to protect an organisation’s reputation from repeated and sustained cyber attacks. Another problem is that the erosion of an organisation’s competitive advantage through the loss of trade secrets through cyber attacks, is difficult to measure and insure.

My research shows executives should be identifying the value and sensitivity of the information in their organisations. Only then can they make sensible decisions about what IT infrastructure should be used and whether to seek expert help by outsourcing.

However identifying all the information that an organisation holds is not as easy as it first sounds. For example, some business conversations take place on social media platforms such as LinkedIn. Businesses need to consider whether those conversations are within the realms of responsibility for employers and therefore if employees should be admonished or supported for holding these electronic conversations.

Organisations can sometimes hold vast pools of information that are secret. However holding sensitive, secret information that is non-strategic is costly and may be pointless. Consider for example a retail organisation that has an online ordering website. This sort of organisation shouldn’t be recording and holding the credit card details of customers, if it can be helped.

Outsourcing the payment for goods or services to finance service intermediaries makes good business sense. By not holding credit card details and effectively outsourcing that function, an organisation has made itself safer because it simply can’t end up on the front page of a newspaper for leaking credit card details.

Sometimes sensitive information is necessary for conducting business operations. If this is unavoidable, then organisations might need to ask whether the security controls they have in place to protect their sensitive information are enough. This might also extend to information being used by suppliers or customers.

If the assessment reveals that security controls are not enough, then a business case needs to be made for increased budget to the board. This may be costly, but if sensitive information is necessary for conducting business operations, then it must be protected and the security budget should be approved. image Retailer Target was affected by a point of sale cyber attack in 2013. Paul Miller/AAP

Organisations routinely fail to fully assess and protect against the risks introduced by storing or sharing information with other organisations. Examples include sharing with suppliers, customers, regulators and contract staff.

High profile cyber bungles from supplier-side attacks include the Target attack in December 2013, where the point-of-sale machines, supplied and operated by a third-party supplier, were infected with a virus that siphoned off all the credit card details of customers.

Board directors not taking the time to understand information security strategy can lead to a blanket approach of mitigating all risk of a cyber security attack by simply purchasing cyber insurance. This clumsy approach is not sustainable and consumers should be demanding more from our business leaders.

Authors: Craig Horne, PhD candidate, Chairman of the Australian Computer Society in Victoria, University of Melbourne

Read more http://theconversation.com/lack-of-cyber-security-knowledge-leads-to-lazy-decisions-from-executives-68065

Business News

How Immigration Lawyers Can Help

Introduction Visa decisions can shape employment, family life, study plans, travel, and future residence. A small omission can lead to delay, added expense, or refusal. Immigration lawyers assess l...

Daily Bulletin - avatar Daily Bulletin

How Industrial Drying Equipment Supports Efficient Processing

Many industrial processes require moisture to be removed from compressed air, products or process materials before they move to the next stage. Excess moisture can affect equipment performance, produc...

Daily Bulletin - avatar Daily Bulletin

Practical Ways a Whiteboard Can Improve Workplace Communication

Effective communication helps teams stay organised, share ideas and keep track of important information. While digital tools are now common in many workplaces, a whiteboard continues to provide a simp...

Daily Bulletin - avatar Daily Bulletin

Designing Eco-Friendly Custom Water Bottles for Your Next Event

The Evolution of Sustainable Event Merchandise Event planning has undergone a massive transformation over the last decade. Gone are the days when organizers could hand out cheap, single use plastic...

Daily Bulletin - avatar Daily Bulletin

Why Choosing a Professional Florist Melbourne Makes Flower Delivery Impactful

Flowers have a great power to speak when humans cannot express their feelings with right words. Flowers are the best gifts when you are celebrating a birthday or welcoming a newborn child into your fa...

Daily Bulletin - avatar Daily Bulletin

The Business Case for Choosing Australian Fabricators Over Imported Alternatives

For a long time, you might have defaulted to overseas suppliers when sourcing fabricated metal components for a project. The unit price was lower on paper, and the maths seemed straightforward. That...

Daily Bulletin - avatar Daily Bulletin

Australian organisations are relying on business continuity plans built for a far more predictable world

Tariff escalations, supply chain fragility, geopolitical events, and the ongoing threat of cyber disruption have reshaped the risk environment facing Australian organisations. The problem is that ma...

Daily Bulletin - avatar Daily Bulletin

How to Rent a Car for Uber in Melbourne: What Every New Driver Needs to Know

Starting out as an Uber driver in Melbourne is not as complicated as it sounds but getting the vehicle right is where most new drivers get stuck. Uber has strict requirements around vehicle age, condi...

Daily Bulletin - avatar Daily Bulletin

When Should You Speak to a Lawyer About a Legal Issue?

Legal issues can begin with a simple question, then become harder to manage once formal steps are involved. Many people wait until a matter feels urgent before seeking guidance, even though earlier ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

How Long Does Interstate Freight Take in Australia?

If you have ever arranged for stock, equipment or materials to travel from one Australian state to a...

How AEC Firms Can Scale Faster Without Sacrificing Project Quality

Growth presents a fundamental dilemma for architecture, engineering, and construction firms: expan...

What Makes an Aesthetic Clinic Worth Going Back To?

Trying an aesthetic clinic for the first time can feel like a bit of a gamble. You can read review...

Elevate Your Morning Routine with Cafe-Style Coffee at Home with the Right Coffee Machine

There's something magical about that first sip of coffee in the morning. It’s more than just a bev...

Top Garment Steamers for Busy Professionals in Australia

The gap between garment steamers built for a quick touch-up and ones built to keep pace with a wor...

Correct Sleeping Posture to Minimize Back Strain

Most people don’t pay much attention to how they sleep until they start waking up with a stiff bac...

Why Product Longevity Matters for Sustainable Australian Buildings

Sustainability in building design is often associated with recycled materials, renewable resources a...

NDIS Support Coordination Explained: What Does a Support Coordinator Actually Do?

NDIS support coordination explained means understanding how a professional can help participants n...

When Should You Speak with Divorce Lawyers in Sydney?

Divorce involves more than completing an online application. It can affect parenting arrangements, p...