The Times Australia
The Times World News

.
The Times Real Estate

.

An expert reviews the government’s 7-year plan to boost Australia’s cyber security. Here are the key takeaways

  • Written by David Tuffley, Senior Lecturer in Applied Ethics & CyberSecurity, Griffith University

After lengthy deliberation, the Australian government has released its 2023–2030 Cyber Security Strategy[1], which aims to make Australia one of the most cyber-secure nations in the world by 2030. It’s a worthy goal, considering Australia was ranked as the fifth-most powerful cyber nation in a 2022 report[2] by Harvard University’s Kennedy School.

The strategy outlines a range of ways Australia can protect its people, businesses and organisations into the next decade. Importantly, it has come at a time when the country is reeling from a series of major cyber incidents, including the Medibank[3] and Optus[4] data breaches last year, a nationwide Optus blackout earlier this month, and the more recent closure of ports[5] across the country due to a cyber breach.

Key takeaways

Among other things, the strategy aims to:

  • protect critical infrastructure
  • provide businesses and organisations with tools to bolster their cyber resilience, especially against ransomware attacks
  • ensure businesses secure products and services to protect customers
  • attract skilled migrants to establish a diverse cyber security workforce
  • prioritise critical threats from the most sophisticated actors
  • engage international partners to share threat intelligence and develop new capabilities
  • expand cyber awareness programs to educate the public.

The government has dedicated $586.9 million to achieving these goals, on top of $2.3 billion committed to existing cyber initiatives, including the REDSPICE program[6] aimed at enhancing the intelligence and cyber capabilities of the Australian Signals Directorate.

Read more: Budget 2022: $9.9 billion towards cyber security aims to make Australia a key 'offensive' cyber player[7]

The most significant investment of $290.8 million will go towards protecting businesses and citizens. A further $143.6 million will be invested in strengthening critical infrastructure, including major telecommunications infrastructure.

By comparison, $9.4 million will be used to build a cyber threat sharing platform for the health sector, and only $4.8 million will go to establishing consumer standards for smart devices and software.

The strategy will also expand the Digital ID program[8], to “reduce the need for people to share sensitive personal information with the government and businesses to access services online” – but details on this were scant.

Plans to ‘break the ransomware business model’

The strategy notes ransomware is “one of the most disruptive cyber threats” in the world – and costs Australia’s economy up to $3 billion in damages each year. The government will make a “ransomware playbook” to help businesses respond to and bounce back from cyber extortion.

It will also work with industry to co-design a mandatory no-fault ransomware reporting scheme to encouraging reporting on ransom incidents. We know, based on past experiences with the Notifiable Data Breaches[9] scheme, that businesses sometimes won’t report[10] breaches for fear of public backlash. A no-liability reporting scheme could change this, and provide important data that will further bolster our defences against ransom attacks.

The strategy also “strongly discourages” making ransom payments. This makes sense, as these payments inevitably fuel the ransomware economy and fund criminals’ future attacks.

Controversially, however, Minister for Cyber Security Clare O’Neil has considered introducing a blanket ban on such payments at some time in the next few years[11].

This could have negative impacts. For instance, a business that legally can’t pay a ransom may not be able to recover stolen data, resulting in permanent data and financial loss. Attackers may also release the stolen data online out of spite. We saw this happen after last year’s Optus data breach[12].

There’s also a risk that announcing an impending ban could make Australia more attractive to criminals in the short term, as they may scramble to carry out as many attacks as possible before payments are made illegal. The impact of this would be lessened if businesses adopt a disciplined approach to regular data backups.

Smart devices and apps

Another strategic initiative will involve working with industry to establish a mandatory cyber security standard (in line with international standards) for consumer-grade smart devices sold in Australia.

The government will also introduce a voluntary cyber security labelling scheme for smart devices. Ideally, such a scheme would keep the public informed about the level of security on the many different devices they own. However, given it’s voluntary, it’s hard to say whether it will have a substantial impact.

Another voluntary code of practice will be introduced for app stores and app developers.

What are the challenges?

If it’s implemented well, the strategy could result in a substantial decrease in cyber crime, greater safety for the public and a thriving cyber sector.

Currently, businesses and individuals struggle with a lack of cyber awareness and skills. They don’t have the resources, nor the incentive, to invest in cyber security. This strategy could change that.

The greatest challenge is the complexity and diversity of cyber threats, which are constantly evolving. Today’s threats may not have crossed anyone’s mind a few year ago. This inherent unpredictability may render some of the assumptions in the strategy redundant in the coming years.

Then there are inevitable trade-offs that come with competing values such as privacy, security, innovation and regulation. For example, a project that strongly maintains the privacy of consumers may end up sacrificing transparency. Similarly, too much transparency can lead to security risks.

We’ll need to innovate in the cyber security domain to stay ahead of criminals. But as we’ve seen in other areas of the tech sector, innovation that outruns regulation is often more harmful than helpful. Striking the balance is difficult.

Read more: OpenAI’s board is facing backlash for firing CEO Sam Altman – but it’s good it had the power to[13]

Moreover, there’s a noticeable lack of detail in many of the initiatives outlined in the strategy. This could make it difficult to measure its progress and impact as a high-level strategic document.

Success will depend on voluntary action and cooperation from stakeholders, which may not be enough to ensure compliance and accountability from some businesses and individuals.

Any shortcomings could be managed by making the strategy inclusive and consultative. If it caters to the needs of all, it may indeed become a successful seven-year plan.

References

  1. ^ 2023–2030 Cyber Security Strategy (www.homeaffairs.gov.au)
  2. ^ 2022 report (www.belfercenter.org)
  3. ^ Medibank (theconversation.com)
  4. ^ Optus (theconversation.com)
  5. ^ closure of ports (theconversation.com)
  6. ^ REDSPICE program (www.asd.gov.au)
  7. ^ Budget 2022: $9.9 billion towards cyber security aims to make Australia a key 'offensive' cyber player (theconversation.com)
  8. ^ Digital ID program (theconversation.com)
  9. ^ Notifiable Data Breaches (www.oaic.gov.au)
  10. ^ sometimes won’t report (www.oaic.gov.au)
  11. ^ in the next few years (australiancybersecuritymagazine.com.au)
  12. ^ Optus data breach (theconversation.com)
  13. ^ OpenAI’s board is facing backlash for firing CEO Sam Altman – but it’s good it had the power to (theconversation.com)

Read more https://theconversation.com/an-expert-reviews-the-governments-7-year-plan-to-boost-australias-cyber-security-here-are-the-key-takeaways-218117

The Times Features

Exclusive Murray River experiences with the PS Murray Princess

SeaLink South Australia is delighted to unveil two brand-new, limited-time cruise experiences aboard the award-winning PS Murray Princess, offering guests an extraordinary oppo...

Carrie Bickmore and Guy Sebastian’s Christmas house swap ends in a hilarious prank

Carrie Bickmore and Guy Sebastian took their celebrity friendship to the next level over summer – by swapping houses. The pair revealed on The Hit Network’s Carrie & Tommy...

Welt Schatz.com Offers Premium Membership To Elevate Users' Status

London, United Kingdom - Welt Schatz.com is a financial services firm that operates across digital platforms, focusing on expanding user benefits through practical tools and acce...

How to buy a coffee machine

For coffee lovers, having a home coffee machine can transform your daily routine, allowing you to enjoy café-quality drinks without leaving your kitchen. But with so many optio...

In the Digital Age, Online Promotion Isn't Just an Option for Small Businesses – It's a Necessity

The shift to an online-first consumer landscape means small businesses must embrace digital promotion to not only survive but thrive in 2025. From expanding reach to fostering cu...

Sorbet Balls by bubbleme Bring Bite-Sized Cool Spin to Frozen Snacking

A cool new frozen treat is rolling into the ice-cream aisle at Woolworths stores nationwide. Dairy-free, gluten-free and free from artificial colours, bubbleme Sorbet Balls ar...

Times Magazine

Senior of the Year Nominations Open

The Allan Labor Government is encouraging all Victorians to recognise the valuable contributions of older members of our community by nominating them for the 2025 Victorian Senior of the Year Awards.  Minister for Ageing Ingrid Stitt today annou...

CNC Machining Meets Stage Design - Black Swan State Theatre Company & Tommotek

When artistry meets precision engineering, incredible things happen. That’s exactly what unfolded when Tommotek worked alongside the Black Swan State Theatre Company on several of their innovative stage productions. With tight deadlines and intrica...

Uniden Baby Video Monitor Review

Uniden has released another award-winning product as part of their ‘Baby Watch’ series. The BW4501 Baby Monitor is an easy to use camera for keeping eyes and ears on your little one. The camera is easy to set up and can be mounted to the wall or a...

Top Benefits of Hiring Commercial Electricians for Your Business

When it comes to business success, there are no two ways about it: qualified professionals are critical. While many specialists are needed, commercial electricians are among the most important to have on hand. They are directly involved in upholdin...

The Essential Guide to Transforming Office Spaces for Maximum Efficiency

Why Office Fitouts MatterA well-designed office can make all the difference in productivity, employee satisfaction, and client impressions. Businesses of all sizes are investing in updated office spaces to create environments that foster collaborat...

The A/B Testing Revolution: How AI Optimized Landing Pages Without Human Input

A/B testing was always integral to the web-based marketing world. Was there a button that converted better? Marketing could pit one against the other and see which option worked better. This was always through human observation, and over time, as d...

LayBy Shopping