Modern Australian
Men's Weekly

.

New guidelines for responding to cyber attacks don't go far enough

  • Written by Adam Henry, Adjunct Lecturer, UNSW

Debates about cyber security in Australia over the past few weeks have largely centred around the passing of the government’s controversial Assistance and Access bill. But while government access to encrypted messages is an important subject, protecting Australia from threat could depend more on the task of developing a solid and robust cyber security response plan.

Australia released its first Cyber Incident Management Arrangements (CIMA) for state, territory and federal governments on December 12. It’s a commendable move towards a comprehensive national civil defence strategy for cyber space.

Coming at least a decade after the need was first foreshadowed by the government, this is just the initial step on a path that demands much more development. Beyond CIMA, the government needs to better explain to the public the unique threats posed by large scale cyber incidents and, on that basis, engage the private sector and a wider community of experts on addressing those unique threats.

Read more: What skills does a cybersecurity professional need?

Australia is poorly prepared

The aim of the new cyber incident arrangements is to reduce the scope, impact and severity of a “national cyber incident”.

A national cyber incident is defined as being of potential national importance, but less severe than a “crisis” that would trigger the government’s Australian Government Crisis Management Framework (AGCMF).

Australia is currently ill-prepared to respond to a major cyber incident, such as the Wannacry or NotPetya attacks in 2017.

Wannacry severely disrupted the UK’s National Health Service, at a cost of A$160 million. NotPetya shut down the world’s largest shipping container company, Maersk, for several weeks, costing it A$500 million.

When costs for random cyber attacks are so high, it’s vital that all Australian governments have coordinated response plans to high-threat incidents. The CIMA sets out inter-jurisdictional coordination arrangements, roles and responsibilities, and principles for cooperation.

A higher-level cyber crisis that would trigger the AGCMF (a process that itself looks somewhat under-prepared) is one that:

… results in sustained disruption to essential services, severe economic damage, a threat to national security or loss of life.

More cyber experts and cyber incident exercises

At just seven pages in length, in glossy brochure format, the CIMA does not outline specific operational incident management protocols.

This will be up to state and territory governments to negotiate with the Commonwealth. That means the protocols developed may be subject to competing budget priorities, political appetite, divergent levels of cyber maturity, and, most importantly, staffing requirements.

Australia has a serious crisis in the availability of skilled cyber personnel in general. This is particularly the case in specialist areas required for the management of complex cyber incidents.

Government agencies struggle to compete with major corporations, such as the major banks, for the top-level recruits.

New guidelines for responding to cyber attacks don't go far enough Australia needs people with expertise in cybersecurity.

The skills crisis is exacerbated by the lack of high quality education and training programs in Australia for this specialist task. Our universities, for the most part, do not teach – or even research – complex cyber incidents on a scale that could begin to service the national need.

Read more: It's time for governments to help their citizens deal with cybersecurity

The federal government must move quickly to strengthen and formalise arrangements for collaboration with key non-governmental partners – particularly the business sector, but also researchers and large non-profit entities.

Critical infrastructure providers, such as electricity companies, should be among the first businesses targeted for collaboration due to the scale of potential fallout if they came under attack.

To help achieve this, CIMA outlines plans to institutionalise, for the first time, regular cyber incident exercises that address nationwide needs.

Better long-term planning is needed

While these moves are a good start, there are three longer term tasks that need attention.

First, the government needs to construct a consistent, credible and durable public narrative around the purpose of its cyber incident policies, and associated exercise programs.

Former Cyber Security Minister Dan Tehan has spoken of a single cyber storm, former Prime Minister Malcolm Turnbull spoke of a perfect cyber storm (several storms together), and Cyber Coordinator Alastair McGibbon spoke of a cyber catastrophe as the only existential threat Australia faced.

But there is little articulation in the public domain of what these ideas actually mean.

The new cyber incident management arrangements are meant to operate below the level of national cyber crisis. But the country is in dire need of a civil defence strategy for cyber space that addresses both levels of attack. There is no significant mention of cyber threats in the website of the Australian Disaster Resilience Knowledge Hub.

This is a completely new form of civil defence, and it may need a new form of organisation to carry it forward. A new, dedicated arm of a existing agency, such as the State Emergency Services (SES), is another potential solution.

One of us (Greg Austin) proposed in 2016 the creation of a new “cyber civil corps”. This would be a disciplined service relying on part-time commitments from the people best trained to respond to national cyber emergencies. A cyber civil corps could also help to define training needs and contribute to national training packages.

The second task falls to private business, who face potentially crippling costs in random cyber attacks.

They will need to build their own body of expertise in cyber simulations and exercise. Contracting out such responsibilities to consulting companies, or one-off reports, would produce scattershot results. Any “lessons learnt” within firms about contingency management could fail to be consolidated and shared with the wider business community.

Read more: The difference between cybersecurity and cybercrime, and why it matters

The third task of all stakeholders is to mobilise an expanding knowledge community led by researchers from academia, government and the private sector.

What exists at the moment is minimalist, and appears hostage to the preferences of a handful of senior officials in Australian Cyber Security Centre (ACSC) and the Department of Home Affairs who may not be in post within several years.

Cyber civil defence is the responsibility of the entire community. Australia needs a national standing committee for cyber security emergency management and resilience that is an equal partnership between government, business, and academic specialists.

Authors: Adam Henry, Adjunct Lecturer, UNSW

Read more http://theconversation.com/new-guidelines-for-responding-to-cyber-attacks-dont-go-far-enough-108908

BMW Used Cars and the Appeal of Driving German Engineering

For drivers who value performance, comfort, and refined design, BMW used cars Melbourne offer an attractive way to experience premium motoring without...

Why Automatic Gates Melbourne are A Smarter Property Access

Security and convenience have become defining features of modern properties, and automatic gates Melbourne are increasingly seen as a practical sol...

The Importance Of Structured Commercial Office Cleaning In Busy Office Environments

Office spaces are dynamic environments where people collaborate, meet clients, and spend a significant portion of their day. Maintaining cleanliness...

Single Tooth Dental Implant for Natural Tooth Replacement and Lasting Stability

Losing a single tooth can have a noticeable impact on comfort, appearance, and confidence, which is why a Single Tooth Dental Implant is considered...

When Grief Doesn’t Follow a Timeline

Grief rarely moves in a straight line. It doesn’t follow stages neatly, and it doesn’t respond well to pressure — especially the quiet pressure ...

Steel Plate And Its Role In Modern Construction And Manufacturing

A steel plate is one of those materials that quietly holds the modern world together. It does not demand attention, yet it supports bridges, buildin...

Understanding Fat Transfer to the Breast: What to Know Before Considering the Procedure

Surgical options for breast enhancement have evolved over time, offering different approaches depending on a person’s goals and body type. One opt...

What to Do When Your Car’s Side Window Is Broken

A shattered side window is more than an inconvenience. Whether caused by a break-in, road debris, or accidental impact, it leaves your vehicle exposed...

Shopify Web Development and Shopify Website Development for Scalable Online Stores

Choosing the right platform is a crucial decision for any online business, and Shopify web development has become a popular choice for brands that ...

How a Burleigh Heads Plumber Tests for Pipe Leaks

Pipe leaks can be deceptively difficult to spot. Some announce themselves with a steady drip under the sink, but many develop quietly behind walls, ...

What Local Businesses Should Expect from IT Services in Melbourne?

If you run a Melbourne business with roughly 7–100 staff, you have probably noticed something over the last couple of years. The IT problems got m...

How Professional Cleaning Improves Indoor Air Quality

Indoor air quality (IAQ) plays a crucial role in our health, comfort, and overall wellbeing. Australians spend nearly 90% of their time indoors-at hom...

Solar and Solar Battery Systems: Powering Smarter Homes in Victoria

As energy prices continue to rise and sustainability becomes a priority for Australian homeowners, more families are investing in Solar and Solar Ba...

Plumbing Emergency Melbourne: What to Do When Every Minute Counts

A sudden plumbing issue can quickly turn into a major disaster if not handled promptly. From burst pipes and overflowing toilets to leaking gas line...

Why Older Melbourne Homes Require Detailed Building & Pest Inspections

Older homes make up a large part of Melbourne’s housing stock. Victorian terraces, Edwardian houses, Californian bungalows, and post-war brick hom...

7 Essential Tips for Choosing Reliable Moving Services in Perth

Moving to a new home or office can be exciting, but it also comes with stress, planning, and plenty of decisions. One of the most important choices yo...

How to Find the Best Real Estate Agent Near You on the Central Coast

Choosing the right real estate agent can make a major difference to your final sale price, days on market, and overall experience. The Central Coast...

Unlock Durability And Beauty With Burnt Timber Cladding Solutions

Imagine a home or commercial space that not only stands the test of time but also tells a story through its very facade. In the world of architectur...