Read The Times Australia

Daily Bulletin

Lack of cyber security knowledge leads to lazy decisions from executives

  • Written by: Craig Horne, PhD candidate, Chairman of the Australian Computer Society in Victoria, University of Melbourne

The numbers and size of cyber security attacks are increasing and Australia is one of the world’s largest targets. The Federal government noted the current impact of cyber attacks on the Australian economy is A$17 billion annually.

The reasons are many and include a lack of direction and commitment to understanding information security at the strategic level. Research from the Australian National University shows executive/board knowledge of cyber risks among medium sized businesses is inadequate and board-level governance of cyber security risks varies wildly between organisations. This is troubling given the ultimate accountability of board directors.

The report found that only 58% of cyber security professionals thought their board had a sufficient understanding of cyber risks. Less than half (46%) said their board discusses cyber security rarely or never. Almost a third (30%) even said their board does not receive reports of cyber threats to the company.

Research from Cambridge University and retail bank Lloyds, also shows this level of uncertainty is causing boards to realise they have no idea what they are dealing with and giving up. Boards are doing this by simply outsourcing the risk of a cyber attack through the purchase of cyber insurance. The report comments:

“The amount of cyber insurance being purchased in Australia [has] increased 168-fold (16,828%) in the last two years, as more and more businesses seek to protect their balance sheets from this emerging threat.”

The problem with this approach to cyber risk is that too little effort is being made to understand the value, control and cost of the information that an organisation holds.

Cyber insurance is a product that covers businesses for the risk of data breaches, employee errors in mishandling data and computer hacking attacks. It covers liabilities and the expense involved in responding to a cyber attack. For example, Sony estimated that it spent US$171 million in cleaning up after its PlayStation Network was famously hacked in 2011.

Simply outsourcing the risk of an attack by purchasing cyber insurance fails to protect an organisation’s reputation from repeated and sustained cyber attacks. Another problem is that the erosion of an organisation’s competitive advantage through the loss of trade secrets through cyber attacks, is difficult to measure and insure.

My research shows executives should be identifying the value and sensitivity of the information in their organisations. Only then can they make sensible decisions about what IT infrastructure should be used and whether to seek expert help by outsourcing.

However identifying all the information that an organisation holds is not as easy as it first sounds. For example, some business conversations take place on social media platforms such as LinkedIn. Businesses need to consider whether those conversations are within the realms of responsibility for employers and therefore if employees should be admonished or supported for holding these electronic conversations.

Organisations can sometimes hold vast pools of information that are secret. However holding sensitive, secret information that is non-strategic is costly and may be pointless. Consider for example a retail organisation that has an online ordering website. This sort of organisation shouldn’t be recording and holding the credit card details of customers, if it can be helped.

Outsourcing the payment for goods or services to finance service intermediaries makes good business sense. By not holding credit card details and effectively outsourcing that function, an organisation has made itself safer because it simply can’t end up on the front page of a newspaper for leaking credit card details.

Sometimes sensitive information is necessary for conducting business operations. If this is unavoidable, then organisations might need to ask whether the security controls they have in place to protect their sensitive information are enough. This might also extend to information being used by suppliers or customers.

If the assessment reveals that security controls are not enough, then a business case needs to be made for increased budget to the board. This may be costly, but if sensitive information is necessary for conducting business operations, then it must be protected and the security budget should be approved. image Retailer Target was affected by a point of sale cyber attack in 2013. Paul Miller/AAP

Organisations routinely fail to fully assess and protect against the risks introduced by storing or sharing information with other organisations. Examples include sharing with suppliers, customers, regulators and contract staff.

High profile cyber bungles from supplier-side attacks include the Target attack in December 2013, where the point-of-sale machines, supplied and operated by a third-party supplier, were infected with a virus that siphoned off all the credit card details of customers.

Board directors not taking the time to understand information security strategy can lead to a blanket approach of mitigating all risk of a cyber security attack by simply purchasing cyber insurance. This clumsy approach is not sustainable and consumers should be demanding more from our business leaders.

Authors: Craig Horne, PhD candidate, Chairman of the Australian Computer Society in Victoria, University of Melbourne

Read more http://theconversation.com/lack-of-cyber-security-knowledge-leads-to-lazy-decisions-from-executives-68065

Business News

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

Options Available When a Company Faces Financial Distress

Financial distress can develop gradually or arrive suddenly, and when it does, the decisions made in the early stages often determine what options remain available later. Directors who act promptly ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...

Australia’s Best Walking Trails and the Shoes You Need to Tackle Them

Australia is not short on spectacular walks. You can follow ocean cliffs in Victoria, cross ancien...

Why Pre-Purchase Building Inspections Are Essential Before Buying a Home in Australia

source Have you ever walked through an open home and started picturing your furniture, family d...