The Times Australia
The Times World News

.

Australia needs a robust cybersecurity overhaul – not whack-a-mole bans on apps like TikTok

  • Written by Lyria Bennett Moses, Professor in the Faculty of Law and Justice at UNSW; Director of the UNSW Allens Hub for Technology, Law and Innovation, UNSW Sydney
Australia needs a robust cybersecurity overhaul – not whack-a-mole bans on apps like TikTok

Australia has joined other countries in announcing a ban[1] on the use of TikTok on government devices, with some states and territories following suit[2]. The rationale was based on security fears and, in particular, the risk the platform will be used for foreign interference operations by China.

TikTok[3] is a video-sharing platform operated by ByteDance[4], a company headquartered in Beijing, but incorporated in the Cayman Islands. Data is allegedly stored[5] in the US and Singapore.

Like similar sites, TikTok’s privacy policy[6] indicates an expansive approach to the collection and use of personal information. It can collect information from users and third parties (such as advertisers), and it can draw inferences about its users’ interests.

All of this information can then be shared with TikTok’s partners and service providers to, among other things, personalise content and advertising.

The policy also says information will be shared when there is a legal requirement to do so. China’s national intelligence law[7] obliges citizens and organisations to support, assist and cooperate with national intelligence efforts, which could include ByteDance sharing people’s TikTok data.

While TikTok denies it would hand over data[8] in such circumstances, there are reports that data from American users has been accessed[9] by China-based employees. TikTok has also censored[10] content that is politically sensitive in China.

The problem with focusing on only one app

While the Australian government’s response can be explained through this logic, questions remain.

Given the ban only affects government devices, couldn’t the same people be susceptible to foreign interference through their use of TikTok on personal devices[11]?

What about other apps, such as Facebook, that collect significant amounts of user data – are these more secure than TikTok? Even if other digital platforms don’t have connections with China, couldn’t they share or sell data to other entities, such as advertisers, data brokers or business partners? And mightn’t those third parties have connections with China? Or other countries with similar laws?

A final point: foreign interference can take place on a range of digital platforms. Russia has run[12] information campaigns designed to influence US elections using platforms[13] such as YouTube, Tumblr, Google, Instagram, PayPal, Facebook and Twitter.

In other words, the problem of digital security and foreign interference is bigger than just one app or the use of government devices.

Indeed, the Department of Home Affairs notes[14] that foreign interference activities are not only directed towards government, but also academia, industries, the media and other communities (which is actually everyone).

Banning TikTok on government devices does eliminate one risk, but the broader pool of risks remain both in government and beyond.

Read more: Why was TikTok banned on government devices? An expert on why the security concerns make sense[15]

A new, more effective cybersecurity strategy

The government is currently developing[16] a new cyber security strategy to replace the one put in place by the previous government[17] just three years ago.

A discussion paper[18] on the new strategy was released earlier this year, with submissions due this week.

This process will hopefully result in a more holistic strategy on how to manage the cybersecurity and foreign interference concerns that led to the TikTok ban.

Rather than the whack-a-mole tactical response of banning one app at a time, the strategy could provide clarity on how the government will manage issues around weak security on mobile apps (particularly used by people in sensitive sectors), as well as the potential for this to be an entry point for foreign interference.

This could include such things as:

  • educating people on digital security and foreign interference

  • streamlined reporting channels for data breaches, foreign interference attempts, cybercrime, bugs and vulnerabilities

  • developing or recommending the use of appropriate standards on cybersecurity, which could include references to international standards in areas such as information security and data governance

  • strengthening cooperation between government and platforms and civil society

  • targeted prohibitions, which may include bans on apps that could share data with countries that might then use it for foreign interference.

This kind of strategic approach, particularly on the education side, would give Australians better tools to arm themselves against foreign interference online, which as Home Affairs emphasises[19], is the “best defence” available.

A stronger privacy act could help, too

Another relevant policy development is the government’s review[20] of the Privacy Act[21], which is the primary Australian law on data protection.

Changing the rules about how data is collected and used by platforms could provide less fodder for those running foreign interference operations. This could include banning unfair uses, such as targeted messaging based on a psychological profile. If the platforms don’t facilitate these uses, it becomes more difficult for foreign governments to use these tools for manipulation.

Enhancing funding for the primary data regulator, the Office of the Australian Information Commissioner, could also strengthen enforcement across the board.

Read more: Proposed privacy reforms could help Australia play catch-up with other nations. But they fail to tackle targeted ads[22]

What is needed is a strategy, not tactics

These two reform initiatives exist within a maze of others, including inquiries or proposals relating to online privacy[23], digital platform services[24], the influence of international digital platforms[25], electronic surveillance[26], and digital economy regulation[27].

Beyond Australia, at the United Nations level, some questions about whether international law can be applied to cyberspace have been resolved[28], while others remain open[29]. Australia’s position on these issues could also be clarified.

Ultimately, what is needed is a strategy, rather than tactics, and better coordination of relevant policies across government. The TikTok example also highlights a truism that we shouldn’t think in terms of privacy or security, but rather privacy and security.

While there is an occasional need to choose between these two values (for example, when government agencies surveil those suspected of a crime, terrorism or espionage), in the vast majority of situations security is enhanced when the privacy of personal information is protected.

For example, the more personal information a foreign agent can access about citizens working in sensitive areas, the better it can target espionage and influence operations. If social media companies are restricted in how they collect, use and share Australians’ data, we can take significant steps towards protecting everyone from foreign interference and other harms.

We need all the policies and associated agencies (cyber, privacy, education, platform regulation, international relations, national security and more) working together if we are to meet the current challenges. It may make sense to ban TikTok on government devices, but we need to address this problem more than one app at a time.

References

  1. ^ announcing a ban (www.abc.net.au)
  2. ^ with some states and territories following suit (www.msn.com)
  3. ^ TikTok (www.tiktok.com)
  4. ^ ByteDance (www.bytedance.com)
  5. ^ stored (www.lifehacker.com.au)
  6. ^ privacy policy (www.tiktok.com)
  7. ^ national intelligence law (www.chinalawtranslate.com)
  8. ^ denies it would hand over data (www.politico.eu)
  9. ^ has been accessed (www.buzzfeednews.com)
  10. ^ censored (www.bbc.com)
  11. ^ their use of TikTok on personal devices (www.smh.com.au)
  12. ^ has run (www.reuters.com)
  13. ^ platforms (www.bbc.com)
  14. ^ notes (www.homeaffairs.gov.au)
  15. ^ Why was TikTok banned on government devices? An expert on why the security concerns make sense (theconversation.com)
  16. ^ developing (www.homeaffairs.gov.au)
  17. ^ one put in place by the previous government (www.homeaffairs.gov.au)
  18. ^ discussion paper (www.homeaffairs.gov.au)
  19. ^ Home Affairs emphasises (www.homeaffairs.gov.au)
  20. ^ review (www.ag.gov.au)
  21. ^ Privacy Act (www.legislation.gov.au)
  22. ^ Proposed privacy reforms could help Australia play catch-up with other nations. But they fail to tackle targeted ads (theconversation.com)
  23. ^ online privacy (consultations.ag.gov.au)
  24. ^ digital platform services (www.accc.gov.au)
  25. ^ the influence of international digital platforms (www.aph.gov.au)
  26. ^ electronic surveillance (www.ag.gov.au)
  27. ^ digital economy regulation (consult.industry.gov.au)
  28. ^ resolved (documents-dds-ny.un.org)
  29. ^ open (bpb-us-w2.wpmucdn.com)

Read more https://theconversation.com/australia-needs-a-robust-cybersecurity-overhaul-not-whack-a-mole-bans-on-apps-like-tiktok-203158

Times Magazine

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Decline of Hyper-Casual: How Mid-Core Mobile Games Took Over in 2025

In recent years, the mobile gaming landscape has undergone a significant transformation, with mid-core mobile games emerging as the dominant force in app stores by 2025. This shift is underpinned by changing user habits and evolving monetization tr...

Understanding ITIL 4 and PRINCE2 Project Management Synergy

Key Highlights ITIL 4 focuses on IT service management, emphasising continual improvement and value creation through modern digital transformation approaches. PRINCE2 project management supports systematic planning and execution of projects wit...

What AI Adoption Means for the Future of Workplace Risk Management

Image by freepik As industrial operations become more complex and fast-paced, the risks faced by workers and employers alike continue to grow. Traditional safety models—reliant on manual oversight, reactive investigations, and standardised checklist...

From Beach Bops to Alpine Anthems: Your Sonos Survival Guide for a Long Weekend Escape

Alright, fellow adventurers and relaxation enthusiasts! So, you've packed your bags, charged your devices, and mentally prepared for that glorious King's Birthday long weekend. But hold on, are you really ready? Because a true long weekend warrior kn...

Effective Commercial Pest Control Solutions for a Safer Workplace

Keeping a workplace clean, safe, and free from pests is essential for maintaining productivity, protecting employee health, and upholding a company's reputation. Pests pose health risks, can cause structural damage, and can lead to serious legal an...

The Times Features

Duke of Dural to Get Rooftop Bar as New Owners Invest in Venue Upgrade

The Duke of Dural, in Sydney’s north-west, is set for a major uplift under new ownership, following its acquisition by hospitality group Good Beer Company this week. Led by resp...

Prefab’s Second Life: Why Australia’s Backyard Boom Needs a Circular Makeover

The humble granny flat is being reimagined not just as a fix for housing shortages, but as a cornerstone of circular, factory-built architecture. But are our systems ready to s...

Melbourne’s Burglary Boom: Break-Ins Surge Nearly 25%

Victorian homeowners are being warned to act now, as rising break-ins and falling arrest rates paint a worrying picture for suburban safety. Melbourne residents are facing an ...

Exploring the Curriculum at a Modern Junior School in Melbourne

Key Highlights The curriculum at junior schools emphasises whole-person development, catering to children’s physical, emotional, and intellectual needs. It ensures early year...

Distressed by all the bad news? Here’s how to stay informed but still look after yourself

If you’re feeling like the news is particularly bad at the moment, you’re not alone. But many of us can’t look away – and don’t want to. Engaging with news can help us make ...

The Role of Your GP in Creating a Chronic Disease Management Plan That Works

Living with a long-term condition, whether that is diabetes, asthma, arthritis or heart disease, means making hundreds of small decisions every day. You plan your diet against m...