Modern Australian
Men's Weekly

.

New guidelines for responding to cyber attacks don't go far enough

  • Written by Adam Henry, Adjunct Lecturer, UNSW

Debates about cyber security in Australia over the past few weeks have largely centred around the passing of the government’s controversial Assistance and Access bill. But while government access to encrypted messages is an important subject, protecting Australia from threat could depend more on the task of developing a solid and robust cyber security response plan.

Australia released its first Cyber Incident Management Arrangements (CIMA) for state, territory and federal governments on December 12. It’s a commendable move towards a comprehensive national civil defence strategy for cyber space.

Coming at least a decade after the need was first foreshadowed by the government, this is just the initial step on a path that demands much more development. Beyond CIMA, the government needs to better explain to the public the unique threats posed by large scale cyber incidents and, on that basis, engage the private sector and a wider community of experts on addressing those unique threats.

Read more: What skills does a cybersecurity professional need?

Australia is poorly prepared

The aim of the new cyber incident arrangements is to reduce the scope, impact and severity of a “national cyber incident”.

A national cyber incident is defined as being of potential national importance, but less severe than a “crisis” that would trigger the government’s Australian Government Crisis Management Framework (AGCMF).

Australia is currently ill-prepared to respond to a major cyber incident, such as the Wannacry or NotPetya attacks in 2017.

Wannacry severely disrupted the UK’s National Health Service, at a cost of A$160 million. NotPetya shut down the world’s largest shipping container company, Maersk, for several weeks, costing it A$500 million.

When costs for random cyber attacks are so high, it’s vital that all Australian governments have coordinated response plans to high-threat incidents. The CIMA sets out inter-jurisdictional coordination arrangements, roles and responsibilities, and principles for cooperation.

A higher-level cyber crisis that would trigger the AGCMF (a process that itself looks somewhat under-prepared) is one that:

… results in sustained disruption to essential services, severe economic damage, a threat to national security or loss of life.

More cyber experts and cyber incident exercises

At just seven pages in length, in glossy brochure format, the CIMA does not outline specific operational incident management protocols.

This will be up to state and territory governments to negotiate with the Commonwealth. That means the protocols developed may be subject to competing budget priorities, political appetite, divergent levels of cyber maturity, and, most importantly, staffing requirements.

Australia has a serious crisis in the availability of skilled cyber personnel in general. This is particularly the case in specialist areas required for the management of complex cyber incidents.

Government agencies struggle to compete with major corporations, such as the major banks, for the top-level recruits.

New guidelines for responding to cyber attacks don't go far enough Australia needs people with expertise in cybersecurity.

The skills crisis is exacerbated by the lack of high quality education and training programs in Australia for this specialist task. Our universities, for the most part, do not teach – or even research – complex cyber incidents on a scale that could begin to service the national need.

Read more: It's time for governments to help their citizens deal with cybersecurity

The federal government must move quickly to strengthen and formalise arrangements for collaboration with key non-governmental partners – particularly the business sector, but also researchers and large non-profit entities.

Critical infrastructure providers, such as electricity companies, should be among the first businesses targeted for collaboration due to the scale of potential fallout if they came under attack.

To help achieve this, CIMA outlines plans to institutionalise, for the first time, regular cyber incident exercises that address nationwide needs.

Better long-term planning is needed

While these moves are a good start, there are three longer term tasks that need attention.

First, the government needs to construct a consistent, credible and durable public narrative around the purpose of its cyber incident policies, and associated exercise programs.

Former Cyber Security Minister Dan Tehan has spoken of a single cyber storm, former Prime Minister Malcolm Turnbull spoke of a perfect cyber storm (several storms together), and Cyber Coordinator Alastair McGibbon spoke of a cyber catastrophe as the only existential threat Australia faced.

But there is little articulation in the public domain of what these ideas actually mean.

The new cyber incident management arrangements are meant to operate below the level of national cyber crisis. But the country is in dire need of a civil defence strategy for cyber space that addresses both levels of attack. There is no significant mention of cyber threats in the website of the Australian Disaster Resilience Knowledge Hub.

This is a completely new form of civil defence, and it may need a new form of organisation to carry it forward. A new, dedicated arm of a existing agency, such as the State Emergency Services (SES), is another potential solution.

One of us (Greg Austin) proposed in 2016 the creation of a new “cyber civil corps”. This would be a disciplined service relying on part-time commitments from the people best trained to respond to national cyber emergencies. A cyber civil corps could also help to define training needs and contribute to national training packages.

The second task falls to private business, who face potentially crippling costs in random cyber attacks.

They will need to build their own body of expertise in cyber simulations and exercise. Contracting out such responsibilities to consulting companies, or one-off reports, would produce scattershot results. Any “lessons learnt” within firms about contingency management could fail to be consolidated and shared with the wider business community.

Read more: The difference between cybersecurity and cybercrime, and why it matters

The third task of all stakeholders is to mobilise an expanding knowledge community led by researchers from academia, government and the private sector.

What exists at the moment is minimalist, and appears hostage to the preferences of a handful of senior officials in Australian Cyber Security Centre (ACSC) and the Department of Home Affairs who may not be in post within several years.

Cyber civil defence is the responsibility of the entire community. Australia needs a national standing committee for cyber security emergency management and resilience that is an equal partnership between government, business, and academic specialists.

Authors: Adam Henry, Adjunct Lecturer, UNSW

Read more http://theconversation.com/new-guidelines-for-responding-to-cyber-attacks-dont-go-far-enough-108908

Affordable Invisalign in Bangkok Why Australians Are Choosing Thailand

More Australians are investing in Invisalign to straighten their teeth, but the treatment in Australia can cost thousands of dollars and often takes m...

Designing a Tranquil Oasis in Your Backyard

Nothing beats a warm summer evening spent in a gorgeous backyard. The backyard is the perfect space to unwind and spend some of the most magical momen...

How a Well-Designed Gym Can Improve Your Performance

Have you ever entered a gym that just feels off and couldn’t focus on your workout? Maybe it’s the layout that was weird, or the lack of natural l...

Wellness Checkups at Work: Key to Employee Happiness and Higher Output

Employee wellness programs are reshaping how companies think about productivity and satisfaction. When people feel healthy, they perform better, sta...

Experience the Elegance of Plantation Shutter Blinds: Enhance Your Décor Today

When it comes to elevating your home’s interior, few window treatments combine sophistication and practicality as effortlessly as plantation shutter...

Common Questions Women Are Afraid to Ask Their Gynaecologist (and Honest Answers)

Visiting your gynaecologist isn’t always easy. Even though reproductive and sexual health are essential parts of overall wellbeing, many women fee...

Designing Homes for Coastal Climates – How to Handle Salt, Humidity, and Strong Winds in Building Materials

Living by the ocean is a dream for many Australians, offering breathtaking views, refreshing sea breezes, and a relaxed lifestyle that’s hard to b...

This OT Week, Australia’s occupational therapists are done staying quiet

Occupational Therapy Week is typically a time to celebrate the difference occupational therapists make in people’s lives. But this year, many sa...

Melbourne EMDR Clinic Sees Growing Interest in Patients with Depression

Depression is a common mental health condition affecting around 1 in 7 Australians. It is typically diagnosed when an individual has experienced a p...

Proactive approaches to mental wellbeing

Life gets busy quickly. For many adults, each week is a constant mix of work commitments, raising kids, managing a household, settling bills, catching...

The Power of Giving Back: How Volunteering Shapes Your Mindset

To say the least, volunteering can maximally change the way you see the world. Period. When you step into someone else’s shoes, even for a few hours...

How to Level Up Your Workouts with Simple Home Equipment

Working out at home has reached the peak of its popularity. Whether you’re short on time or simply prefer the comfort of your own space, home traini...

How to Prepare Financially for Buying a Home

Buying a house is one of the biggest and most exciting money choices you'll ever make. It means you stop giving rent money to someone else and start b...

Why Choosing Local Lawyers in Brisbane Can Make All the Difference

When it comes to legal matters, your choice of representation can influence both the outcome and overall experience. Working with local lawyers in B...

Restoring Volume and Style with Human Hair Toppers for Women

Hair plays a significant role in confidence and self-expression, but thinning hair and hair loss can affect women at any stage of life. While wigs p...

Top Qualities of a Trusted Local Aircon Installer

Choosing the right air conditioning installer can make a big difference to your comfort, safety, and long-term energy costs. A properly installed syst...

Everything You Should Know About Double Chin Treatment

A double chin, medically known as submental fat, is a common concern that affects people of all ages and body types. Thanks to modern cosmetic proce...

The Modern Role of a Dentist in Oral and Overall Health

When most people think of a dentist, they imagine routine check-ups, cleanings, or cavity fillings. While these remain vital aspects of dental care...