The Oceania Times

Top Menu

  • About us
  • Contact Us
  • Cookie Policy
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions

Main Menu

  • Australian Economy
  • Brokers
  • Commodities
  • Currencies
  • Financial Market
  • Gold and Precious Metals
  • Investment
  • Stock Shares
  • About us
  • Contact Us
  • Cookie Policy
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions

logo

The Oceania Times

  • Australian Economy
  • Brokers
  • Commodities
  • Currencies
  • Financial Market
  • Gold and Precious Metals
  • Investment
  • Stock Shares
  • NAPCO Security Technologies Announces Pricing of Secondary Public Offering of 2,100,000 Shares of Common Stock by Selling Stockholders

  • Australia to remove Chinese-made cameras from government sites

  • Vice President Kamala Harris to tout electric vehicle investment in St. Cloud visit

  • A.I.S. Resources’ Optionee C29 Metals Intercepts +30m Brine Aquifer At Pocitos 7 DDH1 Salta, Argentina

  • Boral Shares Surge, Brokers Remain Cautious

Australian Economy
Home›Australian Economy›Cybersecurity rulings important for all Australian businesses

Cybersecurity rulings important for all Australian businesses

By Megan
May 24, 2022
53
0
Share:

The world of cybersecurity is overflowing with principles. Principles about patching, passwords and people. Principles about physical security, phishing and firewalls. But until recently, there has been little legal precedent supporting these principles—and without such precedent, principles can be difficult to enforce.

However, the past month has served up two landmark cases that will help establish a new level of precedent for cybersecurity in Australia—one in the Federal Court and one in the ACT Civil and Administrative Tribunal. Both cases deserve utmost attention from senior management, boards and directors as our nation navigates a new era of cybersecurity uplift. These cases should not be dismissed as just technical ‘principles’.

After years of legal wrangling, on 5 May the Federal Court released its highly anticipated judgement into action brought by the Australian Securities and Investments Commission in 2020 against RI Advice Group. ASIC claimed RI Advice had inadequate cybersecurity controls in place, which the company failed to remedy despite being aware of the issues. This resulted in sensitive client information being compromised multiple times over a six-year period, a brute-force ransomware attack and one client losing $50,000.

It its judgement, the court found that RI Advice had contravened the Corporations Act ‘as a result of its failure to have documentation and controls in respect of cybersecurity and cyber resilience in place that were adequate to manage risk in respect of cybersecurity and cyber resilience’.

While the judgement’s level of detail was reasonably limited given a settlement had been reached, RI Advice was ordered to pay a contribution towards ASIC’s costs, totalling $750,000, and to undertake a comprehensive cybersecurity overhaul, to be monitored by the court, within a month of the judgement.

Importantly, in the judgement, Justice Helen Rofe highlighted the critical role of organisational cybersecurity, stating: ‘Cybersecurity risk forms a significant risk connected with the conduct of the business and provision of financial services. It is not possible to reduce cybersecurity risk to zero, but it is possible to materially reduce cybersecurity risk through adequate cybersecurity documentation and controls to an acceptable level.’

Ultimately, this judgement highlights that ASIC will be paying close attention to the cybersecurity practices of organisations that fall under its remit—and is prepared to take action. More broadly, it is a clear signal to all organisations right across the economy that the Corporations Act will be enforced as it relates to cybersecurity and it’s only a matter of time before more cybersecurity-related actions are brought before the courts.

The second case, a civil dispute between a vendor and a customer in the ACT Civil and Administrative Tribunal, is pertinent to all businesses, but small and medium-sized enterprises should pay careful attention. They are a prime target for cybercriminals and generally have lower cyber protections—the soft underbelly of Australia’s cybersecurity ecosystem.

The case involved a machine supply company (the applicant) and a diesel-fitting business (the respondent).  Their relationship began when the respondent sought to purchase a machine from the applicant. A deal was struck and bank details for the $5,499 purchase exchanged.

Unfortunately, the respondent’s emails had been compromised by a cybercriminal. Within hours the criminal sent a fake email informing the buyer that the bank account details had changed, with the funds to be deposited in a different account. By the time both parties realised what had happened, the money was long gone.

This type of crime, known as business email compromise, or BEC, is on the rise. According to the Australian Cyber Security Centre, Australians reported more than 4,600 BECs equating to $81 million in thefts in 2020–21.

In this case, the applicant brought the matter to the tribunal to recover the $5,499 owing. The respondent argued that payment had been made in good faith and therefore there was no case to answer, despite the money being stolen by a cybercriminal and the applicant never receiving the funds.

Ultimately, the tribunal ruled in favour of the applicant, finding that ‘responsibility for correct payment rests with the respondent and it was incumbent upon the respondent to exercise care in ensuring payment was made. The money was paid into an account that did not belong [to] the applicant and it remains unpaid.’

As Australia races towards an increasingly digitised economy and more businesses, large and small, house valuable data on internet-facing systems—which is a good thing—unfortunately cases like these may become more prevalent. But they don’t have to.

While there’s no perfect solution to the cybersecurity puzzle and no silver bullet to prevent cybercrime, there are steps all organisations can and should be taking to bolster their cyber defences. There are also a range of incentives that small businesses in particular can take advantage of, like the instant write-off for cyber uplift and training announced in this year’s federal budget.

And while principles are essential, there are three key concepts upon which all organisational approaches to cybersecurity should rest: risk, resilience and recovery.

Know what the key risks are and manage them appropriately in a way that uniquely suits your organisation. There is no one-size-fits-all approach. Cyber risk cannot be eliminated but can be effectively managed.

Build up cyber resilience to deal with identified risks, but also ensure that people are central to resilience. Make cybersecurity intrinsic to your organisation’s culture.

And finally there’s recovery, because when things do go wrong you need to have a plan. Organisations with a clear continuity plan can recover more quickly, potentially reduce the impacts of a cyber incident, and get back to business.

Source link

Previous Article

Why JPMorgan chief executive Jamie Dimon says ...

Next Article

Missouri’s education system sees large investment

0
Shares
  • 0
  • +
  • 0
  • 0
  • 0
  • 0

Megan

Related articles More from author

  • Australian Economy

    Riding Out the Storm: Seven Lessons

    July 15, 2022
    By Megan
  • Australian Economy

    Labor told to be bold in manufacturing rebuild

    June 7, 2022
    By Megan
  • Australian Economy

    KTR urges Australia to open CG office in city

    May 30, 2022
    By Megan
  • Australian Economy

    Australia finally has new climate laws. Now, let’s properly consider the astounding social cost of carbon

    September 8, 2022
    By Megan
  • Australian Economy

    Digital advertising contributes $94bn to Australia’s GDP according to PwC Supports over 450,000 jobs particularly in small and medium business

    November 22, 2022
    By Megan
  • Australian Economy

    India, Australia interim trade agreement comes into effect next week

    December 23, 2022
    By Megan

Leave a reply Cancel reply

You may interested

  • Investment

    Sticking with stocks? Younger 401(k) plan participants favor investment in equities

  • Stock Shares

    Hong Kong stocks jump 2% in mixed Asia session, Softbank shares drop 11%

  • Commodities

    Commodity Tracker: 5 charts to watch this week

  • LATEST REVIEWS

  • TOP REVIEWS

Timeline

  • February 9, 2023

    NAPCO Security Technologies Announces Pricing of Secondary Public Offering of 2,100,000 Shares of Common Stock by Selling Stockholders

  • February 9, 2023

    Australia to remove Chinese-made cameras from government sites

  • February 9, 2023

    Vice President Kamala Harris to tout electric vehicle investment in St. Cloud visit

  • February 9, 2023

    A.I.S. Resources’ Optionee C29 Metals Intercepts +30m Brine Aquifer At Pocitos 7 DDH1 Salta, Argentina

  • February 9, 2023

    Boral Shares Surge, Brokers Remain Cautious

Best Reviews

Latest News

Stock Shares

NAPCO Security Technologies Announces Pricing of Secondary Public Offering of 2,100,000 Shares of Common Stock ...

AMITYVILLE, N.Y., Feb. 8, 2023 /PRNewswire/ — NAPCO Security Technologies, Inc. (NASDAQ: NSSC), one of the leading manufacturers and designers of high-tech electronic security devices, wireless recurring communication services for ...
  • Australia to remove Chinese-made cameras from government sites

    By Megan
    February 9, 2023
  • Vice President Kamala Harris to tout electric vehicle investment in St. Cloud visit

    By Megan
    February 9, 2023
  • A.I.S. Resources’ Optionee C29 Metals Intercepts +30m Brine Aquifer At Pocitos 7 DDH1 Salta, Argentina

    By Megan
    February 9, 2023
  • Boral Shares Surge, Brokers Remain Cautious

    By Megan
    February 9, 2023
  • Recent

  • Popular

  • Comments

  • NAPCO Security Technologies Announces Pricing of Secondary Public Offering of 2,100,000 Shares of Common Stock ...

    By Megan
    February 9, 2023
  • Australia to remove Chinese-made cameras from government sites

    By Megan
    February 9, 2023
  • Vice President Kamala Harris to tout electric vehicle investment in St. Cloud visit

    By Megan
    February 9, 2023
  • A.I.S. Resources’ Optionee C29 Metals Intercepts +30m Brine Aquifer At Pocitos 7 DDH1 Salta, Argentina

    By Megan
    February 9, 2023
  • NAPCO Security Technologies Announces Pricing of Secondary Public Offering of 2,100,000 Shares of Common Stock ...

    By Megan
    February 9, 2023
  • Australia’s economy: boom or bust?

    By Megan
    September 9, 2019
  • Australian economy suffers virus symptoms

    By Megan
    February 10, 2020
  • Australian economy likely already slowing in Q2 before Delta downturn

    By Megan
    August 30, 2021

Trending News

  • Stock Shares

    NAPCO Security Technologies Announces Pricing of Secondary Public Offering of 2,100,000 Shares of Common Stock ...

    AMITYVILLE, N.Y., Feb. 8, 2023 /PRNewswire/ — NAPCO Security Technologies, Inc. (NASDAQ: NSSC), one of the leading manufacturers and designers of high-tech electronic security devices, wireless recurring communication services for ...
  • Australian Economy

    Australia to remove Chinese-made cameras from government sites

    The US banned the importation of surveillance equipment made by Hikvision, seen here, and Dahua in November because it posed a ‘risk’ to national security. Photo: FRED DUFOUR / AFPSource: ...
  • Investment

    Vice President Kamala Harris to tout electric vehicle investment in St. Cloud visit

    ST. CLOUD — Vice President Kamala Harris will visit bus manufacturer New Flyer in St. Cloud on Thursday as part of a Biden administration blitz following Tuesday’s State of the ...
  • Gold and Precious Metals

    A.I.S. Resources’ Optionee C29 Metals Intercepts +30m Brine Aquifer At Pocitos 7 DDH1 Salta, Argentina

    A.I.S. Resources Limited (TSX.V: AIS, OTCQB: AISSF) (the “Company” or “AIS”) announces C29 Metals Limited (“C29”, ASX:C29) has intercepted a +30 m brine acquifer at Hole DDH1 on the Pocitos ...
  • Brokers

    Boral Shares Surge, Brokers Remain Cautious

    This story features BORAL LIMITED. For more info SHARE ANALYSIS: BLD Despite consensus-beating earnings in the first half, brokers remain wary around pricing and costs for Boral. -First half earnings ...
  • About us
  • Contact Us
  • Cookie Policy
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© Copyright The Oceania Times. All rights reserved.

SUBSCRIBE TO OUR NEWSLETTER

Get our latest downloads and information first. Complete the form below to subscribe to our weekly newsletter.