Beyond IT Security: The Evolving Obligations of Australian Organisations for Cyber Resiliency

Report Author

Claus Mortensen

Principal Analyst, Ecosystm


Introduction

The surge in digital business transformation over the last few years has propelled the adoption of cloud services, mobile applications, and remote data access. There has also been a significant increase in the use of web and mobile applications for employees and customers alike. Large volumes of data are now being made available across potentially vulnerable attack surfaces and at the same time, cyber adversaries are getting increasingly sophisticated as they start using AI tools to attack organisations worldwide.

58% of technology leaders in Australia feel that a data breach is inevitable within the next year.
Ecosystm Cyber Security Study, 2024

The threat landscape has materially changed, requiring new approaches to cyber security that help organisations detect threats early, reduce the impact of an attack, and minimise risk and damage to the business.

Cyber security has become a key topic of discussion at the board level, raising equal concerns among business and technology leaders. CEOs and business leaders now require a comprehensive understanding of the compliance landscape and the ramifications of incidents and breaches, while technology leaders tasked with implementing transformative technologies must grasp their impact on the threat landscape. Meanwhile, cyber leaders face the challenge of adopting effective technologies to proactively combat threats. A comprehensive cyber strategy should consider the impact on people management, compliance and risk practices, as well as technology investments.

This whitepaper explores the implications of Australia's evolving cyber security landscape for key stakeholders, including boards, company directors, business leaders, and technology leaders.


Current Threats and Future Trends

In recent years, organisations have had to find new ways to engage and connect with customers and employees. Cyber security was not always the main consideration as organisations scrambled to cope with rapidly changing market demands. The resulting increase in attack surfaces continues to grow – especially as employees access company networks and data from multiple locations and devices.

The primary cyber challenges faced by organisations vary greatly based on their size. Large organisations are often preoccupied with compliance and risk management, while smaller entities tend to struggle more with technological and people-related issues (Figure 1).

While challenges might be different, what is universal is that crafting a robust cyber security strategy requires a comprehensive plan. This plan should outline the organisation's approach to identifying, managing, and mitigating cyber security risks.

Figure 1: Cyber Challenges in Australia Differ Based on Organisational Size

  • Finding, assessing, and deploying security technologies
  • Having enough or qualified, trained security staff
  • Managing third party risk

Mid-market Organisations

  • Low cyber security awareness among staff and other stakeholders

N=204 (Australia)
Source: Ecosystm Cyber Security Study, 2024

While many organisations claim to have a cyber security strategy, they often limit themselves to compartmentalised tactical plans addressing specific breach scenarios rather than a holistic strategy spanning the entire organisation.

Key Areas of Focus for a Robust Cyber Strategy

  1. People and Stakeholder Involvement
  2. Incident Response Planning
  3. Risk-Based Vulnerability Management

1 Compliance Management

Cyber security regulations and compliance requirements play a vital role in protecting sensitive data and managing cyber risks. In Australia, these regulations evolve continually, often in response to high-profile breaches. Adhering to specific laws is crucial for organisations to maintain the integrity and security of their digital assets. With an anticipated increase in regulatory scrutiny due to continued cyber security breaches, organisations should as a minimum follow both general and industry-specific guidelines.

The Australian Privacy Principles (APP) provide the guidance on Australia’s cyber compliance and require organisations to take reasonable steps to protect information from misuse, interference, loss, unauthorised access, modification, or disclosure. Additionally, under the Notifiable Data Breaches (NDB) scheme, any organisation covered by the Privacy Act must inform affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is expected to cause serious harm to an individual whose personal information is involved. To complicate the compliance landscape, additional sector-specific regulations apply – particularly within financial services, critical infrastructure, the public sector, and health services. Although not all are mandatory, they are commonly seen as best practices.

Key Steps to Compliance Management

  1. Understand and adhere to Australian regulatory requirements (Privacy Act, ACSC, ISO/ISMS, NDB, ASD, Industry-specific regulations, and standards)
  2. Develop a robust risk management framework
  3. Establish clear cyber security policies and procedures
  4. Perform a gap analysis on the alignment of cyber policies and measures
  5. Implement strong access controls and data protection measures
  6. Formulate an incident response plan involving all stakeholders
  7. Conduct training and awareness sessions for all employees
  8. Assess and audit compliance regularly with a focus on continuous improvement

The Essential 8 Framework and its significance in bolstering security posture

Compliance management involves a series of steps and considerations to ensure an organisation's adherence to laws, regulations, standards, and best practices. In Australia, organisations often follow the Essential 8 cyber security guidelines, established by the Australian Cyber Security Centre (ACSC), which outline fundamental measures to enhance cyber resilience.

Strategies to Prevent Attacks:

  • Application control and whitelisting
  • Application patching
  • Microsoft Office macro management
  • Multi-factor authentication

Strategies to Compartmentalise or Limit Attacks:

  • User application hardening
  • Restricting administrative privileges
  • Patching operating systems

Strategies to Recover from Attacks:

  • Regular backups

It is a good resource for organisations that want a simple checklist approach to cyber security.


2 People and Stakeholder Involvement

Organisations face significant challenges concerning their people. This includes the need for an executive team that prioritises robust cyber strategies; finding and retaining the right cyber talent to navigate the diverse and evolving threat landscape; and driving awareness on cyber threats, measures, and responsibilities among all employees.

Executive Accountability

75% of technology leaders in Australia feel that senior leadership has an inadequate understanding of cyber risk and governance.
Ecosystm Cyber Security Study, 2024

Senior leadership and the board have a pivotal role in the oversight of cyber strategies, risk management, and reporting obligations. As stewards of corporate governance, they are responsible for setting the tone for the organisation's cyber culture and ensuring that cyber security is integrated into overall business strategies.

Key Steps to People and Stakeholder Empowerment

  • Organisation-wide Cyber Culture
  • Enhanced Situational Awareness
  • Improved Incident Response

Despite the challenges, fostering a culture of cyber awareness and responsibility is essential for effective cyber security management.


3 Incident Response Planning

27% of Australian organisations state that inadequate incident response plans are a major cyber security concern.
Ecosystm Cyber Security Study, 2024

Clear security policies and enforcement are essential to ensure employees understand their roles within the broader security framework. Inadequate incident response can lead to significant repercussions, necessitating comprehensive plans that outline roles, responsibilities, and engagement with stakeholders.

Key Considerations of a Robust Incident Response Plan

  1. Business Continuity and Disaster Recovery
  2. Stakeholder Management
  3. Breach Response
  4. Regulator Response
  5. Decision Guidance
  6. Training and Simulation
  7. Third-party Provider Management

4 Risk-Based Vulnerability Management

The annual count of tracked vulnerabilities continues to reach new highs, presenting a daunting challenge for cyber leaders. Vulnerability management requires conducting assessments to identify issues and devising strategies for mitigation. Integrating a risk-based approach with automation allows organisations to effectively identify, prioritise, and mitigate security vulnerabilities.

Key Steps in Risk-Based Vulnerability Management

  1. Identifying Risks
  2. Assigning Ownership
  3. Prioritising Risks
  4. Addressing Risks
  5. Reporting and Monitoring

Involving stakeholders from across the organisation in defining and evaluating risks is essential for developing an effective cyber security strategy.


Conclusion

As technology integrates into essential business functions, the traditional cyber security approach is no longer adequate. A robust cyber security approach requires a comprehensive understanding of how security breaches may affect the organisation and involves upholding regulatory compliance as a baseline rather than an endpoint.

Organisations should continuously assess their cyber strategies, leveraging automation and engaging stakeholders to maintain a vigilant and adaptable security posture.