The Times Australia
Fisher and Paykel Appliances
The Times World News

.

The Optus outage shows us the perils of having vital networks in private hands

  • Written by Helen Bird, DIscipline Leader, Corporate Governance & Senior Lecturer, Swinburne Law School, Swinburne University of Technology
The Optus outage shows us the perils of having vital networks in private hands

Optus chief executive Kelly Bayer Rosmarin is set to front a Senate inquiry[1] this week, probing last week’s colossal outage which left millions stranded without internet or mobile phone connectivity for a staggering 14 hours.

The company has faced severe criticism[2] for its handling of the outage, including for its lack of urgency in updating the public.

Loss of trust and confidence aside, if the national outage has taught us anything, it is there are real dangers in leaving the management of critical national infrastructure to a 100% privately owned company, in this case, a subsidiary of Singapore Telecommunications Limited, or Singtel[3] as it is better known.

As a private company, Optus has no legal obligations to report publicly on its financial statements or governance arrangements, unlike its competitor, Telstra Ltd. They don’t even have to report to government, despite holding a licence to be a carrier under federal legislation.

Image of one of the Singapore based telecommunications company Singtel's storefronts
Optus is Australia’s second largest communications carrier but is privately owned by Singtel. Tang Yan Song/Shutterstock[4]

Optus is the second largest supplier after Telstra of national carrier infrastructure in Australia. Its services are critical to the operation of our economy and community wellbeing. An illustration of this was the failure of the emergency 000 service during the outage. People with Optus couldn’t contact emergency services for up to 14 hours.

The obligations of listed companies

If Optus was a publicly listed company, like Telstra, it would have to comply with the listing rules[5] of the Australian Stock Exchange (ASX). This means it would have to disclose any information that could reasonably be expected to affect the price or value of the entity’s shares[6].

An unexplained system-wide outage of carrier services would arguably warrant this. If these rules applied to Optus, it would have had to issue regular market updates on developments during the outage. The odd, unannounced phone call by the Optus CEO[7] to a radio program would be unsatisfactory.

A quick review of the Optus website’s “About Us[8]” section suggests a number of apparent shortcomings. Contrary to the recommendations of the ASX corporate governance rules[9] not a single member of the Optus executive board of directors qualifies as an independent director, that is, a director with no apparent ties to the company.

The idea of the independent director is to help a company board break out of its group think. In a crisis, for example, this would mean asking hard questions of executive management. While ASX governance rules technically only apply to public companies, they are a role model for all corporates, including large proprietary companies like Optus.

No details of the company’s risk-management arrangements are given either, including the chief risk officer. This is extraordinary for a company whose recent history (cyber hack, system outage) shows its exposure to extremely high levels of risk.

Generic image of an Australian Stock Exchange screen Optus is the second largest communications carrier in the country but is not accountable to the federal government. Stephen Saphore/AAP[10]

There are also no details of who monitors the executive management of Optus. It is important to see this for what it is - Optus devolves its corporate governance responsibilities[11] to Singtel and runs a very lean operation in Australia.

This is seemingly good for Optus from a cost management viewpoint, but bad for Australia because we are leaving the governance of critical national infrastructure to a company with no direct accountability to the public and minimal accountability to the federal government.

Poorly prepared for a crisis

The absence of a comprehensive crisis management plan was obvious during last week’s outage. Despite experiencing a wide-scale cyber hack in 2022[12] Optus seemed ill-prepared to handle the system outage. You have to ask: why wasn’t a plan prepared well in advance of any such crisis?

Crisis management should entail a communication hierarchy and a systematic response. It is a key part of a company’s risk management system. This means knowing who needs to be notified and when to notify them. Presumably, high on that list would be the government. Instead, Bayer Rosmarin phoned radio programs revealing snippets of information in an ad-hoc way.

As part of crisis management, system fixes should be prioritised and companies obliged to tell the public the order in which these will be tackled. For example, the first fix should be health and hospital services. This did not happen. Instead, the absence of a clear plan only fuelled public anger.

Optus likes to control the narrative

Optus likes to tightly control its communication narrative. It refused to publicly release the Deloitte report on its 2022 cyber hack, until late last week[13] when it was ordered to make it available to litigants in a class action.

Similarly, the chief executive was reluctant to explain the current system outage, effectively asserting that there was no point until they had “bottomed out the root cause[14]” and could make it more digestible to the public.

Optus held all the power, yet when it did finally explain the failure days later, it was described as caused by a system upgrade and a failure of routers[15]. Hardly more digestible than the system failure we already knew it to be.

Head and shoulder image of woman with long light brown hair Optus chief Kelly Bayer Rosmarin. Supplied/AAP[16]

In an increasingly digitised world, technology failures and system outages have become a fact of life. ASX Ltd, the licensed operator of Australia’s equity market, experienced a bad one in 2022, known as the collapse[17] of the Clearing House Electronic Subregister System replacement project.

Knowing less than we would like

We know more about that failure than we will ever know about the Optus crisis because the ASX is a public company and was required to make continuous disclosure to the market.

In addition, ASX is also accountable for the management and governance of its critical infrastructure on an annual basis under licence arrangements overseen by the Reserve Bank and the Australian Securities and Investment Commission .

Like Optus, these failures have been the subject of hearings before parliament. However, there are no equivalent accountability requirements for Optus. Surely, the national telecommunications infrastructure managed by Optus is every bit as important as ASX’s clearing house infrastructure?

It is time to ask what accountability mechanisms should be in place for companies like Optus, whether they are enough and who watches over them. Where are the yearly assessments of that infrastructure by government agencies? The Senate inquiry[18], which was announced the day after the outage, will hopefully tackle these issues with the serious attention they deserve.

References

  1. ^ Senate inquiry (www.smh.com.au)
  2. ^ criticism (www.afr.com)
  3. ^ Singtel (en.wikipedia.org)
  4. ^ Tang Yan Song/Shutterstock (www.shutterstock.com)
  5. ^ listing rules (www.asx.com.au)
  6. ^ affect the price or value of the entity’s shares (www.asx.com.au)
  7. ^ phone call by the Optus CEO (www.9news.com.au)
  8. ^ About Us (www.optus.com.au)
  9. ^ ASX corporate governance rules (www.asx.com.au)
  10. ^ Stephen Saphore/AAP (photos.aap.com.au)
  11. ^ devolves its corporate governance responsibilities (www.optus.com.au)
  12. ^ wide-scale cyber hack in 2022 (www.afr.com)
  13. ^ until late last week (www.theguardian.com)
  14. ^ bottomed out the root cause (www.afr.com)
  15. ^ a system upgrade and a failure of routers (ia.acs.org.au)
  16. ^ Supplied/AAP (photos.aap.com.au)
  17. ^ collapse (www.afr.com)
  18. ^ Senate inquiry (www.aph.gov.au)

Read more https://theconversation.com/the-optus-outage-shows-us-the-perils-of-having-vital-networks-in-private-hands-217660

Times Magazine

Home batteries now four times the size as new installers enter the market

Australians are investing in larger home battery set ups than ever before with data showing the ...

Q&A with Freya Alexander – the young artist transforming co-working spaces into creative galleries

As the current Artist in Residence at Hub Australia, Freya Alexander is bringing colour and creativi...

This Christmas, Give the Navman Gift That Never Stops Giving – Safety

Protect your loved one’s drives with a Navman Dash Cam.  This Christmas don’t just give – prote...

Yoto now available in Kmart and The Memo, bringing screen-free storytelling to Australian families

Yoto, the kids’ audio platform inspiring creativity and imagination around the world, has launched i...

Kool Car Hire

Turn Your Four-Wheeled Showstopper into Profit (and Stardom) Have you ever found yourself stand...

EV ‘charging deserts’ in regional Australia are slowing the shift to clean transport

If you live in a big city, finding a charger for your electric vehicle (EV) isn’t hard. But driv...

The Times Features

Anthony Albanese Probably Won’t Lead Labor Into the Next Federal Election — So Who Will?

As Australia edges closer to the next federal election, a quiet but unmistakable shift is rippli...

Top doctors tip into AI medtech capital raise a second time as Aussie start up expands globally

Medow Health AI, an Australian start up developing AI native tools for specialist doctors to  auto...

Record-breaking prize home draw offers Aussies a shot at luxury living

With home ownership slipping out of reach for many Australians, a growing number are snapping up...

Andrew Hastie is one of the few Liberal figures who clearly wants to lead his party

He’s said so himself in a podcast appearance earlier this year, stressing that he has “a desire ...

5 Ways to Protect an Aircraft

Keeping aircraft safe from environmental damage and operational hazards isn't just good practice...

Are mental health issues genetic? New research identifies brain cells linked to depression

Scientists from McGill University and the Douglas Institute recently published new research find...

What do we know about climate change? How do we know it? And where are we headed?

The 2025 United Nations Climate Change Conference (sometimes referred to as COP30) is taking pla...

The Industry That Forgot About Women - Until Now

For years, women in trades have started their days pulling on uniforms made for someone else. Th...

Q&A with Freya Alexander – the young artist transforming co-working spaces into creative galleries

As the current Artist in Residence at Hub Australia, Freya Alexander is bringing colour and creativi...