Read The Times Australia

Daily Bulletin

The Australian government must take cyber security more seriously

  • Written by: The Conversation Contributor
image

Most of us can relate to the government’s plan to build 12 new submarines for A$50 billion, at least in principle. But you might be alarmed to hear the government is investing only a fraction of that amount on protecting us from cyberattacks.

Our research suggests that now may be the time to think more deeply about having fewer submarines so that we can afford to pay for the cyber defence of the civil sector.

This is because we are not spending anywhere near as much as our allies on cyber defence, especially in the civil sector.

In April 2016, having declared cyberattacks to be a national emergency, US President Barack Obama announced a spending plan of A$26 billion in one year for urgent remedial policies largely to protect the non-defence sector.

In December 2015, describing the cyber threat as “one of the great challenges of our lifetime”, the UK Chancellor George Osborne announced a broadly similar remedial plan to spend almost A$800 million per year over five years.

By comparison, the latest federal budget allocated around A$100 million for one year based on its new Cyber Security Strategy released a month earlier. Yet the threats these three countries face are not different by the orders of magnitude suggested by budget comparisons.

In 2015, the Australian government said that the country had never suffered a cyberattack seriously compromising national security, stability or prosperity.

Obama said at the same time that cyberattacks posed an “extraordinary threat to the national security, foreign policy and economy of the United States”. He repeated this in March 2016 when extending the national emergency declaration for another year.

Security gap

There are two important areas where Australia is doing less than our allies, and less than we need to: protecting critical cyber infrastructure; and fighting cybercrime.

Both these areas of cyber policy have separate strategy documents. And there are no strong linkages between them and with the April 2016 Cyber Security Strategy action plan.

In 2015, the government issued two documents on critical infrastructure, a Policy Statement and a Plan, one of which has a single page on cyberattack.

But these documents use anodyne statements, such as ensuring the continuity of “service delivery”, rather than using the concept of an extreme cyber emergency that underpins planning assumptions, exercises, research and operational preparation of the US and the UK.

In terms of research, the Idaho National Laboratory and others like it conduct research on national resilience in the face of “catastrophic and potentially cascading events that will likely require substantial time to assess, respond to, and recover from.”

In the UK, the responsible agency “supports three exercises per month to test cyber resilience and response”. The US and UK work together to prepare for a terrorist cyber-enabled attack on nuclear power stations.

In his preface to the Cyber Security Strategy, Prime Minister Malcolm Turnbull said Australia needed to prepare for a “significant cyber event”, with an unspecified scale of effect.

This exemplifies the laid-back tone of most Australian policy documents on this subject.

In strong contrast, in May 2016, ASIO offered a rather gloomy assessment:

The gap is likely widening between the scale and scope of harm experienced to Australia’s sovereignty, government systems, and commercial and intellectual property, and the ability of ASIO and partner agencies to successfully mitigate that harm.

Getting serious

On cybercrime, the gap between need and and policy is even more starkly visible.

In the Cyber Security Strategy, the government did not see cybercrime as an important focus. It did say that the country doesn’t have a good handle on how much such crime was costing the economy, citing one estimate of A$1 billion and another of A$17 billion.

While collection of data on the cost of cybercrime is notoriously difficult, the wide range for this “estimate” is strong evidence of how low a priority this area of policy has been.

The Cyber Security Strategy does make a commitment to develop and implement a training plan for specialists in the field of countering cybercrime, with no further detail.

It also commits in the broadest terms to increasing the capacity of the AFP and the Australian Crime Commission (ACC) to counter cybercrime. Forward estimates for the latest budget revealed a commitment of almost A$15 million over four years to the ACC to support stronger capability to combat cybercrime.

But in this area, the cyber strategy basically passed the buck. It suggested that the main source of policy was the National Plan to Combat Cyber Crime released in 2013 by the previous government.

This is not much consolation, as that document lacks detail and certainly does not reveal a commitment of funding on a level likely to contain or reduce a cost to the economy estimated in the billions of dollars.

The government needs a more open and candid conversation in public with key stakeholders about the sort of threat scenarios we face, but especially for cybercrime and “significant cyber attack”. It also needs to develop policies and agencies, funded appropriately, that can begin to perform on a level that matches the threats.

Authors: The Conversation Contributor

Read more http://theconversation.com/the-australian-government-must-take-cyber-security-more-seriously-60231

Business News

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

Options Available When a Company Faces Financial Distress

Financial distress can develop gradually or arrive suddenly, and when it does, the decisions made in the early stages often determine what options remain available later. Directors who act promptly ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...

Australia’s Best Walking Trails and the Shoes You Need to Tackle Them

Australia is not short on spectacular walks. You can follow ocean cliffs in Victoria, cross ancien...

Why Pre-Purchase Building Inspections Are Essential Before Buying a Home in Australia

source Have you ever walked through an open home and started picturing your furniture, family d...