Read The Times Australia

Daily Bulletin

New law will force some (but not all) organisations to reveal data breaches

  • Written by: Jai Galliott, Lecturer in Cyber Security, UNSW
image

We live in an era of big data stored digitally, and some of that data is about you. For example, the government keeps your social security and tax data, banks keep your financial data and your phone provider stores your metadata.

There is probably more of your confidential information in the data storage facilities of various organisations than you have in your own filing cabinet.

But these organisations cannot always exercise control over it.

This will become ever more true as the reach of social media technologies increases. More and more of your photos, videos and personal dating stories will be converted into vulnerable bits and bytes.

Security breaches

All of this increases the risks associated with security breaches. Others might steal your information and use it for purposes for which it was not intended, such as fraud and intimidation.

Having identified this risk, the Australian Legal Reform Commission (ALRC) convinced the government that it would be beneficial to impose a notification requirement on organisations that could suffer data breaches.

If your personal information was compromised by a breach, this would allow you to take remedial steps to lessen the adverse impact.

This might range from a simple password change, to telling your spouse, family or employer about financial troubles, health conditions or secret memberships with Tinder, Grindr or Ashley Madison.

The Privacy Amendment (Notifiable Data Breaches) Bill 2016 has therefore quietly passed through parliament. It only needs Royal assent before the relevant legislation is enacted.

But will it do any good in the war on cybercrime?

Will it work?

This Bill is certainly a step in the right direction. It implements the ALRC recommendations by requiring organisations regulated by the Privacy Act to provide notice to the Australian Information Commissioner and affected individuals of an eligible data breach.

This provides both individuals and government with an opportunity to track and respond to events provided they pose a “a likely risk of serious harm” – whether this is financial, psychological, technological or otherwise.

It could be a malicious breach of the secure storage and handling of information, an accidental loss (most commonly of IT equipment or hard copy documents) or a negligent or improper disclosure of information.

But there are several problems that limit the legislations’s effectiveness. To begin with, the means of notification are rather vague and leave much to be desired.

For instance, Section 26WL permits those reporting harmful breaches to use whatever communication method is regularly used with particular individuals, likely email.

But there is no regard for the fact that these regular means of communication are those most likely at risk. The most vulnerable people are typically those who don’t regularly check their email.

In circumstances where it is impracticable to notify individuals or groups affected, the Bill provides that an organisation will not be required to provide direct notice.

Instead it must publicise notification information on its website. But the Bill does not stipulate what constitutes such circumstances or the extent of the “publicity” required.

This leaves open the possibility that breach notifications will be relegated to some deep, dark corner of the websites of less scrupulous organisations.

Who must act?

While the changes to the Privacy Act target businesses and government agencies, there are also some limitations concerning the groups to which the law applies.

Worryingly, the breach notification requirements only apply to those organisations covered by the original Privacy Act.

However, this means that state government organisations and local councils, and organisations with a turnover less than A$3 million a year do not need to comply with the legislation.

But the first two of these hold highly confidential data and are likely to be seen as easy targets by malicious hackers.

Foreign businesses serving Australian clients must comply with the law. But the Australian government lacks effective means to pursue breach information from multinational technology giants headquartered overseas if they are reluctant to comply. These is likely to be of concern if you use such services for email or data storage of personal information.

Law enforcement agencies that believe public knowledge of a breach might prejudice operations are also exempt. But a compromise of sensitive information held by such agencies can be more damaging than information held by private organisations.

Data breach detection

By far the biggest problem with the new legislation is that it fails to recognise that breaches often go undetected for long periods of time. This offsets any benefit that might eventually be gained by reporting and notification.

The median number of days that attackers were present on a victim’s network before being discovered dropped from 205 days in 2014 to 146 days in 2015, according to a report from US cybersecurity firm Mandiant.

This is certainly an improvement of the 416 days back in 2012, but is still of great concern.

Any damage that is going to be done is likely to occur within the first few days or months. Mandiant also reminds us that these are median figures and that some breaches still often go undetected for years.

Proactive action needed

What’s needed is more proactive legislation, something between what is being implemented in Australia and that was recently implemented in China which has a set legal principles for protection of personal data.

So businesses offering products and services here could be required to obtain consent when collecting user information, and be subjected to continual security maintenance and mandated health checks at set intervals.

Those holding critical data could also be required to hold it within Australian territory and perhaps even at dedicated (highly protected) sites.

Moving beyond what China has done, it would also be wise to mandate network operators and major data holders to establish and maintain broader business continuity and cyber security incident response plans.

In the case of attacks leading to data breaches, they could then report to a governmental department that would non-selectively provide live website updates on recent incidents for public consumption.

Authors: Jai Galliott, Lecturer in Cyber Security, UNSW

Read more http://theconversation.com/new-law-will-force-some-but-not-all-organisations-to-reveal-data-breaches-73971

Business News

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

Options Available When a Company Faces Financial Distress

Financial distress can develop gradually or arrive suddenly, and when it does, the decisions made in the early stages often determine what options remain available later. Directors who act promptly ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...

Australia’s Best Walking Trails and the Shoes You Need to Tackle Them

Australia is not short on spectacular walks. You can follow ocean cliffs in Victoria, cross ancien...

Why Pre-Purchase Building Inspections Are Essential Before Buying a Home in Australia

source Have you ever walked through an open home and started picturing your furniture, family d...