Read The Times Australia

Daily Bulletin

One year on, is Australia's cybersecurity strategy on track? Experts respond

  • Written by: Ritesh Chugh, Senior Lecturer (Information Systems Management), CQUniversity Australia

Prime Minister Malcolm Turnbull launched Australia’s cybersecurity strategy in April 2016, and more than one year on, there’s work to be done.

Upon launch, the strategy was criticised for its lack of funding and vague goals. Among other targets, it aimed to ensure more information was shared between government agencies and the private sector about cyber threats, and that universities were training “skilled cyber security professionals”.

The recent Australian Strategic Policy Institute’s (ASPI) publication “Australia’s cyber security strategy: execution & evolution” is something of a report card on the government’s progress so far. The aim of the strategy was to improve the security of Australian government organisations as well as businesses and individuals, and while ASPI said there had been “significant encouraging progress”, it also noted investment in a number of key goals has been insufficient.

We asked a panel of experts to weigh in: how is the government doing 12 months into its cybersecurity strategy?

Ritesh Chugh, Senior Lecturer, School of Engineering & Technology, CQUniversity

As the initial 2016 cybersecurity strategy did not specify quantifiable outcomes for most of its five action plan items – (1) national cyber partnership, (2) strong cyber defences, (3) global responsibility and influence, (4) growth and innovation and (5) cyber smart nation – measuring its progress in the ASPI report is difficult.

An absence of adequate implementation plans as well as poor methodology is evident in the government’s strategy, as witnessed in the bungled 2016 Census, as ASPI mentions. It appears the strategy has also not been fully implemented due to lack of government spending on cyber issues, and inadequate human resource allocation. However, there are lessons to learn.

Education and public awareness will continue to play a vital role in ensuring people are better prepared for cyber threats. The Stay Smart Online website is a good initiative and can be enhanced by encouraging more people to sign up to its Alert Service. Communication should continue to be a key focus.

For the strategy to work effectively, it is also important that better public-private partnerships are established. Small to medium enterprises (estimated to be around 95% of all businesses) form a large part of the Australian landscape and are relatively easy targets. Awareness and educational programs more specifically tailored to their needs are warranted, along with easy access to experts in cybersecurity – perhaps a phone support contact centre.

It is necessary for the government to consider their commitment to the strategy.

image Prime Minister Malcolm Turnbull announces the federal government’s Cyber Security Strategy at the Australian Technology Park in Sydney, Thursday, April 21, 2016. AAP Image/Dean Lewins

Leonie Simpson, Senior Lecturer, Science and Engineering Faculty, Queensland University of Technology

ASPI recommends the government communicate more openly with the private sector, suggesting quarterly threat reporting be issued from the Australian Cyber Security Centre along with regular strategy updates to give confidence to the community.

In my view, that’s an important step. The Australian Computer Crime and Security Survey series published from 2002 to 2006, for example, gave insight into cybersecurity in the Australian context. Its discontinuation, along with the lack of breach notification (until 2017), left a void in public reporting on commonly occurring cyber incidents, which is important in informing cyber risk management of both public and private organisations.

Although there have been similar reports in years since, a regular series from Australian Cyber Security Centre (ACSC) could be highly useful.

As yet, we have not seen much progress on actions under the “Cyber Smart Nation” theme. Academic Centres of Cyber Security Excellence have not yet been established, although the process is underway.

ASPI’s recommendations also do not target gender bias specifically, although it notes in the report that the government has been “proactively tackling” the issue via its 2016 Australian Cyber Security Challenge, among other initiatives.

Recommendation 9 suggests we broaden the concept of cyber skill shortages to include other disciplines, including law, psychology, communications and so on. This may indirectly assist in increasing cyber workforce diversity, but it does not address the common misconception that women or other minority groups do not hold or wish to hold technical security roles.

This is an area that may benefit from other programs, such as the Science in Australia Gender Equity (SAGE) pilot. The predicted cybersecurity workforce shortages make addressing diversity a priority.

Asif Gill, Senior Lecturer, School of Software, University of Technology Sydney

The ASPI report highlights encouraging progress and commitment from both the government and private sector to Australia’s Cyber Security Strategy. Despite this interest, there are some pressing challenges in this report that warrant further analysis.

The report points to the ad hoc nature of the government’s communication and expectation management with industry partners. This calls not only for a clear action plan, but also active stakeholder communication to effectively engage and enact the strategy, and quantitatively track and measure its progress.

The stategy’s five interdependent themes could also be more precisely integrated, prioritised and planned in an ordered cybersecurity value chain to streamline efforts and achieve success incrementally.

For instance, core to cybersecurity is to the ability to effectively and proactively defend against cyber attacks. But the report highlighted a recent Australian National Audit Office audit that found two key government departments had “insufficient protection” against external cyber attacks.

Further, the strategy’s ambitious list of 33 initiatives, from appointing a Cyber Ambassador to co-designing voluntary cybersecurity “health checks” for ASX100 listed businesses, seems too many.

It would be better to identify a small and manageable set of high value initiatives and action them, with the ability to refine and edit as new information emerges. Initiatives identified today may become quickly irrelevant due to rapid changes in the cybersecurity landscape in the next three years or so.

Authors: Ritesh Chugh, Senior Lecturer (Information Systems Management), CQUniversity Australia

Read more http://theconversation.com/one-year-on-is-australias-cybersecurity-strategy-on-track-experts-respond-78675

Business News

How Telematics Helps Australian Companies Improve Productivity

Operating a commercial fleet in Australia is a uniquely demanding endeavour. Between the sprawling urban sprawl of cities like Sydney and Melbourne and the immense, unforgiving stretches of the Outb...

Daily Bulletin - avatar Daily Bulletin

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...